📌 Cryptography secures communication against an adversary, whereas cryptanalysis studies how to break cryptosystems.
📌 Symmetric algorithms use one shared secret key for encryption and decryption, whereas asymmetric algorithms use a private key and a public key.
Cryptography secures communication, whereas cryptanalysis breaks cryptosystems.
★ Must-know
📌 A brute-force attack treats a cipher as a black box and tests all possible keys, whereas an analytical attack exploits the internal structure of the cipher.
A brute-force attack checks every key in the key space by decrypting ciphertext y and testing whether the result matches known plaintext x.
Letter-frequency analysis can exploit:
📌 Kerckhoffs’ Principle states that a cryptosystem should remain secure even when the attacker knows all system details except the secret key. — Auguste Kerckhoffs, 1883
Further detail
Ciphertext-only → known-plaintext → chosen-plaintext → chosen-ciphertext
★ Must-know
📐 Formula — Every integer a can be written as with , which gives .
📌 An element a in Z_m has a multiplicative inverse if and only if gcd(a,m)=1, meaning that a and m are coprime.
📐 Formula — The shift cipher encrypts and decrypts letters represented in Z_26 using and .
📐 Formula — The affine cipher encrypts with and decrypts with , subject to .
Further detail
A clock whose numbers wrap around illustrates modular arithmetic.
★ Must-know
📌 The affine cipher is vulnerable to exhaustive search and letter-frequency analysis because its key space is small and its plaintext-to-ciphertext letter mapping is fixed.
Further detail
The valid multiplier values for the affine cipher modulo 26 are 1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, and 25.
To find the multiplicative inverse of a, test possible values until ; for example, the inverse of 3 is 9 because .
With key k=(9,13), the plaintext ATTACK, represented as 0,19,19,0,2,10, encrypts to the ciphertext nccnfz, represented as 13,2,2,13,5,25, and the inverse of 9 is 3.
Multiplication plus addition produces the affine substitution.
★ Must-know
📌 Cryptography, IT security, and cybersecurity protect information systems against malicious human actors, whereas technical safety and reliability primarily address random technical failures during normal operation.
The traditional CIA triad consists of:
🔄 A systematic IT-security approach proceeds by: defining assets and security needs, evaluating attack potential and possible attack paths, specifying adequate countermeasures
Kerckhoffs’ Principle states that the design of a cryptographic system should not require secrecy and that compromising the system should not inconvenience the correspondents. — Auguste Kerckhoffs, 1883
Further detail
Gentry proposed the first fully homomorphic encryption scheme in 2009, based on lattices.
General secret sharing requires at least t of n participants to collaborate to reconstruct or compute a secret, and it was proposed independently by Shamir and Blakley in 1979.
Security protects against attackers, whereas safety addresses random technical failures.
★ Must-know
📌 Stream ciphers encrypt individual bits by combining each plaintext bit with a key-stream bit, whereas block ciphers encrypt a block of b plaintext bits under the same key.
📌 In a synchronous stream cipher the key stream depends only on the key, whereas in an asynchronous stream cipher it also depends on the ciphertext.
📐 Formula — For plaintext, ciphertext, and key-stream bits in {0,1}, stream-cipher encryption and decryption are both modulo-2 addition: and .
Further detail
Stream ciphers process individual bits, whereas block ciphers process complete blocks.
★ Must-know
📌 True random number generators produce non-reproducible outputs from physical processes, whereas pseudorandom number generators compute deterministic sequences from an initial seed.
📌 Practical stream ciphers replace the one-time pad’s true-random key stream with a deterministic pseudorandom key stream generated from a short secret key, so they aim for computational rather than unconditional security.
Further detail
📌 A one-time pad requires one true-random key bit for every plaintext bit, so its key is as long as the plaintext and the key material cannot be reused.
TRNGs are unpredictable physical sources, PRNGs are deterministic, and CSPRNGs are deterministic but computationally unpredictable.
★ Must-know
📐 Formula — For an LFSR of degree with feedback coefficients , the output sequence satisfies .
The maximum sequence length of an LFSR of degree is , because the all-zero state is excluded and would remain stuck forever.
A known-plaintext attack on a degree- LFSR reconstructs the key stream from plaintext and ciphertext, forms linear equations from the recurrence, and solves for the feedback coefficients using Gaussian elimination or matrix inversion.
