2082

CSC327 · TU past paper

Cryptography 2082 question paper

The complete TU 2082 exam paper for Cryptography (CSC327), all 12 questions with solved model answers written to the mark scheme.

Tap a question to open its answer.

  1. 1NumericalFiestel Cipher StructureAnswer

    Feistel Cipher Structure and AES Key Expansion

    Feistel Cipher Structure and AES Key Expansion

    Part A: Feistel Cipher Structure

    A Feistel Cipher is a symmetric block cipher design that splits a plaintext block into two equal halves and processes them through several rounds of substitution and permutation using round sub-keys derived from the master key.

    Working

    A block of $2w$ bits is divided into $L_0$ (left) and $R_0$ (right).

    For each round $i$:

    $$L_i = R_{i-1}$$ $$R_i = L_{i-1} \oplus F(R_{i-1}, K_i)$$

    where $K_i$ is the round sub-key and $F$ is the round function (which need not be invertible).

    Block Diagram (words)

    • Split plaintext into $L_0$ and $R_0$.
    • Feed $R_0$ and $K_1$ into $F$.
    • XOR $F$ output with $L_0 \Rightarrow R_1$.
    • $R_0$ becomes $L_1$ (swap).
    • Repeat for $n$ rounds; recombine $L_n, R_n$ into ciphertext.

    Key Properties

    • Same structure for encryption and decryption (sub-keys reversed for decryption).
    • $F$ need not be invertible.
    • Security grows with more rounds.
    • Examples: DES (16 rounds), Blowfish, Camellia.

    Part B: AES Key Expansion - First 4 Bytes After First Iteration

    Given Data

    Key (16 bytes) grouped into 4 words:

    WordBytes
    $W_0$2B 7E 15 16
    $W_1$28 AE D2 A6
    $W_2$AB F7 97 66
    $W_3$01 02 03 04

    S-Box row 0 provided (sufficient, since all bytes being substituted have upper nibble 0).

    Formula

    $$W_4 = W_0 \oplus g(W_3)$$

    Step 1: RotWord of $W_3 = [01,02,03,04]$: $$[02,\ 03,\ 04,\ 01]$$

    Step 2: SubBytes (row 0 of S-Box):

    ByteS-Box
    02 → col 277
    03 → col 37B
    04 → col 4F2
    01 → col 17C

    $$[77,\ 7B,\ F2,\ 7C]$$

    Step 3: XOR Rcon(1) = [01,00,00,00]: $$[77\oplus01,\ 7B,\ F2,\ 7C] = [76,\ 7B,\ F2,\ 7C]$$

    So $g(W_3) = [76, 7B, F2, 7C]$.

    Step 4: Compute $W_4 = W_0 \oplus g(W_3)$:

    $W_0$$g(W_3)$XOR
    2B765D
    7E7B05
    15F2E7
    167C6A

    Verification of first byte: $2B = 0010,1011$, $76 = 0111,0110$, XOR $= 0101,1101 = 5D$. ✓

    Final Answer

    $$\boxed{W_4 = [5D,\ 05,\ E7,\ 6A]}$$

    The first 4 bytes of the next key after the first iteration are 5D 05 E7 6A.

  2. 210 marksNumericalMan-in-the-Middle AttackAnswer

    Illustrate the man in middle attack in Diffie-Hellman key exchange protocol. Assume the prime number be 19 and 10 as its primitive root. Select 5 as private key and 4 as random integer. Find the cipher text of M = 2 using Elgamal crypto system.[10]

    Man-in-the-Middle Attack on Diffie-Hellman & ElGamal Cryptosystem

    Given Data

    • Prime number: $p = 19$
    • Primitive root: $g = 10$
    • Private key: $x = 5$
    • Random integer: $k = 4$
    • Message: $M = 2$

    Part 1: Man-in-the-Middle Attack on Diffie-Hellman

    Normal Diffie-Hellman

    Public parameters: $p = 19$, $g = 10$.

    1. Alice picks private $X_A$, sends $Y_A = g^{X_A} \bmod p$.
    2. Bob picks private $X_B$, sends $Y_B = g^{X_B} \bmod p$.
    3. Shared key: $K = Y_B^{X_A} \bmod p = Y_A^{X_B} \bmod p$.

