Cipher Deck

D334 · Intro to Cryptography
Card 1 / 1 All topics
Category
Loading…
tap to flip
Answer
tap to flip back
Mastered 0 of 0

25-question rounds drawn from a 75-question bank — play a few rounds back to back and you'll cycle through everything before it repeats.

Question 1 / 1 Score 0
Asymmetric encryption — the key steps

This is the single most heavily tested concept. The rule that never changes: encrypt with the recipient's public key, sign with your own private key.

Confidentiality only

  1. Sender encrypts the message with the receiver's public key.
  2. Receiver decrypts it with their own private key.

Digitally signed message (authentication + integrity)

  1. Sender hashes the message.
  2. Sender encrypts the hash with their own private key — this is the signature.
  3. Sender transmits the plaintext message + signature.
  4. Receiver hashes the received message, then decrypts the signature with the sender's public key and compares the two hashes.

Confidential AND authenticated message (the full pipeline)

  1. Sender hashes the message and signs the hash with their own private key (authentication).
  2. Sender generates a random one-time symmetric session key.
  3. Sender encrypts the message + signature with that symmetric key (fast, provides confidentiality).
  4. Sender encrypts the symmetric key itself with the receiver's public key (secure key exchange).
  5. Sender transmits the encrypted message bundle + the encrypted symmetric key.
  6. Receiver decrypts the symmetric key with their own private key, then uses it to decrypt the message, then verifies the signature with the sender's public key.

Known before encryption is applied: the plaintext, the algorithm, and a nonce/IV where the mode requires one are known to both sides ahead of time. The recipient's private key is never known to the sender — only the recipient's public key, the algorithm, and the plaintext are shared inputs.

Whiteboard cram sheet — dump this first

This is the exact "memory jogger" layout from the study notes. Write it out from memory a few times before the OA, then dump it onto your whiteboard in the first minute.

CipherBlockKeyRounds
DES645616
3DES6411246
Skipjack648032
Blowfish6432–448*16
IDEA64128< 17
RC264≤ 40—
RC532 / 64 / 1280–2048varies
XTEA6412832
AES128128 / 192 / 25610 / 12 / 14
RC6128128 / 192 / 25620
Twofish128128 / 192 / 25616
Camellia128128 / 192 / 256—

*Some study sheets list Blowfish's key as 128/192/256 — the original spec is a variable 32–448-bit key. Go with whatever your course material states if the two disagree.

Symmetric

DES · 3DES · RC2 · RC4 · AES

Asymmetric

RSA (1024–4096-bit keys) · ECC (more efficient per bit) · ElGamal (encryption + signatures) · DSA (FIPS 186, signatures only)

Hashing

MD5 → 128-bit · SHA-1 → 160-bit · SHA-256 → 256-bit

Block cipher modes, one word each

ECB = same · CBC = chain · CFB = stream · OFB = IV stream · CTR = counter/nonce

Wireless

WEP = RC4, 40-bit key · WPA = TKIP+RC4, 128-bit key · WPA2 = AES-CCMP, 128-bit key

Mobile

GSM (2G) = A5/1 & A5/2 · 3GPP (3G) = KASUMI = A5/3

PKCS #Covers
#1RSA cryptography standard
#5Password-based encryption
#7Cryptographic message syntax (PKI-related messages)
#10Certificate signing request
#12Personal info exchange — key + certificate package
Symmetric block cipher chart
Block size: everything is 64 bits except AES, RC6, Twofish, Camellia (128 bits) and RC5 (variable).
Key size: those same "128‑bit block" algorithms mostly run 128 / 192 / 256 — everything else you memorize individually.
AlgorithmBlock (bits)Key (bits)Rounds
DES645616
3DES6411246
Blowfish6432–44816
IDEA64128< 17
RC264≤ 40—
Skipjack648032
XTEA6412832
RC532 / 64 / 128 (varies)0–2048 (varies)varies
AES (Rijndael)128128 / 192 / 25610 / 12 / 14
RC6128128 / 192 / 25620
Twofish128128 / 192 / 25616
Camellia128128 / 192 / 256—

AES and RC4 are both symmetric — that's the similarity the exam is fishing for, even though AES is a block cipher and RC4 is a stream cipher. RC4 and ChaCha are the two stream ciphers to know; RC4 (historically 40-bit) is what WEP is built on.

