1
00:00:06,510 --> 00:00:09,330
- In this lesson, lesson
4.2, we're gonna focus

2
00:00:09,330 --> 00:00:13,383
in on encryption, both
symmetric and asymmetric.

3
00:00:14,400 --> 00:00:18,300
Encryption is commonly used
to protect the confidentiality

4
00:00:18,300 --> 00:00:21,480
of data that's in transit
and data that's in rest.

5
00:00:21,480 --> 00:00:23,580
And when we talk about
emerging cryptography,

6
00:00:23,580 --> 00:00:26,520
we'll talk about some
ways that in the future

7
00:00:26,520 --> 00:00:29,970
we'll be able to encrypt data
that's actually in process

8
00:00:29,970 --> 00:00:33,450
or being processed by our processor.

9
00:00:33,450 --> 00:00:35,070
But let's take a big picture look

10
00:00:35,070 --> 00:00:37,200
at how we actually do encryption

11
00:00:37,200 --> 00:00:40,740
again, for data that's in
transient and data that's at rest.

12
00:00:40,740 --> 00:00:44,130
We're gonna start with
our cleartext, right?

13
00:00:44,130 --> 00:00:46,170
So text, just like what you
see on the screen, right?

14
00:00:46,170 --> 00:00:47,820
This readable text.

15
00:00:47,820 --> 00:00:51,930
We're then going to take
an algorithm and a key,

16
00:00:51,930 --> 00:00:53,880
so, it doesn't matter
right now for our purposes

17
00:00:53,880 --> 00:00:55,500
whether it's a symmetric or asymmetric

18
00:00:55,500 --> 00:00:57,510
but we're gonna take
an algorithm and a key.

19
00:00:57,510 --> 00:01:01,170
Our algorithm was just a
mathematically complex cipher

20
00:01:01,170 --> 00:01:05,010
that we need a computer to
solve and a key which is a value

21
00:01:05,010 --> 00:01:09,180
and our output is going
to be our ciphertext.

22
00:01:09,180 --> 00:01:11,820
What you can't read, it
won't mean anything to you,

23
00:01:11,820 --> 00:01:13,920
we'll often refer to it as encrypted text,

24
00:01:13,920 --> 00:01:16,530
but just means that
it's not human readable.

25
00:01:16,530 --> 00:01:18,510
How are we gonna transform it back?

26
00:01:18,510 --> 00:01:21,483
We're gonna use an algorithm and a key,

27
00:01:22,410 --> 00:01:24,240
just reversing the process.

28
00:01:24,240 --> 00:01:27,120
And that'll take us back to our cleartext.

29
00:01:27,120 --> 00:01:29,460
So, that's a really big
picture, simple view,

30
00:01:29,460 --> 00:01:31,680
cleartext, algorithm and key,

31
00:01:31,680 --> 00:01:35,553
ciphertext, algorithm and
key, back to cleartext.

32
00:01:38,320 --> 00:01:39,240
Now, we have two types of encryption

33
00:01:39,240 --> 00:01:40,350
we're gonna be talking about,

34
00:01:40,350 --> 00:01:43,590
symmetric encryption and
asymmetric encryption.

35
00:01:43,590 --> 00:01:47,130
Symmetric encryption uses the same key

36
00:01:47,130 --> 00:01:48,780
to encrypt and decrypt.

37
00:01:48,780 --> 00:01:50,370
And as I mentioned in the last lesson,

38
00:01:50,370 --> 00:01:52,740
the key can be referred
to as a single key,

39
00:01:52,740 --> 00:01:56,610
a shared key, a secret key, a session key,

40
00:01:56,610 --> 00:01:59,070
or a symmetric key, they
all mean the same thing.

41
00:01:59,070 --> 00:02:01,440
It means we're using
the same key to encrypt

42
00:02:01,440 --> 00:02:02,850
as we are to decrypt,

43
00:02:02,850 --> 00:02:05,580
just like you use the same
key to open your house door,

44
00:02:05,580 --> 00:02:08,280
your apartment door as you do to lock it.

45
00:02:08,280 --> 00:02:10,140
So, what are the components we have here?

46
00:02:10,140 --> 00:02:13,170
Well, once again, we're gonna
start with our cleartext.

47
00:02:13,170 --> 00:02:15,690
Then we're going to use
a symmetric algorithm,

48
00:02:15,690 --> 00:02:17,610
because our algorithms are different

49
00:02:17,610 --> 00:02:19,470
between symmetric and asymmetric.

50
00:02:19,470 --> 00:02:21,300
So, there's a symmetric algorithm

51
00:02:21,300 --> 00:02:24,930
and importantly a symmetric
key, and you can see here,

52
00:02:24,930 --> 00:02:27,720
our symmetric key, 1,2,3,4,5,6,7,8,9,

53
00:02:27,720 --> 00:02:30,660
and then we will end
up with our ciphertext.

54
00:02:30,660 --> 00:02:34,230
When we wanna transform
back to our cleartext,

55
00:02:34,230 --> 00:02:37,230
we're going to use the
same symmetric algorithm.

