1
00:00:00,120 --> 00:00:02,220
In this section of the course, we're going to be focused

2
00:00:02,220 --> 00:00:05,070
on cryptographic solutions and cryptography.

3
00:00:05,070 --> 00:00:06,810
Now, what is cryptography?

4
00:00:06,810 --> 00:00:08,400
Well, cryptography is the practice

5
00:00:08,400 --> 00:00:10,080
of writing and solving codes

6
00:00:10,080 --> 00:00:12,573
in order to hide the true meaning of the information.

7
00:00:12,573 --> 00:00:15,060
Now, most commonly we're going to use cryptography

8
00:00:15,060 --> 00:00:16,740
as a form of encryption.

9
00:00:16,740 --> 00:00:17,970
Now, encryption is the process

10
00:00:17,970 --> 00:00:19,560
of converting ordinary information,

11
00:00:19,560 --> 00:00:21,060
known as plaintext data,

12
00:00:21,060 --> 00:00:24,270
into an unintelligible format known as ciphertext data.

13
00:00:24,270 --> 00:00:26,070
So if I take some plain words

14
00:00:26,070 --> 00:00:27,960
and I encrypt them into some gobbledygook,

15
00:00:27,960 --> 00:00:30,180
nobody else can read it unless they have the key,

16
00:00:30,180 --> 00:00:32,070
and then they can turn it back into plain text

17
00:00:32,070 --> 00:00:33,960
and read it if they have that key.

18
00:00:33,960 --> 00:00:36,450
That is the basic concept of encryption.

19
00:00:36,450 --> 00:00:38,790
Now, encryption is used to provide us with data at rest,

20
00:00:38,790 --> 00:00:41,040
data in transit, and data in use protections

21
00:00:41,040 --> 00:00:42,870
to make sure we're securing all of our data,

22
00:00:42,870 --> 00:00:45,240
and encryption allows us to do all of that.

23
00:00:45,240 --> 00:00:47,310
Now, data exists in one of these three states

24
00:00:47,310 --> 00:00:48,720
at any given time.

25
00:00:48,720 --> 00:00:51,090
Data at rest is used to encrypt inactive data

26
00:00:51,090 --> 00:00:53,580
that's been archived, such as data that's been resident

27
00:00:53,580 --> 00:00:55,590
on a hard drive or storage device.

28
00:00:55,590 --> 00:00:57,990
So when data is just sitting there as a file,

29
00:00:57,990 --> 00:01:00,300
that data is known as data at rest.

30
00:01:00,300 --> 00:01:03,090
Now, data in transit involves data that is moving around

31
00:01:03,090 --> 00:01:04,290
and going across the network,

32
00:01:04,290 --> 00:01:07,380
or data that's residing inside of the computer's memory,

33
00:01:07,380 --> 00:01:08,820
which is random access memory,

34
00:01:08,820 --> 00:01:10,620
and moving to or from the processor

35
00:01:10,620 --> 00:01:12,180
from the storage devices.

36
00:01:12,180 --> 00:01:14,280
That means it is data in transit.

37
00:01:14,280 --> 00:01:16,440
Now, data in use is described as data

38
00:01:16,440 --> 00:01:19,320
that is undergoing a current constant state of change.

39
00:01:19,320 --> 00:01:21,630
So if you have data inside your processor

40
00:01:21,630 --> 00:01:23,850
and calculations are actively being done on it,

41
00:01:23,850 --> 00:01:26,190
that will be considered data in use.

42
00:01:26,190 --> 00:01:29,280
Now, in order to protect our data, we can encrypt that data

43
00:01:29,280 --> 00:01:31,920
while it's at rest, in transit, or in use.

44
00:01:31,920 --> 00:01:32,850
Now, let me go back

45
00:01:32,850 --> 00:01:35,280
and explain how encryption works a little bit here.

46
00:01:35,280 --> 00:01:36,300
Let's say that I have something

47
00:01:36,300 --> 00:01:37,770
like you see here on the screen.

48
00:01:37,770 --> 00:01:39,090
This is gobbledygook.

