Unit 4: Cryptography
Information Security notes · PTU syllabus (BSIT501)
On this page
- Unit summary
- Cryptography concepts
- Classical techniques: substitution and transposition
- Symmetric and asymmetric key cryptography
- Steganography
- DES: structure and analysis
- AES: structure and analysis
- Public key cryptosystems: principles
- The RSA algorithm
- Digital signatures
- Key terms
- Quick revision
- Important questions
Unit summary
Cryptography is the mathematical core of information security. This unit covers cryptography concepts and techniques, symmetric and asymmetric key cryptography, steganography, the DES and AES symmetric ciphers, public key cryptosystem principles, the RSA algorithm and digital signatures.
After this unit you can
- Explain cryptography concepts and classical techniques
- Distinguish symmetric and asymmetric cryptography and steganography
- Explain the structure of DES and AES
- Apply RSA and explain digital signatures
PTU syllabus topics
- Cryptography concepts and techniques
- symmetric and asymmetric key cryptography
- steganography
- symmetric key ciphers (DES, AES structure and analysis)
- asymmetric key ciphers (public key cryptosystem principles, RSA algorithm)
- digital signatures
DES
Symmetric block cipher
56 bits: now insecure
AES
Symmetric block cipher
128, 192 or 256 bits
RSA
Asymmetric, public key
Typically 2048 bits or more
Topic 1
Cryptography concepts
- 1Plaintext
Readable message
- 2Encryption algorithm with key
- 3Ciphertext
Unreadable message sent
- 4Decryption algorithm with key
- 5Plaintext recovered
- Cryptography
- Science of secret writing
- Cryptanalysis
- Breaking ciphers without the key
- Cryptology
- Cryptography and cryptanalysis together
- Key
- Secret value controlling encryption
- Brute-force attack
- Trying every possible key
Topic 2
Classical techniques: substitution and transposition
Caesar cipher
Shift each letter by k positions
k = 3: HELLO → KHOOR
Monoalphabetic
Each letter replaced by a fixed other letter
26! possible keys, but frequency analysis breaks it
Playfair
Digrams encrypted using a 5 × 5 key square
Used in World War I
Vigenère (polyalphabetic)
Shift varies with a keyword
Key LEMON
Rail fence (transposition)
Write in zigzag rows, read row by row
HELLOWORLD with 2 rails → HLOOLELWRD
Columnar transposition
Write in rows, read columns in key order
Key 3-1-2
- Substitution replaces symbols; transposition rearranges them; modern ciphers combine both in many rounds (product ciphers).
Topic 3
Symmetric and asymmetric key cryptography
Keys
One shared secret key
Pair — public key and private key
Speed
Fast
Slower
Key distribution
Difficult — key must be shared securely
Easy — public key can be published
Examples
AES, DES, 3DES
RSA, ECC
Use
Bulk data encryption
Key exchange, digital signatures
- Hybrid approach (SSL/TLS): asymmetric encryption to exchange a session key, then symmetric encryption for data.
- Public/private key pair: what one key encrypts only the other can decrypt — encrypt with the receiver's public key for confidentiality; sign with the sender's private key for authentication.
- Hash functions (SHA-256) produce fixed-length digests for integrity checks; AES is the common symmetric standard; RSA and elliptic-curve cryptography are common asymmetric methods.
Topic 4
Steganography
- Steganography: hiding the existence of a message inside another medium — image, audio, video or text — rather than making it unreadable.
- Techniques: least significant bit (LSB) substitution in image pixels, invisible ink, hidden text, audio echo hiding; digital watermarking marks ownership.
Goal
Makes the message unreadable
Hides that a message exists
Visibility
Ciphertext is obvious
Cover file looks normal
Attack
Cryptanalysis
Steganalysis
Best practice
Combine both: encrypt, then hide
Combine both: encrypt, then hide
Topic 5
DES: structure and analysis
- Data Encryption Standard (DES, 1977): a symmetric block cipher based on the Feistel structure; 64-bit block, 56-bit effective key (64 with parity), 16 rounds, 48-bit round keys.
- 1Initial permutation of the 64-bit block
- 2Split into left and right 32-bit halves
- 316 Feistel rounds
Right half expanded to 48 bits, XORed with round key, passed through 8 S-boxes, permuted, XORed with left half; halves swapped
- 432-bit swap
- 5Final permutation (inverse of the initial) gives the ciphertext
- Analysis: the 56-bit key is too short — brute-forced in 1998 (EFF's DES Cracker) in days; avalanche effect is strong; S-boxes resist differential cryptanalysis. Triple DES (encrypt–decrypt–encrypt with two or three keys) extended its life but is now deprecated.
