1
00:00:06,587 --> 00:00:08,910
- In this lesson, lesson 4.3

2
00:00:08,910 --> 00:00:12,153
we're gonna talk about hashing
and digital signatures.

3
00:00:13,530 --> 00:00:17,610
Now, the objective of hashing
is to prove integrity, right?

4
00:00:17,610 --> 00:00:18,840
We wanna prove

5
00:00:18,840 --> 00:00:22,140
that a message has not
changed in transmission.

6
00:00:22,140 --> 00:00:23,430
And the way it works is

7
00:00:23,430 --> 00:00:27,252
that the hashing process
produces a visual representation

8
00:00:27,252 --> 00:00:31,440
of a data set that can be
used for comparative purposes.

9
00:00:31,440 --> 00:00:33,690
Now, that output, that
visual representation

10
00:00:33,690 --> 00:00:35,280
has lots of different names.

11
00:00:35,280 --> 00:00:37,170
Sometimes it's known as a hash,

12
00:00:37,170 --> 00:00:39,060
sometimes it's known as a message digest.

13
00:00:39,060 --> 00:00:40,980
Sometimes it's known as a fingerprint.

14
00:00:40,980 --> 00:00:43,953
Sometimes it's referred
to as the hash value.

15
00:00:46,050 --> 00:00:47,850
Now, hashing can be used to validate

16
00:00:47,850 --> 00:00:50,490
that the message wasn't
changed in transmission.

17
00:00:50,490 --> 00:00:53,910
It can be used to verify that
a file has not been altered

18
00:00:53,910 --> 00:00:55,530
and it can be used to verify

19
00:00:55,530 --> 00:00:58,470
that a forensic clone is the exact same

20
00:00:58,470 --> 00:01:00,150
as the original media.

21
00:01:00,150 --> 00:01:01,050
But in all cases

22
00:01:01,050 --> 00:01:03,960
what we're trying to do
is prove integrity right?

23
00:01:03,960 --> 00:01:06,022
That the message

24
00:01:06,022 --> 00:01:09,033
or the data set or the
file has not changed.

25
00:01:11,670 --> 00:01:13,980
So let's talk through the hashing process.

26
00:01:13,980 --> 00:01:15,870
We take a variable length input.

27
00:01:15,870 --> 00:01:20,220
We can take anything from
three words, two words,

28
00:01:20,220 --> 00:01:22,920
one word to a full novel.

29
00:01:22,920 --> 00:01:25,680
It's a variable length input
and we're going to put it

30
00:01:25,680 --> 00:01:28,350
through a hash function
or a hash algorithm.

31
00:01:28,350 --> 00:01:30,330
And then we're going to have the output.

32
00:01:30,330 --> 00:01:32,400
Now the output being the hash, hash value,

33
00:01:32,400 --> 00:01:35,610
message digest, fingerprint,
whatever you wanna call it.

34
00:01:35,610 --> 00:01:38,231
But here's some of the key
characteristics of that output.

35
00:01:38,231 --> 00:01:42,270
Unique, one-way, fixed length output.

36
00:01:42,270 --> 00:01:44,970
Unique means that the
output will always be unique

37
00:01:44,970 --> 00:01:46,110
to that input.

38
00:01:46,110 --> 00:01:47,340
Now, I can put that input

39
00:01:47,340 --> 00:01:49,500
through the same hash
function a million times.

40
00:01:49,500 --> 00:01:51,600
It'll end up with the same output.

41
00:01:51,600 --> 00:01:54,210
But if I make any change,
the slightest change

42
00:01:54,210 --> 00:01:57,000
whatsoever then the
output will be different.

43
00:01:57,000 --> 00:02:00,060
So it's always uniquely tied to the input.

44
00:02:00,060 --> 00:02:01,800
One way means that we can go

45
00:02:01,800 --> 00:02:05,160
from that clear text to
this visual representation

46
00:02:05,160 --> 00:02:07,950
to this hash fingerprint message digest.

47
00:02:07,950 --> 00:02:11,262
But we can't go from this hash
fingerprint message digest

48
00:02:11,262 --> 00:02:13,050
back to the original.

49
00:02:13,050 --> 00:02:15,570
It's not like encryption where
we're transforming plain text

50
00:02:15,570 --> 00:02:16,980
to cipher text and back. Right?

