# Modern Cryptography

Generally speaking there are two *kinds* of encryption: symmetric and asymmetric.

In symmetric encryption, the parties involved share the ***same*** key.

In asymmetric encryption, the parties use ***different*** keys, that are mathematically ***related*** to each other.

<img src="img/sym_vs_asym.png" width="750">

## Symmetric Encryption

In the following, we look at symmetric encryption algorithms. In symmetric crypto, we use the same key for encryption and decryption. **Therefore, the two parties need to establish a secret key between them.** Symmetric encryption can be up to 1000 times faster than asymmetric encryption. Given the support of some crypto algorithm in the CPU and at hardware level, even faster.

### Advanced Encryption Algorithm (AES)

AES is based on Rijndael encryption algorithm, designed by Joan Daemen and Vincent Rijmen. It was one of the algorithms submitted to U.S. National Institute of Standards and Technology (NIST) to replace DES and 3DES. It was published in 1998 and accepted and standardized in 2001.

 * AES supports key sizes of 128/192/256 bits
 * Block size: 128 bit
 * It's iterative rather than Feistel cipher
 * Treats data in 4 groups of 4 bytes
 * Operates on an entire block in every round
 * Resistant against known attacks
 * Speed and code compactness on many CPUs
 * Rijndael block and key size vary between 128, 192, 256
 * However, in AES block size in 128
 * Number of rounds a function of key size
  * 128 bits     10 rounds
  * 192 bits     12 rounds
  * 256 bits     14 rounds

 * Today most implementations use the CPU support (Intel AES-NI)

### Block cipher mode of operation

To encrypt messages of arbitrary size with block ciphers, we use the following algorithms, called the modes of operation. They define how to encrypt each block of the plaintext to produce the corresponding cipher text block. Some of these are completely insecure (ECB) and should not be used.

 * Electronic Codebook (ECB)
 * Cipher Block Chaining (CBC)
 * Counter (CTR)
 
 
### Electronic Codebook (ECB)

<img src="img/ECB_enc.png">
<img src="img/ECB_dec.png">



### Cipher Block Chaining (CBC)

<img src="img/CBC_enc.png">
<img src="img/CBC_dec.png">



### Counter (CTR)

<img src="img/CTR_enc.png">
<img src="img/CTR_dec.png">


## SHA Family

Secure Hash Algorithm (SHA) family, is a series of hashing algorithms.

    Ranging from SHA-0 to SHA-3. 
    SHA-0 should never be used. 
    It's advised to move from SHA-1 to SHA-2. 
    SHA-3 is the most recent version, published in 2015.


    SHA-1: Digest size (160), Block size (512)
    SHA-2: Digest size (224, 256, 384, or 512), Block size (512, 1024)
    SHA-3: Digest size (224, 256, 384, 512), Block size (1600)


In [None]:
hashes.

In [3]:
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes
import base64 # to produce human readable encoding of the bytes

digest = hashes.Hash(hashes.SHA256(), backend=default_backend())
digest.update(b"Cryptography Class2019")
# digest.update(b"2019")
msg_digest = digest.finalize()
# Notice the output size of the digest
print ("msg_digest:", len(msg_digest), len(msg_digest) * 8)
print ("base64 encoding:", base64.b64encode(msg_digest))

print()
print('*'*70)

digest = hashes.Hash(hashes.SHA256(), backend=default_backend())
digest.update(b"Cryptography Class 2019")
msg_digest = digest.finalize()
# Notice the output size of the digest
print ("msg_digest:", len(msg_digest), len(msg_digest) * 8)
print ("base64 encoding:", base64.b64encode(msg_digest))

print()
print('*'*70)

digest = hashes.Hash(hashes.SHA256(), backend=default_backend())
digest.update(b"Cryptography Class 2018")
msg_digest = digest.finalize()
# Notice the output size of the digest
print ("msg_digest:", len(msg_digest), len(msg_digest) * 8)
print ("base64 encoding:", base64.b64encode(msg_digest))

msg_digest: 32 256
base64 encoding: b'Ac3zIwNL0+Tm2TwmwUiZXIKzQ5Wy+ON7DdisgBdw8Ys='