56
00:02:37,230 --> 00:02:39,870
So, if I used 3DES to encrypt

57
00:02:39,870 --> 00:02:42,630
I'll use 3DES to decrypt
or AES to encrypt,

58
00:02:42,630 --> 00:02:47,630
I'll use AES to decrypt
and the same exact key.

59
00:02:48,030 --> 00:02:50,400
So 1, 2, 3, 4, 5, 6, 7, 8, 9.

60
00:02:50,400 --> 00:02:52,800
Same key to encrypt and decrypt

61
00:02:52,800 --> 00:02:57,120
and that will get us
back to our cleartext.

62
00:02:57,120 --> 00:02:58,820
Pretty straightforward and simple.

63
00:03:01,560 --> 00:03:03,780
There are four symmetric algorithms,

64
00:03:03,780 --> 00:03:05,670
I wanna make sure that you know.

65
00:03:05,670 --> 00:03:10,670
DES, 3DES, AES, also
known as Rijndael and RC4.

66
00:03:11,640 --> 00:03:15,720
The DES, 3DES and AES,
are all block ciphers,

67
00:03:15,720 --> 00:03:18,480
meaning that we're working
with blocks of data at a time.

68
00:03:18,480 --> 00:03:20,430
RC4 is a stream cipher.

69
00:03:20,430 --> 00:03:22,410
Remember that faucet, drip, drip, drip.

70
00:03:22,410 --> 00:03:24,600
We're working with one
bit of a data at a time

71
00:03:24,600 --> 00:03:26,133
using an XOR function.

72
00:03:27,450 --> 00:03:30,630
So, DES in 1977, was established

73
00:03:30,630 --> 00:03:34,050
as the US government standard
for symmetric encryption.

74
00:03:34,050 --> 00:03:35,910
It's a 64 bit key size

75
00:03:35,910 --> 00:03:39,780
with 16 rounds of substitution
and transposition.

76
00:03:39,780 --> 00:03:42,420
But in 1998, it was demonstrated

77
00:03:42,420 --> 00:03:45,690
that it could be broken
in less than 56 hours.

78
00:03:45,690 --> 00:03:47,190
Broken meaning exploitable,

79
00:03:47,190 --> 00:03:49,590
meaning we're not gonna use DES anymore.

80
00:03:49,590 --> 00:03:52,843
Now, that was quickly replaced by 3DES.

81
00:03:52,843 --> 00:03:55,530
3DES in 1999, replaced DES

82
00:03:55,530 --> 00:03:58,950
as the US government standard
for symmetric encryption.

83
00:03:58,950 --> 00:04:02,640
It's a 64 bit key, goes to
48 rounds of substitution

84
00:04:02,640 --> 00:04:05,970
and transposition either
using two or three keys,

85
00:04:05,970 --> 00:04:09,690
but there's been a lot of
weaknesses found in 3DES.

86
00:04:09,690 --> 00:04:12,600
And what's the term we
use for weakness now?

87
00:04:12,600 --> 00:04:15,810
Deprecated, so it is
considered to be deprecated,

88
00:04:15,810 --> 00:04:17,970
means you could use it, but it's weak

89
00:04:17,970 --> 00:04:20,843
and there's a lot of risk and
you need to be aware of that.

90
00:04:22,080 --> 00:04:25,590
In 2002, the US government replaced 3DES

91
00:04:25,590 --> 00:04:27,330
with AES or Rijndael

92
00:04:27,330 --> 00:04:31,200
as the US government standard
for symmetric encryption.

93
00:04:31,200 --> 00:04:36,200
Now, it's either 128
or 192 or a 256 bit key

94
00:04:36,330 --> 00:04:38,550
with 10 or 12 or 14 rounds

95
00:04:38,550 --> 00:04:40,170
of substitution and transposition,

96
00:04:40,170 --> 00:04:42,320
just depending on the
version you're using.

97
00:04:43,770 --> 00:04:47,460
And then lastly, we have RC4,
again, that's a Stream Cipher

98
00:04:47,460 --> 00:04:50,880
with key sizes from 40 to 2,048 bits.

99
00:04:50,880 --> 00:04:52,590
And there are multiple variants.

100
00:04:52,590 --> 00:04:57,590
There's SPRITZ, there's
RC4A, there's VMPC and RC4A+.

101
00:05:01,740 --> 00:05:03,870
So, let's review
symmetric characteristics.

102
00:05:03,870 --> 00:05:07,410
Remember, symmetric
encryption only uses one key,

103
00:05:07,410 --> 00:05:10,923
same key to lock as unlock,
encrypt and decrypt.

104
00:05:11,850 --> 00:05:14,793
It is really, really, really
computationally efficient.

105
00:05:15,630 --> 00:05:20,470
Its key sizes are generally
128, 192, or 256 bit.

106
00:05:22,710 --> 00:05:26,220
But here's the problem, it's not scalable.