51
00:02:16,980 --> 00:02:19,230
There is no transformation.

52
00:02:19,230 --> 00:02:20,430
Someone once explained it to me

53
00:02:20,430 --> 00:02:23,280
as you can make chicken
nuggets from a chicken

54
00:02:23,280 --> 00:02:24,810
but you really can't make a chicken

55
00:02:24,810 --> 00:02:26,220
from chicken nuggets, right?

56
00:02:26,220 --> 00:02:28,110
It's a one-way process.

57
00:02:28,110 --> 00:02:30,120
And then it's a fixed length output.

58
00:02:30,120 --> 00:02:33,313
So the various hash functions
will have a specific length

59
00:02:33,313 --> 00:02:36,450
that their output is so unique, one-way,

60
00:02:36,450 --> 00:02:37,743
fixed length output.

61
00:02:39,060 --> 00:02:40,175
Now, in order to be secure

62
00:02:40,175 --> 00:02:44,490
a cryptographic hash function
has to meet three criteria.

63
00:02:44,490 --> 00:02:47,340
One, the output must
not be reversible means

64
00:02:47,340 --> 00:02:49,140
that one-way representation,

65
00:02:49,140 --> 00:02:52,200
two, a variable length input must produce

66
00:02:52,200 --> 00:02:53,910
a fixed length output.

67
00:02:53,910 --> 00:02:57,060
And three, the output must
be unique to the input.

68
00:02:57,060 --> 00:03:00,060
Now, if a hash function
ever ends up producing

69
00:03:00,060 --> 00:03:03,420
the same value for two different
inputs, the result is known

70
00:03:03,420 --> 00:03:06,960
as a collision and that
hash process, right

71
00:03:06,960 --> 00:03:09,843
or that hash function is
no longer useful to us.

72
00:03:12,660 --> 00:03:15,690
Now, there are three hash
functions you wanna recognize.

73
00:03:15,690 --> 00:03:18,450
Message Digest, you'll
see it abbreviated as MD,

74
00:03:18,450 --> 00:03:20,070
Secure Hash Algorithm.

75
00:03:20,070 --> 00:03:22,440
You'll see that abbreviated as SHA, S H A

76
00:03:22,440 --> 00:03:24,547
and then RIPEMD.

77
00:03:24,547 --> 00:03:26,910
The MD4 was developed by Ron Rivest

78
00:03:26,910 --> 00:03:31,410
of RSA fame in 1990
and it has been broken.

79
00:03:31,410 --> 00:03:34,320
The MD5, which is still in use

80
00:03:34,320 --> 00:03:38,250
has been subject to collision attacks.

81
00:03:38,250 --> 00:03:40,860
And for cryptographic purposes,
it is considered broken

82
00:03:40,860 --> 00:03:44,610
however, it's sometimes used
for non-cryptographic purposes.

83
00:03:44,610 --> 00:03:49,140
Secure hash algorithm, SHA
was developed by the NSA,

84
00:03:49,140 --> 00:03:51,900
the National Security Agency
here in the United States.

85
00:03:51,900 --> 00:03:54,120
Now, SHA-1 is subject
to collision attacks.

86
00:03:54,120 --> 00:03:55,080
Remember, collision attack

87
00:03:55,080 --> 00:03:59,190
is when we could have different
output for the same input.

88
00:03:59,190 --> 00:04:01,890
But secure versions include the SHA-2

89
00:04:01,890 --> 00:04:03,693
and the SHA-3 families.

90
00:04:04,650 --> 00:04:09,075
Then RIPEMD-160 is a
cryptographic hash function

91
00:04:09,075 --> 00:04:12,960
that is based on the
Merkle-Damgard construction.

92
00:04:12,960 --> 00:04:16,473
And it is actually what's
used in the Bitcoin standard.

93
00:04:18,270 --> 00:04:20,970
So how do we generate this fingerprint

94
00:04:20,970 --> 00:04:24,360
or hash or message digest,
whatever we're calling it?

95
00:04:24,360 --> 00:04:27,240
Well, we use a hash calculator.

96
00:04:27,240 --> 00:04:30,420
So in this case, I just access
to hash calculator online.

97
00:04:30,420 --> 00:04:32,130
You can do bring one, use one online.

98
00:04:32,130 --> 00:04:33,390
You can have one locally.

