NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security · May 2014

Question 3 of 7: Cryptographic Hashes, MACs, and Digital Signatures

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, May 2014 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control, Least Privilege), Ch. 1 & 9 (Defense in Depth, Separation of Duty).

Question 3: Cryptographic Hashes, MACs, and Digital Signatures (20 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Part a) — cryptographic vs. non-cryptographic hash. A general-purpose (non-cryptographic) hash, such as a CRC or a simple checksum, is designed purely for speed and good statistical distribution across a hash table — it is not designed to resist a deliberate adversary. A cryptographic hash function $H$ must additionally satisfy: pre-image resistance (given $h = H(m)$, it is computationally infeasible to find any $m$); second pre-image resistance (given $m_1$, infeasible to find $m_2 \ne m_1$ with $H(m_1) = H(m_2)$); collision resistance (infeasible to find any pair $m_1 \ne m_2$ with $H(m_1) = H(m_2)$); and the avalanche effect (flipping a single input bit changes roughly half the output bits, unpredictably). These properties make the output unforgeable and unpredictable in a way a CRC's output is not — a CRC is trivial to adjust deliberately so a modified message keeps the same checksum, defeating its use as a security control.

Part b) — cryptographic hash vs. MAC. A plain cryptographic hash $H(m)$ has no secret key: it is a public function of the message alone, so anyone — including an attacker — can recompute $H(m')$ for a tampered message $m'$ and simply resend the new hash alongside it; a bare hash therefore proves only accidental-error integrity (e.g. transmission corruption), not that the message came from a trusted source. A message authentication code (MAC), such as HMAC, incorporates a shared secret key $K$: $\text{MAC} = H_K(m)$ (or a keyed construction such as HMAC-SHA256). Only someone who knows $K$ can compute a MAC that will verify correctly, so a valid MAC proves both integrity (the message was not altered) and authentication (it came from someone possessing the shared key) — properties a keyless hash alone cannot provide.

Part c) — security properties of digital signatures. A digital signature is computed over a message (typically over its hash) using the signer's private key and verified by anyone using the signer's corresponding public key. It provides: (1) integrity — any change to the signed message invalidates the signature; (2) authentication — only the holder of the private key could have produced a signature that verifies against the matching public key; and (3) non-repudiation — because the signing key is private to one party, that party cannot later credibly deny having signed the message, unlike a symmetric MAC where either party sharing the key could have produced it.