107
00:05:26,220 --> 00:05:29,880
If I wanted to send a
symmetrically encrypted message

108
00:05:29,880 --> 00:05:32,310
to everybody who's watching this video,

109
00:05:32,310 --> 00:05:35,880
I would have to create a
different symmetric key

110
00:05:35,880 --> 00:05:38,310
for every single person.

111
00:05:38,310 --> 00:05:40,260
So, it's really not scalable, right?

112
00:05:40,260 --> 00:05:41,760
Doesn't make sense.

113
00:05:41,760 --> 00:05:45,930
The other problem is key
exchange is inherently insecure.

114
00:05:45,930 --> 00:05:47,910
If I wanna get you the key,

115
00:05:47,910 --> 00:05:50,460
I've gotta find a way to
securely get you the key.

116
00:05:50,460 --> 00:05:52,470
I can't just email it to you, right?

117
00:05:52,470 --> 00:05:54,360
I have to find a secure way.

118
00:05:54,360 --> 00:05:58,440
So, on the good side, it's
computationally really efficient

119
00:05:58,440 --> 00:06:01,653
and it means it also works
great on large blocks of data,

120
00:06:02,490 --> 00:06:05,970
but on the negative
side, it's not scalable

121
00:06:05,970 --> 00:06:09,273
and the key exchange
is inherently insecure.

122
00:06:11,820 --> 00:06:14,640
The asymmetric encryption
uses two mathematically

123
00:06:14,640 --> 00:06:17,610
related keys to encrypt and decrypt.

124
00:06:17,610 --> 00:06:19,830
But bear in mind that
either key could do either.

125
00:06:19,830 --> 00:06:23,370
But when they're used in a
pair, they only do one function.

126
00:06:23,370 --> 00:06:24,960
Now the keys are often referred to

127
00:06:24,960 --> 00:06:27,630
as a public key and a private key.

128
00:06:27,630 --> 00:06:30,420
The public key is freely distributed.

129
00:06:30,420 --> 00:06:32,070
So, if I have a public
key and a private key,

130
00:06:32,070 --> 00:06:34,140
which I'm gonna get from
my digital certificates,

131
00:06:34,140 --> 00:06:36,810
the public key, not a
secret freely distributed

132
00:06:36,810 --> 00:06:40,080
to everybody, but the
private key must be secured.

133
00:06:40,080 --> 00:06:41,370
It must be kept secret.

134
00:06:41,370 --> 00:06:44,280
Just like we had to keep
the symmetric key secret,

135
00:06:44,280 --> 00:06:48,123
the private asymmetric
key must be kept secret.

136
00:06:50,160 --> 00:06:53,310
So, what does this look like
from a 10,000 foot view?

137
00:06:53,310 --> 00:06:56,520
So, I am gonna start with my cleartext.

138
00:06:56,520 --> 00:07:00,030
Then I am going to use
an asymmetric algorithm

139
00:07:00,030 --> 00:07:01,980
and an asymmetric key.

140
00:07:01,980 --> 00:07:04,830
In this case, I'm gonna use key M1,

141
00:07:04,830 --> 00:07:07,650
because I have
mathematically related pair.

142
00:07:07,650 --> 00:07:12,030
I will then end up with my
ciphertext or my encrypted text.

143
00:07:12,030 --> 00:07:14,670
Now, to transform it back,
what do I need to do?

144
00:07:14,670 --> 00:07:17,190
Well, I'll use the same
asymmetric algorithm.

145
00:07:17,190 --> 00:07:19,830
So, if I used 3DES, I'll use 3DES.

146
00:07:19,830 --> 00:07:22,440
If I used AES, I'll use AES.

147
00:07:22,440 --> 00:07:26,520
And I am going to use the
mathematically related key,

148
00:07:26,520 --> 00:07:29,040
in this case, key M2.

149
00:07:29,040 --> 00:07:31,773
And I will end up with my cleartext.

150
00:07:32,970 --> 00:07:35,490
So, cleartext, asymmetric algorithm,

151
00:07:35,490 --> 00:07:37,410
and one of the two keys,

152
00:07:37,410 --> 00:07:40,110
ciphertext, asymmetric algorithm

153
00:07:40,110 --> 00:07:42,300
and the other part of that key pair,

154
00:07:42,300 --> 00:07:44,253
coming back to my cleartext.

155
00:07:45,630 --> 00:07:49,050
So, there are four asymmetric algorithms

156
00:07:49,050 --> 00:07:51,390
that I want you to know,
starting with the very first one,

157
00:07:51,390 --> 00:07:54,210
the most popular, which is RSA.

158
00:07:54,210 --> 00:07:57,390
RSA is kind of the widely implemented

159
00:07:57,390 --> 00:07:59,820
de facto commercial standard.

160
00:07:59,820 --> 00:08:01,530
And it works with both encryption

161
00:08:01,530 --> 00:08:05,070
and as we'll see next,
with digital signatures.

162
00:08:05,070 --> 00:08:07,740
The next one is Elliptic
Curve Crypto System,

163
00:08:07,740 --> 00:08:09,750
generally referred to as ECC.

