What is cryptology?
The general field including cryptography and cryptanalysis.
What does cryptography secure communication against?
An adversary.
What does cryptanalysis study?
How to break cryptosystems.
What key types do symmetric algorithms use?
One shared secret key for encryption and decryption.
What key types do asymmetric algorithms use?
A private key and a public key.
What do cryptographic protocols use as building blocks?
Cryptographic algorithms.
In a symmetric cryptosystem, how does Bob recover plaintext?
By decrypting ciphertext with the same key used for encryption.
What is plaintext?
The original readable message before encryption.
What distinguishes a brute-force attack from an analytical attack?
A brute-force attack tests all keys treating the cipher as a black box, while an analytical attack exploits the cipher's internal structure.
How does a brute-force attack verify each key?
By decrypting ciphertext and checking if it matches known plaintext.
What is the size of the substitution cipher's key space?
The substitution cipher's key space is 26! (factorial).
Approximately how many possible keys does the substitution cipher have?
About 2^88 possible keys.
What methods does letter-frequency analysis use to break substitution ciphers?
It examines single-letter frequencies, repeated symbol groups, and frequent short words with separators.
What does Kerckhoffs’ Principle state about cryptosystem security?
A cryptosystem should remain secure even if all system details except the secret key are known.
Who formulated Kerckhoffs’ Principle and when?
Auguste Kerckhoffs in 1883.
What are the recommended symmetric key lengths for long-term security with quantum resistance?
256 bits for several decades even with known quantum algorithms.
When does the relation a ≡ r mod m hold for integers a, r, m?
When m divides a minus r.
How can every integer a be expressed using integers q, m, and r?
As a = q·m + r with 0 ≤ r < m.
What is the integer ring Z_m?
The set {0, 1, ..., m − 1} with addition and multiplication modulo m.
When does an element a in Z_m have a multiplicative inverse?
If and only if gcd(a, m) = 1.
What is the encryption formula of the shift cipher in Z_26?
e_k(x) ≡ x + k mod 26.
What is the decryption formula of the affine cipher in Z_26?
x ≡ a⁻¹ · (y − b) mod 26.
What condition must a satisfy in the affine cipher for decryption?
gcd(a, 26) = 1.
Why does the affine cipher have 312 possible keys?
Because it has 12 valid a values and 26 b values.
How does the affine cipher encrypt a value x?
By computing with key k=(a,b).
What condition must the multiplier a satisfy in the affine cipher?
must hold for a.
Which values are valid multipliers a modulo 26 in the affine cipher?
1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, and 25.
How do you find the multiplicative inverse of a modulo 26?
Test values until .
What is the multiplicative inverse of 3 modulo 26 in the affine cipher?
The inverse of 3 is 9.
What is the size of the key space for the affine cipher?
The key space has 312 keys.
Why is the affine cipher vulnerable to exhaustive search?
Because its key space is small and letter mapping is fixed.
What ciphertext results from encrypting ATTACK with key (9,13)?
The ciphertext is nccnfz.
What do cryptography, IT security, and cybersecurity protect against?
Malicious human actors.
What are the traditional basic security goals known as the CIA triad?
Confidentiality, integrity, and availability.
What is the first step in a systematic IT-security approach?
Defining assets and security needs.
What does Kerckhoffs’ Principle state about cryptographic system design?
It should not require secrecy and compromising it should not inconvenience correspondents.
What does provable security require besides an algorithmic description?
A precise security model and a mathematical proof under a hardness assumption.
Who proposed the first fully homomorphic encryption scheme and when?
Gentry in 2009.
What does multiparty computation allow parties to do?
Jointly compute a function while learning only their own input and the result.
What is the minimum number of participants needed to reconstruct a secret in general secret sharing?
At least t of n participants.
How do stream ciphers encrypt plaintext bits?
By combining each plaintext bit with a key-stream bit.
What does the key stream depend on in a synchronous stream cipher?
Only on the key.
What does the key stream depend on in an asynchronous stream cipher?
On both the key and the ciphertext.
What is the formula for stream-cipher encryption in modulo-2 addition?
What operation is equivalent to modulo-2 addition?
The exclusive-OR (XOR) operation.
What ASCII value results from encrypting uppercase A (1000001) with key-stream 0101100?
1101101, the ASCII value of lowercase m.
What is a key property of outputs from true random number generators?
They cannot be reproduced.
What is the chance of exactly reproducing a 100-coin-flip sequence?
.
What distinguishes true random from pseudorandom number generators?
True random generators produce non-reproducible outputs from physical processes, pseudorandom generators compute deterministic sequences from a seed.
How does a general pseudorandom number generator produce its sequence?
It generates recursively with and .
What formula defines a linear congruential generator?
It uses to generate sequences.
What makes a pseudorandom number generator cryptographically secure?
