Symmetric Encryption Principles�
Symmetric Encryption Principles
Plaintext
Message
Encryption
Algorithm
Secret
Key
Plaintext
Message
Decryption
Algorithm
Secret
Key
Transmitted Ciphertext
Symmetric encryption
Symmetric encryption is a form of cryptosystem in which encryption and decryption are performed using the same key. It is also known as conventional encryption.
● Symmetric encryption transforms plaintext into ciphertext using a secret key and an encryption algorithm. Using the same key and a decryption algorithm, the plaintext is recovered from the ciphertext.
Figure :Symmetric encryption and decription
Traditional symmetric ciphers use substitution and/or transposition techniques.
●Rotor machines are sophisticated precomputer hardware devices that use substitution techniques.
Symmetric Cryptography�
chapter-3rd
7
Symmetric key
chapter-3rd
8
Fig. Symmetric cryptography
Attributes of Strong Encryption
chapter-3rd
9
Types of Encryption
Encrypts blocks of data, often 128 bits
Operates on a continuous stream of data
Block Chiper
A block cipher is an encryption/decryption scheme in which a block of plaintext is treated as a whole and used to produce a ciphertext block of equal length.
● Many block ciphers have a Feistel structure. Such a structure consists of a number of identical rounds of processing. In each round, a substitution is performed on one half of the data being processed, followed by a permutation that interchanges the
two halves. The original key is expanded so that a different key is used for each round.
● The Data Encryption Standard (DES) has been the most widely used encryption algorithm until recently. It exhibits the classic Feistel structure. DES uses a 64-bit block and a 56-bit key.
Feistel Cipher
Feistel Network Structure
chapter-3rd
13
Encrypt
Decrypt
CIPHERTEXT
PLAINTEXT
Decryption of Fiestel cipher
Data Encryption Standard (DES)
chapter-3rd
15
Symmetric Encryption
chapter-3rd
16
Modern Block Ciphers
chapter-3rd
17
Block Cipher Principles
chapter-3rd
18
chapter-3rd
19
Figure 8-5 Example of Symmetric Encryption
Symmetric Encryption (cont’d.)
chapter-3rd
20
DES
chapter-3rd
21
DES - Basics
chapter-3rd
22
DES
Looking at the left-hand side of the figure, we can see that the processing of the plaintext proceeds in three phases. First, the 64-bit plaintext passes through an initial permutation (IP) that rearranges the bits to produce the permuted input. This is followed by a phase consisting of 16 rounds of the same function, which involves both permutation and substitution functions. The output of the last (sixteenth) round consists of 64 bits that are a function of the input plaintext and the key. The left and right halves of the output are swapped to produce the preoutput. Finally, the preoutput is passed through a permutation (IP-1) that is the inverse of the initial permutation function, to produce the 64-bit ciphertext. With the exception of the initial and final permutations, DES has the exact structure of a Feistel cipher.
The right-hand portion of shows the way in which the 56-bit key is used. Initially, the key is passed through a permutation function. Then, for each of the 16 rounds, a subkey (Ki) is produced by the combination of a left circular shift and a permutation. The permutation function is the same for each round, but a different subkey is produced because of the repeated shifts of the key bits.
DES Overview
chapter-3rd
27
Figure Encryption and decryption with DES
DES Structure
chapter-3rd
28
DES uses 16 rounds. Each round of DES is a Feistel cipher
chapter-3rd
29
The heart of DES is the DES function. The DES function applies a 48-bit key to the rightmost 32 bits to produce a 32-bit output. �
chapter-3rd
30
Expansion P-box
chapter-3rd
31
chapter-3rd
32
S-Boxes
The S-boxes do the real mixing (confusion). DES uses 8 S-boxes, each with a 6-bit input and a 4-bit output. See Figure 6.7.
Continue
Figure 6.7 S-boxes
chapter-3rd
33
Continue
Figure 6.8 S-box rule
Feistel Network Structure
chapter-3rd
34
Encrypt
Decrypt
CIPHERTEXT
PLAINTEXT
Each Iteration Use of a Different Sub-key
chapter-3rd
35
DES Key Processing
chapter-3rd
36
The Key Schedule
chapter-3rd
37
DES Decryption
Decrypt must unwind steps of data computation
With Feistel design, do encryption steps again
Using subkeys in reverse order (SK16 … SK1)
Note that IP undoes final FP step of encryption
1st round with SK16 undoes 16th encrypt round
….
16th round with SK1 undoes 1st encrypt round
then final FP undoes initial encryption IP
thus recovering original data value
chapter-3rd
38
Strength of DES – Key Size
chapter-3rd
39
Strength of DES – Timing Attacks
chapter-3rd
40
Strength of DES – Analytic Attacks
chapter-3rd
41
Security of DES
chapter-3rd
6.42
Attack Methods
chapter-3rd
43
6.5.1
Attack Methods-II
chapter-3rd
44
DES- Current State
chapter-3rd
45
3DES or Triple-DES
chapter-3rd
46
Triple DES - More Secure
chapter-3rd
47
3DES
chapter-3rd
48
3DES
chapter-3rd
49
3DES
chapter-3rd
50
3DES or Triple-DES
chapter-3rd
51
3DES or Triple-DES
chapter-3rd
52
Triple DES
AES – The Advanced Encryption Standard
AES (2)
AES (3)
AES
chapter-3rd
57
AES
chapter-3rd
58
AES
chapter-3rd
59
AES
chapter-3rd
60
Evaluation Criteria for �AES Proposals
chapter-3rd
61
Symmetric Key Encryption- Strength
chapter-3rd
62
AES Algorithm – High Level
chapter-3rd
63
chapter-3rd
64
The State and Key Schedule
chapter-3rd
65
Rounds and Transformation Stages
chapter-3rd
66
Rounds and Transformation Stages
chapter-3rd
67