164
00:08:09,750 --> 00:08:11,610
It's a very similar function to RSA,

165
00:08:11,610 --> 00:08:13,200
but with smaller key sizes,

166
00:08:13,200 --> 00:08:16,230
so, it requires a little
bit less computing power.

167
00:08:16,230 --> 00:08:18,933
It is the current US government standard.

168
00:08:20,160 --> 00:08:23,550
Diffie-Hellman is primarily
used for key agreement

169
00:08:23,550 --> 00:08:27,240
or key exchange and
that allows two parties

170
00:08:27,240 --> 00:08:28,680
in the same Diffie-Hellman group

171
00:08:28,680 --> 00:08:30,990
that have no prior knowledge of each other

172
00:08:30,990 --> 00:08:34,053
to jointly establish a shared secret key.

173
00:08:34,980 --> 00:08:36,690
And lastly, we have El-Gamal.

174
00:08:36,690 --> 00:08:39,660
Now, El-Gamal is primarily
used for transmitting

175
00:08:39,660 --> 00:08:42,900
digital signatures and key exchange.

176
00:08:42,900 --> 00:08:44,340
So, in the commercial environment,

177
00:08:44,340 --> 00:08:47,850
the one that you will probably
work with most will be RSA.

178
00:08:47,850 --> 00:08:51,120
If you're in government
agencies or the military,

179
00:08:51,120 --> 00:08:53,403
the chance you're working with ECC.

180
00:08:55,740 --> 00:08:58,110
So, let's look at our
asymmetric characteristics.

181
00:08:58,110 --> 00:09:02,640
Remember, asymmetric
encryption requires two keys.

182
00:09:02,640 --> 00:09:04,320
Now, because it requires two keys,

183
00:09:04,320 --> 00:09:07,290
it is really computationally intensive.

184
00:09:07,290 --> 00:09:09,300
It doesn't work well on
large blocks of data.

185
00:09:09,300 --> 00:09:10,680
Matter of fact, it works much better

186
00:09:10,680 --> 00:09:13,410
on very small blocks of data.

187
00:09:13,410 --> 00:09:14,820
But key sizes are large,

188
00:09:14,820 --> 00:09:17,643
generally could be greater than 2,048.

189
00:09:18,600 --> 00:09:22,470
It is really scalable and I'm
gonna demonstrate that to you.

190
00:09:22,470 --> 00:09:25,170
And key exchange, well, it
was designed for key exchange.

191
00:09:25,170 --> 00:09:30,090
Inherent in the asymmetric
environment is a key exchange.

192
00:09:30,090 --> 00:09:32,190
And I'll be demonstrating that to you too.

193
00:09:33,600 --> 00:09:37,620
So, let's look at an asymmetric
message flow illustration.

194
00:09:37,620 --> 00:09:39,090
I have Alice and I have Bob.

195
00:09:39,090 --> 00:09:40,890
And Alice wants to send Bob

196
00:09:40,890 --> 00:09:43,383
an asymmetrically encrypted message.

197
00:09:44,790 --> 00:09:47,190
So, she's gonna take
her plaintext message.

198
00:09:47,190 --> 00:09:49,545
So, we've got a plaintext message

199
00:09:49,545 --> 00:09:51,390
and she's going to use
an asymmetric algorithm.

200
00:09:51,390 --> 00:09:55,260
So, let's say she's going
to use RSA for our purposes.

201
00:09:55,260 --> 00:09:59,550
Now, she's using two keys
and she needs to use a key

202
00:09:59,550 --> 00:10:04,320
so that the corresponding
key only belongs to Bob,

203
00:10:04,320 --> 00:10:06,180
because she's sending a message to Bob

204
00:10:06,180 --> 00:10:08,970
and she wants to make sure that only Bob,

205
00:10:08,970 --> 00:10:12,120
only Bob can decrypt the message.

206
00:10:12,120 --> 00:10:13,740
So, what is she gonna use?

207
00:10:13,740 --> 00:10:16,020
She's gonna use a copy
of Bob's public keys.

208
00:10:16,020 --> 00:10:18,120
Remember, public keys
are freely distributed.

209
00:10:18,120 --> 00:10:20,430
Why Bob's public key?

210
00:10:20,430 --> 00:10:24,557
Because what is the corresponding
key to Bob's public key?

211
00:10:24,557 --> 00:10:26,220
Well, hopefully you
said, Bob's private key.

212
00:10:26,220 --> 00:10:28,980
And who should have a
copy of Bob's private key?

213
00:10:28,980 --> 00:10:31,200
Hopefully you said, only Bob.

214
00:10:31,200 --> 00:10:34,890
So, she'll use an asymmetric
algorithm, let's say RSA,

215
00:10:34,890 --> 00:10:37,110
and a copy of Bob's public key,

216
00:10:37,110 --> 00:10:39,633
and we'll end up with
an encrypted message.

217
00:10:40,830 --> 00:10:42,780
Bob is gonna get that message.

218
00:10:42,780 --> 00:10:46,260
He is gonna use the same
asymmetric algorithm,

219
00:10:46,260 --> 00:10:48,360
so let's say he uses RSA,

220
00:10:48,360 --> 00:10:50,550
but he's gonna be using
the corresponding key.

