1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:04,140
we're going to discuss symmetric and asymmetric encryption.

3
00:00:04,140 --> 00:00:06,240
Now, every encryption cipher is categorized

4
00:00:06,240 --> 00:00:08,400
as either symmetric or asymmetric

5
00:00:08,400 --> 00:00:09,810
based on the algorithm they use

6
00:00:09,810 --> 00:00:13,170
and the type of key that's going to be used to secure the data.

7
00:00:13,170 --> 00:00:15,480
Now, when you're using symmetric key encryption,

8
00:00:15,480 --> 00:00:16,830
you're going to have a single key

9
00:00:16,830 --> 00:00:19,440
that's used to encrypt and decrypt that data.

10
00:00:19,440 --> 00:00:21,120
With asymmetric encryption though,

11
00:00:21,120 --> 00:00:22,920
you're going to use two different keys,

12
00:00:22,920 --> 00:00:24,420
one key to encrypt the data

13
00:00:24,420 --> 00:00:27,000
and a second key to decrypt that data.

14
00:00:27,000 --> 00:00:28,500
Now, symmetric key algorithms

15
00:00:28,500 --> 00:00:30,330
are often called private key encryption

16
00:00:30,330 --> 00:00:31,800
or private key algorithms,

17
00:00:31,800 --> 00:00:33,390
because of the fact that both the sender

18
00:00:33,390 --> 00:00:36,210
and the receiver need to know the same shared secret,

19
00:00:36,210 --> 00:00:38,430
and this is that privately held key.

20
00:00:38,430 --> 00:00:40,230
Now, in symmetric key encryption,

21
00:00:40,230 --> 00:00:42,420
this is a fairly easy concept for us to understand,

22
00:00:42,420 --> 00:00:45,270
because most of us use it on a daily basis.

23
00:00:45,270 --> 00:00:47,280
I mean, after all, when you go home tonight

24
00:00:47,280 --> 00:00:49,110
and unlock the front door to your house,

25
00:00:49,110 --> 00:00:51,780
you're actually using symmetric key encryption to do it.

26
00:00:51,780 --> 00:00:54,900
Basically, you're using the exact same key that your spouse

27
00:00:54,900 --> 00:00:56,263
and your roommate or anybody else will have

28
00:00:56,263 --> 00:00:59,280
to be able to unlock and open your door.

29
00:00:59,280 --> 00:01:01,530
Now, if you wanted me to be able to get into your house,

30
00:01:01,530 --> 00:01:02,363
you have to give me

31
00:01:02,363 --> 00:01:05,190
an exact same copy of the key in your pocket.

32
00:01:05,190 --> 00:01:08,100
That way, we both have the exact same private key

33
00:01:08,100 --> 00:01:09,420
and we can both unlock

34
00:01:09,420 --> 00:01:12,150
or lock your house as needed to get in and out.

35
00:01:12,150 --> 00:01:14,460
This is our shared secret key.

36
00:01:14,460 --> 00:01:17,010
Now, due to the fact that we have this shared secret key,

37
00:01:17,010 --> 00:01:18,810
we can make sure that there is confidentiality

38
00:01:18,810 --> 00:01:20,760
of all the items inside of your house,

39
00:01:20,760 --> 00:01:23,040
because only the people who you give this key to

40
00:01:23,040 --> 00:01:25,620
are going to be able to open the door and get inside.

41
00:01:25,620 --> 00:01:28,500
But you can't be assured of non-repudiation,

42
00:01:28,500 --> 00:01:30,510
because if somebody is able to go into your house

43
00:01:30,510 --> 00:01:32,130
like your spouse or your roommate,

44
00:01:32,130 --> 00:01:34,080
or even me because you gave me a key,

45
00:01:34,080 --> 00:01:35,580
and one of us took your laptop,

46
00:01:35,580 --> 00:01:36,780
because you weren't home,

47
00:01:36,780 --> 00:01:38,940
you're not going to know who took that laptop.

