Skip to main content
Cryptography and
Network Security
Principles
Cryptography is the study and practice of techniques for
secure communication in the presence of third parties called
adversaries. It deals with developing and analyzing protocols
that prevents malicious third parties from retrieving
information being shared between two entities thereby
following the various aspects of information security.
Secure Communication refers to the scenario where the message
or data shared between two parties can’t be accessed by an
adversary. In Cryptography, an Adversary is a malicious
entity, which aims to retrieve precious information or data
What is Cryptography
Cryptography concepts
The Main principles of cryptography are Confidentiality, Data
Integrity, Authentication, Non-repudiation
• Confidentiality refers to rules and regulations that make
sure that the data is restricted to certain people or
certain places.
• Data integrity ensures that data remains accurate and
consistent over its whole transmission process.
• Authentication ensures that the data is being claimed by
the person who is related to it.
• Non-repudiation ensures that a person or a party related to
the transmission process cannot deny the authenticity of
their signature on the data or the transmission of a
message.
Cryptography concepts
 Cryptography is the art and science of achieving
security by encoding messages to make them non-
readable.
 Cryptanalysis is the technique of decoding messages
from a non-readable format back to readable format
without knowing how they were initially converted from
readable format to non-readable format.
 Cryptology is a combination of cryptography and
cryptanalysis.
Cryptography Concepts
PLAIN TEXT & CIPHER TEXT
Plain Text : Clear text or plain text signifies a
message that can be understood by the sender, the
recipient and also by anyone else who gets an access to
that message.
Cipher Text : When a plain text message is codified
using any suitable scheme, the resulting message is
called as cipher text.
Cryptography operation
Receiver
Sender
Plain text
Plain text
Encryption Decryption
Cipher text Transmission Cipher text
Elements of a cryptographic operation
Cryptography operation
There are two primary ways in which a plain text message can be
codified to obtain the corresponding cipher text :
•Substitution
•Transposition.
Substitution-cipher technique:
In the substitution-cipher technique, the each characters of a
plain-text message are replaced by other characters, numbers or
symbols.
There are several techniques. They are:
• Caesar Cipher
• Modified version of Caesar Cipher
• Monoalphabetic Cipher
• Polyalphabetic Cipher
• Homophonic Substitution Cipher
• Polygram Substitution Cipher
• Playfair Cipher
• Hill Cipher
Caesar Cipher
Caesar Cipher
Proposed by Julius Caesar.
 Mechanism to make a plaintext message into ciphertext message.
 It replacing each letter of the alphabet with the letter
standing 3 places further down the alphabet.
 Example: Replace each A with D, B with E, etc.
ENCRYPTION & DECRYPTION
The process of encoding plain text messages into cipher
text message called as encryption.
The reverse process of transforming cipher text message
back to plain text is called decryption.
Decryption is exactly opposite of encryption. Encryption
transforms a plain text message into cipher text, where as
decryption transforms a cipher text message back into plain
text.
ENCRYPTION & DECRYPTION
The confidentiality and integrity of encrypted message
is given by two factors:
 The strength of encryption algorithm.
 The secrecy of the encryption key.
Every encryption and decryption process has two aspects the
algorithm and key used for encryption and decryption.
Input to encryption and decryption process is Algorithm and
key
Cryptography mechanisms
Broadly there are two cryptography mechanisms depending
on what keys are used. If the same key is used for
encryption and decryption is called a Symmetric key
cryptography. However two different key are used for
decryption is called Asymmetric key Cryptography.
Cryptography techniques
Symmetric key cryptography Asymmetric key cryptography
Symmetric key cryptography
 With symmetric encryption, both parties use the same key for
encryption and decryption purposes. Each user must possess the
same key to send encrypted messages to each other.
 The sender uses the key to encrypt their message, and then
transmits it to the receiver. The receiver, who is in
procession of the same key, uses it to decrypt the message.
 The security of this encryption model relies on the end users
to protect the secret key properly. If an unauthorized user
were able to intercept the key, they would be able toread any
encrypted messages sent by other users.
Asymmetric key cryptography
 Asymmetric Encryption is a form of Encryption where keys come
in pairs. What one key encrypts, only the other can decrypt. In
the sense that if key A encrypts a message, and then B can
decrypt it, and if key B encrypts a message, then key A can
decrypt it.
