NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security · December 2016

Question 1 of 7: Symmetric Ciphers — One-Time Pad vs. Stream Cipher

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, December 2016 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Stream/Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 10 (Key Management, Diffie–Hellman, RSA), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow), Ch. 1 (Security Concepts — CIA Triad); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control), Ch. 1 (Security Concepts).

Question 1: Symmetric Ciphers — One-Time Pad vs. Stream Cipher (20 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Part a) — the one-time pad. A one-time pad (OTP) encrypts a plaintext by combining it, bit by bit (or character by character), with a truly random key — the pad — that is at least as long as the message, using a reversible operation such as XOR: $C_i = P_i \oplus K_i$. The receiver recovers the plaintext with the identical operation, $P_i = C_i \oplus K_i$, using its own copy of the same pad. Security depends on the pad being (1) truly random (not produced by any algorithm), (2) at least as long as the plaintext, and (3) used exactly once and then destroyed. When all three hold, the scheme achieves perfect (information-theoretic) secrecy: every possible plaintext of that length is equally consistent with the observed ciphertext under some key, so an attacker with unlimited computing power learns nothing about the message from the ciphertext alone.

Part b) — stream ciphers, and a block-cipher example. A stream cipher approximates the one-time pad using a much shorter, reusable secret key: a keystream generator (a deterministic pseudorandom-number generator seeded by the key, and typically a nonce) produces a keystream $K_1, K_2, \dots$ one symbol at a time, which is combined with the plaintext stream the same way as the pad, $C_i = P_i \oplus K_i$, and decrypted identically, $P_i = C_i \oplus K_i$, by regenerating the same keystream from the shared key. Because the keystream is only pseudorandom (algorithmically generated, not truly random), the security is computational, not information-theoretic — but the same short key can now be reused (with a fresh nonce/IV) across many messages, and encryption/decryption can proceed one byte at a time without waiting for a whole block, which suits real-time streams such as audio/video links. A commonly used block cipher, by contrast, encrypts fixed-size blocks (not a running stream) under a keyed, invertible transformation: AES (Advanced Encryption Standard, 128-bit blocks, 128/192/256-bit keys) is the standard modern example.

Part c) — advantage and disadvantage of the OTP versus a stream cipher. Advantage: the OTP offers unconditional (information-theoretic) security that does not depend on any assumption about an attacker's computing power or on the presumed hardness of a mathematical/algorithmic problem; a stream cipher's security is only computational — it rests on the keystream generator being unpredictable to a realistic attacker, and can in principle be weakened by cryptanalysis of the generator or by keystream reuse (e.g. the historical RC4/WEP failures). Disadvantage: the OTP's key must be truly random, as long as the entire message, and used only once, making key generation, distribution and storage impractical for anything beyond small, occasional exchanges; a stream cipher instead reuses one short key (with fresh nonces) across an arbitrarily long stream and across many sessions, which is what makes it practical for real systems such as secure network links.

← Paper overview