48
00:01:38,940 --> 00:01:41,231
All you know is that that laptop is gone.

49
00:01:41,231 --> 00:01:42,660
Now, it could be any of us,

50
00:01:42,660 --> 00:01:45,930
because we all have the same copy of that shared secret key.

51
00:01:45,930 --> 00:01:48,720
Your spouse, your roommate, you, and even me.

52
00:01:48,720 --> 00:01:50,190
We all have that key.

53
00:01:50,190 --> 00:01:52,140
Now, a lot of us have a copy of that key,

54
00:01:52,140 --> 00:01:53,250
which means that any of us

55
00:01:53,250 --> 00:01:55,740
could have gone in and taken that laptop.

56
00:01:55,740 --> 00:01:58,590
Now, beyond the challenge of proving who used the key,

57
00:01:58,590 --> 00:01:59,790
there's also another big challenge

58
00:01:59,790 --> 00:02:01,620
when we deal with symmetric algorithms,

59
00:02:01,620 --> 00:02:04,860
and that is the distribution of that shared secret key.

60
00:02:04,860 --> 00:02:06,810
So, if you wanted to encrypt an email

61
00:02:06,810 --> 00:02:08,820
and send it to your five closest friends,

62
00:02:08,820 --> 00:02:10,470
each of you would have to have a set

63
00:02:10,470 --> 00:02:13,980
of shared secret keys set up for each one of those pairs.

64
00:02:13,980 --> 00:02:16,380
That way, we'd have five different pairs of keys,

65
00:02:16,380 --> 00:02:19,530
one for you and one for each of your five friends.

66
00:02:19,530 --> 00:02:21,210
Now, if every one of those friends

67
00:02:21,210 --> 00:02:23,490
also wanted to be able to share things with each other,

68
00:02:23,490 --> 00:02:24,930
they're going to have to have another set

69
00:02:24,930 --> 00:02:26,970
of keys for each of those five friends.

70
00:02:26,970 --> 00:02:29,520
And in fact, this means we're going to have 15 sets

71
00:02:29,520 --> 00:02:30,930
of different keys that are required,

72
00:02:30,930 --> 00:02:33,870
so that everybody can communicate with everybody else.

73
00:02:33,870 --> 00:02:35,850
This means that for every two people,

74
00:02:35,850 --> 00:02:36,750
we each are going to have

75
00:02:36,750 --> 00:02:39,330
to have our own set of individual keys.

76
00:02:39,330 --> 00:02:40,380
Now, for the same reason

77
00:02:40,380 --> 00:02:42,540
that peer-to-peer connections become untenable

78
00:02:42,540 --> 00:02:45,480
at large scale, you're going to see the same thing happen here

79
00:02:45,480 --> 00:02:47,160
when you're dealing with symmetric keys,

80
00:02:47,160 --> 00:02:49,800
because as you get larger numbers and more users,

81
00:02:49,800 --> 00:02:52,590
you need to share that secret among more people,

82
00:02:52,590 --> 00:02:54,630
and this means you have a big distribution problem

83
00:02:54,630 --> 00:02:55,680
on your hands to be able

84
00:02:55,680 --> 00:02:58,230
to distribute all of these shared secret keys.

85
00:02:58,230 --> 00:03:00,540
Now, most wireless networks used in small business

86
00:03:00,540 --> 00:03:01,890
or home office networks

87
00:03:01,890 --> 00:03:03,930
are going to utilize a shared secret key

88
00:03:03,930 --> 00:03:06,300
in the form of a Wi-Fi password.

89
00:03:06,300 --> 00:03:09,000
So, if I go over to your house this weekend for a big party

90
00:03:09,000 --> 00:03:11,100
and you have 50 of your closest friends over

91
00:03:11,100 --> 00:03:13,590
and you have to give them all that same shared secret key,

92
00:03:13,590 --> 00:03:15,840
which is the password to get access to your network,

93
00:03:15,840 --> 00:03:18,120
now, we have no confidentiality at all,

94
00:03:18,120 --> 00:03:20,730
because so many people know that shared secret key.