Computing subsequent or preceding bits from output bits is computationally infeasible.
What does unconditional security mean in cryptography?
A cryptosystem cannot be broken even with infinite computational resources.
What defines a one-time pad key stream?
It is generated by a true random number generator, known only to legitimate parties, and each bit is used once.
Why must a one-time pad key be as long as the plaintext?
Because it requires one true-random key bit for every plaintext bit and key material cannot be reused.
How do practical stream ciphers differ from one-time pads?
They use deterministic pseudorandom key streams from short keys aiming for computational security, not unconditional security.
What defines the degree of a linear feedback shift register?
The number of flip-flops in the register.
What is the input of a linear feedback shift register?
The XOR-sum of selected register bits.
What recurrence relation does an LFSR output sequence satisfy?
for feedback coefficients .
Why is the maximum sequence length of an LFSR ?
Because the all-zero state is excluded and would remain stuck forever.
What is the period of an LFSR with degree 4 and coefficients $(0,0,1,1)$?
15
What period results from coefficients $(1,1,1,1)$ in a degree-4 LFSR?
5
What is the first step in a known-plaintext attack on a degree- LFSR?
Reconstruct the key stream from plaintext and ciphertext.
How are feedback coefficients recovered in a known-plaintext attack on an LFSR?
By forming linear equations and solving them using Gaussian elimination or matrix inversion.
Who developed the Salsa20 stream cipher and when?
Daniel J. Bernstein developed Salsa20 in 2005.
How many rounds does Salsa20/20 use?
Salsa20/20 uses 20 rounds.
What operation do Salsa20 and ChaCha20 use to encrypt and decrypt data?
They XOR the key stream with plaintext or ciphertext.
Why must a nonce change for every encryption session?
To avoid reusing the same key stream under the same key.
What size are the key-stream blocks generated by Salsa20 and ChaCha20?
They generate 512-bit key-stream blocks.
Who designed the Trivium stream cipher and what key size does it use?
Christophe De Cannière and Bart Preneel designed Trivium using an 80-bit key.
What are the lengths of Trivium's three shift registers?
They are 93, 84, and 111 bits long.
During Trivium initialization, how many times is the cipher clocked without output?
It is clocked 1152 times without producing output.
What are the lengths of Trivium's three nonlinear registers?
93, 84, and 111 bits.
What is the formula for updating register A in Trivium?
.
What is the formula for updating register B in Trivium?
.
What is the formula for updating register C in Trivium?
.
How does Trivium produce its keystream bit?
.
How is Trivium initialized with key and IV?
Load 80-bit key into register A, 80-bit IV into B, others zero, and set three rightmost bits of C to one.
How many clock cycles does Trivium's warm-up phase last?
1152 clock cycles, four times the total register length of 288 bits.
When does Trivium start producing output bits?
At cycle 1153, after the warm-up phase.
How many gate equivalents does a hardware Trivium implementation occupy?
Approximately 3500 to 5500 gate equivalents.
What encryption rate does a 16-bit-per-cycle Trivium achieve at 500 MHz?
8 Gbit/s.
What is the minimum known attack complexity on full Trivium?
At least steps.
What does a true random number generator exploit?
An entropy source that behaves truly randomly.
Name one hardware phenomenon used by true random number generators.
Electronic jitter.
In which year did Gilbert Vernam develop the stream-cipher concept?
1917.
Who developed the stream-cipher concept with an electromechanical machine?
Gilbert Vernam.
Which ciphers did the eSTREAM project select for hardware applications?
Grain v1, MICKEY v2, and Trivium.
What is confusion in encryption according to Claude Shannon?
It obscures the relationship between the key and ciphertext, often via substitution.
What does diffusion do in encryption as defined by Claude Shannon?
It spreads one plaintext symbol's influence over many ciphertext symbols, often by permutation.
What block size and key size does DES use for encryption?
DES encrypts 64-bit blocks with a 56-bit keys.
How many rounds does DES perform and how are round keys derived?
DES performs 16 rounds using different round keys derived from the main key.
What are the formulas for each DES Feistel round?
and for .
What steps does the DES f function perform on its input?
It expands 32 bits to 48, XORs with a round key, applies eight S-boxes, then a permutation P.
What role do DES S-boxes play in the cipher?
They are the only nonlinear elements and provide the principal source of confusion.
How do the expansion and P permutation in DES contribute to encryption?
They contribute to diffusion and the avalanche effect.
Test your knowledge with 60 questions on Affine and Stream Ciphers.
1. Regarding cryptology, which statement or statements are correct?
2. Cryptography and cryptanalysis are distinguished by which correct statements?
Review the complete course in the study sheet for Affine and Stream Ciphers.
See study sheet →Import your course and AI generates flashcards in 30 seconds.
Flashcard generator