    The Attack

    An attacker Darth (D) sits between Alice and Bob. Since plain Diffie-Hellman has no authentication, Darth impersonates each side to the other.

    csc327-dh-mitm
    

    Darth chooses two private keys $X_{D1}, X_{D2}$ and computes: $$Y_{D1} = g^{X_{D1}} \bmod p, \qquad Y_{D2} = g^{X_{D2}} \bmod p$$

    Alice (A)                Darth (D)                Bob (B)
       |--- Y_A ------------->|                          |
       |                      |--- Y_D1 ---------------->|
       |                      |<-- Y_B ------------------|
       |<-- Y_D2 -------------|                          |
    

    Steps:

    1. Alice sends $Y_A$; Darth intercepts it.
    2. Darth sends $Y_{D1}$ to Bob.
    3. Bob sends $Y_B$; Darth intercepts it.
    4. Darth sends $Y_{D2}$ to Alice.

    Resulting keys:

    PartyKey computed
    Alice$K_1 = Y_{D2}^{X_A} \bmod p$
    Darth (with Alice)$K_1 = Y_A^{X_{D2}} \bmod p$
    Darth (with Bob)$K_2 = Y_B^{X_{D1}} \bmod p$
    Bob$K_2 = Y_{D1}^{X_B} \bmod p$

    Consequence: Alice shares $K_1$ with Darth (thinking it is Bob), Bob shares $K_2$ with Darth (thinking it is Alice). Darth decrypts, reads, possibly alters, and re-encrypts every message. The attack succeeds because DH does not authenticate the parties.


    Part 2: ElGamal Cryptosystem

    Step 1: Key Generation

    Public key: $$y = g^x \bmod p = 10^5 \bmod 19$$

    • $10^2 = 100 \equiv 5 \pmod{19}$
    • $10^4 \equiv 5^2 = 25 \equiv 6 \pmod{19}$
    • $10^5 \equiv 6 \cdot 10 = 60 \equiv 60 - 57 = 3 \pmod{19}$

    $$\boxed{y = 3}$$

    Public key = $(p=19,\ g=10,\ y=3)$; Private key = $5$.

    Step 2: Encryption of $M = 2$ with $k = 4$

    Compute $C_1$: $$C_1 = g^k \bmod p = 10^4 \bmod 19 = 6$$

    Compute $C_2$: $$y^k \bmod p = 3^4 \bmod 19 = 81 \bmod 19 = 5$$ $$C_2 = (y^k \cdot M)\bmod p = (5 \cdot 2)\bmod 19 = 10$$

    Final Answer

    $$\textbf{Ciphertext } (C_1, C_2) = (6,\ 10)$$

    Verification (Decryption)

    $$M = C_2 \cdot (C_1^{x})^{-1} \bmod p$$

    • $6^5 \bmod 19$: $6^2 = 36 \equiv 17$; $6^4 \equiv 17^2 = 289 \equiv 4$; $6^5 \equiv 4 \cdot 6 = 24 \equiv 5$.
    • $5^{-1} \bmod 19 = 4$ (since $5 \cdot 4 = 20 \equiv 1$).
    • $M = 10 \cdot 4 \bmod 19 = 40 \bmod 19 = 2 \checkmark$

    Recovered $M = 2$, matching the original message.

  3. 310 marksProperties of Hash functionsAnswer

    Describe the properties of hash functions. Discuss how hash value is generated using SHA-1 algorithm.[10]

    A hash function is a function that maps a message of any length into a fixed-length hash value, which serves as the authenticator. Cryptographic hash functions play a fundamental role in efficient and secure information processing. Prope...

  4. 45 marksTypes of Malicious LogicAnswer

    Describe any three types of malicious logic. [5]

    Malicious Logic


    Malicious Logic (Malicious Code / Rogue Programs)

    Malicious logic refers to a set of instructions or programs that are intentionally designed to cause harm, unauthorized access, or disruption to a computer system or network.


    1. Trojan Horse

    A Trojan Horse is a program that appears to perform a legitimate or useful function but secretly contains hidden code that performs unauthorized or harmful actions when executed.

    • It does not replicate itself (unlike a virus).
    • It tricks the user into running it by disguising itself as a legitimate program.
    • Example: A user downloads what appears to be a free game, but the program secretly installs a backdoor, allowing an attacker to gain remote access to the system.
    • Damage: Data theft, unauthorized access, system damage.

    2. Virus

    A virus is a piece of malicious code that attaches itself to a legitimate program or file and replicates when that program is executed. It requires a host program to spread.