221
00:10:50,550 --> 00:10:53,520
Remember we had two mathematically
related keys, 1 and 2?

222
00:10:53,520 --> 00:10:57,333
What is the mathematically
related key to Bob's public key?

223
00:10:58,230 --> 00:10:59,730
Bob's private key

224
00:10:59,730 --> 00:11:02,850
and only Bob should ever
have Bob's private key.

225
00:11:02,850 --> 00:11:05,490
So, he'll be able to use
that asymmetric algorithm

226
00:11:05,490 --> 00:11:07,980
and a copy of his private key,

227
00:11:07,980 --> 00:11:11,370
and voila, he's gonna have
the plaintext message.

228
00:11:11,370 --> 00:11:12,630
And if we do it this way,

229
00:11:12,630 --> 00:11:16,380
only Bob would ever be able
to decrypt the message.

230
00:11:16,380 --> 00:11:18,570
All right, so why don't we
just do everything this way

231
00:11:18,570 --> 00:11:19,710
if it works?

232
00:11:19,710 --> 00:11:20,700
Well, remember what I said,

233
00:11:20,700 --> 00:11:22,950
the problems were with asymmetric, right?

234
00:11:22,950 --> 00:11:25,560
Asymmetric is computationally intensive

235
00:11:25,560 --> 00:11:29,070
and it doesn't work well
on large blocks of data.

236
00:11:29,070 --> 00:11:30,520
So, we need another solution.

237
00:11:32,520 --> 00:11:35,520
Our solution is really a hybrid solution.

238
00:11:35,520 --> 00:11:36,840
In our hybrid solution,

239
00:11:36,840 --> 00:11:40,380
what we're gonna do is we're
gonna use the best of symmetric

240
00:11:40,380 --> 00:11:43,560
and the best of asymmetric
to be able to deliver

241
00:11:43,560 --> 00:11:47,520
an encrypted message, so,
I've got Allison, Bob again,

242
00:11:47,520 --> 00:11:50,160
we wanna send a message from Alice to Bob.

243
00:11:50,160 --> 00:11:52,773
So, what she's gonna do is,

244
00:11:54,150 --> 00:11:56,400
we're gonna start with
the plaintext message,

245
00:11:56,400 --> 00:11:57,840
down here on the bottom.

246
00:11:57,840 --> 00:12:00,160
So, Alice is gonna take
her plaintext message

247
00:12:01,260 --> 00:12:04,140
and she's gonna use a symmetric algorithm.

248
00:12:04,140 --> 00:12:04,973
Why?

249
00:12:04,973 --> 00:12:07,500
Because symmetric is
computationally efficient

250
00:12:07,500 --> 00:12:08,820
on large blocks of data

251
00:12:08,820 --> 00:12:11,760
and she's gonna use a
key, a symmetric key,

252
00:12:11,760 --> 00:12:14,100
but she's only ever gonna
use it this one time.

253
00:12:14,100 --> 00:12:16,800
And if you have a symmetric
key that's only ever used

254
00:12:16,800 --> 00:12:19,020
one time in a particular session,

255
00:12:19,020 --> 00:12:21,360
it's referred to as a session key.

256
00:12:21,360 --> 00:12:23,880
So, now she has encrypted the message.

257
00:12:23,880 --> 00:12:26,790
So, she has sent that
encrypted message to Bob.

258
00:12:26,790 --> 00:12:30,120
Now what's Bob gonna need
to decrypt the message?

259
00:12:30,120 --> 00:12:33,570
Well, he's gonna need a
copy of that session key.

260
00:12:33,570 --> 00:12:36,153
So, now, I want you to come up to the top.

261
00:12:37,740 --> 00:12:40,230
So, Alice is gonna take that session key.

262
00:12:40,230 --> 00:12:43,860
Remember small little bits
of data, it's just a key.

263
00:12:43,860 --> 00:12:46,480
She's gonna use an asymmetric algorithm

264
00:12:47,400 --> 00:12:50,730
and she's gonna use a
copy of Bob's public key.

265
00:12:50,730 --> 00:12:51,930
Why Bob's public key?

266
00:12:51,930 --> 00:12:53,070
Well, we just talked about it.

267
00:12:53,070 --> 00:12:55,470
What's the corresponding
key to Bob's public key?

268
00:12:55,470 --> 00:12:56,850
Bob's private key.

269
00:12:56,850 --> 00:12:58,950
Who has a copy of Bob's private key?

270
00:12:58,950 --> 00:13:00,690
Only Bob.

271
00:13:00,690 --> 00:13:02,820
So, she's gonna take
an asymmetric algorithm

272
00:13:02,820 --> 00:13:05,250
and a copy of Bob's public key.

273
00:13:05,250 --> 00:13:09,510
And now she's going to send
him the encrypted session key.

274
00:13:09,510 --> 00:13:11,220
So, what have we sent to Bob?

275
00:13:11,220 --> 00:13:14,670
Encrypted session key and
the encrypted message.

