U30606 Assignment Question - Cryptographic Data Objects

Assignment Help Other Subject
Reference no: EM132486837

U30606 Assignment - University of Portsmouth, UK

Answer ALL of the following EIGHT questions.

Question 1 - Cryptographic Data Objects

B has just received the following message, which represents a cryptographic data object:

{(

{(KPbB)KPrS mod KPbS}K1,

{|(NB, NA , {{({K2}KPbB, NS)}(G1)KPrA mod NA}K1, {|{( {G3}(KPbA)KPrS mod KPbS, G2)}K1|}KPrB)|}KPrA

)}KBS

The following explains various terms in this object and some of the abbreviations used:

- {M} K represents the encryption of some message/data M using the key K

- {|M|} K represents the digital signing of some message/data M using the key K

- NX represents a nonce (i.e. a fresh and possibly random number used once only) generated by X

- KpbX represents the public part of the key pair presumably owned by X

- KprX represents the private part of the key pair presumably owned by X

- KAB represents a symmetric key shared between A and B

- K (or K1, K2, K3 etc.) represents some arbitrary key with no assumptions about its scope

- M represents some alphanumeric/textual message with no assumptions

- G1, G2, G3 etc. are prime numbers

which of the following sets of keys, nonces, numbers, and alphanumeric/textual messages "best" represents B's knowledge , after B applies any number of possible cryptographic operations to the object above, and assuming that B already has access to key K1 and the public key of any agent:

a) KBS, G2, KPrB

b) {(KPbB)KPrS mod KPbS, G2, KBS, KPrB, {(KPbB)KPrS mod KPbS}K1, NA, NB

c) NA, NB

d) NA, NB, KBS, KPrB

e) {(KPbB)KPrS mod KPbS}K1, {|(NB, NA, {{({K2}KPbB, NS)}(G1)KPrA mod NA}K1, {|{({G3}(KPbA)KPrS mod KPbS, G2)}K1|}KPrB)|}KPrA, NA, NB, KBS, KPrB, {(KPbB)KPrS mod KPbS

f) G2, NA, NB, G1, KBS, KPrB

g) (KPbB)KPrS mod KPbS, NA, NB, G2, KBS, KPrB

h) (KPbB)KPrS mod KPbS, (G1)KPrA mod NA, NA, NB, G2, KBS, KPrB

i) (KPbB)KPrS mod KPbS, G3, G2, KBS, KPrB

j) (KPbB)KPrS mod KPbS, NA, NB, G2, KBS, KPrB, G3, (KPbA)KPrS mod KPbS

k) NB

Explain your answer.

Question 2 - Authentication Protocols

Consider the following 4-message protocol:

1. A → S: (B, {(A, K1) }KpbS)

2. S → B: A

3. B → S: (A, {( B, K2) }KpbS)

4. S → A: (B, {K2}K1)

Which of the following statements is true, at the end of the protocol, and with regards to the purpose of the protocol:

a) Both A and B establish a session key K2, and B is sure of A's identity

b) Both A and B establish a session key K1, and B is sure of A's identity

c) Both A and B establish a session key K1, and A is sure of B's identity

d) Both A and B establish a session key K1, and both B and A are sure of each other's identity

e) Both A and B establish a session key K2, and A is sure of B's identity

f) Both A and B establish a session key K1

g) Both A and B establish a session key K2

h) Both A and B authenticate each other by knowing each other's identities

i) A ends up knowing B's identity

j) B ends up knowing A's identity

k) None of the above

l) All of the above

Explain your answer.

Question 3 - Non -Repudiation and Anonymity Protocols

For the Zhou-Gollman non-repudiation protocol discussed in the lecture on "Non -Repudiation and Anonymity Protocols", which one of the following statements is false:

a) At time point 4, both A and B can produc e evidence to prove that they received K

b) At time point 2, both A and B can produce evidence to prove that they received a signed message from the other party

c) At time point 0, S cannot prove anything

d) At time point 3, B cannot produce evidence to prove that A has access to key K

e) At time point 1, A can prove that B is alive

f) At time point 4, S can prove that A is alive

g) At time point 3, S can produce evidence that that A has access to key K

h) At time point 0, A is alive

i) At time point 2, A can produce evidence to prove that B is alive

j) At time point 4, the protocol terminates

Explain your answer.