49
00:01:39,090 --> 00:01:41,010
You have no idea what it means, right?

50
00:01:41,010 --> 00:01:42,330
Do you know what this message is?

51
00:01:42,330 --> 00:01:44,160
Well, I don't the way it's currently written

52
00:01:44,160 --> 00:01:46,980
but if we know that it's using a ROT13 cipher,

53
00:01:46,980 --> 00:01:48,600
then that can tell you how we can figure out

54
00:01:48,600 --> 00:01:50,580
how to get it back to the original plaintext

55
00:01:50,580 --> 00:01:52,020
so you and I can read it.

56
00:01:52,020 --> 00:01:54,000
Now, what is a ROT13 cipher?

57
00:01:54,000 --> 00:01:57,030
Well, it stands for rotate 13 spots.

58
00:01:57,030 --> 00:01:59,340
So if I start with something like the letter C

59
00:01:59,340 --> 00:02:01,440
and I count 13 letters to the right of that,

60
00:02:01,440 --> 00:02:02,730
that gets me to P.

61
00:02:02,730 --> 00:02:05,370
So anytime you see a C, the answer is actually P.

62
00:02:05,370 --> 00:02:06,540
If I go with an R,

63
00:02:06,540 --> 00:02:09,210
13 letters to the right goes all the way past Z,

64
00:02:09,210 --> 00:02:12,780
goes into A, B, C, D, E, and it gets me back to E.

65
00:02:12,780 --> 00:02:17,780
So I now know I have P and E, which is C and R.

66
00:02:17,820 --> 00:02:18,870
Do you see what I'm saying here?

67
00:02:18,870 --> 00:02:20,220
Do you understand what it says yet?

68
00:02:20,220 --> 00:02:21,450
Well, let me help you out.

69
00:02:21,450 --> 00:02:22,860
Instead of making you do all the math

70
00:02:22,860 --> 00:02:25,260
and figuring it on your own, I'm just going to show it to you.

71
00:02:25,260 --> 00:02:28,050
And it stands for cryptography is fun.

72
00:02:28,050 --> 00:02:30,630
Now that you know what the key is, that 13 places,

73
00:02:30,630 --> 00:02:32,370
this makes it really easy for you to figure out

74
00:02:32,370 --> 00:02:34,440
anything we want to convert back and forth,

75
00:02:34,440 --> 00:02:36,180
and that is the idea with encryption.

76
00:02:36,180 --> 00:02:37,800
It's not the fact that we have some algorithm

77
00:02:37,800 --> 00:02:39,180
that's really complicated.

78
00:02:39,180 --> 00:02:41,130
It's about the fact that we know what the key is.

79
00:02:41,130 --> 00:02:43,080
And if you and I both know what that key is,

80
00:02:43,080 --> 00:02:45,390
then we know how to secure our data.

81
00:02:45,390 --> 00:02:47,580
Now, if I told you everything was a rotation,

82
00:02:47,580 --> 00:02:49,710
you simply could figure it out by knowing what the key is

83
00:02:49,710 --> 00:02:52,440
and the number there, which in this case was 13.

84
00:02:52,440 --> 00:02:54,900
Now our encryption is going to be a lot more complicated that

85
00:02:54,900 --> 00:02:56,130
inside of our computers,

86
00:02:56,130 --> 00:02:58,200
but it's basically the same basic principle,

87
00:02:58,200 --> 00:02:59,940
and I want you to understand how this works,

88
00:02:59,940 --> 00:03:03,570
and seeing this ROT13 cipher is a really easy way to do it.

89
00:03:03,570 --> 00:03:05,970
So now that we talked about ROT13

90
00:03:05,970 --> 00:03:07,680
and we understand that it's a rotation,

91
00:03:07,680 --> 00:03:09,570
we would call that an algorithm.

92
00:03:09,570 --> 00:03:11,910
This is a cipher, and we're going to use the cipher,

93
00:03:11,910 --> 00:03:13,260
which is simply an algorithm,

94
00:03:13,260 --> 00:03:15,720
and perform an encryption or decryption function.

95
00:03:15,720 --> 00:03:18,870
In my example, if you added 13, you encrypted.