    • It can spread from one computer to another through infected files, email attachments, or removable media.
    • A virus typically has two phases:
      • Infection phase: It attaches itself to other programs.
      • Attack phase: It performs its malicious activity (deleting files, corrupting data, etc.).
    • Example: A virus attached to a .exe file that corrupts system files when executed.
    • Damage: File corruption, system crashes, data loss.

    3. Worm

    A worm is a self-contained, self-replicating program that spreads across networks without needing to attach itself to a host program. Unlike a virus, it does not require user interaction to propagate.

    • It exploits vulnerabilities in operating systems or network services to spread automatically.
    • Worms consume network bandwidth and system resources, causing slowdowns or crashes.
    • Example: The Morris Worm (1988) spread across the Internet by exploiting UNIX vulnerabilities, causing widespread system slowdowns.
    • Damage: Network congestion, system resource exhaustion, data theft.

    Summary Table

    TypeReplicates?Needs Host?Spreads Via
    Trojan HorseNoYes (disguise)User deception
    VirusYesYes (host file)Infected files/media
    WormYesNoNetwork/vulnerabilities

    Other types of malicious logic include Logic Bombs (code that triggers under specific conditions) and Trapdoors/Backdoors (hidden entry points left by developers for unauthorized access).

  5. 55 marksNumericalSubstitution TechniquesAnswer

    Given the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]

    Playfair Cipher: Encrypting "TURINGTEST" with Key "HELLOWORLD"

    STEP 1 - EXTRACT (Given data)

    • Key: HELLOWORLD
    • Plaintext: TURINGTEST
    • Cipher: Playfair (5x5 matrix, I/J combined)

    STEP 2 - SOLVE

    Build the 5x5 Matrix

    Key letters, removing duplicates (keep first occurrence): H, E, L, O, W, R, D
    (HELLOWORLD → H, E, L, [L dup], O, W, [O dup], R, [L dup], D)

    Fill remaining alphabet (I/J together): A, B, C, F, G, I/J, K, M, N, P, Q, S, T, U, V, X, Y, Z

    C1C2C3C4C5
    R1HELOW
    R2RDABC
    R3FGI/JKM
    R4NPQST
    R5UVXYZ

    Split into digrams

    TURINGTEST → TU | RI | NG | TE | ST

    No double letters within a pair, length is even, so no padding needed.

    Apply rules

    TU: T(R4,C5), U(R5,C1) → rectangle
    T → (R4, C1) = N; U → (R5, C5) = Z → NZ

    RI: R(R2,C1), I(R3,C3) → rectangle
    R → (R2, C3) = A; I → (R3, C1) = F → AF

    NG: N(R4,C1), G(R3,C2) → rectangle
    N → (R4, C2) = P; G → (R3, C1) = F → PF

    TE: T(R4,C5), E(R1,C2) → rectangle
    T → (R4, C2) = P; E → (R1, C5) = W → PW

    ST: S(R4,C4), T(R4,C5) → same row (shift right, wrap)
    S → C5 = T; T → C1 (wrap) = N → TN

    Final Ciphertext

    Plain pairCipher pair
    TUNZ
    RIAF
    NGPF
    TEPW
    STTN

    $$\boxed{\text{Ciphertext} = \text{NZAFPFPWTN}}$$

  6. 65 marksModes of Block Cipher EncryptionsAnswer

    Explain any two modes of block cipher encryption. [5]

    A block cipher encrypts data in fixed-size blocks. When a message is longer than one block, a mode of operation defines how the cipher is applied repeatedly. Two important modes are described below. --- Definition: In ECB mode, the plain...

  7. 75 marksDigital Signature StandardAnswer

    Describe the working mechanism of digital signature algorithm. [5]

    A Digital Signature is a cryptographic mechanism where content is digitally signed with an individual's private key and verified using the individual's public key. It provides authentication, integrity, and non-repudiation. --- - Signing...

  8. 85 marksNumber TheoryAnswer

    State Fermat's theorem with example. What is the implication of discrete logarithm? [5]

    Statement: If p is a prime number and a is a positive integer such that gcd(a, p) = 1 (i.e., a is not divisible by p), then: $$a^{p-1} \equiv 1 \pmod{p}$$ An alternative (and equally important) form of Fermat's theorem is: $$a^p \equiv a...

  9. 95 marksFirewalls and their typesAnswer

    List and explain the types of firewall. [5]

    Types of Firewall


    Firewall

    A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It establishes a barrier between a trusted internal network and untrusted external networks.