Question 4 - Forwards Secrecy Protocols

Consider the following 4 -message protocol:

1. A → S: ( B, {(A, K1)}KpbS)

2. S → B: A

3. B → S: (A, {(B, K2)}KpbS)

4. S → A: (B, {K2}K1)

Assume three runs of the above protocol, that we call P1, P2 and P3. If after completion of run P3, K1 is compromised, i.e. it is leaked to some external intruder, how would this impact the forward secrecy property of K2 for all the three runs of the protocol P1, P2 and P3? Choose the right answer:

a) Compromising K1 in P3 compromises every other key in all of the three runs of the protocol

b) The secrecy of P3.K2 is not compromised, and therefore P2.K 2 and P1.K 2 would remain secret

c) Compromising K1 in P3 compromises P3.K 2, and therefore, every other previous version of K1 and K2 are also compromised

d) The secrecy of P3.K 2 is compromised, but P2.K 2 and P1.K 2 would remain secret since K1 is refreshed after each run, therefore P3.K1 is different from P2.K 1 and is different from P1.K1

e) Even though K1 is compromised in P3, K2 is not compromised in any of the three runs

Explain your answer.

Question 5 - Attacks on Security Protocols

Consider the following 4 -message protocol:

1. A → S: (B, {(A, K1)}KpbS)

2. S → B: A

3. B → S: (A, {(B, K2)}KpbS)

4. S → A: (B, {K2}K1)

And the following attack trace:

1. I(A) → S: (B, {(A, K)}KpbS)

2. S → B: A

3. B → S: (A, {(B, K2)}KpbS)

4. S → I(A): (B, {K2}K)

Which one of these changes to the protocol messages would fix the attack trace above, such as the attack then becomes impossible:

a) 3. B → S: (A, {(B, {K2}KpbA)}KpbS)

b) 4. S → A: (B, {K2, A}K1)

c) 2. S → B: {A}KpbB

d) 2. S → B: B

e) 3. B → S: (A, {(B, {K2} KprS)}KpbS)

f) 1. A → S: {(B, A, K1)}KpbS

g) 1. A → S: (A, {(B, K1)}KpbS)

h) 4. S → A: (B, {K1}K2)

i) 4. S → A: (A, B, {K2}K1)

j) 2. S → B: A, B

Explain your answer.

Question 6 - Mutation and Type-Flaw Attacks

Consider the following 4-message protocol between A and B, where (N+1) represents the increment of N:

1. A → B: (A, {NA}KAB)

2. B → A: {(NA+1, NB)}KAB

3. A → B: {NB+1}KAB

4. B → A: {(K'AB, NA)}KAB

Which of the following mutations to messages of the protocol above, would constitute a harmful attack:

a) 1. A → B: (C, {NA}KAB)

b) 1. A → B: ({NA}KAB, A)

c) 4. B → A: {(KAB, NA)}KAB

d) 4. B → A: {(K'AB, NB+1)}KAB

e) 3. A → B: {NB+1}KpbB

f) 2. B → A: {(NA+1, NA)}KAB

Explain your answer.

Question 7 - Access Control Models and Policies

Assume a network that consists of a set of nodes, {a, b, c, d, e, f, g, h, j, k, l, x, z}. These nodes have the following partial order relation on them: {(b≤a), ( f≤e), (z≤l), (z≤x), (l≤g), (c≤b), (g≤k), (e≤d), ( g≤h ), (k≤j), (g≤e), (e≤c) , (d≤b) , (x≤e)}

Furthermore, assume that a BLP policy is being enforced in the above network. Now assume that at some stage, node z becomes infected with a virus. Which one of the following sets of actions would also lead to infecting node a, assuming that viruses propagate through a network using the read and write commands. A virus would propagate from one node to another either because the second node read from the first one, or because the first node wrote to the second one. All read and write commands are subject to the policy being enforced and no read or write operation is possible in the absence of an order (either direct or indirect) between two nodes:

a) (l read from z), (l write to g), (g read from l ), (g read from e ) , (e write to c), (c write to b), (a read from b)

b) (z read from l), (a read from l)

c) (z write to x ) , (x write to e), (a read from e)

d) (z write to c), (b write to c), (a read from b)

e) (z write to g), (g write to h), (b read from h), (b write to a)

f) (x read from z), ( x write to e ) , (e write to d), ( a write to d)

g) (z write to g), (j read from g), (j write to d), (d write to b), (a read from b)

h) (z write to l) , (l write to g), (g write to c), (c write to d), (d write to b), (b write to a)

i) (a write to z)

j) (f read from z), (a read from f)

Explain your answer.