96
00:03:18,870 --> 00:03:21,450
If you subtracted 13, you were decrypting,

97
00:03:21,450 --> 00:03:24,390
and that's all you're going to do with a ROT13 cipher.

98
00:03:24,390 --> 00:03:25,230
Now, we're going to do things

99
00:03:25,230 --> 00:03:27,480
that are much, much more complicated with ciphers,

100
00:03:27,480 --> 00:03:28,313
and we're going to get into

101
00:03:28,313 --> 00:03:30,540
all the different ciphers we use in our computers

102
00:03:30,540 --> 00:03:32,370
and we'll talk about all their different algorithms,

103
00:03:32,370 --> 00:03:35,730
both symmetric and asymmetric, block and stream ciphers.

104
00:03:35,730 --> 00:03:38,220
We'll talk all about that in this section of the course.

105
00:03:38,220 --> 00:03:39,930
And when we talk about these algorithms,

106
00:03:39,930 --> 00:03:42,660
what we are referring to is a mathematical function.

107
00:03:42,660 --> 00:03:44,100
Something is going to be input,

108
00:03:44,100 --> 00:03:46,350
some things are going to get mathematically changed out,

109
00:03:46,350 --> 00:03:49,290
and out the other side comes some scrambled up value.

110
00:03:49,290 --> 00:03:51,750
So when I took my input as a C

111
00:03:51,750 --> 00:03:53,820
and I went through my ROT13 cipher,

112
00:03:53,820 --> 00:03:55,590
it came out the other side as a P

113
00:03:55,590 --> 00:03:57,870
because it moved 13 spots to the right.

114
00:03:57,870 --> 00:03:59,670
That is the idea with encryption.

115
00:03:59,670 --> 00:04:02,250
All an algorithm is, is a mathematical formula

116
00:04:02,250 --> 00:04:03,900
that tells you how you're going to encrypt

117
00:04:03,900 --> 00:04:05,430
or decrypt something.

118
00:04:05,430 --> 00:04:07,590
Now, as we move through this, we have to think

119
00:04:07,590 --> 00:04:09,060
about what gives us security

120
00:04:09,060 --> 00:04:11,970
inside of our cryptography and encryption devices.

121
00:04:11,970 --> 00:04:15,360
What really is the strength here? Is it that ROT 13 cipher?

122
00:04:15,360 --> 00:04:17,850
Well, no, it wasn't the rotation part.

123
00:04:17,850 --> 00:04:19,740
It wasn't the rotation that was giving us anything,

124
00:04:19,740 --> 00:04:21,089
that was just the algorithm.

125
00:04:21,089 --> 00:04:24,090
Instead, it was the key, and the 13 is the key

126
00:04:24,090 --> 00:04:27,480
because now we know how to move the letters back and forth.

127
00:04:27,480 --> 00:04:30,090
All of our encryption strength always comes from the key,

128
00:04:30,090 --> 00:04:31,410
not the algorithm.

129
00:04:31,410 --> 00:04:34,020
In fact, almost all the algorithms we're going to talk about,

130
00:04:34,020 --> 00:04:36,030
probably all the algorithms we're going to talk about,

131
00:04:36,030 --> 00:04:37,710
have undergone public review,

132
00:04:37,710 --> 00:04:39,870
meaning people have actually designed them

133
00:04:39,870 --> 00:04:42,120
and opened them up so anybody could see the code

134
00:04:42,120 --> 00:04:44,040
and know exactly how it works.

135
00:04:44,040 --> 00:04:45,060
And if you can do that

136
00:04:45,060 --> 00:04:46,740
and you've a good encryption algorithm,

137
00:04:46,740 --> 00:04:50,100
that means that algorithm is not having to be secure.

138
00:04:50,100 --> 00:04:51,840
It's the key that makes it secure.

139
00:04:51,840 --> 00:04:53,910
And we're going to talk about that over and over again

140
00:04:53,910 --> 00:04:54,810
throughout this section

141
00:04:54,810 --> 00:04:57,240
because that is critically important to understand.

