Quiz: Affine and Stream Ciphers — 60 questions

Detailed questions and answers

1. Regarding cryptology, which statement or statements are correct?

Cryptography attempts to defeat cryptosystems, whereas cryptanalysis builds protections.
Cryptology includes the study of constructing and attacking cryptosystems.
Cryptology is the general field encompassing cryptography and cryptanalysis.
The broad scope of cryptology covers protective and adversarial techniques.
Cryptography and cryptanalysis are both subfields within cryptology.

Cryptology includes the study of constructing and attacking cryptosystems. · Cryptology is the general field encompassing cryptography and cryptanalysis. · The broad scope of cryptology covers protective and adversarial techniques. · Cryptography and cryptanalysis are both subfields within cryptology.

Explanation

Cryptology is the overarching field that includes both cryptography and cryptanalysis. Cryptography builds protections for communication, whereas cryptanalysis studies ways to defeat cryptosystems; cryptology therefore covers both activities.

2. Cryptography and cryptanalysis are distinguished by which correct statements?

Cryptography and cryptanalysis both focus on producing secret keys.
Cryptography builds protections, whereas cryptanalysis attempts to defeat cryptosystems.
Cryptography and cryptanalysis are identical terms for encryption procedures.
Cryptography attacks cipher structure, whereas cryptanalysis secures communication.
Cryptography studies how to break systems, whereas cryptanalysis constructs protections.

Cryptography builds protections, whereas cryptanalysis attempts to defeat cryptosystems.

Explanation

Cryptography secures communication against adversaries, while cryptanalysis studies how cryptosystems can be broken. The other statements reverse or erase this distinction.

3. Which statements correctly compare symmetric and asymmetric cryptography?

Symmetric and asymmetric algorithms have identical key arrangements.
Symmetric cryptography uses separate private and public keys.
Symmetric encryption and decryption use one shared secret key.
Asymmetric cryptography uses the same secret key for both users.
Asymmetric encryption uses a private key, while decryption uses a public key.

Symmetric encryption and decryption use one shared secret key.

Explanation

Symmetric encryption and decryption use one shared secret key, so symmetric algorithms do not have identical key arrangements, separate private and public keys, or distinct secret keys for the two users. Asymmetric cryptography uses a public key for encryption and the corresponding private key for decryption, rather than reversing these roles.

4. In a symmetric cryptosystem, Alice encrypts plaintext xx with key kk to obtain ciphertext yy. Which statements are correct?

Bob recovers plaintext xx by decrypting ciphertext yy with a different key.
Alice encrypts plaintext xx with a public key and Bob decrypts it privately.
Bob decrypts ciphertext yy with the same key kk to recover plaintext xx.
The symmetric process produces ciphertext xx and recovers plaintext yy.
Alice decrypts ciphertext yy with key kk before Bob receives it.

Bob decrypts ciphertext $$y$$ with the same key $$k$$ to recover plaintext $$x$$.

Explanation

The symmetric process is x→kyx \xrightarrow{k} y followed by decryption of yy with the same key kk to recover xx. Public-key use, a different decryption key, reversed operations, and swapped plaintext labels do not describe this process.

5. Which statements accurately distinguish brute-force and analytical attacks?

An analytical attack checks every key as a black-box search.
A brute-force attack tests possible keys without analyzing cipher structure.
Brute-force and analytical attacks use the same method of key discovery.
A brute-force attack depends on identifying structural weaknesses first.
An analytical attack exploits the internal structure of a cipher.

A brute-force attack tests possible keys without analyzing cipher structure. · An analytical attack exploits the internal structure of a cipher.

Explanation

Brute force treats the cipher as a black box and searches keys, whereas analytical attacks exploit internal structure. The remaining statements exchange or collapse these distinct methods.

6. A ciphertext and its corresponding plaintext are available for testing. Which statements describe a brute-force attack?

The attack requires discovering the cipher’s internal weakness first.
Each candidate key is used to decrypt ciphertext yy.
The attacker infers substitutions primarily from letter-frequency statistics.
The attacker tests candidate keys across the entire key space.
The attacker encrypts plaintext xx to generate unrelated test messages.

Each candidate key is used to decrypt ciphertext $$y$$. · The attacker tests candidate keys across the entire key space.

Explanation

A brute-force attack searches candidate keys and decrypts yy with each one, checking whether the result matches known plaintext xx. Frequency inference and structural analysis describe other approaches, while generating unrelated messages is not the stated procedure.

7. Regarding the congruence relation a≡r(modm)a\equiv r\pmod m, which statements are correct?

The remainder determines the modulus used in the congruence.
The modulus determines the relevant equivalence relation.
The positive integer mm is called the modulus.
The relation holds when mm divides a−ra-r.
The value rr is called a remainder in the relation.

The modulus determines the relevant equivalence relation. · The positive integer $$m$$ is called the modulus. · The relation holds when $$m$$ divides $$a-r$$. · The value $$r$$ is called a remainder in the relation.

Explanation

The congruence holds precisely when m∣(a−r)m\mid(a-r); mm is the modulus and rr is a remainder. The modulus determines the equivalence relation, not the remainder.

8. Which statements correctly describe the division representation of an integer?

The associated congruence is a≡q(modm)a\equiv q\pmod m.
The representation requires r≥mr\ge m for every positive modulus.
Every integer aa can be written as a=q⋅m+ra=q\cdot m+r.
The quotient and remainder satisfy a=q+m+ra=q+m+r.
The remainder satisfies 0≤r<m0\le r<m.