276
00:13:14,670 --> 00:13:16,140
What's Bob gonna do?

277
00:13:16,140 --> 00:13:17,580
Well, we're on the other side of the line.

278
00:13:17,580 --> 00:13:18,930
That's where Bob is.

279
00:13:18,930 --> 00:13:21,540
Bob is gonna take an asymmetric algorithm

280
00:13:21,540 --> 00:13:24,780
and his corresponding
key, his private key,

281
00:13:24,780 --> 00:13:26,220
and what's he gonna end up with?

282
00:13:26,220 --> 00:13:28,650
Cool, he's gonna end up
with the session key.

283
00:13:28,650 --> 00:13:32,050
And then he's gonna be able
to take that session key

284
00:13:33,270 --> 00:13:37,290
and use the symmetric
algorithm, let's say AES,

285
00:13:37,290 --> 00:13:39,780
with that session key and voila.

286
00:13:39,780 --> 00:13:41,550
What is he gonna end up with?

287
00:13:41,550 --> 00:13:44,100
He is gonna get the plaintext message.

288
00:13:44,100 --> 00:13:47,760
So, in this example, we got to
use the best of both worlds.

289
00:13:47,760 --> 00:13:50,490
We use symmetric on the message itself.

290
00:13:50,490 --> 00:13:51,323
Why?

291
00:13:51,323 --> 00:13:52,260
Because it's large blocks of data

292
00:13:52,260 --> 00:13:55,470
and symmetric is very
computationally efficient

293
00:13:55,470 --> 00:13:58,290
and we used asymmetric to get the key

294
00:13:58,290 --> 00:13:59,730
from one place to another.

295
00:13:59,730 --> 00:14:01,530
That session key, right?

296
00:14:01,530 --> 00:14:04,320
Why did Alice used Bob's public key?

297
00:14:04,320 --> 00:14:06,330
Because the corresponding
key to Bob's public key

298
00:14:06,330 --> 00:14:09,360
was Bob's private key,
and only Bob, right,

299
00:14:09,360 --> 00:14:12,450
should be able to have
the corresponding key,

300
00:14:12,450 --> 00:14:13,890
right, the private key.

301
00:14:13,890 --> 00:14:17,550
So, we're ensuring the
confidentiality of what's been sent

302
00:14:17,550 --> 00:14:19,950
because nobody else would
be able to decrypt it.

303
00:14:20,790 --> 00:14:22,563
Clear as day or clear as mud?

304
00:14:24,000 --> 00:14:26,760
All right, so let's compare
symmetric and asymmetric, right?

305
00:14:26,760 --> 00:14:28,800
Symmetric is a single shared key.

306
00:14:28,800 --> 00:14:30,330
Asymmetric key pair, right?

307
00:14:30,330 --> 00:14:31,560
We have M1 and M2.

308
00:14:31,560 --> 00:14:33,903
We can refer to 'em as private and public.

309
00:14:35,370 --> 00:14:38,370
Symmetric, works really well
in large blocks of data.

310
00:14:38,370 --> 00:14:42,360
Asymmetric, much more efficient
on small blocks of data.

311
00:14:42,360 --> 00:14:43,193
Why?

312
00:14:43,193 --> 00:14:45,630
Because symmetric is
computationally efficient.

313
00:14:45,630 --> 00:14:48,570
Asymmetric is computationally intensive.

314
00:14:48,570 --> 00:14:51,210
Symmetric, not the least bit scalable,

315
00:14:51,210 --> 00:14:53,910
asymmetric, absolutely scalable.

316
00:14:53,910 --> 00:14:57,360
Key exchange in symmetric,
inherently insecure,

317
00:14:57,360 --> 00:14:59,310
key distribution system is built

318
00:14:59,310 --> 00:15:02,370
right into the asymmetric process.

319
00:15:02,370 --> 00:15:04,560
So, while we could use
just one or the other

320
00:15:04,560 --> 00:15:06,840
when we combine, you know, parts of both,

321
00:15:06,840 --> 00:15:09,243
we really get the best of all worlds.

322
00:15:12,350 --> 00:15:14,760
And we need to make sure that
we're always securing our key.

323
00:15:14,760 --> 00:15:15,930
If it's symmetric, right?

324
00:15:15,930 --> 00:15:18,150
It's that key that has to be secured.

325
00:15:18,150 --> 00:15:20,820
If it's asymmetric, remember,
we have public and private,

326
00:15:20,820 --> 00:15:23,760
it's always the private
key that has to be secured.

327
00:15:23,760 --> 00:15:26,250
So, key management describes
the activities involved

328
00:15:26,250 --> 00:15:28,950
during the handling of cryptographic keys

329
00:15:28,950 --> 00:15:30,873
during their entire lifecycle.

330
00:15:32,250 --> 00:15:36,030
Usage, a key should only be
used for one purpose, right?