142
00:04:57,240 --> 00:05:00,150
Now, when I talk about a key, what am I talking about?

143
00:05:00,150 --> 00:05:02,220
Well, it's that essential piece of information

144
00:05:02,220 --> 00:05:04,410
that determines the output of the cipher.

145
00:05:04,410 --> 00:05:08,070
When we talked about the ROT13 example, the key was the 13.

146
00:05:08,070 --> 00:05:10,620
It was knowing that you need to move 13 places to the right

147
00:05:10,620 --> 00:05:13,410
or to the left to encrypt or decrypt the data.

148
00:05:13,410 --> 00:05:14,730
Now, that's the whole idea,

149
00:05:14,730 --> 00:05:16,140
and so it's really important for you to understand

150
00:05:16,140 --> 00:05:18,810
that the key to security inside of our encryption

151
00:05:18,810 --> 00:05:20,640
is the actual key itself.

152
00:05:20,640 --> 00:05:22,260
To ensure that our keys stay secure,

153
00:05:22,260 --> 00:05:24,690
we need to ensure we're using long, strong keys

154
00:05:24,690 --> 00:05:26,610
and that we rotate those keys frequently

155
00:05:26,610 --> 00:05:29,550
in order to keep our cryptographic implementation secure.

156
00:05:29,550 --> 00:05:32,370
The longer the key, the more secure it's going to be.

157
00:05:32,370 --> 00:05:34,950
And in cryptography, we say that the length of the key

158
00:05:34,950 --> 00:05:36,450
is directly proportional

159
00:05:36,450 --> 00:05:38,430
to the level of security it provides.

160
00:05:38,430 --> 00:05:40,470
So if you have a really long key,

161
00:05:40,470 --> 00:05:42,480
it's going to be stronger and more resistant

162
00:05:42,480 --> 00:05:44,040
to a brute force attack.

163
00:05:44,040 --> 00:05:46,920
For example, if you have 128-bit key,

164
00:05:46,920 --> 00:05:49,350
that is considered secure for most applications.

165
00:05:49,350 --> 00:05:52,170
But if you can go to a 256-bit key,

166
00:05:52,170 --> 00:05:54,780
that's going to give you a much higher degree of protection

167
00:05:54,780 --> 00:05:57,300
and it renders it exponentially more challenging

168
00:05:57,300 --> 00:05:58,710
for an attacker to break it.

169
00:05:58,710 --> 00:06:03,270
Moving from 128 bits to 256 bits is not doubly as strong.

170
00:06:03,270 --> 00:06:05,160
It's actually exponentially as strong

171
00:06:05,160 --> 00:06:07,140
because you're squaring the value.

172
00:06:07,140 --> 00:06:10,140
Now, however, even if you have the strongest key possible,

173
00:06:10,140 --> 00:06:12,390
that key can become vulnerable over time,

174
00:06:12,390 --> 00:06:14,850
and the reason for that is technology advances

175
00:06:14,850 --> 00:06:16,470
or you have prolonged exposure

176
00:06:16,470 --> 00:06:17,520
because that key's been out there

177
00:06:17,520 --> 00:06:18,990
for two years or three years

178
00:06:18,990 --> 00:06:20,910
and somebody can eventually guess it.

179
00:06:20,910 --> 00:06:23,940
Now, this is where the idea of key rotation comes into play.

180
00:06:23,940 --> 00:06:26,130
Regularly changing out your cryptographic keys

181
00:06:26,130 --> 00:06:27,630
is considered a best practice

182
00:06:27,630 --> 00:06:30,450
and it will mitigate the risk of unauthorized decryption.

183
00:06:30,450 --> 00:06:33,480
For example, many organizations implement policies

184
00:06:33,480 --> 00:06:35,580
that rotate their transport layer security,

185
00:06:35,580 --> 00:06:37,620
or TLS keys, annually,

186
00:06:37,620 --> 00:06:40,680
and some cloud providers actually will auto rotate your keys

187
00:06:40,680 --> 00:06:44,070
for you every 90 days to give you additional security.