Question 8 - Security Datasets and Metrics

Considering the Cyber security open datasets provided by the Los Alamos National laboratory. Choose which one of the datasets below, would be most suitable to the definition of a metric for measuring the probability of the leakage of data from computers. To help you consider which dataset is best suited, you can imagine the scenario where you use the public laptops provided in the lockers in the Future Technology Centre (FTC) floors 1 or 2 during your tutorial hour for this module.

a) dns.txt.gz

b) redteam.txt.gz

c) User-Computer Authentication Associations in Time

d) Unified Host and Network Dataset

e) auth.txt.gz

f) proc.txt.gz

g) flows.txt.gz

Explain your answer.

Reference no: EM132486837

Questions Cloud

Intervertebral disc disease : Intervertebral Disc Disease (IVDD) is a common condition seen in dachshunds, beagles, poodles and other breeds of dog. Its course is generally progressive
Review article - epidemiology of paratuberculosis : Review article - Epidemiology Of Paratuberculosis - Prospectus For Improved Diagnosis And Control continue the work - Clinical Signs and Disease Manifestation
How does the long nectar tube increase the fitness of plant : The long tube that evolved with the nectar at the bottom, as with most traits we see today, one can reasonably assume that this trait evolved to increase
Discuss why value-based decision-making is required : Discuss why Value-Based Decision-making is required Material Selection and Use and Complexity areas of engineering practice.
U30606 Assignment Question - Cryptographic Data Objects : U30606 Assignment - University of Portsmouth, UK. Question 1 - Cryptographic Data Objects, and Question 2 - Authentication Protocols
Discuss the overall design of the space shuttle system : Discuss the overall design of the space shuttle system, and made 3 observations about this design from our perspective as engineers.
What is the significance of using chelating agents : Question 1) What are the physical and chemical barriers in purifying the DNA from intact animal and plant cells?
Discuss about the big data fraud management : Discuss about the Big data fraud management. Is it possible to implement Alibaba style of fraud management (risk analysis) for US based institutions?
What is dosage compensation : What is dosage compensation and why does it occur? provide one example and include the specific mechanism of how this is achieved.

Reviews

Write a Review

Other Subject Questions & Answers

  Appealing to the suspects self-interest

In the second phase of the interrogation process, there are several outcome-based tactics that may be used to obtain a confession.

  Define aspects of researching and developing strategies

Considering the aspects of researching and developing strategies, what areas do you think our current healthcare administrators struggle with the most?

  Describe the measurable outcomes you hope to achieve

Describe the measurable outcomes you hope to achieve with the implementation of this evidence-based change. Be sure to provide APA citations of the supporting.

  Why is a logical linear sequence useful

Why is it logical to write test items or assessments before producing instructional strategies? Why is a logical linear sequence useful, even though in practice instructional design components may be more concurrent

  How attentive is policy to needs of health care consumers

How attentive is the policy to the needs of health care consumers? Is health care accessible, affordable, and appropriate? Who is responsible for ensuring that care is delivered to those in need? In what ways do they meet this responsibility? In wha..

  Affirmative action programs

Current law requires that affirmative  action programs(AAP) be eliminated once affirmative action goals have been achieved. Do you feel that a company that was discriminating against minorities for years, and implenemted a court order AAP, should be ..

  Determine two standardized actions and ethical practices

Determine two (2) standardized actions and ethical practices that emergency management practitioners might implement in order to further professionalize.

  Explain the rationale behind the benchmarks

Identify how data for these measures will be collected and analyzed.

  Define the disorder and its main symptoms

After you have selected the disorder you wish to investigate, present a thorough overview of the chosen disorder. Assume your audience has no prior knowledge.

  Disorders in older adulthood-alcoholism-phobias-depression

Discuss the three most common disorders in older adulthood: alcoholism, phobias, and depression.  Why are these three disorders, in particular, so common in elderly communities?  What is the epidemiology and causes of each disorder?

  Describe specific and therapeutic endpoints

Recommend psychopharmacologic treatments and describe specific and therapeutic endpoints for your psychopharmacologic agent. (This should relate to HPI and).

  Write the full outline below

Write the full outline below and the topic will be about effects of video games and has to be the information from .gov website and it has to be from Scholarly journal, magazine & newspaper articles.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd