10/07/2007

Encryption Resources

Here are some books with good information on Encryption/Cryptography:

Cryptography: Theory and Practice - Douglas R. Stinson's Cryptography: Theory and Practice is a mathematically intensive examination of cryptography, including ciphers, the Data Encryption Standard (DES), public key cryptography, one-way hash functions, and digital signatures. Stinson's explication of "zero- sum proofs"--a process by which one person lets another person know that he or she has a password without actually revealing any information--is especially good.

SSH, The Secure Shell: The Definitive Guide - You can't go wrong with thisO'Rielly book - and this one is a mustall Unix users/admins as SSH quickly becomes a popular choice for securing remote transfers and connections.

Handbook of Applied Cryptography - A hefty handbook for both novices and experts, introducing practical aspects of conventional and public-key cryptography and offering information on the latest techniques and algorithms in the field. Mathematical treatments accompany practical discussions of areas including pseudorandom bits and sequences, stream and block ciphers, hash functions, and digital signatures.

Computer and Internet Ebooks - Helpful computer and Internet related ebooks.

The Internet has thousands of encryption/cryptography related resources. Here are a few that cover a broad range of topics:

Radius.net Software Archive - Your one stop shop for any and all encryption related software.

Phil Zimmermann's Homepage - The creator of PGP and a cryptography pioneer.

PGP Distribution site - MIT Distribution Center for PGP (Pretty Good Privacy).

Hushmail - Web based email with strong encryption.

AES - Information on AES (Advanced Encryption Standard) from NIST.

Cryptographic Toolkit - NIST's cryptography standard.

Windows 2000 Hight Encryption pack - Upgrade security on this popular operating system.

Encryption and Linux - The Linux Encryption-HOWTO Homepage.

Cipher - IEEE security and privacy newsletter.

C.R.I.S. - The Cryptography and Information Security Research Laboratory.

Encryption in the workplace - How electronic encryption works and how it will change your business.

Encryption and computer crime - Computer Crime and Intellectual Property Section (CCIPS).

Revised U.S. Encryption Export Control Regulations - As of January 2000.

Encryption Tools

There are many free and paid encryption tools available on the Internet. Some better than others, but nonetheless one can setup a secure messaging system (email encryption), secure transactions (SSL enabled web browsers) and secure connectivity (VPNs and SSH) on a very small budget. Some of the small business/individual solutions available include:


EMAIL
PGP - this is the defacto secure messaging standard on the Internet. Network Associates has dropped this product suite but fortunately the strong user base of PGP means it is likely to stay as the most popular email encryption tool.

Hushmail - here is another way of adding encryption to your email. But unlike software tools (say PGP) it is a service built into web based email. With free and paid service, one can get the flexibility of a web based email account combined with the security of 1,024-bit encryption, digital signatures and support for the OpenPGP standard.


FILE ENCRYPTION
Private File - Private File is a fast and easy way to protect yourself and your company by encrypting your files before sending them. With a simple drag-and-drop, or a menu point-and-click, your information is safe. And with the strongest encryption, you can be sure that no one but your desired recipient will be able to use your information.

F-Secure FileCrypto - developed by Datafellows Corp, this is a long standing file encryption application that supports strong encryption. Also comes for Pocket PC.

ShyFile - free and paid versions of a strong encryption application that lets you create self-executable, encrypted packages.


VPNs
Guardster - secure surfing and VPN type solution for individuals.

Secure Shuttle Transport - ideal solution for individuals or small businesses, providing complete VPN solution with a 20 user license.

PGP - certain versions of this applications allow point to point encrypted VPN sessions.

Windows NT/2000/XP & Linux - they allow 'secure' data transmssion between two nodes using the PPTP protocol.

Virtual Private Networks (VPNs)

Recent technological advances in broadband and dial data access offer a more cost-effective solution for supporting large numbers of remote users, as well as unprecedented network scalability and flexibility. These technology advances have created virtual private networks (VPN) using public links. They can be used to provide mobile workers with remote access to the corporate network - at the price of a local call. As with any use of public networks, one sacrifices privacy for cost and availability. Except a VPN is a network tunnel created for data transmission between two or more authenticated parties. A secure VPN encrypts data before passing it through the network tunnel. This creates an encrypted "pipe" between the user and the access device ensuring data integrity/authenticity, and user privacy. Apart from providing connectivity for remote users, VPNs can also be used to interconnect servers and complete networks, creating entities known as Extranets.