95
00:03:20,730 --> 00:03:23,070
And at this point, any one of the 50 people

96
00:03:23,070 --> 00:03:25,200
could have been looking at the information on that network.

97
00:03:25,200 --> 00:03:26,790
And that really is the big problem

98
00:03:26,790 --> 00:03:29,220
when you start dealing with symmetric key encryption.

99
00:03:29,220 --> 00:03:30,053
You have to figure out

100
00:03:30,053 --> 00:03:31,950
how are you going to protect this shared secret

101
00:03:31,950 --> 00:03:34,140
and how are you going to distribute it at scale

102
00:03:34,140 --> 00:03:37,080
for all the people who need access to that data.

103
00:03:37,080 --> 00:03:38,730
This brings us to our second category

104
00:03:38,730 --> 00:03:40,260
that we use for encryption ciphers,

105
00:03:40,260 --> 00:03:42,690
which is known as asymmetric algorithms.

106
00:03:42,690 --> 00:03:44,520
Now, unlike symmetric algorithms,

107
00:03:44,520 --> 00:03:47,940
asymmetric algorithms do not require a shared secret key.

108
00:03:47,940 --> 00:03:48,900
And for this reason,

109
00:03:48,900 --> 00:03:52,050
we often refer to this as public key cryptography.

110
00:03:52,050 --> 00:03:53,880
Now, with asymmetric algorithms,

111
00:03:53,880 --> 00:03:56,040
we are going to use two separate keys.

112
00:03:56,040 --> 00:03:58,020
One key is going to be used to encrypt the data

113
00:03:58,020 --> 00:04:00,840
and another key is going to be used to decrypt the data.

114
00:04:00,840 --> 00:04:02,160
Now, the most commonly used forms

115
00:04:02,160 --> 00:04:04,170
of asymmetric algorithms are going to be things

116
00:04:04,170 --> 00:04:06,540
like the Diffie-Hellman algorithm, RSA,

117
00:04:06,540 --> 00:04:10,140
an elliptic curve cryptography known as ECC.

118
00:04:10,140 --> 00:04:13,020
Now, when we compare symmetric and asymmetric algorithms,

119
00:04:13,020 --> 00:04:15,030
you may be wondering which one is better,

120
00:04:15,030 --> 00:04:16,680
because it sounds like there's a lot of problems

121
00:04:16,680 --> 00:04:18,300
with symmetric encryption, right?

122
00:04:18,300 --> 00:04:20,519
Well, this really is a hard thing to discuss,

123
00:04:20,519 --> 00:04:22,320
because there is no pure answer

124
00:04:22,320 --> 00:04:24,330
where it's going to be great a hundred percent of the time

125
00:04:24,330 --> 00:04:26,070
to use symmetric or asymmetric,

126
00:04:26,070 --> 00:04:27,330
because both have been designed

127
00:04:27,330 --> 00:04:30,330
for different purposes and they have different benefits.

128
00:04:30,330 --> 00:04:33,000
For example, symmetric algorithms are very popular,

129
00:04:33,000 --> 00:04:35,970
because they tend to be about 100 to 1,000 times faster

130
00:04:35,970 --> 00:04:38,730
than an equivalently secure asymmetric algorithm.

131
00:04:38,730 --> 00:04:40,980
But asymmetric algorithms do allow us

132
00:04:40,980 --> 00:04:42,810
to overcome that key distribution challenge

133
00:04:42,810 --> 00:04:44,700
that we face with symmetric algorithms.

134
00:04:44,700 --> 00:04:48,000
Therefore, both of them have a place in our networks.