 While common, this property is not essential to asymmetric
encryption. Asymmetric Encryption is also known as Public Key
Cryptography, since users typically create a matching key pair,
and make one public while keeping the other secret.
Hash Function
 Hash functions: A hash function is a mathematical algorithm
that converts data of any size into a fixed-size output. This
means you can turn any length or type of message into a fixed
length of encrypted text. The process is one-way – there is no
way to reverse the encryption and get the original message
back. Hash functions are often used to verify the integrity of
data and ensure that it has not been tampered with.
One simple example of the system’s usefulness is to save hashes of
passwords instead of actual passwords. That way, even if you suffer a
breach, all the hacker would find are useless hashes. When a user
logs in with their password, you run it through the hash function and
compare the result with what you have on file. A match would mean
Applications of Cryptography
Cryptography has a wide range of applications in modern-day
communication, including:
•Secure online transactions: Cryptography is used to secure
online transactions, such as online banking and e-commerce,
by encrypting sensitive data and protecting it from
unauthorized access.
•Digital signatures: Digital signatures are used to verify
the authenticity and integrity of digital documents and
ensure that they have not been tampered with.
•Password protection: Passwords are often encrypted using
cryptographic algorithms to protect them from being stolen
or intercepted.
Military and intelligence applications: Cryptography is
widely used in military and intelligence applications to
Benefits of Cryptography
Secure communication: Encryption enables us to transmit private
information, bank details, passwords, and other sensitive
information over the internet. Apart from the Secure Sockets
Layer (SSL) and Transport Layer Security (TLS) protocols (that
are used almost everywhere) secure websites also use the HTTPS
protocol to help safeguard communication and protect from DNS
spoofing attacks.
Protection from attacks: You can defend against cyber attacks
like replay and man-in-the-middle. Keeping information private
also helps protect your business from identity theft or the
proliferation of private information made public.
Access control: Cryptography guarantees only parties with the
appropriate permissions have access to a resource.
Legal compliance: It helps businesses comply with several legal
requirements, such as data protection and privacy regulations.
some use cases for cryptography
BYOD device encryption
Most workplaces offer free WiFi to their employees, who
regularly bring their own phones and computers to access
the company network. With remote work still a common
practice, most workplaces should consider adding BYOD
(bring your own device) encryption to their network
security implementation.
Digital signatures
A digital signature is basically a way to ensure that an
electronic document (e-mail, spreadsheet, text file, etc.)
is authentic.
A digital signature is a mathematical scheme for
demonstrating the authenticity of a digital message or
document. A valid digital signature gives a recipient
reason to believe that the message was created by a known
sender, such that the sender cannot deny having sent the
message (authentication and non-repudiation) and that the
message was not altered in transit (integrity). Digital
signatures are commonly used for software distribution,
financial transactions, and in other cases where it is
important to detect forgery or tampering.
You could add digital signatures to almost any data created
or shared on your network using a combination of public key
cryptography and hash functions. It’s an excellent
technique to add integrity and identity verification to
Digital signatures
A digital signature is basically a way to ensure that an
electronic document (e-mail, spreadsheet, text file, etc.)
is authentic.
A digital signature is a mathematical scheme for
demonstrating the authenticity of a digital message or
document. A valid digital signature gives a recipient
reason to believe that the message was created by a known
sender, such that the sender cannot deny having sent the
message (authentication and non-repudiation) and that the
message was not altered in transit (integrity). Digital
signatures are commonly used for software distribution,
financial transactions, and in other cases where it is
important to detect forgery or tampering.
You could add digital signatures to almost any data created
or shared on your network using a combination of public key
cryptography and hash functions. It’s an excellent
technique to add integrity and identity verification to
Digital certificate
A digital certificate is an electronic
"passport" that allows a person, computer
or organization to exchange information
securely over the Internet using the public
key infrastructure (PKI). A digital
certificate may also be referred to as a
public key certificate.
Just like a passport, a digital certificate
provides identifying information is forgery
resistant and can be verified because it
was issued by an official, trusted agency.