188
00:06:44,070 --> 00:06:45,570
By combining appropriate key lengths

189
00:06:45,570 --> 00:06:47,580
with consistent key rotation techniques,

190
00:06:47,580 --> 00:06:50,400
your organization can significantly enhance the robustness

191
00:06:50,400 --> 00:06:53,190
and longevity of your cryptographic defenses.

192
00:06:53,190 --> 00:06:55,710
Now, another key thing to remember about encryption

193
00:06:55,710 --> 00:06:56,930
is that most, if not all,

194
00:06:56,930 --> 00:06:58,800
of the encryption algorithms we use today

195
00:06:58,800 --> 00:07:01,680
are considered open-source and publicly accessible.

196
00:07:01,680 --> 00:07:03,840
This means that the secrecy and integrity

197
00:07:03,840 --> 00:07:06,150
of the encryption keys are really what provides us

198
00:07:06,150 --> 00:07:07,950
with that security, like we said before,

199
00:07:07,950 --> 00:07:10,290
and not the encryption algorithm itself.

200
00:07:10,290 --> 00:07:12,440
Cryptographic algorithms are intentionally designed

201
00:07:12,440 --> 00:07:15,150
to be transparent while still ensuring that their strength

202
00:07:15,150 --> 00:07:17,280
is derived from rigorous peer reviews

203
00:07:17,280 --> 00:07:19,650
and not dependent on obfuscation techniques,

204
00:07:19,650 --> 00:07:21,390
because security through obscurity

205
00:07:21,390 --> 00:07:23,010
is considered to be unreliable

206
00:07:23,010 --> 00:07:26,400
and an insecure process when you're operating with security.

207
00:07:26,400 --> 00:07:28,980
Instead, the confidentiality of our data

208
00:07:28,980 --> 00:07:31,230
lies in the secrecy and confidentiality

209
00:07:31,230 --> 00:07:32,880
of those encryption keys.

210
00:07:32,880 --> 00:07:34,440
If your keys are compromised,

211
00:07:34,440 --> 00:07:37,290
the security assurances of the entire system crumbles,

212
00:07:37,290 --> 00:07:39,780
no matter how robust your algorithm is.

213
00:07:39,780 --> 00:07:43,290
Because of this, the keys must be safeguarded at all costs.

214
00:07:43,290 --> 00:07:45,360
These encryption keys should always be stored

215
00:07:45,360 --> 00:07:48,360
in secure hardware modules, encrypted when they're at rest,

216
00:07:48,360 --> 00:07:51,180
and transmitted securely whenever they're going to be used.

217
00:07:51,180 --> 00:07:53,070
Additionally, access to these keys

218
00:07:53,070 --> 00:07:55,710
should be strictly limited to regular audits and monitoring

219
00:07:55,710 --> 00:07:57,090
for unauthorized access

220
00:07:57,090 --> 00:07:58,650
because you want to continuously make sure

221
00:07:58,650 --> 00:07:59,610
that's being performed

222
00:07:59,610 --> 00:08:01,440
and make sure nobody's accessing these keys

223
00:08:01,440 --> 00:08:02,640
that shouldn't be.

224
00:08:02,640 --> 00:08:04,950
In essence, while the entire cryptographic community

225
00:08:04,950 --> 00:08:07,500
trusts the algorithms because of their transparency,

226
00:08:07,500 --> 00:08:08,670
it is the secretive nature

227
00:08:08,670 --> 00:08:10,500
and the stringent protection mechanisms

228
00:08:10,500 --> 00:08:12,090
around those encryption keys

229
00:08:12,090 --> 00:08:15,570
that ensures our data remains confidential and tamper proof.

230
00:08:15,570 --> 00:08:17,520
All right, now that we covered all that,

231
00:08:17,520 --> 00:08:19,290
let's talk about what we're going to talk about

232
00:08:19,290 --> 00:08:20,670
in this section of the course

233
00:08:20,670 --> 00:08:23,370
where we're going to be focused on Domain 1 and Domain 2,

234
00:08:23,370 --> 00:08:26,550
and specifically looking at objectives 1.4, 2.3, and 2.4.