135
00:04:48,000 --> 00:04:50,250
Now, as with most things in cybersecurity,

136
00:04:50,250 --> 00:04:52,590
you're going to see that we can take the best of both worlds

137
00:04:52,590 --> 00:04:55,170
by combining these into a hybrid approach.

138
00:04:55,170 --> 00:04:58,020
Now, to overcome the key distribution problem for example,

139
00:04:58,020 --> 00:05:00,510
most implementations are going to use asymmetric

140
00:05:00,510 --> 00:05:01,980
or public key encryption

141
00:05:01,980 --> 00:05:04,410
to be able to encrypt and share a shared secret key

142
00:05:04,410 --> 00:05:06,390
or private key that can then be used

143
00:05:06,390 --> 00:05:08,460
for symmetric encryption to secure the bulk

144
00:05:08,460 --> 00:05:09,990
of the data transfer that's going to happen

145
00:05:09,990 --> 00:05:11,670
between a sender and a receiver

146
00:05:11,670 --> 00:05:13,980
now that they have the same shared secret.

147
00:05:13,980 --> 00:05:15,780
And now, they're going to be able to pass information

148
00:05:15,780 --> 00:05:17,850
back and forth much faster than they could

149
00:05:17,850 --> 00:05:20,700
if they used asymmetric algorithms by themself.

150
00:05:20,700 --> 00:05:21,960
This type of a hybrid approach

151
00:05:21,960 --> 00:05:24,570
really does give you the best of both worlds.

152
00:05:24,570 --> 00:05:26,460
Now, in addition to classifying algorithms

153
00:05:26,460 --> 00:05:28,290
as either symmetric or asymmetric

154
00:05:28,290 --> 00:05:30,210
based on their key and algorithm type,

155
00:05:30,210 --> 00:05:31,860
we can also categorize an algorithm

156
00:05:31,860 --> 00:05:33,960
as either a stream or a block cipher

157
00:05:33,960 --> 00:05:35,610
based on the mathematical algorithm

158
00:05:35,610 --> 00:05:36,443
that they're going to be using

159
00:05:36,443 --> 00:05:38,586
to do their encryption and decryption processes.

160
00:05:38,586 --> 00:05:41,280
Now, a stream cipher performs their computations

161
00:05:41,280 --> 00:05:43,740
and encryptions a single byte at a time.

162
00:05:43,740 --> 00:05:45,930
This makes it a bit by bit process,

163
00:05:45,930 --> 00:05:47,640
and they utilize a key stream generator

164
00:05:47,640 --> 00:05:48,780
to create a bitstream

165
00:05:48,780 --> 00:05:50,610
that's going to be mixed with the input plain text

166
00:05:50,610 --> 00:05:52,350
using a mathematically exclusive

167
00:05:52,350 --> 00:05:55,320
or function known as an XOR function.

168
00:05:55,320 --> 00:05:57,450
This will be used to create the encrypted cipher text

169
00:05:57,450 --> 00:06:00,150
that is going to be there to store your data in.

170
00:06:00,150 --> 00:06:01,650
Now, because these stream ciphers

171
00:06:01,650 --> 00:06:03,450
can perform bit by bit encryption,

172
00:06:03,450 --> 00:06:04,590
they're very well-suited

173
00:06:04,590 --> 00:06:06,990
for securing real-time communication data streams

174
00:06:06,990 --> 00:06:09,540
like streaming audio or streaming video.

175
00:06:09,540 --> 00:06:12,420
Now, stream ciphers also tend to be symmetric algorithms

176
00:06:12,420 --> 00:06:13,440
and they use the same key

177
00:06:13,440 --> 00:06:16,020
for both encryption and decryption.

178
00:06:16,020 --> 00:06:17,220
Now, the second type we have

179
00:06:17,220 --> 00:06:19,110
is what's known as a block cipher.