Every integer $$a$$ can be written as $$a=q\cdot m+r$$. · The remainder satisfies $$0\le r<m$$.

Explanation

For a positive modulus, every integer has the form a=q⋅m+ra=q\cdot m+r with 0≤r<m0\le r<m, yielding a≡r(modm)a\equiv r\pmod m. The other formulas impose an incorrect remainder condition or alter the quotient and remainder relationship.

9. An element aa of Zm\mathbb Z_m has a multiplicative inverse under which condition?

A multiplicative inverse exists exactly when gcd⁡(a,m)=1\gcd(a,m)=1.
An inverse exists when aa is divisible by mm.
Every element has an inverse whenever mm is positive.
Invertibility requires a=ma=m in the integer ring.
An inverse exists when aa and mm share a common factor.

A multiplicative inverse exists exactly when $$\gcd(a,m)=1$$.

Explanation

An element of Zm\mathbb Z_m is invertible if and only if aa and mm are coprime, meaning gcd⁡(a,m)=1\gcd(a,m)=1. Sharing a factor, equality with the modulus, positivity alone, or divisibility by the modulus does not establish invertibility.

10. Regarding the affine cipher, which statements are correct?

Decryption uses the modular inverse of the multiplier.
Encryption combines multiplication and addition modulo 26.
The cipher uses addition without multiplication, like a shift cipher.
The multiplier may be any residue modulo 26.
The key consists of a single additive displacement value.

Decryption uses the modular inverse of the multiplier. · Encryption combines multiplication and addition modulo 26.

Explanation

Affine encryption uses multiplication by a and addition of b modulo 26, while decryption uses the inverse of a. A shift cipher uses addition only, the affine key contains two values, and the multiplier must be relatively prime to 26.

11. The key space of the affine cipher has which characteristics?

The total number of keys is 312.
The cipher has 676 possible keys from unrestricted parameter pairs.
The multiplier contributes 26 valid choices modulo 26.
There are 26 possible additive values for b.
There are 12 possible valid multiplier values for a.

The total number of keys is 312. · There are 26 possible additive values for b. · There are 12 possible valid multiplier values for a.

Explanation

The affine cipher has 12 valid choices for a and 26 choices for b, giving 12×26=31212\times26=312 keys. The multiplier is restricted to residues relatively prime to 26, so unrestricted parameter counting is incorrect.

12. Concerning the cryptanalytic weaknesses of the affine cipher:

Its small key space permits exhaustive search attacks.
Its security is limited by the fixed nature of its mapping.
Each plaintext letter maps consistently to one ciphertext letter.
Fixed letter mappings support letter-frequency analysis.
Frequency patterns can remain detectable under its substitution.

Its small key space permits exhaustive search attacks. · Its security is limited by the fixed nature of its mapping. · Each plaintext letter maps consistently to one ciphertext letter. · Fixed letter mappings support letter-frequency analysis. · Frequency patterns can remain detectable under its substitution.

Explanation

The affine cipher has only 312 keys, making exhaustive search feasible. Its fixed plaintext-to-ciphertext mapping preserves exploitable frequency patterns, so frequency analysis can assist attacks.

13. Regarding security, safety, and reliability, select the correct statement.

Reliability focuses on hostile human behavior during operation.
Security addresses threats from malicious human actors.
Cybersecurity primarily concerns random hardware failures.
Technical safety and security describe identical threat models.
Technical safety primarily addresses deliberate cyberattacks.

Security addresses threats from malicious human actors.

Explanation

Security and cybersecurity protect against malicious human actors. Technical safety and reliability primarily concern random technical failures during normal operation, so the other statements confuse these threat models.

14. Which statements accurately describe the basic security goals?

Availability belongs to the traditional CIA triad.
Confidentiality belongs to the traditional CIA triad.
Authenticity may be treated as an additional security goal.
Integrity belongs to the traditional CIA triad.
The CIA triad consists of confidentiality, authenticity, and availability.

Availability belongs to the traditional CIA triad. · Confidentiality belongs to the traditional CIA triad. · Authenticity may be treated as an additional security goal. · Integrity belongs to the traditional CIA triad.

Explanation

The CIA triad comprises confidentiality, integrity, and availability. Authenticity is often added as a further goal, whereas it does not replace integrity within the traditional triad.

15. A systematic IT-security approach includes which activities?

It examines possible paths attackers could use.
It identifies assets and their security needs.
It specifies countermeasures suited to the application.
It selects countermeasures before identifying assets.
It evaluates possible attack potential against the environment.

It examines possible paths attackers could use. · It identifies assets and their security needs. · It specifies countermeasures suited to the application. · It evaluates possible attack potential against the environment.

Explanation

A systematic approach defines assets and needs, evaluates attack potential and attack paths, and specifies adequate countermeasures. Countermeasures are selected as part of an informed process rather than before assets are identified.

16. Concerning Kerckhoffs’ Principle, which propositions are correct?

The principle requires the encryption key to be publicly disclosed.
Compromising the system should not inconvenience correspondents.
The principle is associated with Auguste Kerckhoffs.
The cryptographic design should not depend on design secrecy.
Kerckhoffs stated the principle in 1883.

Compromising the system should not inconvenience correspondents. · The principle is associated with Auguste Kerckhoffs. · The cryptographic design should not depend on design secrecy. · Kerckhoffs stated the principle in 1883.