The certificate contains the name of the
certificate holder, a serial number,
expiration dates, a copy of the certificate
holder's public key (used for encrypting
messages and digital signatures) and the
digital signature of the certificate-
issuing authority (CA) so that a recipient
can verify that the certificate is real.
Contents of Digital Certificate:
Version: Version of X.509 protocol.
Version can be 1,2 or 3
Certificate Serial No.: Contains unique
integer which is generated by CA
Signature Algorithm Identifier: Identifies
the algorithm used by CA to sign the
certificate.
Issuer Name: Identifies the Distinguished
Name that created & signed the certificate
Validity: (not before/not after) Contains two
date-time values. This value generally
specifies the date & time up to seconds or
milliseconds.
Subject name: Distinguished Name of the
end user (user or organization)
Subject Public key info.: This field can
never be blank. Contains public key &
algorithm related.
Issuer Unique Identifier: Helps identify a CA
uniquely if two or more CAs have used the
same Issuer Name over time.
Subject Unique Identifier: Helps identify a
subject uniquely if two or more subjects have
What is Network Security?
Network Security generally refers to action taken by an
enterprise or organization to protect and secure its computer
network and data. The main aim is to ensure the confidentiality
and accessibility of the network and data.
The network security model represents the secure communication
between sender and receiver. This model depicts how the security
service has been implemented over the network to prevent the
opponent from causing a threat to the authenticity or
What is Network Security?
 Network security covers a huge amount of technologies,
devices, and processes
 In simple words, it is a set of rules and regulations
designed for protecting and securing the integrity,
confidentiality, and accessibility of data and computer
networks.
 The most common example of network security is password
protection which was chosen by itself.
Importance of Network Security
 To protect sensitive information safe from cyber-
attacks.
 This is important to secure sensitive data safe from
cyber attacks and to ensure that the network is
usable and can be trusted
 Network security protects the data of the client by
ensuring that hackers can not get into your network
easily.
 Network security also improves the performance of
the network by ensuring that the system is not
slowed down due to redundant tools and data.
Applications of Cryptography and Network
Security
Cryptography Applications
 Authentication/Digital
Signatures
 Time Stamping
 Electronic Money
 Encryption/Decryption in
email
 WhatsApp Encryption
 Instagram Encryption
Network Security
Applications
 Protection of network.
 Protection from
intrusions.
 To protect from
threats.
 Protection of data from
breaches
Quiz
What does the term 'adversary' refer to in
cryptography?
 The sender of the message
 The recipient of the message
 A malicious entity trying to access data
 A secure communication channel
Which application of cryptography is used to verify
the authenticity of a digital document or message?
 Time Stamping
 Digital Signatures
 Encryption
 Network Security
INTERNET SECURITY PROTOCOL
In computing, Internet Protocol Security (IPSec) is a secure
network protocol suite that authenticates and encrypts the
packets of data to provide secure encrypted communication between
two computers over an Internet Protocol network. It is used in
virtual private networks (VPNs).
IPSec protects one or more paths between a pair of hosts, a pair
of security gateways, or a security gateway and a host. A
security gateway is an intermediate device, such as a router or
firewall, that implements IPsec. Two devices that use IPsec to
protect a path between them are called peers.
IPSec is not a single protocol, but rather a set of services and
protocols that provide a complete security solution for an IP
network. These services and protocols combine to provide various
IPSec protocol
Some of the kinds of protection services offered by IPsec
include the following:
■Encryption of user data for privacy
■ Confidentiality (encryption) – ensuring that the data has not
been read enroute.
■Protection against certain types of security attacks, such as
replay attacks.
■The ability for devices to negotiate the security algorithms
and keys required to meet their security needs.
■Two security modes, tunnel and transport, to meet different
network needs.
Types of IPSec
IPSEc Protocols Two primary types of IP Security (IPSec) protocols
exist:
• Encapsulating Security Payload (ESP) and
• Authentication Header (AH)
ESP provides authentication and encryption; AH provides
authentication but not encryption.
IPSec also implementation Data Encryption Standard (DES) or Triple
DES (3DES) for encryption. Both AH and ESP can used one of the two
mode.
1. Tunnel Mode : IPSec tunnel mode is useful for protecting traffic between different networks, when traffic must pass
through an intermediate, untrusted network. Tunnel mode is primarily used for interoperability with gateways.