99
00:04:33,390 --> 00:04:35,760
And what you're gonna do is
you're gonna put your input

100
00:04:35,760 --> 00:04:37,200
in or your input of any length.

101
00:04:37,200 --> 00:04:39,162
So I just put the Gettysburg Address

102
00:04:39,162 --> 00:04:40,770
beginning of it, four score

103
00:04:40,770 --> 00:04:42,630
and seven years ago, our
fathers brought forth

104
00:04:42,630 --> 00:04:44,202
on this continent a new
nation conceived in liberty

105
00:04:44,202 --> 00:04:46,678
and dedicated to the
proposition that all men

106
00:04:46,678 --> 00:04:49,440
are created equal.

107
00:04:49,440 --> 00:04:51,780
Now it says, what kind
of checksum do you want?

108
00:04:51,780 --> 00:04:53,580
Really what kind of hash do you want?

109
00:04:53,580 --> 00:04:56,766
MD5, SHA-1, SHA-256 and I chose SHA-256.

110
00:04:56,766 --> 00:04:59,610
And then where it says string hash,

111
00:04:59,610 --> 00:05:02,550
that's the visual representation, right?

112
00:05:02,550 --> 00:05:03,780
Now, I can't go from that

113
00:05:03,780 --> 00:05:06,090
if I just said that back to my four score

114
00:05:06,090 --> 00:05:07,380
and seven years ago.

115
00:05:07,380 --> 00:05:08,760
That's the visual representation

116
00:05:08,760 --> 00:05:10,953
but it is unique to that input.

117
00:05:14,010 --> 00:05:15,600
So what if I do this again?

118
00:05:15,600 --> 00:05:19,110
What if I take the same exact string?

119
00:05:19,110 --> 00:05:20,520
Four score and seven years ago

120
00:05:20,520 --> 00:05:22,290
our fathers brought
forth to this continent

121
00:05:22,290 --> 00:05:24,241
a new nation conceived
in liberty and dedicated

122
00:05:24,241 --> 00:05:27,600
to the proposition that
all men are created equal.

123
00:05:27,600 --> 00:05:28,920
But I make one change.

124
00:05:28,920 --> 00:05:31,740
I take that first word
and instead of capital F,

125
00:05:31,740 --> 00:05:35,520
lowercase O U R, I did capital
F, capital O, capital U

126
00:05:35,520 --> 00:05:36,750
and capital R.

127
00:05:36,750 --> 00:05:38,820
No change to the content, just change

128
00:05:38,820 --> 00:05:43,200
in this case to the capitalization,
still using SHA-256.

129
00:05:43,200 --> 00:05:45,240
And if you look, you'll see

130
00:05:45,240 --> 00:05:48,900
that the visual representation,
right now ends in,

131
00:05:48,900 --> 00:05:50,460
well it's a completely different number,

132
00:05:50,460 --> 00:05:52,020
but just to make it easier

133
00:05:52,020 --> 00:05:55,950
you can see it's ending
down at the bottom at D85.

134
00:05:55,950 --> 00:05:57,420
So made any change.

135
00:05:57,420 --> 00:06:00,120
If I changed spacing,
change capitalization,

136
00:06:00,120 --> 00:06:02,730
change punctuation or of
course if I changed any

137
00:06:02,730 --> 00:06:05,010
of the words or even one single letter,

138
00:06:05,010 --> 00:06:06,510
the output would be different.

139
00:06:08,280 --> 00:06:10,750
So here's how we use our
message digest in action.

140
00:06:10,750 --> 00:06:14,610
Alice is gonna put a message
to a hashing algorithm

141
00:06:14,610 --> 00:06:18,390
and she's gonna generate a
message digest or a hash value.

142
00:06:18,390 --> 00:06:20,910
Remember, what is Alice
trying to accomplish here?

143
00:06:20,910 --> 00:06:23,305
She wants to make sure that
when a message gets to Bob,

144
00:06:23,305 --> 00:06:27,400
Bob knows the message wasn't
changed in transmission.

145
00:06:27,400 --> 00:06:30,240
So she's going to send
the plain text message

146
00:06:30,240 --> 00:06:31,920
'cause we're not looking
at confidentiality here.

147
00:06:31,920 --> 00:06:33,810
We only care about integrity right now.