Hashing & asymmetric algorithm quick reference
Hash algorithmOutput size
MD5128-bit
SHA-1160-bit
SHA-256256-bit

RSA

Key sizes typically range 1024–4096 bits; can both encrypt and sign.

ECC (Elliptic Curve)

Achieves the same security as RSA with much smaller keys — more efficient per bit of security.

ElGamal

Asymmetric algorithm usable for both encryption and digital signatures.

DSA

Digital Signature Algorithm — signatures only (no encryption), defined by FIPS 186.

Block cipher modes of operation

ECB — Electronic Codebook

Each block is encrypted independently with the same key. No IV, no chaining, so identical plaintext blocks always produce identical ciphertext blocks. Weakest mode — patterns in the plaintext leak through.

CBC — Cipher Block Chaining

The IV is XORed with the first plaintext block before encryption. The resulting ciphertext block is then XORed with the next plaintext block before it's encrypted, and so on — each block's encryption depends on the one before it.

CFB — Cipher Feedback

The IV is encrypted (not the plaintext). That encrypted output is XORed with the plaintext block to make the ciphertext. That same ciphertext block is then fed back in and encrypted to produce the keystream for the next block. Turns a block cipher into a self-synchronizing stream cipher.

OFB — Output Feedback

The IV is encrypted, and that output is XORed with the plaintext block to make ciphertext — but unlike CFB, the encrypted output itself (not the ciphertext) is fed back and re-encrypted to generate the next block's keystream. The keystream can be precomputed independent of the data.

CTR — Counter

A nonce combined with an incrementing counter is encrypted, and the result is XORed with the plaintext block. Every block is completely independent, which makes CTR parallelizable and fast — no chaining dependency at all.

Classical / historical ciphers

Caesar cipher

Simple substitution — every letter is shifted a fixed number of positions through the alphabet.

Vigenère / polyalphabetic cipher

Uses a repeating keyword to pick a different Caesar shift for each letter. Broken by the Kasiski examination, which looks for repeated sequences in the ciphertext — the distance between repeats reveals likely key lengths.

Playfair cipher

Encrypts pairs of letters (digraphs) using a 5×5 matrix built from a keyword (I and J share a cell).

Bifid cipher

Plots each letter onto coordinates in a Polybius square (mapping letters to numeric values), then fractionates and recombines those coordinates to diffuse a single letter's information across the ciphertext.

Attacks & cryptanalysis

Brute force

Systematically tries every possible key until the correct one is found.

Differential cryptanalysis

Studies how differences in plaintext input propagate into differences in the resulting ciphertext, to recover information about the key.

Linear cryptanalysis

Builds linear approximations that describe the cipher's behavior well enough to recover key bits statistically.

Algebraic attack

Models the cipher as a system of equations (often Boolean) and solves the system to recover the key.

Rainbow table

Precomputed table of hash chains used to reverse hashed passwords quickly instead of brute forcing each one.

Birthday attack

Exploits the birthday paradox to find hash collisions faster than brute force would suggest.

Wireless security: WEP, WPA, WPA2
WEPWPAWPA2
Encryption methodRC4TKIP + RC4AES-CCMP
Key size40-bit128-bit128-bit
Cipher typeSymmetric streamSymmetric streamSymmetric block
IV size24-bit48-bit48-bit

WEP's short 24-bit IV combined with a static key is what breaks it — the IV space is small enough that it reuses quickly, exposing the keystream. WPA fixed this as a stop-gap by rotating keys per packet with TKIP, still riding on RC4. WPA2 replaced the stream cipher entirely with an AES-based block cipher (CCMP) — the newest standard this course covers (no WPA3 content on the exam).

WPA-Personal

Authenticates with a shared pre-shared key (PSK) — for home/small networks.

WPA-Enterprise

Authenticates each user individually against a RADIUS/802.1X server rather than one shared password.

IPSec: transport vs. tunnel mode

Transport mode

Encrypts only the payload of the IP packet; the original header stays visible. Used end-to-end between two hosts. Traffic can be inspected at intermediate points, since routing information is not protected.

Tunnel mode

Encrypts the entire original packet (header included) and wraps it in a new IP header. Used gateway-to-gateway (e.g. site-to-site VPN). Traffic is fully protected in transit; it can only be inspected before it enters the tunnel or after it exits.

ComponentPort / Protocol
IKE (key negotiation)UDP 500
ESPIP protocol 50
AHIP protocol 51
Hashing & password storage

SHA-1

Produces a 160-bit hash value.

LM hash / NTLM (as tested in this course)

The password is padded with null characters up to 14 characters, then the padded value is encrypted with DES to produce the hash. This padding-to-14 weakness is a big reason legacy LAN Manager–style hashing is considered broken.

Chaskey

A lightweight MAC algorithm built around a 128-bit permutation.

Hashing digital evidence

Investigators hash evidence at collection time so they can later prove the data was never altered — any change to the evidence produces a completely different hash value, demonstrating integrity in court.

Certificates, PKI & PKCS standards

PEM (Privacy Enhanced Mail)

Base64, text-based encoding format used for certificates and keys — the ".pem" file you see everywhere.

Key / certificate lifecycle

Initialization

Key pair generated, identity verified, certificate request created.

Issued

CA signs and publishes the certificate; it's now active and usable.

Cancellation

Certificate is revoked or expires and is removed from trusted use.

OCSP (Online Certificate Status Protocol)

Lets a client check in real time whether a specific certificate has been revoked, instead of downloading a full CRL.

StandardWhat it defines
PKCS #1RSA cryptography standard — RSA encryption and signature schemes.
PKCS #5Password-based encryption standard.
PKCS #7Cryptographic Message Syntax — format for signed/encrypted PKI messages.
PKCS #10Certificate signing request (CSR) format.
PKCS #12Package format bundling a private key with its certificate for storage/transport.
Other core concepts

TRNG (True Random Number Generator)

Generates randomness from unpredictable physical phenomena (thermal noise, radioactive decay, etc.), as opposed to a deterministic pseudo-random algorithm.

Clipper chip

1990s NSA-backed encryption chip that used the Skipjack algorithm with a built-in government key-escrow backdoor.

Forward secrecy

Ensures that if a long-term private key is ever compromised, past session traffic still can't be decrypted, because each session used its own ephemeral key (typically via ephemeral Diffie-Hellman) that was never derived from the long-term key.

Homomorphic encryption

Allows computations to be performed directly on encrypted data, producing an encrypted result that matches what you'd get computing on the plaintext — without ever revealing the plaintext.

Mobile network stream ciphers

2G GSM networks used A5/1 and the deliberately weaker export-grade A5/2 for over-the-air voice/data encryption. 3G (3GPP) networks moved to KASUMI, also known as A5/3.

Key length vs. performance vs. security

As key length increases: security improves, but performance (encryption/decryption speed) decreases.

Prime numbers

A number greater than 1 that is only evenly divisible by 1 and itself — the foundation of RSA and other asymmetric algorithms.

Blockchain basics

A blockchain is a distributed, append-only ledger — each block references and cryptographically hashes the block before it, so altering old data breaks every block after it. Bitcoin adds a new block roughly every 10 minutes, and as the chain grows longer the mining reward decreases over time (block reward halving), even though total network difficulty tends to rise.

Bitcoin vs. Ethereum

Bitcoin uses proof-of-work mining (solving hash puzzles) purely to move currency. Ethereum also runs a blockchain but adds smart contracts — self-executing code stored on-chain — and has since moved from proof-of-work to proof-of-stake, where validators are chosen based on coins they lock up rather than computing power spent.

—
XOR reminder: compare each bit position — the result is 1 only when the two bits differ (0⊕0=0, 1⊕1=0, 0⊕1=1, 1⊕0=1).

MOD reminder: a mod n is just the remainder when a is divided by n. A result of 0 means n divides evenly into a (e.g. 8 mod 4 = 0).