Terminology
^ Historically, for encrypting elements of a plaintext made up of more than a single letter only digraphs (two successive letters) have ever been used.- Cryptology 10 February 2010 13:51 UTC www.ridex.co.uk [Source type: Reference]
The study of characteristics of languages which have some application in cryptography (or cryptology), i.e. frequency data, letter combinations, universal patterns, etc., is called cryptolinguistics.
History of cryptography and cryptanalysis
Classic cryptography
More literacy, or literate opponents, required actual cryptography.
There is record of several early Hebrew ciphers as well.
The next oldest is bakery recipes from Mesopotamia.
Cryptography is recommended in the
Kama Sutra as a way for lovers to communicate without inconvenient discovery.
An early example, from
Herodotus, concealed a message—a tattoo on a slave's shaved head—under the regrown hair.
^{[2]}
This fundamental principle was first explicitly stated in 1883 by
Auguste Kerckhoffs and is generally called
Kerckhoffs' principle; alternatively and more bluntly, it was restated by
Claude Shannon, the inventor of
information theory and the fundamentals of theoretical cryptography, as
Shannon's Maxim—'the enemy knows the system'.
With the invention of polyalphabetic ciphers came more sophisticated aids such as Alberti's own
cipher disk,
Johannes Trithemius'
tabula recta scheme, and
Thomas Jefferson's
multi-cylinder (not publicly known, and reinvented independently by
Bazeries around 1900).
^{[7]} The ciphers implemented by better quality examples of these machine designs brought about a substantial increase in cryptanalytic difficulty after WWI.
^{[8]}
The computer era
The development of digital computers and
electronics after WWII made possible much more complex ciphers.
However, computers have also assisted cryptanalysis, which has compensated to some extent for increased cipher complexity.
Alternate methods of attack (bribery, burglary, threat, torture, ...) have become more attractive in consequence.
Credit card with
smart-card capabilities. The 3-by-5-mm chip embedded in the card is shown, enlarged. Smart cards combine low cost and portability with the power to compute cryptographic algorithms.
Extensive open academic research into cryptography is relatively recent; it began only in the mid-1970s.
^{[10]}
Modern cryptography
The modern field of cryptography can be divided into several areas of study.
Symmetric-key cryptography
This was the only kind of encryption publicly known until June 1976.
^{[9]}
One round (out of 8.5) of the
patented IDEA cipher, used in some versions of
PGP for high-speed encryption of, for instance,
e-mail
The U.S.
National Security Agency developed the
Secure Hash Algorithm series of MD5-like hash functions: SHA-0 was a flawed algorithm that the agency withdrew; SHA-1 is widely deployed and more secure than MD5, but cryptanalysts have identified attacks against it; the SHA-2 family improves on SHA-1, but it isn't yet widely deployed, and the U.S. standards authority thought it "prudent" from a security perspective to develop a new standard to "significantly improve the robustness of NIST's overall hash algorithm toolkit."
^{[16]} Thus, a
hash function design competition is underway and meant to select a new U.S. national standard, to be called SHA-3, by 2012.
Public-key cryptography
^{[18]} The historian
David Kahn described public-key cryptography as "the most revolutionary new concept in the field since polyalphabetic substitution emerged in the Renaissance".
^{[19]}
.^ In Secure Sockets Layer (SSL) or the later version Transport Layer Security (TLS) which provides secure web browsing (http s ), digital certificates are used for source authentication and connections are generally encrypted with a stream cipher .- Cryptography - encyclopedia article - Citizendium 10 February 2010 13:51 UTC en.citizendium.org [Source type: FILTERED WITH BAYES]
However, such an icon is not a guarantee of security; any subverted browser might mislead a user by displaying such an icon when a transmission is not actually being protected by SSL or TLS.
^{[15]}
Cryptanalysis
Main article:
Cryptanalysis
The goal of cryptanalysis is to find some weakness or insecurity in a cryptographic scheme, thus permitting its subversion or evasion.
It is a common misconception that every encryption method can be broken.
.^ Stream ciphers were developed as an approximation to the one-time pad.- Cryptology 10 February 2010 13:51 UTC www.ridex.co.uk [Source type: Reference]
^ Can use as a one-time pad.
^ One-time pads (Chapter 1) are provably secure if the bits in the key are generated from a truly random source.
A common distinction turns on what an attacker knows and what capabilities are available.
Cryptographic primitives
Cryptosystems
Cryptosystems (e.g.
El-Gamal encryption) are designed to provide particular functionality (e.g. public key encryption) while guaranteeing certain security properties (e.g.
Cryptosystems use the properties of the underlying cryptographic primitives to support the system's security properties. Of course, as the distinction between primitives and cryptosystems is somewhat arbitrary, a sophisticated cryptosystem can be derived from a combination of several more primitive cryptosystems.
Such cryptosystems are sometimes called
cryptographic protocols.
More complex cryptosystems include
Legal issues
Prohibitions
Actually secret communications may be criminal or even
treasonous; those whose communications are open to inspection may be less likely to be either.
.^ Public key cryptography requires a fundamentally different type of cryptanalysis than is used for single key cryptanalysis.- Cryptology 10 February 2010 13:51 UTC www.ridex.co.uk [Source type: Reference]
Among the more restrictive are laws in
As a result, export controls came to be seen to be an impediment to commerce and to research.
Export controls
No charges were ever filed, however.
The 1995 case
) in their browsers; examples are
NSA involvement
According to
Steven Levy, IBM rediscovered differential cryptanalysis,
but kept the technique secret at NSA's request. The technique became publicly known only when Biham and Shamir re-rediscovered and announced it some years later.
.^ In a ciphertext only attack the cryptanalyst has only the encoded message from which to determine the plaintext, with no knowledge whatsoever of the actual message.- Cryptology 10 February 2010 13:51 UTC www.ridex.co.uk [Source type: Reference]
Another instance of NSA's involvement was the 1993
Clipper chip affair, an encryption microchip intended to be part of the
Capstone cryptography-control initiative. Clipper was widely criticized by cryptographers for two reasons. The cipher algorithm was then classified (the cipher, called
Skipjack, though it was declassified in 1998 long after the Clipper initiative lapsed). The secret cipher caused concerns that NSA had deliberately made the cipher weak in order to assist its intelligence efforts. The whole initiative was also criticized based on its violation of
Kerckhoffs' principle, as the scheme included a special
escrow key held by the government for use by law enforcement, for example in wiretaps.
^{[33]}
Digital rights management
This had a noticeable impact on the cryptography research community since an argument can be made that
any cryptanalytic research violated, or might violate, the DMCA. Similar statutes have since been enacted in several countries and regions, including the implementation in the EU Copyright Directive. Similar restrictions are called for by treaties signed by
World Intellectual Property Organization member-states.
One well-respected cryptography researcher,
Niels Ferguson, has publicly stated
^{[41]} that he will not release some of his research into an
Intel security design for fear of prosecution under the DMCA, and both
Alan Cox (longtime number 2 in
Linux kernel development) and Professor
Edward Felten (and some of his students at Princeton) have encountered problems related to the Act.
Dmitry Sklyarov was arrested during a visit to the US from Russia, and jailed for some months for alleged violations of the DMCA which had occurred in Russia, where the work for which he was arrested and charged was then, and when he was arrested, legal. In 2007, the cryptographic keys responsible for
Blu Ray and
HD DVD content scrambling were
discovered and released onto the
Internet.
See also