Further detail
Linearity enables reconstruction of the feedback coefficients, making a single LFSR insecure.
★ Must-know
📌 Salsa20 and ChaCha20 XOR a key stream generated from a key, nonce, and block number with the plaintext for encryption and with the ciphertext for decryption.
📌 A nonce must change for every encryption session so that two encryptions under the same key do not reuse the same key stream.
Trivium is a hardware-oriented stream cipher designed by Christophe De Cannière and Bart Preneel that uses an 80-bit key and combines three shift registers with nonlinear components.
🔄 Trivium setup consists of: loading the 80-bit key into register A, loading the 80-bit initialization vector into register B, setting the remaining bits to zero except for the three rightmost bits of register C, clocking the cipher 1152 times without producing output
Further detail
Salsa20 is a software-efficient ARX stream cipher developed by Daniel J. Bernstein in 2005; Salsa20/20 uses 20 rounds, and Salsa20 also has 12-round and 8-round variants.
Salsa20 and ChaCha20 generate 512-bit key-stream blocks from 32-bit words and can compute blocks independently for parallel processing.
ChaCha20 is a software-oriented stream cipher developed by Daniel J. Bernstein in 2008 and uses twenty rounds with a 256-bit key in the configuration described.
Trivium’s three registers have lengths 93, 84, and 111 bits, for a total internal length of 288 bits.
Salsa20 and ChaCha20 target efficient software, whereas Trivium targets efficient hardware.
📐 Formula — The Trivium register updates are , , and .
📐 Formula — Trivium produces its keystream bit as .
Trivium initialization loads an 80-bit key into register A, an 80-bit initialization vector into register B, sets all other bits to zero, and sets the three rightmost bits of register C to one.
Trivium performs a warm-up phase of 1152 clock cycles, equal to four times its total register length of 288 bits, before producing output.
Trivium output begins with the bit produced in cycle 1153, and the resulting keystream is XORed with plaintext for encryption or ciphertext for decryption.
AND-based nonlinear feedback → resistance to linear attacks
★ Must-know
Further detail
A hardware implementation of Trivium occupies approximately 3500 to 5500 gate equivalents, and an implementation with 4000 gates can produce 16 bits per clock cycle.
At a clock rate of 500 MHz, a 16-bit-per-cycle Trivium implementation achieves an encryption rate of 8 Gbit/s.
True random number generators can use hardware phenomena such as electronic jitter and uncorrelated oscillators, or system events such as keystroke timings, interrupt timings, packet arrival times, memory or disk checksums, and the Linux-like system source /dev/random.
Gilbert Vernam developed the stream-cipher concept in 1917 with an electromechanical machine that automated encryption and transmission of teletypewriter communication.
The selected software-oriented ciphers were:
True randomness supplies entropy; pseudorandomness supplies efficient keystreams
📐 Formula — Each DES Feistel round applies and for .
The DES f function expands 32 input bits to 48 bits, XORs them with a 48-bit round key, applies eight S-boxes that each map 6 bits to 4 bits, and then applies a permutation P.
DES S-boxes are the only nonlinear elements of the cipher and provide its principal source of confusion, while the expansion and P permutation contribute to diffusion and the avalanche effect.
Permutation → Feistel rounds → S-box confusion → P-permutation diffusion
★ Must-know
DES derives 16 round keys of 48 bits from an effective 56-bit key, although the input is commonly represented as 64 bits containing eight parity bits.
The DES key schedule removes the eight parity bits with PC–1, splits the resulting key into 28-bit halves C0 and D0, rotates both halves left each round, and applies PC–2 to produce each 48-bit subkey.
DES decryption uses the same Feistel structure as encryption but applies the subkeys in reverse order, namely k16, k15, through k1.
Further detail
📌 In DES rounds 1, 2, 9, and 16, the two key halves are rotated left by one bit, whereas in all other rounds they are rotated left by two bits.
PC–1 → rotations → PC–2 → reversed schedule
★ Must-know
DES can be attacked by exhaustive key search because its key space contains only 256 possible keys.
A DES exhaustive key search takes a known plaintext–ciphertext pair and tests keys until a key satisfies .
Differential cryptanalysis requires 247 chosen plaintext–ciphertext pairs in its favorable setting and 255 pairs for random plaintext, whereas linear cryptanalysis requires 243 plaintext–ciphertext pairs.