331
00:15:36,030 --> 00:15:37,710
We don't ever wanna use the same key

332
00:15:37,710 --> 00:15:39,360
for different cryptographic purposes

333
00:15:39,360 --> 00:15:42,210
because it might weaken
the security provided

334
00:15:42,210 --> 00:15:43,890
by one or both.

335
00:15:43,890 --> 00:15:46,770
Our strength of our key
should always be commensurate

336
00:15:46,770 --> 00:15:49,803
with the data process
protection requirements.

337
00:15:50,640 --> 00:15:53,730
The storage of our key, remember
symmetric and private keys,

338
00:15:53,730 --> 00:15:57,570
must be securely stored
and that the measures taken

339
00:15:57,570 --> 00:16:00,540
to protect a private key
must be at least equal

340
00:16:00,540 --> 00:16:03,240
to the required security
of the use of the key.

341
00:16:03,240 --> 00:16:07,470
And lastly, a KMPS is a Key
Management Practices Statement

342
00:16:07,470 --> 00:16:09,900
and that's gonna be a
document that an organization

343
00:16:09,900 --> 00:16:12,990
is gonna create that describes in detail,

344
00:16:12,990 --> 00:16:16,890
the organizational structure,
the responsible roles,

345
00:16:16,890 --> 00:16:19,290
and the rules for key management.

346
00:16:19,290 --> 00:16:22,890
So, managing that key is
extraordinarily important.

347
00:16:22,890 --> 00:16:26,433
Whether you're doing symmetric
or asymmetric encryption.

348
00:16:27,660 --> 00:16:29,790
And that my friends, brings
us to a three second challenge

349
00:16:29,790 --> 00:16:30,630
on encryption.

350
00:16:30,630 --> 00:16:31,779
You ready?

351
00:16:31,779 --> 00:16:32,612
Five questions, three seconds each.

352
00:16:32,612 --> 00:16:33,445
Let's do it.

353
00:16:34,290 --> 00:16:37,380
Number of keys in symmetric encryption.

354
00:16:37,380 --> 00:16:38,883
One, two, three.

355
00:16:40,260 --> 00:16:41,160
It's gonna be one.

356
00:16:42,690 --> 00:16:44,850
All right, the key mathematically related

357
00:16:44,850 --> 00:16:46,860
to a public key is a?

358
00:16:46,860 --> 00:16:48,750
One, two, three.

359
00:16:48,750 --> 00:16:51,390
Oh, I hope you shouted out, private key.

360
00:16:51,390 --> 00:16:53,610
Number three, the US government

361
00:16:53,610 --> 00:16:56,130
symmetric algorithm standard.

362
00:16:56,130 --> 00:16:59,100
So, it's a current standard
for symmetric algorithm.

363
00:16:59,100 --> 00:17:01,140
One, two, three.

364
00:17:01,140 --> 00:17:03,963
It's gonna be AES, also known as Rijndael.

365
00:17:04,950 --> 00:17:07,800
Number four, the key that Mary should use

366
00:17:07,800 --> 00:17:10,833
to send an asymmetrically
encrypted packet to Bob.

367
00:17:11,880 --> 00:17:14,340
So, she's gonna asymmetrically
encrypt a packet,

368
00:17:14,340 --> 00:17:16,620
she needs to send that packet to Bob,

369
00:17:16,620 --> 00:17:19,800
she wants to make sure
only Bob can decrypt it.

370
00:17:19,800 --> 00:17:22,050
So, think about what key Bob's gonna have

371
00:17:22,050 --> 00:17:24,450
and then tell me what
the corresponding key is

372
00:17:24,450 --> 00:17:26,970
that Mary's gonna use to
send an asymmetrically

373
00:17:26,970 --> 00:17:28,860
encrypted packet to Bob.

374
00:17:28,860 --> 00:17:31,020
I'm gonna give you six
seconds on this one.

375
00:17:31,020 --> 00:17:36,020
One, two, three, four, five, six.

376
00:17:36,900 --> 00:17:38,610
What'd you come up with?

377
00:17:38,610 --> 00:17:40,380
Should be Bob's public key.

378
00:17:40,380 --> 00:17:42,540
She's gonna use Bob's public key,

379
00:17:42,540 --> 00:17:45,750
because Bob has the corresponding
key, Bob's private key.

380
00:17:45,750 --> 00:17:48,210
So only Bob would be able to decrypt

381
00:17:48,210 --> 00:17:50,403
the asymmetrically encrypted packet.

382
00:17:51,480 --> 00:17:53,400
And lastly, number five,

383
00:17:53,400 --> 00:17:55,770
the key that Mary should use to decrypt

384
00:17:55,770 --> 00:17:59,430
an asymmetrically encrypted
packet sent by Bob.

385
00:17:59,430 --> 00:18:02,070
So, Bob sends Mary a packet this time.

386
00:18:02,070 --> 00:18:03,450
What key is she gonna use

387
00:18:03,450 --> 00:18:06,840
to decrypt the asymmetrically
encrypted packet?

388
00:18:06,840 --> 00:18:10,230
It's really the same question
I asked you in reverse.

389
00:18:10,230 --> 00:18:11,550
I'll give you six seconds again.