Explanation

Kerckhoffs’ Principle requires security not to depend on keeping the system design secret, and compromise of the system should not inconvenience correspondents. It is attributed to Auguste Kerckhoffs in 1883, but it does not require publishing the key.

17. Regarding stream and block ciphers, which statements are correct?

A block cipher processes a block containing b plaintext bits.
A stream cipher combines plaintext bits with key-stream bits.
Stream ciphers operate on individual bits.
Block ciphers operate on groups of bits under one key.
A stream cipher encrypts fixed blocks of b bits as its basic unit.

A block cipher processes a block containing b plaintext bits. · A stream cipher combines plaintext bits with key-stream bits. · Stream ciphers operate on individual bits. · Block ciphers operate on groups of bits under one key.

Explanation

Stream ciphers combine individual plaintext bits with key-stream bits, whereas block ciphers process blocks of b bits under the same key. Therefore, fixed blocks are characteristic of the block-cipher description, not the stream-cipher basic unit.

18. How do synchronous and asynchronous stream ciphers differ?

The two constructions generate key streams from identical inputs.
Asynchronous generation depends on the key but not ciphertext.
An asynchronous key stream also depends on ciphertext.
Synchronous generation requires ciphertext feedback.
A synchronous key stream depends on the key.

An asynchronous key stream also depends on ciphertext. · A synchronous key stream depends on the key.

Explanation

In a synchronous stream cipher, the key stream depends only on the key. In an asynchronous stream cipher, ciphertext also contributes to key-stream generation, so the remaining statements reverse or erase this distinction.

19. For stream-cipher bits, select the correct propositions:

The ciphertext satisfies yi≡xi+si(mod2)y_i\equiv x_i+s_i\pmod{2}.
The plaintext satisfies xi≡yi+si(mod2)x_i\equiv y_i+s_i\pmod{2}.
Decryption adds ciphertext and key-stream bits modulo 2.
Encryption adds plaintext and key-stream bits modulo 2.
Decryption subtracts the key-stream bit modulo 2.

The ciphertext satisfies $$y_i\equiv x_i+s_i\pmod{2}$$. · The plaintext satisfies $$x_i\equiv y_i+s_i\pmod{2}$$. · Decryption adds ciphertext and key-stream bits modulo 2. · Encryption adds plaintext and key-stream bits modulo 2.

Explanation

Both encryption and decryption use modulo-2 addition: yi≡xi+si(mod2)y_i\equiv x_i+s_i\pmod{2} and xi≡yi+si(mod2)x_i\equiv y_i+s_i\pmod{2}. Modulo-2 addition is its own inverse, so decryption is not described as subtraction here.

20. Modulo-2 addition in a stream cipher has which equivalent interpretation?

It produces the same result as logical AND for binary inputs.
It combines two binary inputs using XOR logic.
It is equivalent to ordinary decimal addition without carries.
It is equivalent to the exclusive-OR operation.
It is the operation used for bitwise stream-cipher mixing.

It combines two binary inputs using XOR logic. · It is equivalent to the exclusive-OR operation. · It is the operation used for bitwise stream-cipher mixing.

Explanation

Modulo-2 addition is equivalent to exclusive OR, or XOR, and is used to combine plaintext and key-stream bits. It is not ordinary decimal addition without carries in every interpretation, nor is it equivalent to AND.

21. Regarding true and pseudorandom number generators, which propositions are correct?

A pseudorandom generator obtains each output directly from an unpredictable physical process.
A pseudorandom generator computes a deterministic sequence from an initial seed.
A true random generator obtains non-reproducible outputs from a physical process.
A pseudorandom generator can produce reproducible outputs when its seed is known.
A true random generator reproduces its entire sequence from a stored seed.

A pseudorandom generator computes a deterministic sequence from an initial seed. · A true random generator obtains non-reproducible outputs from a physical process. · A pseudorandom generator can produce reproducible outputs when its seed is known.

Explanation

True random generators rely on physical processes and therefore produce non-reproducible outputs. Pseudorandom generators compute deterministic sequences from seeds, so known seeds permit reproducibility; they do not directly obtain each output from physical randomness.

22. A cryptographically secure pseudorandom number generator is characterized by which propositions?

Its output sequence is required to originate from a physical random process.
Its subsequent bits remain computationally infeasible to predict from consecutive outputs.
Its security concerns both future and past output-bit prediction.
Its preceding bits are efficiently recoverable from any consecutive output segment.
It remains difficult to compute hidden sequence bits from observed consecutive bits.

Its subsequent bits remain computationally infeasible to predict from consecutive outputs. · Its security concerns both future and past output-bit prediction. · It remains difficult to compute hidden sequence bits from observed consecutive bits.

Explanation

A cryptographically secure pseudorandom generator makes computing subsequent or preceding bits computationally infeasible from consecutive outputs. This is a computational property of a PRNG, not a requirement that the generator use a physical process.

23. Unconditional security means that a cryptosystem has which property?

It cannot be broken even when an attacker has unlimited computational resources.
Its security depends on an attacker having insufficient computational resources.
It cannot be defeated by increasing the available computation.
Its protection remains valid against attackers with infinite computing power.
It is secure because its key stream is generated deterministically.

It cannot be broken even when an attacker has unlimited computational resources. · It cannot be defeated by increasing the available computation. · Its protection remains valid against attackers with infinite computing power.