Virtual Private Networks can be implemented by using propreitory systems from Nortel Networks, Cisco, Datafellows, Intel, Nokia, Checkpoint, Lucent and others. Point to point VPNs can also be created using imbedded protocols in Operating Systems like Windows 2000/XP/Linux or even by applications like PGP.


IPSEC
The IP Security Protocol (IPSec) working group has defined a set of specifications for cryptographically-based authentication, integrity, and confidentiality services at the IP datagram layer. This protocol is intended to secure data communications on the Internet and is one of the fastest growing security standards worldwide. IPSec supports multiple algorithms and key management systems within its design architecture.

Most people associate VPNs with corporate or government use. But individual users can utilize the power of personal VPN services like Guardster. This service allow you to surf the Internet anonymously, use encrypted email, have private instant messaging, secure file transfers, etc. Secure Shuttle Transport is an ideal small business VPN solution, coming with a 20 user license while priced at well below $100.

Encrypted Email

One of the most common uses of encryption is in electronic messaging. Encryption can be used to secure email on public and private networks. Unlike e-mail on a private system, which goes directly to a mail server and resides there until it is retrieved, Internet e-mail bounces from server to server on its way to a recipient. This makes the transmission channel impossible to secure and provides numerous opportunities for interception. Here it makes sense to secure the message itself by using encryption. But private networks are not immune to the need for higher security and often employ encryption to guarantee the integrity of the message.

Sending plaintext email is like sending a postcard - what type of information do you disclose when mailing a postcard? When do you consider putting the letter in an envelope to resist tampering and to protect your privacy? Similarly, encrypting email is the first step to securing the contents of your message. One of the most popular methods of email encryption is the use of public key encryption.

The two most widely fielded methods of email encryption are PGP (Pretty Good Privacy) and Entrust. The former provides solutions for both individuals and corporations while Entrust focuses on the larger enterprise based secure messaging solutions. Also availabe to individual users/small businesses is encrypted email on a web based platform through Hushmail. This service allows you to send and receive email from their website, never having to buy any software or have the need for extra infrastructure.

Also available is S/MIME (Secure / Multipurpose Internet Mail Extensions) - a protocol that adds digital signatures and encryption to Internet MIME messages. The MIME format allows the body of the message to be text, graphics, audio/video, etc allowing one to encrypt multiple forms of newsgroup communications.

Encrypted mail enables the 'little guy' to decide how much privacy they want and when and where they want it. The Tools section has resources one could use for encrypted and anonymous email.

Planning on getting a new email address? Check this site out for email hosting options!

Cracking Encryption Algorithms

Need for secure encryption algorithms
Good cryptographic systems should always be designed so that they are as difficult to break as possible. Governments have always had concerns with strong encryption fearing that it could be used against their countries by criminals. Sophisticated technology is used by law enforcement agencies to decipher encrypted information that might contain incriminating evidence. In theory one can break any encryption algorithm by exhausting every key in a sequence. This brute force method requires vast amounts of computing power as length of the key increase. For example a 32-bit key takes 2^32 (4294967296) steps. A system with 40 bit keys (e.g. US-exportable version of RC4) takes 2^40 steps - this kind of computing power is available in most universities and even small companies.


Encryption key lengths & hacking feasibility
Type of Attacker Budget Tool Time & Cost/Key
40 bit Time & Cost/Key
56 bit
Regular User Minimal

$400 Scavenged computer time

FPGA 1 week

5 hours ($.08) Not feasible

38 years ($5,000)
Small Business $10,000 FPGA 1 12 min.($.08) 556 days ($5,000)
Corporate Department $300,000 FPGA

ASIC 2 24 sec. ($.08)

0.18 sec. ($.001) 19 days ($5,000)

3 hours ($38)
Large Corporation $10M ASIC 0.005 sec.($0.001) 6 min. ($38)
Intelligence Agency $300M ASIC 0.0002 sec.($0.001) 12 sec. ($38)


As key lengths increase, the number of combinations that must be tried for a brute force attack increase exponentially. For example a 128-bit key would have 2^128 (3.402823669209e+38) total possible combinations. For example, to theoretically crack the 128-bit IDEA key using brute force one would have to:


develop a CPU that can test 1 billion IDEA keys per second

build a parallel machine that consists of one million of these processors

mass produce them to an extent that everyone can own one hundred of these machines

network them all together and start working through the 128 bit key space
Assuming ideal performance and no downtime, one should be able to exhaustively search the key-space in over 20,000 years. A common concern amongst many is deciding what key length is secure. There is a metronome for technological progress called Moore's Law which states that; "the number of components that can be packed on a computer chip doubles every 18 months while the price stays the same" . Essentially, this means that computing power per dollar doubles every eighteen months. Using a derivative of this above law one can also say that, if a key length of x is considered safe today, in 18 months the key length would have to be x+1 to keep up to par with the computing power. Recent studies performed by independent scientists have shown that key lengths should be no less than 90-bits long to ensure complete security for the next 20 years.

1 FPGA (Field Programmable Gate Arrays) are programmable pieces of hardware specifically designed for encryption/decryption.

2 ASIC (Application Specific Integrated Circuits) are also specialized hardware that can test 200 million keys per second.

Public Key Encryption

1976 saw the introduction of a radical new idea into the field of cryptography. This idea centered around the premise of making the encryption and decryption keys different - where the knowledge of one key would not allow a person to find out the other. Public key encryption algorithms are based on the premise that each sender and recipient has a private key, known only to him/her and a public key, which can be known by anyone. Each encryption/decryption process requires at least one public key and one private key. A key is a randomly generated set of numbers/ characters that is used to encrypt/decrypt information.

A public key encryption scheme has six major parts:

Plaintext - this is the text message to which an algorithm is applied.

Encryption Algorithm - it performs mathematical operations to conduct substitutions and transformations to the plaintext.

Public and Private Keys - these are a pair of keys where one is used for encryption and the other for decryption.

Ciphertext - this is the encrypted or scrambled message produced by applying the algorithm to the plaintext message using key.

Decryption Algorithm - This algorithm generates the ciphertext and the matching key to produce the plaintext.


Selecting the Public and Private Keys
Select large prime numbers p and q and form n = pq.
Select an integer e > 1 such that GCD(e, (p - 1)(q - 1)) = 1.
Solve the congruence, ed º 1 (mod (p - 1), (q - 1))
for an integer d where 1 < d < (p - 1)(q - 1).
The public encryption key is (e,n).
The private encryption key is (d,n).
The Encryption Process
• The process of encryption begins by converting the text to a pre hash code. This code is generated using a mathematical formula.

• This pre hash code is encrypted by the software using the senders private key. The private key would be generated using the algorithm used by the software.

• The encrypted pre hash code and the message are encrypted again using the sender's private key.

• The next step is for the sender of the message to retrieve the public key of the person this information is intended for.

• The sender encrypts the secret key with the recipient's public key, so only the recipient can decrypt it with his/her private key, thus concluding the encryption process.


Lookup the user's public key (e , n ).
Make sure that the message M is an integer such that 0 £ M £ n.
Compute, M ^ e º C (mod n) where 0 £ C £ n.
Transmit the integer C.
The Decryption Process
• The recipient uses his/her private key to decrypt the secret key.

• The recipient uses their private key along with the secret key to decipher the encrypted pre hash code and the encrypted message.

• The recipient then retrieves the sender's public key. This public key is used to decrypt the pre hash code and to verify the sender's identity.

• The recipient generates a post hash code from the message. If the post hash code equals the pre hash code, then this verifies that the message has not been changed en-route.


Use your private key (d , n ).
Receive the integer C, where 0 £ C £ n.
Compute, C ^ d º R (mod n) where 0 £ R £ n.
R is the original message.
Featured article:
A Primer on Public Key Encryption
by Charles C. Mann.

How Encryption Works

The concept behind encryption is quite simple - make the data unlegible for everyone else except those specified. This is done using cyrptography - the study of sending 'messages' in a secret form so that only those authorized to receive the 'message' be able to read it.

The easy part of encryption is applying a mathematical function to the plaintext and converting it to an ecrypted cipher. The harder part is to ensure that the people who are supposed to decipher this message can do so with ease, yet only those authorised are able to decipher it. We of-course also have to establish the legitimacy of the mathematical function used to make sure that it is sufficiently complex and mathmatically sound to give us a high degree of safety.

The essential concept underlying all automated and computer security application is cyptography. The two ways of going about this process are conventional (or symmetric) encryption and public key (or asymmetic) encryption.

Featured articles:
A Primer on Public Key Encryption
by Charles C. Mann.

Introduction to Cryptography
by Peter Meyer.