390
00:18:11,550 --> 00:18:15,480
One, two, three, four, five, six.

391
00:18:15,480 --> 00:18:16,770
Something came to her,

392
00:18:16,770 --> 00:18:20,850
we wanna make sure that only
Mary can decrypt that packet.

393
00:18:20,850 --> 00:18:23,400
Only Mary, not Bob, not anybody else.

394
00:18:23,400 --> 00:18:25,080
So, what key is she gonna use?

395
00:18:25,080 --> 00:18:27,570
She'll use her private key.

396
00:18:27,570 --> 00:18:30,900
Bob will have encrypted the
packet using Mary's public key.

397
00:18:30,900 --> 00:18:33,570
She'll decrypt it using her private key,

398
00:18:33,570 --> 00:18:35,010
corresponding keys.

399
00:18:35,010 --> 00:18:36,270
Best way to always think about this

400
00:18:36,270 --> 00:18:38,940
is what are we trying
to accomplish, right?

401
00:18:38,940 --> 00:18:40,739
What's are the key?

402
00:18:40,739 --> 00:18:43,703
And that'll help us understand
what keys now we need to use.

403
00:18:44,610 --> 00:18:48,180
Okay, here's a security in
action about encrypting messages.

404
00:18:48,180 --> 00:18:51,150
Jim, the procurement officer
at your organization,

405
00:18:51,150 --> 00:18:55,080
Anytown Medical Supply
Company, plans to send messages

406
00:18:55,080 --> 00:18:58,830
to his counterpart, Tom,
at Anytown Hospital.

407
00:18:58,830 --> 00:19:01,050
So, my question for you is,

408
00:19:01,050 --> 00:19:03,930
should symmetric or asymmetric encryption

409
00:19:03,930 --> 00:19:06,120
be used to encrypt the message?

410
00:19:06,120 --> 00:19:09,873
And two, what keys should
be used for this process?

411
00:19:11,250 --> 00:19:13,860
So, is he gonna use symmetric
or asymmetric encryption

412
00:19:13,860 --> 00:19:15,780
to encrypt the message itself?

413
00:19:15,780 --> 00:19:18,660
And then what keys should he
be using for this process?

414
00:19:18,660 --> 00:19:21,460
Great time to put me on pause
and write down some notes.

415
00:19:22,440 --> 00:19:24,780
All right, well, here
might be your instructions.

416
00:19:24,780 --> 00:19:26,940
Large blocks of data like messages,

417
00:19:26,940 --> 00:19:29,190
should be symmetrically encrypted.

418
00:19:29,190 --> 00:19:31,110
That's gonna mean using a single key,

419
00:19:31,110 --> 00:19:32,820
symmetric is single key.

420
00:19:32,820 --> 00:19:36,363
Often it's a single use key
referred to as a session key.

421
00:19:38,610 --> 00:19:40,080
But the challenge is gonna be,

422
00:19:40,080 --> 00:19:45,030
how is Jim gonna get Tom that key, right?

423
00:19:45,030 --> 00:19:48,540
The challenge is how to securely
provide the symmetric key

424
00:19:48,540 --> 00:19:50,370
to the recipient.

425
00:19:50,370 --> 00:19:53,730
So, asymmetric encryption can
be used to secure the key.

426
00:19:53,730 --> 00:19:57,360
In this case, the session
key will be encrypted

427
00:19:57,360 --> 00:20:01,590
using Tom's public key and
then transmitted to Tom.

428
00:20:01,590 --> 00:20:04,470
And Tom will be able to
decrypt the session key,

429
00:20:04,470 --> 00:20:07,350
because he's gonna use the
mathematically related key

430
00:20:07,350 --> 00:20:09,573
which is his private key.

431
00:20:10,470 --> 00:20:12,960
Now, once Tom has
decrypted the session key,

432
00:20:12,960 --> 00:20:16,380
he can then decrypt the original message.

433
00:20:16,380 --> 00:20:18,600
I know this feels a
little confusing at first,

434
00:20:18,600 --> 00:20:21,330
but if you kind of draw
it out, diagram it out,

435
00:20:21,330 --> 00:20:22,530
what you're trying to accomplish

436
00:20:22,530 --> 00:20:26,190
and what needs to be secret,
you know, and what doesn't,

437
00:20:26,190 --> 00:20:29,610
it'll really be helpful
to understand what keys

438
00:20:29,610 --> 00:20:32,070
you're going to be using, and doing that,

439
00:20:32,070 --> 00:20:34,350
which is really really important to do,

440
00:20:34,350 --> 00:20:35,793
is security in action.

441
00:20:36,870 --> 00:20:39,540
There's your word cloud,
you know what to do.

442
00:20:39,540 --> 00:20:42,630
Don't move on until you really understand

443
00:20:42,630 --> 00:20:43,860
all of these terms.

444
00:20:43,860 --> 00:20:45,360
But when you're ready,

445
00:20:45,360 --> 00:20:47,610
up next we're gonna talk about hashing.

446
00:20:47,610 --> 00:20:48,443
See you there.