Explanation

Unconditional security means that breaking the cryptosystem is impossible even with infinite computational resources. Security based on limited computational power is computational security, and deterministic generation alone does not establish unconditional security.

24. Which propositions correctly describe a one-time pad?

The key stream is generated deterministically from a short secret key.
The key stream is known to the legitimate communicating parties.
Each key-stream bit is used exactly once during encryption.
Each key-stream bit may be reused across several messages.
Its key stream is generated using a true random number generator.

The key stream is known to the legitimate communicating parties. · Each key-stream bit is used exactly once during encryption. · Its key stream is generated using a true random number generator.

Explanation

A one-time pad uses a true-random key stream shared by the legitimate parties, with every bit used once. It is not generated deterministically from a short key, and reusing key-stream bits violates the one-time-pad construction.

25. Concerning the structure of a linear feedback shift register, which propositions are correct?

The number of flip-flops determines the register degree.
The register is clocked to shift its stored contents over time.
Its structure differs from nonlinear designs that include AND operations.
Its feedback operation is linear over binary values.
Its input is formed by XORing selected bits of the register.

The number of flip-flops determines the register degree. · The register is clocked to shift its stored contents over time. · Its structure differs from nonlinear designs that include AND operations. · Its feedback operation is linear over binary values. · Its input is formed by XORing selected bits of the register.

Explanation

An LFSR is clocked and uses the XOR-sum of selected register bits as its input. Its degree equals the number of flip-flops, and XOR feedback is linear, unlike constructions incorporating nonlinear operations such as AND.

26. For an LFSR of degree mm, which recurrence statements are correct?

The sequence value at position m+im+i depends on the preceding mm sequence values.
The recurrence is evaluated modulo 22.
The feedback coefficients are denoted p0p_0 through pm−1p_{m-1}.
The recurrence combines terms using ordinary integer arithmetic without reduction.
The recurrence requires nonlinear products between sequence terms.

The sequence value at position $$m+i$$ depends on the preceding $$m$$ sequence values. · The recurrence is evaluated modulo $$2$$. · The feedback coefficients are denoted $$p_0$$ through $$p_{m-1}$$.

Explanation

The LFSR recurrence uses the preceding mm values, coefficients p0p_0 through pm−1p_{m-1}, and arithmetic modulo 22. It is linear binary arithmetic, not unreduced integer arithmetic or nonlinear multiplication.

27. Which propositions correctly describe the maximum period of a degree-mm LFSR?

An all-zero state eventually develops nonzero register bits through feedback.
The all-zero state is excluded from the maximum-length sequence.
The maximum length includes the all-zero state as a cycling state.
The all-zero state remains stuck because its feedback remains zero.
Its maximum sequence length is 2m−12^m-1.

The all-zero state is excluded from the maximum-length sequence. · The all-zero state remains stuck because its feedback remains zero. · Its maximum sequence length is $$2^m-1$$.

Explanation

A degree-mm LFSR can have maximum length 2m−12^m-1 because the all-zero state is excluded. That state remains stuck at zero, so it neither cycles through the maximum sequence nor develops nonzero bits.

28. A known-plaintext attack against a degree-mm LFSR involves which steps?

The recurrence supplies mm linear equations for the unknown coefficients.
Gaussian elimination can solve the resulting linear system.
The attack requires guessing the entire feedback sequence without using equations.
The attacker must first introduce nonlinear AND equations into the recurrence.
The attacker derives the key stream from known plaintext and ciphertext.

The recurrence supplies $$m$$ linear equations for the unknown coefficients. · Gaussian elimination can solve the resulting linear system. · The attacker derives the key stream from known plaintext and ciphertext.

Explanation

Known plaintext and ciphertext reveal the key stream, allowing the attacker to form mm linear recurrence equations. Gaussian elimination or matrix inversion can solve for the feedback coefficients; nonlinear equations and blind guessing are not required.

29. Regarding Salsa20 and ChaCha20 encryption and decryption, which propositions are correct?

The key stream is generated from a key, nonce, and block number.
Decryption XORs the ciphertext with the same key stream.
Encryption XORs the plaintext with a key stream.
The secret key must remain confidential during normal use.
The nonce does not need to be kept secret from observers.

The key stream is generated from a key, nonce, and block number. · Decryption XORs the ciphertext with the same key stream. · Encryption XORs the plaintext with a key stream. · The secret key must remain confidential during normal use. · The nonce does not need to be kept secret from observers.

Explanation

Salsa20 and ChaCha20 generate a key stream from the key, nonce, and block number. XOR with plaintext encrypts, XOR with ciphertext decrypts, the nonce may be public, and the key must remain secret.

30. Why must a nonce change for every encryption session in these stream-cipher constructions?

Nonce variation protects against repeated key-stream generation.
Changing the nonce prevents key-stream reuse under the same key.
Using a new nonce separates encryptions performed with one secret key.
A fixed nonce guarantees a fresh key stream for every session.
The nonce must be kept secret to prevent key-stream reuse.

Nonce variation protects against repeated key-stream generation. · Changing the nonce prevents key-stream reuse under the same key. · Using a new nonce separates encryptions performed with one secret key.

Explanation

A new nonce ensures that encryptions under the same key do not reuse the same key stream. A fixed nonce can reproduce the stream, and nonce secrecy is not the required protection mechanism.