148
00:06:33,810 --> 00:06:36,870
So send the the message and
that message digest to Bob.

149
00:06:36,870 --> 00:06:38,280
And you might have seen a message digest,

150
00:06:38,280 --> 00:06:40,050
some point you might have gotten one that

151
00:06:40,050 --> 00:06:42,930
underneath a signature line
you see kind of a block

152
00:06:42,930 --> 00:06:45,180
of letters and numbers.

153
00:06:45,180 --> 00:06:47,103
That would be that message digest.

154
00:06:48,210 --> 00:06:51,660
So Alice sends the message
and the message digest to Bob.

155
00:06:51,660 --> 00:06:53,490
Bob receives that clear text message

156
00:06:53,490 --> 00:06:55,830
and the message digest.

157
00:06:55,830 --> 00:06:57,416
Bob is gonna put the message

158
00:06:57,416 --> 00:07:00,240
through the same hashing algorithm, right?

159
00:07:00,240 --> 00:07:04,500
So whatever Alice used, Bob is gonna use,

160
00:07:04,500 --> 00:07:06,930
it's gonna the same through
the same hashing algorithm.

161
00:07:06,930 --> 00:07:09,930
And he's gonna generate a message digest

162
00:07:09,930 --> 00:07:11,640
or a hash value, right?

163
00:07:11,640 --> 00:07:13,830
So now he's got the
one that Alice sent him

164
00:07:13,830 --> 00:07:15,543
and the one he created.

165
00:07:16,440 --> 00:07:18,210
And he is gonna compare the two.

166
00:07:18,210 --> 00:07:19,650
And what's he gonna know?

167
00:07:19,650 --> 00:07:22,140
Well, if the message digests are the same

168
00:07:22,140 --> 00:07:25,350
he knows that the message was
not changed in transmission.

169
00:07:25,350 --> 00:07:28,830
He can trust the integrity of the message.

170
00:07:28,830 --> 00:07:31,170
But if the message digests are different

171
00:07:31,170 --> 00:07:34,830
then he knows that the message
was modified in transmission.

172
00:07:34,830 --> 00:07:39,003
And that's how we use
hashing to verify integrity.

173
00:07:41,010 --> 00:07:42,540
Now, there are some hash extensions.

174
00:07:42,540 --> 00:07:45,630
There's what's known as
a hash MAC or an HMAC.

175
00:07:45,630 --> 00:07:49,860
A hash MAC message,
authentication code or HMAC

176
00:07:49,860 --> 00:07:54,030
is a hash value that actually
includes a symmetric key.

177
00:07:54,030 --> 00:07:57,480
So you take the, whatever the the value is

178
00:07:57,480 --> 00:07:59,610
whatever the string is that you wanna hash

179
00:07:59,610 --> 00:08:02,370
and you throw in a symmetric key.

180
00:08:02,370 --> 00:08:03,570
Ah, so that's interesting.

181
00:08:03,570 --> 00:08:04,620
Why would you do that?

182
00:08:04,620 --> 00:08:07,170
Well, if you control both sides, right?

183
00:08:07,170 --> 00:08:10,950
The HMAC can't be reproduced
without knowing the key.

184
00:08:10,950 --> 00:08:14,130
So you have to also get
that symmetric key somehow.

185
00:08:14,130 --> 00:08:16,530
So the HMAC provides integrity

186
00:08:16,530 --> 00:08:18,360
and data origin authentication.

187
00:08:18,360 --> 00:08:20,250
You know where it came from.

188
00:08:20,250 --> 00:08:23,220
The HMAC is used by
cryptographic protocols such

189
00:08:23,220 --> 00:08:26,010
as TLS and IPsec, both
of which we'll be talking

190
00:08:26,010 --> 00:08:28,950
about a little bit later
on to verify the integrity

191
00:08:28,950 --> 00:08:32,523
of transmitted data during
secure communications.

192
00:08:34,410 --> 00:08:37,069
The other hash extension that
is used pretty frequently

193
00:08:37,069 --> 00:08:39,090
are salts or salting.

194
00:08:39,090 --> 00:08:42,000
Salts are just random
values that are appended

195
00:08:42,000 --> 00:08:45,630
to the input to negate the
value of a rainbow table.

196
00:08:45,630 --> 00:08:48,360
Rainbow tables are just
pre-computed hashes.

