What does SSL/TLS stand for?
Secure Sockets Layer
Transport Layer Security
Describe what is meant by symmetric key encryption.
A single key is used for both encryption and decryption
Identify two items commonly found within a digital certificate.
Two from: • Name of certificate holder // Subject • Serial number • Version number • Expiration date // Start date // Validity (not before/not after) • Certificate holder’s public key // Subject public key • Subject digital signature • Certificate Issuer // Digital signature of CA
State two functions of SSL/TLS.
Ensure security/privacy when using the internet
Data encryption
Identification / authentication of client and server
Give two examples of situations where the use of SSL/TLS would be appropriate.
When transmitting authentication data e.g. passwords, session cookies
When transmitting data that must be protected from modification on its way to or from a server e.g. user input, or results from the server
When transmitting data classified as non-public.
State two drawbacks of symmetric encryption
Key has to be exchanged securely [1]
Once compromised the key can be used to decrypt both sent and received messages [1]
Cannot ensure non-repudiation (proof of integrity and origin of data) [1]
State two drawbacks of quantum cryptography.
Currently can only be used over relatively short distances
Very expensive to implement initially due to costs of installation / hardware / implementation // Requires a dedicated line and specialist hardware
The technology to fully implement quantum cryptography is not currently/readily available
Photon polarization might be impacted in the travelling medium // It is possible for the polarisation of the light to be altered while travelling down fibre optic cables
Due to the inherent security system generated by quantum cryptography, terrorists and other criminals can use the technology to hide their activities from government law enforcement
Describe what is meant by a digital certificate.
A digital certificate is an electronic/online document.
used to authenticate/prove the identity of a website/the online identity of an individual/organisation
typically issued by a CA
it contains information identifying a website owner/individual and a public key
Describe the purpose of asymmetric key cryptography
To provide better security
… by using two different keys / a public key and a private key
State what is meant by a private key.
A private key is the unpublished/secret key/never transmitted anywhere.
It has a matching public key
It is used to decrypt data that was encrypted with its matching public key
Outline the process that would allow a business to use encryption keys to send a verified message to a group of people
The organisation generates a matched pair of encryption keys
The organisation makes its public key available to the group of people / via its website
The organisation encrypts its message using its private key
and sends it to the group of people
Anyone receiving the message can decrypt it using the organisation’s public key
Therefore, verifying the sender // Providing non-repudiation
State three possible benefits of using quantum cryptography.
Better security for internet communication
Can detect eavesdropping, enabling the receiver to request another key
Virtually unhackable due to rapidly changing quantum states
Keys are non-duplicable // No-cloning theorem
BONUS
BONUS
Explain how a digital signature is produced before the message is sent.
The message is hashed with (the agreed hashing algorithm)
to produce a message digest
The message digest is then encrypted with the sender’s private key to form the digital signature
Give two reasons for using key cryptography and give two methods of key cryptography that can be used.
Reasons for using key cryptography:
To ensure the message is authentic // came from a trusted source
To ensure that only the intended receiver is able to understand the message
To ensure the message has not been altered during transmission
Non-repudiation, neither the sender or receiver can deny the transmission occurred
Explain why a digital certificate is required to validate a digital signature.
A digital certificate provides a public key
… which validates the private key used to create the digital signature
It makes a digital signature virtually impossible to spoof // Provides evidence of signer identity that the document was not altered and the signatures are valid
Non repudiation.
Identify the two main protocols that form Transport Layer Security (TLS) and state the purpose of each.
Handshake protocol
To establish a secure and reliable connection between two devices, systems or networks // Permits the web server and client to authenticate each other to make use of encryption algorithms
Record protocol
Provides a secure and reliable way to send and receive data over a network // To exchange records between the client and server // Responsible for securing application data end ensuring its integrity and authenticity during transmission // Encrypts and authenticates data exchanged between a client and a server // Deals with the format for data transmission.
Outline the process followed to acquire a digital certificate.
*answer on the slide*
Secure Socket Layer (SSL) and Transport Layer Security (TLS) are two protocols. Explain how SSL/TLS is used when client-server communication is initiated.
An SSL/TLS connection is initiated by an application/client.
Every new session begins with a handshake as defined by the SSL/TLS protocols.
The client requests the digital certificate from the server // The server sends the digital certificate to the client.
The client verifies the server’s digital certificate
… and obtains the server’s public key.
The encryption algorithms are agreed. // The symmetric session keys are generated/defined.
A secure session is established between client and server
Explain how the digital signature can be checked on receipt to ensure that the message has not been altered during transmission.
The digital signature received is decrypted with the sender’s public key to recover the message digest sent
The decrypted message received is hashed with the agreed hashing algorithm to reproduce the message digest of the message received
The two message digests are compared
… if they are the same the message has not been altered // if they are different the message has been altered