**********************************************************************
msg_digest: 32 256
base64 encoding: b'e0X8i9hmsRwIC11vopL7wF+2M5sMcfkq5KNRAaPlSdA='

**********************************************************************
msg_digest: 32 256
base64 encoding: b'RWc2f3CGpkZMWeVBtl7dbqMYmoYmGgGML3egCvrUh3E='


In [4]:
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes
import base64 # to produce human readable encoding of the binary bytes

for _hash in [hashes.SHA1, hashes.SHA224, hashes.SHA256, hashes.SHA384, hashes.SHA512]:
    digest = hashes.Hash(_hash(), backend=default_backend())
    digest.update(b"Cryptography Class 2019")
    # digest.update(b"2019")
    msg_digest = digest.finalize()
    # Notice the output size of the digest
    print(_hash.name, len(msg_digest), len(msg_digest) * 8,'\n', base64.b64encode(msg_digest), '\n')

sha1 20 160 
 b'33aBOypIgAiFptpOz7tyEvg6Ock=' 

sha224 28 224 
 b'xYr2ZdcSZACj2j52Lg/YlS5vSvJImM5zcI4Txg==' 

sha256 32 256 
 b'e0X8i9hmsRwIC11vopL7wF+2M5sMcfkq5KNRAaPlSdA=' 

sha384 48 384 
 b'ayosYcv2ijTBVNlSKg4jchpXYzrzRA9036wwGaNBiEtinvqYt0KxyY3pzChv9nUs' 

sha512 64 512 
 b'qdMZZ/v008yB+PqPBkFki04UJQjL8S1PIeiCDxU9FbFsxFpFqjTmg9Cst0OXn2Dzwp9x4TChQfWB6AfxmZA81w==' 



In [14]:
import os
from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes
from cryptography.hazmat.backends import default_backend
key = os.urandom(16) # in bytes, 128 bits
iv = os.urandom(16)

In [6]:
# ECB Mode, we only need a key
### *** DO NOT USE ECB. IT IS INSECURE *** ###

cipher = Cipher(algorithms.AES(key), modes.ECB(), backend=default_backend())
encryptor = cipher.encryptor()
# note that we don't need padding here, since len("Cryptography2019") = 16
cipher_text = encryptor.update(b"Cryptography2019") + encryptor.finalize()

In [7]:
cipher_text

b'\x9a\x7f\xb7\x8a\xe2P\x7f2\xd6\xa9\x9e%\xe2R0\x90'

In [8]:
print (len(cipher_text))

16


In [9]:
decryptor = cipher.decryptor()
decryptor.update(cipher_text) + decryptor.finalize()

b'Cryptography2019'

In [15]:
# CBC Mode, we also need an IV
cipher = Cipher(algorithms.AES(key), modes.CBC(iv), backend=default_backend())
encryptor = cipher.encryptor()
# note that we don't need padding here, since len("Cryptography2019") = 16
cipher_text = encryptor.update(b"Cryptography2019") + encryptor.finalize()

In [16]:
cipher_text

b'\xe6\n\xd3a\x93\x8a\xa0Y\xa0\x1a1\xc8\x85T\xb3H'

In [17]:
decryptor = cipher.decryptor()
decryptor.update(cipher_text) + decryptor.finalize()

b'Cryptography2019'

In [18]:
# CTR Mode, we don't need padding in CTR mode. In transforms a block cipher into a stream cipher
# we only need to introduce the nonce
cipher = Cipher(algorithms.AES(key), modes.CTR(os.urandom(16)), backend=default_backend())
encryptor = cipher.encryptor()
# len(b"Cryptography Class 2019") = 23, however no padding is needed.
cipher_text = encryptor.update(b"Cryptography Class 2019") + encryptor.finalize()

In [19]:
cipher_text

b'9\xbdI4yL=I\xf8z\t\x84\x8abR\xb507\xf5>\x0b\x0e\xc2'

## *<font color=" #6495ED">Exercise</font>*

 - Encrypt the file following text using the ECB, and CBC or CTR mode and compare the results.