197
00:08:48,360 --> 00:08:49,320
So someone said, okay

198
00:08:49,320 --> 00:08:52,590
I'm gonna take 10,000
common dictionary words.

199
00:08:52,590 --> 00:08:55,340
I'm gonna put them through SHA-256,

200
00:08:55,340 --> 00:08:57,163
I'm gonna see what the hash is

201
00:08:57,163 --> 00:08:59,430
and now I'll have their
visual representation.

202
00:08:59,430 --> 00:09:01,500
So if I ever capture a hash, I can say, oh

203
00:09:01,500 --> 00:09:02,640
was it in my table?

204
00:09:02,640 --> 00:09:04,290
And I'll know what it is

205
00:09:04,290 --> 00:09:06,780
if I'm the bad guy doing
that obviously, right?

206
00:09:06,780 --> 00:09:09,240
The rainbow tables are
publicly available tables

207
00:09:09,240 --> 00:09:11,850
of those pre-computed hashes.

208
00:09:11,850 --> 00:09:14,640
So now let's turn our attention
in digital signatures.

209
00:09:14,640 --> 00:09:18,111
The objective of a digital
signature is to prove integrity

210
00:09:18,111 --> 00:09:20,280
and non-repudiation, right.

211
00:09:20,280 --> 00:09:21,900
Integrity, a message hasn't changed.

212
00:09:21,900 --> 00:09:23,340
And non-repudiation means

213
00:09:23,340 --> 00:09:26,250
that the signer can't
deny sending the message.

214
00:09:26,250 --> 00:09:28,440
And conversely, the receiver can trust

215
00:09:28,440 --> 00:09:31,023
that the message came
from that name signer.

216
00:09:31,950 --> 00:09:33,780
So a digital signature.

217
00:09:33,780 --> 00:09:37,350
All right, get ready for
this is a message digest

218
00:09:37,350 --> 00:09:40,560
that's been encrypted using
the sender's private key.

219
00:09:40,560 --> 00:09:42,390
Now, we're not encrypting
the message digest

220
00:09:42,390 --> 00:09:44,160
'cause we're trying to
keep anything secret

221
00:09:44,160 --> 00:09:45,120
about the message digest.

222
00:09:45,120 --> 00:09:47,670
Remember, the message digest
is a bunch of gobbly-cook.

223
00:09:47,670 --> 00:09:50,670
Why are we encrypting it with
the sender's private key?

224
00:09:50,670 --> 00:09:53,790
Because who should have
the sender's private key?

225
00:09:53,790 --> 00:09:55,050
Only the sender.

226
00:09:55,050 --> 00:09:58,620
What's the corresponding key
to the sender's private key?

227
00:09:58,620 --> 00:10:01,830
Sender's public key which
is freely distributed.

228
00:10:01,830 --> 00:10:05,010
So if we can decrypt a message digest

229
00:10:05,010 --> 00:10:10,010
with the sender's public key,
right the corresponding key

230
00:10:10,920 --> 00:10:12,963
we know who the message came from.

231
00:10:13,849 --> 00:10:15,851
Now, digital signatures
require two algorithms

232
00:10:15,851 --> 00:10:20,010
a hashing algorithm and a
digital signature algorithm.

233
00:10:20,010 --> 00:10:21,118
So again, often used RSA,

234
00:10:21,118 --> 00:10:24,990
right defacto commercial standard works

235
00:10:24,990 --> 00:10:27,540
with both encryption
and digital signatures.

236
00:10:27,540 --> 00:10:30,780
Or DSA, digital signature
algorithm, which is published

237
00:10:30,780 --> 00:10:33,390
by NIST, the National Institute
of Standards and Technology

238
00:10:33,390 --> 00:10:36,900
in cooperation with the NSA,
the National Security Agency

239
00:10:36,900 --> 00:10:40,890
and it is the US Government
Digital Signature standard.

240
00:10:40,890 --> 00:10:43,533
Now let's walk through
digital signatures in action.

241
00:10:44,520 --> 00:10:46,620
Alice is gonna put a message
for hashing algorithm

242
00:10:46,620 --> 00:10:49,893
and he's gonna generate a message
digest or a hash function.

243
00:10:50,940 --> 00:10:53,310
Alice is gonna encrypt that message digest

244
00:10:53,310 --> 00:10:55,773
with her private key.