31. During Trivium initialization, which propositions are correct?

The remaining positions are set to zero except for three rightmost bits of register C.
The 80-bit key fills the leftmost locations of register A.
The cipher is clocked 1152 times before output generation begins.
The 80-bit initialization vector fills register C.
The cipher produces keystream output during all 1152 initialization clocks.

The remaining positions are set to zero except for three rightmost bits of register C. · The 80-bit key fills the leftmost locations of register A. · The cipher is clocked 1152 times before output generation begins.

Explanation

Trivium places the key in register A, the initialization vector in register B, and initializes the remaining positions with zeros except for three rightmost bits of register C. It then performs 1152 clocks without producing output, so the initialization vector does not fill register C and output is not produced during these clocks.

32. Which statements correctly describe the arithmetic in Trivium's register-update equations?

The remaining additions in the update equations represent XOR operations.
The AND terms in the update equations are multiplications modulo 2.
The nonlinear terms use modulo-2 exponentiation rather than multiplication.
The update equations contain no nonlinear products involving register bits.
Every term in the update equations is evaluated as an ordinary integer sum.

The remaining additions in the update equations represent XOR operations. · The AND terms in the update equations are multiplications modulo 2.

Explanation

The products in Trivium's update equations are modulo-2 multiplications, creating the nonlinear terms. The other additions are XOR operations; therefore, the equations are not ordinary integer sums and do contain nonlinear products.

33. A Trivium implementation has completed its initialization phase. Which statements about the warm-up phase are correct?

The warm-up phase ends when output begins in cycle 1152.
The warm-up phase lasts 1152 clock cycles.
The warm-up length equals four times the total register length.
The warm-up phase lasts 288 clock cycles.
The total register length used in this calculation is 288 bits.

The warm-up phase lasts 1152 clock cycles. · The warm-up length equals four times the total register length. · The total register length used in this calculation is 288 bits.

Explanation

Trivium performs a warm-up phase of 1152 clock cycles, equal to four times its total register length of 288 bits. Output begins in cycle 1153, so the warm-up does not end in cycle 1152 and does not last 289 or 288 cycles.

34. Which statements accurately describe how Trivium is initialized?

The initialization vector is loaded into register C.
All three registers are initialized entirely with zeros.
The 80-bit key is loaded into register A.
The 80-bit initialization vector is loaded into register B.
The three rightmost bits of register C are set to one.

The 80-bit key is loaded into register A. · The 80-bit initialization vector is loaded into register B. · The three rightmost bits of register C are set to one.

Explanation

Initialization loads the 80-bit key into A and the 80-bit initialization vector into B. Other positions are zero, while the three rightmost bits of C are one; thus C is not entirely zero and the initialization vector is not loaded there.

35. Which statements correctly characterize the known attack context for Trivium?

Reducing initialization to 799 iterations enabled the reported attack.
The weakened version required more than 2802^{80} steps for the reported attack.
No attack on full Trivium was known below a complexity of 2802^{80} steps.
A weakened version using 799 initialization iterations could be attacked in 2682^{68} steps.
The full cipher was attacked in 2682^{68} steps with its standard initialization.

Reducing initialization to 799 iterations enabled the reported attack. · No attack on full Trivium was known below a complexity of $$2^{80}$$ steps. · A weakened version using 799 initialization iterations could be attacked in $$2^{68}$$ steps.

Explanation

No attack on full Trivium was known below 2802^{80} steps, whereas a version with 799 initialization iterations was attacked in 2682^{68} steps. The reported attack applies to the weakened initialization, not standard full Trivium, and its complexity is below 2802^{80}.

36. Concerning true random number generators, which proposition is correct?

A true random number generator uses an entropy source that behaves truly randomly.
A true random number generator derives bits primarily from a deterministic recurrence.
A true random number generator requires a fixed secret key as its entropy source.
A true random number generator replaces physical entropy with a cryptographic permutation.
A true random number generator produces bits from a predictable clock sequence.

A true random number generator uses an entropy source that behaves truly randomly.

Explanation

A true random number generator exploits an entropy source that behaves truly randomly to produce random bits. A deterministic recurrence, a fixed secret key, a cryptographic permutation, or a predictable clock sequence does not provide the stated random entropy source.

37. Regarding confusion in block-cipher design, which statements are correct?

Confusion primarily spreads one plaintext symbol across many ciphertext symbols.
Confusion obscures the relationship between the key and the ciphertext.
Permutation is the operation commonly associated with confusion in the definition.
Substitution is a common way to provide confusion.
Claude Shannon identified confusion as an encryption operation.

Confusion obscures the relationship between the key and the ciphertext. · Substitution is a common way to provide confusion. · Claude Shannon identified confusion as an encryption operation.

Explanation

Confusion obscures key–ciphertext relationships and is commonly achieved through substitution. It is attributed here to Claude Shannon; spreading plaintext influence is diffusion, while permutations are commonly associated with diffusion.

38. Which statements correctly describe diffusion?

Permutations commonly contribute to diffusion.
Diffusion primarily obscures the relationship between the key and ciphertext.
Diffusion spreads the influence of one plaintext symbol over many ciphertext symbols.
Claude Shannon described diffusion as an encryption operation.
Substitution is the operation identified here as the common mechanism for diffusion.

Permutations commonly contribute to diffusion. · Diffusion spreads the influence of one plaintext symbol over many ciphertext symbols. · Claude Shannon described diffusion as an encryption operation.

Explanation

Diffusion spreads plaintext influence across many ciphertext symbols and commonly uses permutations. Claude Shannon described this operation; obscuring key–ciphertext relationships and using substitution characterize confusion instead.