2. Transport Mode: Transport mode is the default mode for IPSec, and it is used for end-to-end cmmunications (for
example, for communications between a client and a server). When transport mode is used, IPSec encrypts only the IP payload. In
USER AUTHENTICATION
Authentication means verifying the identity of someone (a
user, device, or an entity) who wants to access data,
resources, or applications. Validating that identity
establishes a trust relationship for further interactions.
Authentication also enables accountability by making it
possible to link access and actions to specific identities.
After authentication, authorization processes can allow or
Password Authentication
Passwords are the most common form of authentication. A password is
a string of alphabets, number and special character, which is
supposed to be known only to the entity that is being authenticated.
Simple password authentication offers an easy way of authenticating
users. In password authentication, the user must supply a password
for each server, and the administrator must keep track of the name
and password for each user, typically on separate servers.
Password-Based
Authentication
Password Authentication steps
Password authentication is performed in the following steps.
1. Prompt For user id and Password- The application sends a screen to
the user, prompting user id and password.
2. User enters user id and password- The user enters her id and password
and presses the ok button.This causes the user id and password to
travel in clear text to the server.
3. User id and pass word validation- the server consults the user
database to validate the user id and password. This job is done by
user authentication program.
4. Authentication Results-Depending on the failure or success of the
validation of the user id and password, the user authentication
program return an appropriate result back to the server.
5. Inform user accordingly-Depending on the outcome (success or
Authentication token
An authentication token is an extremely useful alternative to a
password. An authentication token is a small device that
generates a new random value every time it is used.
This random value becomes the basis for authentication. The small
devices are typically of the size of small key chains,
calculators of credit cards. Usually an authentication token has
the following features:
• Processor
• Liquid crystal display(LCD)for display outputs
• Battery
• (optionally )a small keypad for entering information
• (optionally )a real-time clock
• Each authentication token (i.e. device) is pre-programmed with
a unique number, called as random seed, or just seed. The seed
forms the basis for ensuring the uniqueness of the output
produced by the token.
Authentication token types
There are two main types of authentication tokens.
•Challenge/Response Tokens
•Time based Tokens
Authentication Token
Challenge/Response Time based tokens
Tokens
Challenge-response authentication is a family of protocols in
which one party presents a question ("challenge") and another
party must provide a valid answer ("response") to be
authenticated. The simplest example of a challenge-response
protocol is password authentication, where the challenge is
asking for the password and the valid response is the correct
password.
In time based token the server need not send any random
challenge to the user. The theory behind this is usage of time
as variable input to the authentication process.
Biometric Authentication
Biometrics refers to the automatic identification of a person
based on his or her physiological or behavioral
characteristics.
➢ A biometric device works on the basis of some human
characteristics, such as
fingerprints,voice or the pattern of lines in the iris of
your eye
➢ The user database contains a sample of user’s biometric
characteristics
➢ During the authentication, the user is required to provide
another sample of the users’ biometric characteristic.
➢ This is matched with the one in the database, and if the
two samples are same, the user is considered to be a valid
one.
Biometric Authentication
Any Biometric Authentication System defines two configurable
parameters:
False Accept Ratio (FAR):
• It is a measurement of the chance that a user who
should be rejected is actually accepted bya system as
good enough.
False Reject Ratio (FRR):
• It is a measurement of the chance that a user who
should be accepted as valid is actually rejected by a
system as not good enough
Thus FAR and FRR are exactly opposite to each other.
Biometric Authentication
Biometric characteristics:
1) Physiological
2) Behavioral
Physical biometrics:
➢ Fingerprint
➢ Facial recognition/face location
➢ Hand geometry
➢ Iris scan
➢ Retina scan
Fingerprint recognition
➢ A live acquisition of a person’s
fingerprint.
➢ Dots (very small ridges),
➢ Space between two temporarily divergent
ridges),
Firewall
A firewall is a system designed to prevent unauthorized access
to or from a private network. Firewalls can be implemented in
both hardware and software, or a combination of both. Firewalls
are frequently used to prevent unauthorized Internet users from
accessing private networks connected to the Internet,
especially intranets.