    Types of Firewall

    1. Packet Filtering Firewall

    • Operates at the Network Layer (Layer 3) of the OSI model.
    • Inspects each packet passing through the network and filters them based on rules such as source IP, destination IP, port numbers, and protocols.
    • It does not examine the content of the packet.
    • Advantage: Fast and efficient.
    • Disadvantage: Cannot detect application-level attacks; stateless (does not track connection state).

    2. Stateful Inspection Firewall (Dynamic Packet Filtering)

    • Operates at the Network and Transport Layer.
    • Tracks the state of active connections and makes filtering decisions based on the context of traffic (e.g., whether a packet is part of an established connection).
    • Maintains a state table to monitor ongoing sessions.
    • Advantage: More secure than simple packet filtering.
    • Disadvantage: Slower than packet filtering; cannot inspect application-layer data.

    3. Application Layer Firewall (Proxy Firewall)

    • Operates at the Application Layer (Layer 7).
    • Acts as an intermediary (proxy) between the client and the server; it intercepts all messages entering and leaving the network.
    • Can inspect the full content of network traffic including HTTP, FTP, DNS, etc.
    • Advantage: Provides deep packet inspection; hides internal network details.
    • Disadvantage: Slower performance due to deep inspection; requires more resources.

    4. Circuit-Level Gateway

    • Operates at the Session Layer (Layer 5).
    • Monitors TCP handshaking and session establishment to determine whether a requested session is legitimate.
    • Does not inspect the actual content of the packets.
    • Advantage: Faster than application-layer firewalls; hides internal network information.
    • Disadvantage: Cannot filter individual packets after the session is established.

    5. Next-Generation Firewall (NGFW)

    • Combines the features of traditional firewalls with advanced capabilities such as:
      • Deep Packet Inspection (DPI)
      • Intrusion Prevention System (IPS)
      • Application awareness and control
      • SSL/TLS inspection
    • Can identify and block sophisticated attacks including malware and application-layer threats.
    • Advantage: Comprehensive security; highly effective against modern threats.
    • Disadvantage: Expensive and complex to configure.

    Summary Table

    TypeOSI LayerKey Feature
    Packet FilteringNetwork (L3)Filters by IP/port rules
    Stateful InspectionNetwork/TransportTracks connection state
    Application Layer (Proxy)Application (L7)Deep content inspection
    Circuit-Level GatewaySession (L5)Monitors TCP handshake
    Next-Generation FirewallMultiple LayersDPI + IPS + App control
  10. 105 marksChallenge Response SystemAnswer

    Define authentication system. Discuss about challenge response system. [5]

    Authentication System and Challenge Response System

    Authentication System

    An authentication system is a security measure put in place to secure data and systems by requiring additional input beyond username and password for users to access a system.

    Components of an Authentication System

    An authentication system consists of five components required for the overall authentication process:

    ComponentDescription
    Authentication Information (A)Information that provides identity (e.g., password, PIN)
    Complementary Information (C)Information stored on the computer used to validate authentication information
    Complementation Function (F)Function that generates complementary information from authentication information
    Authentication Function (I)Function that verifies and provides identity
    Selection Function (S)Function enabling an entity to create or alter information A or C

    Types of Authentication Factors

    • Something the individual knows: Password, PIN
    • Something the individual possesses: Smart cards, cryptographic keys
    • Something the individual is: Fingerprint, retina, face recognition
    • Something the individual does: Voice pattern, handwriting recognition

    Challenge Response System

    A challenge response system is a handshake authentication process in which the authenticator issues a challenge to the user seeking authentication, and the user must provide a correct response in order to be authenticated.

    Working Process

    The process works as follows:

    Step 1: User requests access to the system
    Step 2: Server (authenticator) issues a CHALLENGE to the user
    Step 3: User responds to the challenge
    Step 4: Server verifies the response
             - If CORRECT  --> User is AUTHENTICATED
             - If INCORRECT --> User is DENIED
    

    Forms of Challenge

    The challenge may take many forms depending on the system:

    • A password request
    • A set of security questions that were answered by the user during first-time registration
    • A random number or token that the user must process using a shared secret key

    Example (One-Way Authentication using Challenge Response)

    Assume Alice and Bob share a secret key K_AB:

    Alice                              Bob
      |                                  |
      |--- "I am Alice" --------------->|
      |                                  |
      |<-- Challenge: R1 ---------------|
      |                                  |
      |--- Response: K_AB(R1) -------->|
      |                                  |
      |     Bob verifies K_AB(R1)        |
      |     If correct --> Authenticated |
    