📌 Single DES should no longer be used for confidential data because its 56-bit key can be searched at relatively low cost, although current analytical attacks are not practically efficient against it.
Further detail
Brute force breaks the short key; analytical attacks face resistant S-boxes
★ Must-know
📐 Formula — Triple DES applies encryption–decryption–encryption as .
Further detail
📌 NIST limits 3TDEA to 220 64-bit plaintext blocks under one key set, and 3DES is being discontinued as a U.S. standard after 2023.
AES targets general security, while PRESENT targets constrained hardware
★ Must-know
AES is the most widely used symmetric cipher and is incorporated into standards such as TLS, IPsec, IEEE 802.11i, and numerous commercial applications.
In 2001, NIST declared Rijndael the new AES and published it as the U.S. standard FIPS PUB 197.
AES candidates were required to use a 128-bit block size, support key lengths of 128, 192, and 256 bits, provide competitive security, and be efficient in software and hardware.
📌 AES uses a 128-bit block for all supported key lengths, whereas Rijndael also permits block lengths of 192 and 256 bits.
Further detail
📌 Unlike DES, AES is not a Feistel network and encrypts all 128 state bits in each iteration.
DES/3DES limitations → public NIST competition → Rijndael becomes AES
★ Must-know
📌 A finite field with order q exists only when q is a prime power, , where p is prime and is the field characteristic.
Further detail
📐 Formula — AES constructs GF(2^8) using the irreducible polynomial .
Prime-power order → finite field existence
The AES round layers are:
The AES S-box first computes inversion in GF(2^8), with zero mapped to zero, and then applies an affine transformation.
ShiftRows leaves the first state row unchanged and cyclically shifts the second, third, and fourth rows right by three, two, and one byte, respectively.
📐 Formula — MixColumns multiplies each four-byte state column by a fixed matrix over GF(2^8), whose first output column is computed as .
📌 The Key Addition layer combines the 16-byte state with a 16-byte subkey using bitwise XOR, which is addition in GF(2).
The AES key schedule produces 11, 13, or 15 128-bit subkeys for 128-, 192-, or 256-bit keys, respectively, because the number of subkeys equals the number of rounds plus one.
AES uses a word-oriented key schedule in which one word equals 32 bits and expanded subkeys are stored in a word array W.
AES-128 uses 11 subkeys stored in 44 words W[0] through W[43], AES-192 uses 13 subkeys stored in 52 words W[0] through W[51], and AES-256 uses 15 subkeys stored in 60 words W[0] through W[59].
📐 Formula — For AES-128, the first word of each later subkey is computed as for i from 1 through 10.
📌 Precomputation expands and stores all subkeys before encryption or decryption, whereas on-the-fly generation derives a new subkey during each AES round.
📌 Because AES is not based on a Feistel network, decryption must invert the AES layers rather than reuse the encryption layers unchanged.
🔄 The decryption structure uses:
The first decryption round omits inverse MixColumns because the last encryption round omitted MixColumns.
Inverse MixColumns multiplies each four-byte state column by the constant matrix with rows (0E, 0B, 0D, 09), (09, 0E, 0B, 0D), (0D, 09, 0E, 0B), and (0B, 0D, 09, 0E) over GF(2^8).
Substitute → ShiftRows → MixColumns → AddRoundKey
| Branch | Key structure or method | Typical role |
|---|---|---|
| Symmetric algorithms | Shared secret key | Data encryption and message integrity checking |
| Asymmetric algorithms | Private key and public key | Digital signatures, key establishment, and data encryption |
| Cryptographic protocols | Algorithms combined as building blocks | Complex functions such as secure web communication |
| Feature | Stream cipher | Block cipher |
|---|---|---|
| Basic unit | Individual bit | Block of b bits |
| Key-stream dependence | Key only or key and ciphertext | Same key encrypts each block |
| Typical block size | Not applicable | 128 bits for AES; 64 bits for DES and 3DES |
Test your knowledge on Affine and Stream Ciphers with 60 multiple-choice questions with detailed corrections.
1. Regarding cryptology, which statement or statements are correct?
2. Cryptography and cryptanalysis are distinguished by which correct statements?
Memorize the key concepts of Affine and Stream Ciphers with 96 interactive flashcards.
What is cryptology?
The general field including cryptography and cryptanalysis.
What does cryptography secure communication against?
An adversary.
What does cryptanalysis study?
How to break cryptosystems.
Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.
Sheet generator