39. For a DES Feistel round, which statements correctly apply the round transformation?

The new right half satisfies Ri=Li−1⊕f(Ri−1,ki)R_i=L_{i-1}\oplus f(R_{i-1},k_i).
The new right half satisfies Ri=Ri−1⊕f(Li−1,ki)R_i=R_{i-1}\oplus f(L_{i-1},k_i).
The round update uses the round function on the previous left half.
The new left half satisfies Li=Li−1L_i=L_{i-1}.
The new left half satisfies Li=Ri−1L_i=R_{i-1}.

The new right half satisfies $$R_i=L_{i-1}\oplus f(R_{i-1},k_i)$$. · The new left half satisfies $$L_i=R_{i-1}$$.

Explanation

A DES Feistel round copies the previous right half into the new left half and computes the new right half as Li−1⊕f(Ri−1,ki)L_{i-1}\oplus f(R_{i-1},k_i). The alternatives either preserve the wrong half or apply the round function to the wrong input.

40. Regarding the DES key representation and effective key size, which statement(s) are correct?

The effective DES key contains 56 bits available for cryptographic use.
The standard DES input representation contains 64 bits, including eight parity bits.
DES input keys are commonly represented with 56 total bits, including parity.
The eight parity bits contribute to the effective cryptographic key space.
DES generates sixteen round keys, each having a length of 48 bits.

The effective DES key contains 56 bits available for cryptographic use. · The standard DES input representation contains 64 bits, including eight parity bits. · DES generates sixteen round keys, each having a length of 48 bits.

Explanation

DES produces sixteen 48-bit round keys from an effective 56-bit key. Its input is commonly represented as 64 bits, of which eight are parity bits; those parity bits do not enlarge the effective key space.

41. The DES key schedule performs which sequence of operations?

PC–2 expands each 28-bit half into a 64-bit round key.
The post-PC–1 key is split into halves named C0 and D0.
PC–2 selects a 48-bit subkey from the rotated halves.
Both key halves are rotated left before round-key selection.
PC–1 removes parity bits before the key is divided into two halves.

The post-PC–1 key is split into halves named C0 and D0. · PC–2 selects a 48-bit subkey from the rotated halves. · Both key halves are rotated left before round-key selection. · PC–1 removes parity bits before the key is divided into two halves.

Explanation

PC–1 removes the eight parity bits and leaves two 28-bit halves, C0 and D0. The halves are rotated left each round, and PC–2 selects the resulting 48-bit subkey; it does not expand them to 64 bits.

42. A DES implementation is decrypting a ciphertext with the standard Feistel construction. Which statement(s) are correct?

The first decryption round uses subkey k16.
Decryption replaces the Feistel network with a separate substitution process.
Decryption uses the same Feistel structure as DES encryption.
The decryption subkeys are applied in reverse order from encryption.
The final decryption round uses subkey k16.

The first decryption round uses subkey k16. · Decryption uses the same Feistel structure as DES encryption. · The decryption subkeys are applied in reverse order from encryption.

Explanation

DES decryption retains the Feistel structure and reverses the subkey order. Thus it begins with k16 and proceeds through k1, so the final round uses k1 rather than k16.

43. Which statement(s) correctly describe the vulnerability of DES to exhaustive key search?

DES has a key space containing 2562^{56} possible effective keys.
Analytical attacks and exhaustive search are identical because both test every key.
DES is resistant to exhaustive search because its input representation has 64 bits.
The eight parity bits increase the DES key space from 2562^{56} to 2642^{64} keys.
DES exhaustive search must examine 2642^{64} independent cryptographic keys.

DES has a key space containing $$2^{56}$$ possible effective keys.

Explanation

DES has an effective 56-bit key, giving a key space of 2562^{56} possibilities. The 64-bit representation includes eight non-key parity bits, so it does not create 2642^{64} cryptographic keys; exhaustive and analytical attacks are different approaches.

44. During an exhaustive DES key search using a known plaintext–ciphertext pair, which statement(s) are correct?

The search requires a chosen plaintext–ciphertext pair for every candidate key.
A candidate is accepted when decryption produces a value different from the plaintext.
The test applies the encryption operation to the ciphertext and compares it with the key.
A candidate key is tested by checking whether DESki−1(y)=xDES^{-1}_{k_i}(y)=x.
The procedure uses a known plaintext–ciphertext pair as its reference.

A candidate key is tested by checking whether $$DES^{-1}_{k_i}(y)=x$$. · The procedure uses a known plaintext–ciphertext pair as its reference.

Explanation

Exhaustive search uses a known plaintext–ciphertext pair and tests candidate keys using the relation DESki−1(y)=xDES^{-1}_{k_i}(y)=x. It does not require a separately chosen pair for every key, and a matching plaintext—not a different value—identifies a candidate.

45. Which statements accurately compare differential and linear cryptanalysis of DES?

Differential cryptanalysis may require 2472^{47} chosen plaintext–ciphertext pairs.
Linear cryptanalysis requires 2472^{47} plaintext–ciphertext pairs.
With random plaintext, differential cryptanalysis may require 2552^{55} pairs.
Linear cryptanalysis uses the same pair requirement as favorable differential analysis.
Differential cryptanalysis has a fixed requirement independent of plaintext selection.