235
00:08:28,020 --> 00:08:29,640
Now, objective 1.4 states

236
00:08:29,640 --> 00:08:31,380
that you must be able to explain the importance

237
00:08:31,380 --> 00:08:33,870
of using appropriate cryptographic solutions.

238
00:08:33,870 --> 00:08:35,880
Objective 2.3 states that you must be able

239
00:08:35,880 --> 00:08:37,890
to explain various types of vulnerabilities,

240
00:08:37,890 --> 00:08:39,870
specifically those types of different attacks

241
00:08:39,870 --> 00:08:40,890
that are trying to overcome

242
00:08:40,890 --> 00:08:43,260
our cryptographic systems or algorithms.

243
00:08:43,260 --> 00:08:45,840
Objective 2.4 states that given a scenario,

244
00:08:45,840 --> 00:08:48,690
you must be able to analyze indicators of malicious activity

245
00:08:48,690 --> 00:08:51,000
in cases of those efforts being successful,

246
00:08:51,000 --> 00:08:53,490
especially downgrade attacks, collision attacks,

247
00:08:53,490 --> 00:08:56,490
birthday attacks, and quantum-based cryptographic attacks.

248
00:08:56,490 --> 00:08:58,530
Now, as we kick off this section,

249
00:08:58,530 --> 00:09:00,720
we're going to start out with the basics of cryptography

250
00:09:00,720 --> 00:09:02,970
and then work our way through the different implementations

251
00:09:02,970 --> 00:09:05,130
and then into the different attack methods.

252
00:09:05,130 --> 00:09:06,780
First, we'll discuss symmetric

253
00:09:06,780 --> 00:09:08,550
and asymmetric encryption algorithms,

254
00:09:08,550 --> 00:09:09,990
and the difference between them.

255
00:09:09,990 --> 00:09:12,150
Symmetric algorithms are going to use the same key

256
00:09:12,150 --> 00:09:14,100
for both encryption and decryption,

257
00:09:14,100 --> 00:09:16,860
while asymmetric algorithms will use a pair of keys

258
00:09:16,860 --> 00:09:18,103
with a public key and a private key

259
00:09:18,103 --> 00:09:21,090
to be able to encrypt and decrypt your data.

260
00:09:21,090 --> 00:09:22,770
Next, we're going to cover the different types

261
00:09:22,770 --> 00:09:24,030
of symmetric algorithms

262
00:09:24,030 --> 00:09:29,030
including DES, 3DES, IDEA, AES, Blowfish, Twofish,

263
00:09:29,040 --> 00:09:31,500
and the Rivest Cipher suite of algorithms.

264
00:09:31,500 --> 00:09:33,360
Then we're going to be focused on our coverage

265
00:09:33,360 --> 00:09:36,690
of asymmetric algorithms, including Diffie-Hellman, RSA,

266
00:09:36,690 --> 00:09:38,670
and Elliptic Curve Cryptography.

267
00:09:38,670 --> 00:09:41,070
After that, we'll explore the world of hashing.

268
00:09:41,070 --> 00:09:42,870
Hashing is a process that converts data

269
00:09:42,870 --> 00:09:44,820
into a fixed-sized string of characters

270
00:09:44,820 --> 00:09:48,450
which we call a message digest using a hash function.

271
00:09:48,450 --> 00:09:49,283
There are various types

272
00:09:49,283 --> 00:09:50,850
of hashing algorithms we're going to cover,

273
00:09:50,850 --> 00:09:55,850
including MD5, the Sha family of hashes, RIPEMD, and HMAC.

274
00:09:55,920 --> 00:09:57,870
Next, we're going to take a look at various types

275
00:09:57,870 --> 00:10:00,870
of hashing attacks and how to increase your hash security.

276
00:10:00,870 --> 00:10:03,360
Then we'll move into public key infrastructure,

277
00:10:03,360 --> 00:10:04,980
known as PKI.

278
00:10:04,980 --> 00:10:07,200
Now, public key infrastructure is a framework

279
00:10:07,200 --> 00:10:09,120
for managing digital keys and certificates

280
00:10:09,120 --> 00:10:12,300
to ensure secure data transfer and authentication occurs.

