1 of 18

PRF

collision-resistant

hash function

CPA-secure encryption

message authentication code

CCA-secure encryption

2 of 18

Cryptography v. real-life security

  • If I proved “scheme S is secure under assumption A” and someone uses S in real life, in what cases can things go wrong?
  • 1. Security definition does not match real-life attacking scenario
    • “Provable security” only protects security on the network level; other levels could go wrong (hardware/software attacks)
    • Use a weak security definition (e.g., EAV-security) in scenario where attacker is stronger than what definition covers (e.g., can observe (plaintext,ciphertext) pairs)
  • 2. Assumption A is false
  • 3. Implementation of S does not match algorithmic description of S
    • Conceptual mistakes while implementing
    • Software bugs

3 of 18

Public-key cryptography

  • Both MAC and encryption schemes are in “symmetric” setting
    • Setup: both honest parties share the same key in advance
    • Assume you have some physical method to share the key (not super practical in modern setting)

  • Public-key cryptography: remove this physical assumption
  • Require (heavy?) knowledge of number theory / algebra / other areas of math (depends on how deep you want to dive into the area)

4 of 18

Lecture 14: Modular Arithmetic

5 of 18

  •  

6 of 18

Division

  •  

7 of 18

Modular arithmetic

  •  

8 of 18

General rules for modular arithmetic

  •  

9 of 18

  •  

10 of 18

 

  •  

11 of 18

  •  

12 of 18

  •  

13 of 18

Group Theory

14 of 18

  •  

15 of 18

  •  

16 of 18

  •  

17 of 18

  •  

18 of 18

  •