In [20]:
plain_text = b"Cryptography2019" * 128

In [21]:
plain_text

b'Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Cryptography2019Crypto

In [22]:
def print_text(text, b64=False):
    for i in range(0, 128, 16):
        if b64:
            pt = base64.b64encode(text[i:i+16])
        else:
            pt = text[i:i+16]
        print(pt)

In [23]:
import os
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes
import base64 # to produce human readable encoding of the bytes
key = os.urandom(16) # in bytes, 128 bits

cipher = Cipher(algorithms.AES(key), modes.ECB(), backend=default_backend())
encryptor = cipher.encryptor()
ecb_ct = encryptor.update(plain_text) + encryptor.finalize()

In [24]:
print_text(ecb_ct)

b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'
b'\x1a\xbd\xe8\xab\xec\xdbe\xaf\xc8\xb9s\xab\xe8\x05\x16\xbb'


In [25]:
cipher = Cipher(algorithms.AES(key), modes.CBC(iv), backend=default_backend())
encryptor = cipher.encryptor()
cbc_ct = encryptor.update(plain_text) + encryptor.finalize()

In [26]:
print_text(cbc_ct)

b'\xe2\x1b\x04\xfe\x08\xc8\x1c%mm\xf8O\xa2i\r\x0c'
b'\xb2\x8d@\xd9Q\xb7\xd2\x0e\x9fT3\xdc\xa7\x84\x84P'
b'G\xfe\xb7\x81\xd4\xf9\xa5\x94\x92!\xcb@\xb5\x87U\xf1'
b'pT\xdc\xd9\xael\xdd[0\x9ek\xf4g1G\x02'
b'OO\x18\x07\xf2\xe9\xfe=\xbe\x14@\xa5\x81R\x1e\xca'
b'\xf6\xf4\x039\xcb\x7f\x0f\x90\xc9L\x81\xba\x19\xed\x95\x1a'
b'Z\xe30\x92\xd6\xe7\xb1C\xa3\xd38%d\xc4\x83U'
b'\x005\x17\x95\xc7?\xe1\xa7\x14\xa9T\x80\xb4\xdbs\xad'


In [27]:
cipher = Cipher(algorithms.AES(key), modes.CTR(os.urandom(16)), backend=default_backend())
encryptor = cipher.encryptor()
ctr_ct = encryptor.update(plain_text) + encryptor.finalize()

In [28]:
print_text(ctr_ct)

b'\xdb\xa0\xb09\xb7\x01\x92:?\xb8z\xd0\x1dq\xdb\xbb'
b'\xfa\xbb\x01\x07\xdaD\x1f\xbd\n\xaen\xc4\x83\xd5\xf6\x9f'
b'\xaf\xd8&\xc8\xcc\x16]\x9e\xcd\xa0Q\xa3_#%\x80'
b'W$\xf05\xf0e\x06\x8a\x84\xbc\x87\x13.\xfe\xd4\xb1'
b'\xf2L\xd8\xc2\xa8?\xef\x90\xec\xb8Y\x9c\xd7\xe2\xa76'
b'\xb3\x95\xa3+V>\xf3\xb8\xe7\xd5{6\x1fQ\xbf\xfa'
b'\x05XAz\xc0j\x03_\xe3\xb8w~g\xafg+'
b'\xd7\xd0\xecG\xddJ\xf42\xa2\xfd6\xe1\x14p\xf1\xbd'


In [None]:
import PIL

with open('img/tux.png', 'rb') as f:
    clear = f.read()
    
len(clear)
len(clear)%16
clear_trimmed = clear[64:-2]
len(clear_trimmed)%16

In [None]:
cipher = Cipher(algorithms.AES(key), modes.ECB(), backend=default_backend())
encryptor = cipher.encryptor()
ecb_ct = encryptor.update(clear_trimmed) + encryptor.finalize()

In [None]:
with open('img/tux_ecb.png', 'wb') as f:
    f.write(ecb_ct)