245
00:10:56,730 --> 00:10:58,740
She's gonna send the plain text message

246
00:10:58,740 --> 00:11:01,802
and that encrypted message digest to Bob.

247
00:11:01,802 --> 00:11:06,032
Bob receives the message and
the encrypted message digest.

248
00:11:06,032 --> 00:11:08,970
Bob is gonna decrypt
the message digest using

249
00:11:08,970 --> 00:11:11,220
the corresponding key
to Alice's private key,

250
00:11:11,220 --> 00:11:12,840
which is Alice's public key.

251
00:11:12,840 --> 00:11:16,500
And if he can decrypt,
right the message digest

252
00:11:16,500 --> 00:11:18,060
it proves authenticity.

253
00:11:18,060 --> 00:11:22,440
It proves that it came from
Alice, right, non-repudiation.

254
00:11:22,440 --> 00:11:24,600
Then Bob is gonna take
that plain text message.

255
00:11:24,600 --> 00:11:26,171
He's gonna put it

256
00:11:26,171 --> 00:11:27,570
through the same hashing
algorithm that Alice used.

257
00:11:27,570 --> 00:11:29,850
He's gonna generate a message digest.

258
00:11:29,850 --> 00:11:31,140
And just like we saw before

259
00:11:31,140 --> 00:11:33,240
he'll compare the two message digests.

260
00:11:33,240 --> 00:11:35,550
If they're the same, he
knows that the message

261
00:11:35,550 --> 00:11:38,790
wasn't modified in
transmission, proving integrity.

262
00:11:38,790 --> 00:11:40,200
And if they're different

263
00:11:40,200 --> 00:11:44,220
he knows the message was
modified in transmission.

264
00:11:44,220 --> 00:11:46,590
In this lesson, we talked about hashing

265
00:11:46,590 --> 00:11:49,526
and digital signatures,
hashing to prove integrity

266
00:11:49,526 --> 00:11:53,850
and digital signatures
to prove non-repudiation

267
00:11:53,850 --> 00:11:54,840
and authenticity.

268
00:11:54,840 --> 00:11:56,820
We know who the message came from.

269
00:11:56,820 --> 00:11:59,130
That sender can't deny sending it.

270
00:11:59,130 --> 00:12:02,610
We can trust that they were
the ones that sent the message.

271
00:12:02,610 --> 00:12:06,030
So hashing and digital signatures.

272
00:12:06,030 --> 00:12:08,100
And that brings us to a
three-second challenge.

273
00:12:08,100 --> 00:12:09,844
Now you ready? All right.

274
00:12:09,844 --> 00:12:13,290
A unique fixed length
representation of data.

275
00:12:13,290 --> 00:12:15,450
This is the thing I said
had multiple names to it.

276
00:12:15,450 --> 00:12:16,283
What is this?

277
00:12:16,283 --> 00:12:18,180
One, two, three.

278
00:12:18,180 --> 00:12:20,880
A hash, a fingerprint, a message digest

279
00:12:20,880 --> 00:12:22,080
all of those would work.

280
00:12:23,040 --> 00:12:25,140
Number two, the term used to describe

281
00:12:25,140 --> 00:12:27,390
when a hash function
produces the same output

282
00:12:27,390 --> 00:12:28,863
for two different inputs?

283
00:12:30,030 --> 00:12:32,119
This is when we have a, this is a problem.

284
00:12:32,119 --> 00:12:36,183
One, two, three that's
known as a collision.

285
00:12:37,920 --> 00:12:41,100
Number three, a hash value
that includes a symmetric key.

286
00:12:41,100 --> 00:12:45,463
So we add the symmetric
key in with the hash value.

287
00:12:45,463 --> 00:12:48,933
Said it was used by TLS and IPsec.

288
00:12:50,580 --> 00:12:53,910
That's gonna be a Hashed
Message Authentication Code,

289
00:12:53,910 --> 00:12:55,863
we just call it an HMAC all the time.

290
00:12:57,390 --> 00:12:59,850
Number four, random values appended

291
00:12:59,850 --> 00:13:02,943
to the input to negate the
value of a rainbow table.

292
00:13:04,560 --> 00:13:06,363
One, two, three.

293
00:13:07,620 --> 00:13:08,883
That's gonna be salts.