281
00:10:12,300 --> 00:10:14,880
After that, we're going to look at digital certificates.

282
00:10:14,880 --> 00:10:17,040
Digital certificates are electronic credentials

283
00:10:17,040 --> 00:10:18,630
issued by a trusted authority

284
00:10:18,630 --> 00:10:20,610
that verifies the identity of an entity

285
00:10:20,610 --> 00:10:23,280
and provides a means to establish secure communications.

286
00:10:23,280 --> 00:10:25,080
We'll also perform a quick demonstration

287
00:10:25,080 --> 00:10:26,640
to show you how to explore the contents

288
00:10:26,640 --> 00:10:28,650
of a digital certificate to ensure it's valid

289
00:10:28,650 --> 00:10:30,720
and safe for use on your system.

290
00:10:30,720 --> 00:10:33,150
Next, we're going to be talking about the blockchain.

291
00:10:33,150 --> 00:10:35,970
Now, the blockchain is a decentralized, immutable ledger

292
00:10:35,970 --> 00:10:38,490
that records transactions across multiple computers

293
00:10:38,490 --> 00:10:40,860
to ensure data integrity and transparency.

294
00:10:40,860 --> 00:10:42,960
We'll also talk about things like the blockchain,

295
00:10:42,960 --> 00:10:45,840
the public ledger, cryptocurrency, digital controls,

296
00:10:45,840 --> 00:10:48,540
and supply chain management using the blockchain.

297
00:10:48,540 --> 00:10:51,300
Then we'll move into our coverage of encryption tools

298
00:10:51,300 --> 00:10:53,550
including TPM, HSM,

299
00:10:53,550 --> 00:10:56,100
key management systems and secure enclaves,

300
00:10:56,100 --> 00:10:57,660
all of which play critical roles

301
00:10:57,660 --> 00:10:59,550
in ensuring data security and integrity

302
00:10:59,550 --> 00:11:02,040
across various platforms and environments.

303
00:11:02,040 --> 00:11:05,040
After that, we're going to cover obfuscation techniques,

304
00:11:05,040 --> 00:11:08,400
including steganography, tokenization, and data masking.

305
00:11:08,400 --> 00:11:10,980
Steganography is the practice of hiding secret data

306
00:11:10,980 --> 00:11:13,740
within ordinary non-secret files or messages

307
00:11:13,740 --> 00:11:15,990
to avoid detection and ensure the very existence

308
00:11:15,990 --> 00:11:17,760
of the message remains concealed.

309
00:11:17,760 --> 00:11:19,290
Tokenization is going to involve

310
00:11:19,290 --> 00:11:21,030
substituting sensitive data elements

311
00:11:21,030 --> 00:11:23,400
with nonsensitive equivalents called tokens

312
00:11:23,400 --> 00:11:26,040
which have no intrinsic or exploitable meaning.

313
00:11:26,040 --> 00:11:28,710
Data masking or data obfuscation is the process

314
00:11:28,710 --> 00:11:31,500
of disguising original data to protect sensitive information

315
00:11:31,500 --> 00:11:32,940
while maintaining its authenticity

316
00:11:32,940 --> 00:11:35,460
and usability for a specific purpose.

317
00:11:35,460 --> 00:11:37,620
Then we're going to learn about cryptographic attacks,

318
00:11:37,620 --> 00:11:39,750
including downgrade attacks, collision attacks,

319
00:11:39,750 --> 00:11:41,310
and the threat of quantum computing

320
00:11:41,310 --> 00:11:43,920
against our current family of encryption algorithms.

321
00:11:43,920 --> 00:11:45,360
Finally, we'll take a short quiz

322
00:11:45,360 --> 00:11:47,340
to see what you learned during this section of the course,

323
00:11:47,340 --> 00:11:49,230
and review each of those quiz questions fully

324
00:11:49,230 --> 00:11:52,020
to ensure you understand why each right answer was right.

325
00:11:52,020 --> 00:11:54,750
So if you're ready, let's get started with our coverage

326
00:11:54,750 --> 00:11:57,600
of cryptographic solutions in this section of the course.