180
00:06:19,110 --> 00:06:20,610
A block cipher is going to be able

181
00:06:20,610 --> 00:06:23,160
to break the input into fixed length blocks of data

182
00:06:23,160 --> 00:06:25,500
before performing their encryption functions.

183
00:06:25,500 --> 00:06:27,090
For example, if you had a message

184
00:06:27,090 --> 00:06:28,740
that was one kilobyte in size,

185
00:06:28,740 --> 00:06:32,520
we could break that up into 16 blocks of 64 bytes each.

186
00:06:32,520 --> 00:06:33,524
Each of these 16 blocks

187
00:06:33,524 --> 00:06:35,460
could then be processed by the cipher,

188
00:06:35,460 --> 00:06:37,560
and then output out the other side of this algorithm

189
00:06:37,560 --> 00:06:39,990
the block of cipher text that we are expecting.

190
00:06:39,990 --> 00:06:42,120
If your message is less than 64 bytes,

191
00:06:42,120 --> 00:06:44,310
then we'll use extra padding that's going to be added

192
00:06:44,310 --> 00:06:46,380
to the data prior to it going through the encryption

193
00:06:46,380 --> 00:06:49,560
to make sure it is a full 64 byte chunk.

194
00:06:49,560 --> 00:06:51,270
Now, block ciphers in general

195
00:06:51,270 --> 00:06:53,610
have several advantages over a stream cipher,

196
00:06:53,610 --> 00:06:55,860
including being easier to set up and implement

197
00:06:55,860 --> 00:06:58,500
and being less susceptible to security problems.

198
00:06:58,500 --> 00:07:00,330
Block ciphers are also easily implemented

199
00:07:00,330 --> 00:07:02,760
through software solutions, whereas most stream ciphers

200
00:07:02,760 --> 00:07:05,340
tend to be used in hardware-based solutions.

201
00:07:05,340 --> 00:07:07,170
So, remember, symmetric encryption

202
00:07:07,170 --> 00:07:09,060
is a method of encryption where the same key

203
00:07:09,060 --> 00:07:11,940
is used for both the encryption and decryption of data.

204
00:07:11,940 --> 00:07:13,470
Asymmetric encryption on the other hand,

205
00:07:13,470 --> 00:07:14,520
is a system of encryption

206
00:07:14,520 --> 00:07:16,230
in which two different keys are used,

207
00:07:16,230 --> 00:07:19,050
one for encryption and one for decryption.

208
00:07:19,050 --> 00:07:20,190
There are also two different types

209
00:07:20,190 --> 00:07:21,330
of ciphers that we can use.

210
00:07:21,330 --> 00:07:23,880
These are stream ciphers and block ciphers.

211
00:07:23,880 --> 00:07:25,890
A stream cipher is an encryption algorithm

212
00:07:25,890 --> 00:07:27,240
that encrypts data bit by bit

213
00:07:27,240 --> 00:07:29,700
or byte by byte in a continuous stream.

214
00:07:29,700 --> 00:07:31,110
A block cipher, on the other hand,

215
00:07:31,110 --> 00:07:32,940
is an encryption algorithm that encrypts data

216
00:07:32,940 --> 00:07:35,370
in fixed size blocks that are typically sized

217
00:07:35,370 --> 00:07:39,360
as 64, 128, or 256 bits in a block,

218
00:07:39,360 --> 00:07:41,760
rather than doing one bit at a time.

219
00:07:41,760 --> 00:07:43,427
We can then use these basic categorizations

220
00:07:43,427 --> 00:07:46,740
of symmetric, asymmetric, stream, and block ciphers

221
00:07:46,740 --> 00:07:47,573
to be able to help

222
00:07:47,573 --> 00:07:48,990
group our different encryption technologies

223
00:07:48,990 --> 00:07:51,330
into these different categories for easier reference,

224
00:07:51,330 --> 00:07:52,530
as we're working out in the field

225
00:07:52,530 --> 00:07:54,123
as cybersecurity professionals.