All messages entering or leaving the intranet pass through the
firewall, which examines each message and blocks those that do
not meet the specified security criteria. A firewall is a
network security system, either hardware or software based,
that controls incoming and outgoing network traffic based on a
Firewall
A firewall is a network security system, either hardware or
software based, that controls incoming and outgoing network
traffic based on a set of rules. a firewall controls access to
the resources of a network through a positive control model.
Firewall
Packet Filters
 Using network communication, a node transmits a packet that is
filtered and matched with predefined rules and policies. Once
matched, a packet is either accepted or denied. Packet filtering
checks source and destination IP addresses.
 If both IP addresses match, the packet is considered secure and
verified. Because the sender may use different applications and
programs, packet filtering also checks source and destination
protocols, such as User Datagram Protocol (UDP) and Transmission
Control Protocol (TCP).
 Packet filters also verify source and destination port addresses.
Some packet filters are not intelligent and unable to memorize used
packets. However, other packet filters can memorize previously used
Packet Filters
In the context of a TCP/IP network, a packet filter watches each
individual IP datagram, decodes the header information of in-bound
and out-bound traffic and then either blocks the datagram from
passing or allows the datagram to pass based upon the contents of the
source address, destination address, source port, destination port
and/or connection status. This is based upon certain criteria defined
to the packet filtering tool.
Spoofing is a means to hide one s true identity on the network.
To create a spoofed expectations, working style identity, an
attacker uses a fake source address that does not represent the
actual address of the packet.
Spoofing may be used to hide the original source of an attack or
to work around network access control lists (ACLs) that are in
place to limit host access based on source address rules. An
intruder outside the corporate network can attempt to send a
packet with IP address same as the one of the IP address of the
internal users.
Prevention measures
This attack can be defeated by discarding all the packets that
arrive at the incoming side of firewall, with the source address
equal to one of the internal address.
Ip address spoofing
The Source Route option in IP packets is usually used in network path
troubleshooting and temporary transmission of some special services.
Packets carrying the Source Route option ignore the forwarding entries
of devices along the transmission path during the forwarding process.
For example, if you want an IP packet to pass through routers R1, R2,
and R3, you can specify the IP addresses of the interfaces on the three
routers in the Source Route option of the packet. In this case, the IP
packet will pass through R1, R2, and R3 in turn, regardless of the
routing tables of the routers.
During the transmission of an IP packet carrying the Source Route
option, the source address and destination address are always changing.
An attacker may forge some legal IP addresses by configuring the Source
Route option, thus mingling in the target network.
Prevention measures
Check whether received packets carry the Source Route option. If yes,
drop or forward the packets and log the event, depending on the
configuration.
Source Routing
attack
An application gateway is known as application proxy or
application-level proxy, an application gateway is an
application program that runs on a firewall system between two
networks. When a client program establishes a connection to a
destination service, it connects to an application gateway, or
proxy.
The client then negotiates with the proxy server in order to
communicate with the destination service. In effect, the proxy
establishes the connection with the destination behind the
firewall and acts on behalf of the client, hiding and protecting
individual computers on the network behind the firewall.
This creates two connections: one between the client and the
proxy server and one between the proxy server and the
destination. Once connected, the proxy makes all packet-
forwarding decisions. Since all communication is conducted
through the proxy server, computers behind the firewall are
protected.
Application Gateways
It filters incoming node traffic to certain specifications which mean
that only transmitted network application data is filtered. Such
network applications include File Transfer Protocol (FTP), Telnet, Real
Time Streaming Protocol (RTSP) and BitTorrent.
While this is considered a highly secure method of firewall protection,
application gateways require great memory and processor resources
compared to other firewall technologies, such as stateful inspection.
Application Gateways
Network Address Translation (NAT) is a method of connecting multiple
computers to the Internet (or any other IP network) using one IP
address. This allows home users and small businesses to connect their
network to the Internet cheaply and efficiently.
Security needs
Ease and flexibility of network administration
Network Address Translation (NAT)
Network Address Translation (NAT)
Network Address Translation (NAT) is a method of connecting multiple
computers to the Internet (or any other IP network) using one IP
address. This allows home users and small businesses to connect their
network to the Internet cheaply and efficiently.
Security needs
Ease and flexibility of network administration
Network Address Translation (NAT)
Network Address Translation (NAT)
Thank you for listening