    1. Alice sends her identity claim: "I am Alice"
    2. Bob issues a challenge (random number R1)
    3. Alice encrypts R1 using the shared key K_AB and sends it back
    4. Bob decrypts and verifies the response
    5. If the response matches, Alice is authenticated

    Advantages

    • Prevents replay attacks since a new challenge is issued each time
    • More secure than simple password-based authentication
    • The actual secret (key/password) is never transmitted directly over the network

    Summary: An authentication system verifies the identity of a user through its five components (A, C, F, I, S). The challenge response system strengthens this by requiring the user to prove knowledge of a secret by correctly responding to a server-issued challenge, making it resistant to eavesdropping and replay attacks.

  11. 11NumericalSubstitution TechniquesAnswer

    Decrypt the ciphertext 'HI' using Hill Cipher where the key is. Ciphertext: HI, Key: $$\begin{bmatrix} 5 & 3 \ 4 & 3 \end{bmatrix}$$

    Hill Cipher Decryption of Ciphertext 'HI'

    Given Data

    • Ciphertext: HI
    • Key Matrix:

    $$K = \begin{bmatrix} 5 & 3 \ 4 & 3 \end{bmatrix}$$

    • Alphabet mapping: A=0, B=1, ..., Z=25, modulus 26.

    Step 1: Convert Ciphertext to Numbers

    • H = 7
    • I = 8

    $$C = \begin{bmatrix} 7 \ 8 \end{bmatrix}$$


    Step 2: Decryption Formula

    $$P = K^{-1} C \pmod{26}$$


    Step 3: Determinant of K

    $$\det(K) = (5)(3) - (3)(4) = 15 - 12 = 3$$


    Step 4: Inverse of Determinant mod 26

    $$3 \cdot d^{-1} \equiv 1 \pmod{26}$$

    $$3 \times 9 = 27 \equiv 1 \pmod{26} \Rightarrow d^{-1} = 9$$


    Step 5: Adjugate of K

    $$\text{adj}(K) = \begin{bmatrix} 3 & -3 \ -4 & 5 \end{bmatrix} \equiv \begin{bmatrix} 3 & 23 \ 22 & 5 \end{bmatrix} \pmod{26}$$


    Step 6: Compute K⁻¹

    $$K^{-1} = 9 \cdot \begin{bmatrix} 3 & 23 \ 22 & 5 \end{bmatrix} \pmod{26} = \begin{bmatrix} 27 & 207 \ 198 & 45 \end{bmatrix} \pmod{26}$$

    • $27 \bmod 26 = 1$
    • $207 \bmod 26 = 207 - 182 = 25$
    • $198 \bmod 26 = 198 - 182 = 16$
    • $45 \bmod 26 = 19$

    $$K^{-1} = \begin{bmatrix} 1 & 25 \ 16 & 19 \end{bmatrix}$$

    Check: $K^{-1}K \pmod{26}$:

    • $(1)(5)+(25)(4)=5+100=105 \equiv 1$
    • $(1)(3)+(25)(3)=3+75=78 \equiv 0$
    • $(16)(5)+(19)(4)=80+76=156 \equiv 0$
    • $(16)(3)+(19)(3)=48+57=105 \equiv 1$

    Gives identity: inverse is correct.


    Step 7: Multiply K⁻¹ by C

    $$P = \begin{bmatrix} 1 & 25 \ 16 & 19 \end{bmatrix}\begin{bmatrix} 7 \ 8 \end{bmatrix} \pmod{26}$$

    • Row 1: $7 + 200 = 207 \equiv 207 - 182 = 25$
    • Row 2: $112 + 152 = 264 \equiv 264 - 260 = 4$

    $$P = \begin{bmatrix} 25 \ 4 \end{bmatrix}$$


    Step 8: Convert to Letters

    • 25 = Z
    • 4 = E

    Result

    $$\boxed{\text{Plaintext} = \textbf{ZE}}$$

    The ciphertext 'HI' decrypts to 'ZE'.

  12. 125 marksCertificate Life Cycle ManagementAnswer

    What is digital certificate? Discuss the certificate life cycle. [5]

    A digital certificate is a certificate issued by a Certificate Authority (CA) to verify the identity of the certificate holder. The CA issues an encrypted digital certificate containing the applicant's public key along with a variety of ...