Topic 6
AES: structure and analysis
- Advanced Encryption Standard (AES, 2001): the Rijndael cipher selected by NIST; 128-bit block; key sizes 128, 192 or 256 bits with 10, 12 or 14 rounds; not a Feistel cipher (substitution–permutation network).
- 1SubBytes
Each byte replaced using the S-box
- 2ShiftRows
Rows shifted cyclically left by 0, 1, 2, 3
- 3MixColumns
Columns mixed by matrix multiplication (omitted in the last round)
- 4AddRoundKey
State XORed with the round key
- Analysis: no practical attack on full AES is known; fast in hardware and software (AES-NI instructions); used in Wi-Fi WPA2/WPA3, TLS, disk encryption and VPNs.
Block size
64 bits
128 bits
Key size
56 bits
128, 192, 256 bits
Rounds
16
10, 12, 14
Structure
Feistel network
Substitution–permutation network
Security today
Insecure
Secure
Topic 7
Public key cryptosystems: principles
- Proposed by Diffie and Hellman (1976). Each user has a public key (published) and a private key (secret); deriving the private key from the public key must be computationally infeasible (based on hard problems — factoring, discrete logarithms).
- Encryption and decryption
- Encrypt with receiver's public key; only the private key decrypts
- Digital signature
- Sign with sender's private key; anyone verifies with the public key
- Key exchange
- Agree a shared secret session key (Diffie–Hellman)
Topic 8
The RSA algorithm
- 1
Choose two large primes p and q
- 2
Compute n = p × q and φ(n) = (p − 1)(q − 1)
- 3
Choose e with 1 < e < φ(n) and gcd(e, φ(n)) = 1
- 4
Compute d such that d × e mod φ(n) = 1
- 5
Public key (e, n); private key (d, n)
- 6
Encrypt C = M^e mod n; decrypt M = C^d mod n
Example
p = 3, q = 11 → n = 33, φ(n) = 20. Choose e = 3 (gcd(3, 20) = 1). d = 7, since 3 × 7 = 21 mod 20 = 1. Encrypt M = 4: C = 4³ mod 33 = 64 mod 33 = 31. Decrypt: 31⁷ mod 33 = 4.
- Security: rests on the difficulty of factoring n; keys of 2048 bits or more are recommended.
Topic 9
Digital signatures
- Digital signature: an electronic signature using asymmetric cryptography and a hash function to authenticate the signer and ensure integrity.
- 1Hash the document
- 2Encrypt the hash with the signer's private key
- 3Send document, signature and certificate
- 4Receiver decrypts the signature with the public key
- 5Compare with a fresh hash — match means authentic and unaltered
- Digital Signature Certificate (DSC): classes based on verification level (Class 3 and document signer certificates now in use); used for MCA filings, income-tax returns, GST, e-tenders.
- Aadhaar e-Sign: online electronic signature using Aadhaar OTP or biometric authentication.
- Properties: authentication of the signer, integrity of the message, non-repudiation. Standards: RSA signatures, DSA (Digital Signature Standard), ECDSA; legally valid in India under the IT Act, 2000.
Key terms
- Ciphertext
- Encrypted, unreadable message
- Steganography
- Hiding the existence of a message
- Feistel cipher
- Structure splitting blocks into halves processed over rounds
- AES
- Current symmetric block cipher standard
- RSA
- Public key algorithm based on factoring large numbers
Quick revision
- Plaintext, ciphertext, key, cryptanalysis; substitution and transposition ciphers.
- Symmetric vs asymmetric; hybrid systems; hashing.
- Steganography vs cryptography.
- DES: 64-bit block, 56-bit key, 16 rounds; AES: 128-bit block, 10/12/14 rounds.
- Public key principles; RSA steps; digital signatures.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Encrypt "CAB" with the Caesar cipher (k = 3).
- Q2.Distinguish substitution and transposition ciphers.
- Q3.What is steganography?
- Q4.State the block and key sizes of DES.
- Q5.Name the four steps of an AES round.
- Q6.On what mathematical problem is RSA based?
Long-answer questions
- Q1.Explain classical encryption techniques with examples.
- Q2.Explain the structure of DES and AES and compare them.
- Q3.Explain the principles of public key cryptosystems and the RSA algorithm with an example.
- Q4.Explain digital signatures.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.