Differential cryptanalysis may require $$2^{47}$$ chosen plaintext–ciphertext pairs. · With random plaintext, differential cryptanalysis may require $$2^{55}$$ pairs.

Explanation

In the stated favorable setting, differential cryptanalysis requires 2472^{47} chosen pairs, while random plaintext may require 2552^{55} pairs. Linear cryptanalysis has a separate requirement of 2432^{43} plaintext–ciphertext pairs, so the remaining statements confuse these attack conditions.

46. What is the appropriate current security assessment of single DES for confidential data?

Single DES is unsafe because its effective key contains 64 bits.
Single DES should not be used for confidential data because its key is too easy to search.
Single DES is acceptable when its 64-bit input representation is retained.
Single DES remains suitable because analytical attacks are practically efficient against it.
Single DES should be preferred because its key search cost is prohibitively high.

Single DES should not be used for confidential data because its key is too easy to search.

Explanation

Single DES should no longer protect confidential data because its effective 56-bit key can be searched at relatively low cost. Its 64-bit input representation includes eight parity bits, which are not key material. Current analytical attacks are not practically efficient against DES, but brute-force search is still feasible enough to rule out its use for confidential data.

47. Which statement(s) correctly characterize AES in comparison with DES?

AES is the algorithm of choice for many modern applications.
AES supports key lengths of 128, 192, and 256 bits.
AES offers substantially larger standard key sizes than DES.
AES accepts 64-bit keys with eight parity bits in its standard configurations.
AES uses an effective 56-bit key like single DES.

AES is the algorithm of choice for many modern applications. · AES supports key lengths of 128, 192, and 256 bits. · AES offers substantially larger standard key sizes than DES.

Explanation

AES supports 128-, 192-, and 256-bit keys and is the algorithm of choice for many modern applications. These standard key sizes are substantially larger than DES’s effective 56-bit key. AES does not use 64-bit keys with DES-style parity bits, nor does it use a 56-bit effective key.

48. Triple DES applies which transformation to a plaintext block?

Triple DES applies encryption, then two successive decryptions.
Triple DES applies encryption, then decryption, then encryption.
Triple DES applies a single DES encryption followed by a key permutation.
Triple DES applies decryption, then encryption, then decryption.
Triple DES applies three successive encryption operations with one key.

Triple DES applies encryption, then decryption, then encryption.

Explanation

Triple DES uses the EDE sequence: encryption under k1k_1, decryption under k2k_2, and encryption under k3k_3. The other sequences do not match the specified construction.

49. Regarding AES and Rijndael, which statement or statements are correct?

AES uses a 128-bit block for every supported key length.
Rijndael permits block lengths of 192 and 256 bits.
AES retains a fixed block size when its key length changes.
AES uses 192-bit blocks with its 192-bit keys.
Rijndael supports a broader range of block lengths than AES.

AES uses a 128-bit block for every supported key length. · Rijndael permits block lengths of 192 and 256 bits. · AES retains a fixed block size when its key length changes. · Rijndael supports a broader range of block lengths than AES.

Explanation

AES uses a fixed 128-bit block, while Rijndael also permits 192- and 256-bit blocks. Changing the AES key length changes the number of rounds, not the block size; AES does not use 192-bit blocks with 192-bit keys.

50. The number of AES rounds varies with the key length as follows:

A 256-bit AES key is processed through 12 rounds.
A 256-bit AES key is processed through 14 rounds.
A 192-bit AES key is processed through 12 rounds.
A 128-bit AES key is processed through 10 rounds.
Longer AES keys require more rounds than shorter supported keys.

A 256-bit AES key is processed through 14 rounds. · A 192-bit AES key is processed through 12 rounds. · A 128-bit AES key is processed through 10 rounds. · Longer AES keys require more rounds than shorter supported keys.

Explanation

AES uses 10, 12, and 14 rounds for 128-, 192-, and 256-bit keys, respectively. Thus, longer supported keys correspond to more rounds, while a 256-bit key does not use 12 rounds.

51. Which statements correctly describe NIST’s standardization of AES?

FIPS PUB 197 published Rijndael as the DES replacement in 1999.
NIST’s AES publication occurred in the year 2001.
NIST selected Rijndael as the new AES in 2001.
FIPS PUB 197 published AES as a United States standard.
The AES standardization decision identified Rijndael as the selected algorithm.

NIST’s AES publication occurred in the year 2001. · NIST selected Rijndael as the new AES in 2001. · FIPS PUB 197 published AES as a United States standard. · The AES standardization decision identified Rijndael as the selected algorithm.

Explanation

NIST selected Rijndael as AES and published it in FIPS PUB 197 in 2001. The publication was not issued in 1999, and the stated fact identifies it as the AES standard rather than describing it as a DES replacement.

52. AES candidates were expected to satisfy which requirements?

They had to offer competitive security.
They had to support 128-, 192-, and 256-bit keys.
They had to operate efficiently in software and hardware.
They had to use a 128-bit block size.
They were required to use 192-bit blocks for every candidate.

They had to offer competitive security. · They had to support 128-, 192-, and 256-bit keys. · They had to operate efficiently in software and hardware. · They had to use a 128-bit block size.

Explanation

AES candidates were required to use 128-bit blocks, support the three specified key lengths, provide competitive security, and be efficient in both software and hardware. A 192-bit block size was not the stated requirement.