294
00:13:10,200 --> 00:13:12,030
And lastly number five,

295
00:13:12,030 --> 00:13:15,963
key used to decrypt an
encrypted message digest.

296
00:13:17,550 --> 00:13:20,093
So if I get sent an
encrypted message digest

297
00:13:20,093 --> 00:13:24,810
what key should I use to decrypt it?

298
00:13:24,810 --> 00:13:26,160
Think about that for a sec.

299
00:13:28,560 --> 00:13:30,123
One, two, three.

300
00:13:31,650 --> 00:13:34,230
I'm going to use the sender's public key

301
00:13:34,230 --> 00:13:36,945
because the sender's always
gonna encrypt the message digest

302
00:13:36,945 --> 00:13:39,840
with their private key
because only the sender

303
00:13:39,840 --> 00:13:41,310
should have their private key.

304
00:13:41,310 --> 00:13:44,340
So the correspondent of the
mathematically related key

305
00:13:44,340 --> 00:13:46,233
will be the sender's public key.

306
00:13:47,550 --> 00:13:49,560
Okay, that brings us
to a security-in-action

307
00:13:49,560 --> 00:13:51,420
about secure communication.

308
00:13:51,420 --> 00:13:54,240
The local police department
needs to communicate regularly

309
00:13:54,240 --> 00:13:56,010
with the Department of Homeland Security

310
00:13:56,010 --> 00:13:58,170
about national security issues.

311
00:13:58,170 --> 00:14:02,730
Confidentiality, integrity
and sender authenticity

312
00:14:02,730 --> 00:14:05,250
are equally important to both parties.

313
00:14:05,250 --> 00:14:07,020
So here's my question to you.

314
00:14:07,020 --> 00:14:10,695
What cryptographic processes
and associated algorithms

315
00:14:10,695 --> 00:14:12,720
are you gonna recommend?

316
00:14:12,720 --> 00:14:16,980
Confidentiality, integrity
and sender authenticity.

317
00:14:16,980 --> 00:14:19,500
What a great time to put me
on pause, write some notes

318
00:14:19,500 --> 00:14:20,333
and then come on back

319
00:14:20,333 --> 00:14:22,380
and we'll talk about your recommendations.

320
00:14:24,510 --> 00:14:26,730
So our recommended processes
would be encryption

321
00:14:26,730 --> 00:14:30,660
for confidentiality,
hashing, right for integrity

322
00:14:30,660 --> 00:14:33,753
and digital signatures
for sender authenticity.

323
00:14:34,710 --> 00:14:37,350
Now for encryption, we're
probably gonna wanna use AES

324
00:14:37,350 --> 00:14:38,310
for confidentiality.

325
00:14:38,310 --> 00:14:41,280
That's current US Government standard.

326
00:14:41,280 --> 00:14:45,030
For hashing, we'll use the
SHA-2 or the SHA-3 family

327
00:14:45,030 --> 00:14:48,406
for message integrity and
for digital signatures

328
00:14:48,406 --> 00:14:52,290
because this is government,
right the US government

329
00:14:52,290 --> 00:14:56,100
we're going to use DSA, the
digital signature algorithm.

330
00:14:56,100 --> 00:15:00,093
So digital signatures using
DSA for non-repudiation.

331
00:15:00,930 --> 00:15:01,833
Do all that.

332
00:15:02,942 --> 00:15:05,070
You'll have confidentiality, integrity

333
00:15:05,070 --> 00:15:06,933
and sender authenticity.

334
00:15:07,937 --> 00:15:08,770
If you can do that,

335
00:15:08,770 --> 00:15:11,040
well that's definitely security-in-action.

336
00:15:11,040 --> 00:15:12,960
All right, let's go to our Word Cloud.

337
00:15:12,960 --> 00:15:14,100
It's a bunch here.

338
00:15:14,100 --> 00:15:15,090
You know what to do.

339
00:15:15,090 --> 00:15:17,640
Make sure that you can
define all of these terms.

340
00:15:17,640 --> 00:15:19,920
You know what they mean,
you know how to use them.

341
00:15:19,920 --> 00:15:22,967
And once you're there, then
come on over to the next lesson.

342
00:15:22,967 --> 00:15:25,890
We'll be talking about
digital certificates.

343
00:15:25,890 --> 00:15:26,723
See you there.