53. Which statements about the order of a finite field are correct?

The prime p in q=pmq=p^m is the field characteristic.
A finite field of order q can exist when q is a prime power.
A finite field of order 12 is permitted because 12 is even.
A finite field of order 15 is permitted because 15 has prime factors.
The order can be written as q=pmq=p^m with p prime.

The prime p in $$q=p^m$$ is the field characteristic. · A finite field of order q can exist when q is a prime power. · The order can be written as $$q=p^m$$ with p prime.

Explanation

Finite fields have prime-power order, expressed as q=pmq=p^m, where p is prime and is the characteristic. Twelve and fifteen are not prime powers, so their being composite does not make them valid finite-field orders.

54. Regarding the algebraic structure of a field, which statements are correct?

Multiplication distributes over addition in a field.
The field elements form an additive abelian group.
A field permits nonzero elements without multiplicative inverses.
The nonzero field elements form a multiplicative abelian group.
A field requires multiplication to be noncommutative.

Multiplication distributes over addition in a field. · The field elements form an additive abelian group. · The nonzero field elements form a multiplicative abelian group.

Explanation

A field has an additive abelian group, a multiplicative abelian group on its nonzero elements, and distributive multiplication. Nonzero elements must have multiplicative inverses, and multiplication is commutative rather than noncommutative.

55. A byte in AES is represented algebraically in which way?

The polynomial coefficients belong to GF(3).
AES represents each byte by a polynomial of degree at most 8.
Each byte is treated as an element of GF(2^8).
The byte is represented by a polynomial of degree at most 7.
The corresponding finite field contains 256 elements.

Each byte is treated as an element of GF(2^8). · The byte is represented by a polynomial of degree at most 7. · The corresponding finite field contains 256 elements.

Explanation

AES represents bytes as elements of GF(2^8), which has 256 elements. The polynomial representation has degree at most 7 and coefficients in GF(2); a degree of at most 8 is not the stated representation.

56. Which statements characterize the prime field GF(p)?

GF(p) contains the elements from 0 through p−1.
Its arithmetic is performed modulo a composite number p.
Multiplication in GF(p) is performed modulo the prime p.
GF(p) contains p+1 elements.
Addition in GF(p) is performed modulo the prime p.

GF(p) contains the elements from 0 through p−1. · Multiplication in GF(p) is performed modulo the prime p. · Addition in GF(p) is performed modulo the prime p.

Explanation

The prime field GF(p) consists of the elements from 0 through p−1, with both addition and multiplication taken modulo the prime p. It therefore contains p elements, includes zero, and excludes p itself.

57. Which statements correctly describe the transformations in an AES round?

A standard AES round includes byte substitution.
The final AES round omits ShiftRows and key addition.
The final AES round includes MixColumns.
ShiftRows contributes diffusion within the AES state.
Every AES round applies MixColumns, including the final round.

A standard AES round includes byte substitution. · ShiftRows contributes diffusion within the AES state.

Explanation

AES rounds use byte substitution and diffusion through ShiftRows and MixColumns, together with key addition. The final round omits MixColumns but retains ShiftRows and key addition, so statements asserting the opposite are incorrect.

58. The AES S-box construction involves which operations?

The field element zero is mapped to zero during inversion.
The affine transformation is applied before the field inversion.
The construction begins with inversion in GF(2^4).
It begins by computing inversion in GF(2^8).
An affine transformation is applied after the inversion step.

The field element zero is mapped to zero during inversion. · It begins by computing inversion in GF(2^8). · An affine transformation is applied after the inversion step.

Explanation

The AES S-box first computes inversion in GF(2^8), maps zero to zero, and then applies an affine transformation. It does not begin in GF(2^4), and the affine transformation follows rather than precedes inversion.

59. Regarding the AES ShiftRows transformation, which statements are correct?

The second state row shifts cyclically left by three bytes.
The third state row shifts cyclically right by two bytes.
The fourth state row shifts cyclically right by one byte.
The first state row remains unchanged.
The second state row shifts cyclically right by three bytes.

The third state row shifts cyclically right by two bytes. · The fourth state row shifts cyclically right by one byte. · The first state row remains unchanged. · The second state row shifts cyclically right by three bytes.

Explanation

ShiftRows leaves the first row unchanged and cyclically shifts the second, third, and fourth rows right by three, two, and one bytes. The second row therefore does not shift left by three bytes.

60. Which statements correctly describe AES Key Addition?

Key Addition combines the state and subkey using integer multiplication.
The state and subkey each contain 16 bytes.
Key Addition combines the state and subkey using bitwise XOR.
The operation incorporates a 16-byte subkey into the 16-byte state.
The XOR operation corresponds to addition in GF(2).

The state and subkey each contain 16 bytes. · Key Addition combines the state and subkey using bitwise XOR. · The operation incorporates a 16-byte subkey into the 16-byte state. · The XOR operation corresponds to addition in GF(2).

Explanation

Key Addition combines a 16-byte state with a 16-byte subkey by bitwise XOR. XOR is addition in GF(2); integer multiplication is not the operation used for this layer.

Review with flashcards

Memorize the answers with 96 flashcards on Affine and Stream Ciphers.

What is cryptology?

The general field including cryptography and cryptanalysis.

What does cryptography secure communication against?

An adversary.

What does cryptanalysis study?

How to break cryptosystems.

See flashcards →

Read the study sheet

Read the complete study sheet on Affine and Stream Ciphers.

See study sheet →

Similar courses

Create your own quizzes

Import your course and AI generates quizzes with corrections in 30 seconds.

Quiz generator