Skip to main content

Cryptography and Network Security Principles and Practice, Global Edition, 7th Edition William Stall

Page 1

Type:

Solution Manual

Resource:

Cryptography and Network Security Principles and Practice

Edition:

7th Edition

Author(s):

William Stallings


TABLE OF CONTENTS

Chapter 1 Introduction.............................................................. 5 Chapter 2 Introduction to Number Theory ................................. 10 Chapter 3 Classical Encryption Techniques ................................. 20 Chapter 4 Block Ciphers and the Data Encryption Standard .......... 28 Chapter 5 Finite Fields ............................................................ 40 Chapter 6 Advanced Encryption Standard .................................. 45 Chapter 7 Block Cipher Operation ............................................. 52 Chapter 8 Random and Pseudorandom Number Generation and Stream Ciphers....................................................................... 59 Chapter 9 Public-Key Cryptography and RSA .............................. 63 Chapter 10 Other Public-Key Cryptosystems .............................. 73

-4-


CHAPTER 1 INTRODUCTION ANSWERS TO QUESTIONS 1.1 The OSI Security Architecture is a framework that provides a systematic way of defining the requirements for security and characterizing the approaches to satisfying those requirements. The document defines security attacks, mechanisms, and services, and the relationships among these categories. 1.2 Confidentiality, Integrity and Availability (CIA) are the three key objectives of computer security. Confidentiality preserves authorized restrictions on information access and protects personal privacy and proprietary information. Integrity guards against improper information modification or destruction, and also ensures information nonrepudiation and authenticity. Availability assures that systems work promptly and service is not denied to authorized users. 1.3 Passive attacks: release of message contents and traffic analysis. Active attacks: masquerade, replay, modification of messages, and denial of service. 1.4 Authentication: The assurance that the communicating entity is the one that it claims to be. Access control: The prevention of unauthorized use of a resource (i.e., this service controls who can have access to a resource, under what conditions access can occur, and what those accessing the resource are allowed to do). Data confidentiality: The protection of data from unauthorized disclosure. Data integrity: The assurance that data received are exactly as sent by an authorized entity (i.e., contain no modification, insertion, deletion, or replay). Nonrepudiation: Provides protection against denial by one of the entities involved in a communication of having participated in all or part of the communication. Availability service: The property of a system or a system resource being accessible and usable upon demand by an authorized system entity, according to performance specifications for the system (i.e., a system is available if it provides services according to the system design whenever users request them). -5-


1.5 See Table 1.3. 1.6 Authentication: The assurance that the communicating entity is the one that it claims to be. Access control: The prevention of unauthorized use of a resource (i.e., this service controls who can have access to a resource, under what conditions access can occur, and what those accessing the resource are allowed to do). Data confidentiality: The protection of data from unauthorized disclosure. Data integrity: The assurance that data received are exactly as sent by an authorized entity (i.e., contain no modification, insertion, deletion, or replay). Nonrepudiation: Provides protection against denial by one of the entities involved in a communication of having participated in all or part of the communication. Availability service: The property of a system or a system resource being accessible and usable upon demand by an authorized system entity, according to performance specifications for the system (i.e., a system is available if it provides services according to the system design whenever users request them). 1.7 An attack surface consists of the reachable and exploitable vulnerabilities in a system. An attack tree is a branching, hierarchical data structure that represents a set of potential techniques for exploiting security vulnerabilities.

ANSWERS TO PROBLEMS 1.1 For the cash deposit system, maintaining the confidentiality of the account number to which the deposit is being made is not crucial. However, it is important to maintain the integrity. Similarly, integrity of the amount being deposited also needs to be maintained. In short, we can say that confidentiality of the account number and amount is of moderate concern, while integrity of both of them is crucially important. Availability of the host system is important to the economic well-being of the bank, but not to its fiduciary responsibility. The availability of individual cash deposit machines is of less concern. 1.2 In this system, the payment details as well as authorization by the user need be kept confidential. The integrity of the amount agreed by the user needs to be protected (i.e. neither the gateway nor the merchant bank can modify the amount agreed by the user). The confidentiality as -6-


well as integrity of the payment details needs to be protected in the host system as well as during the transmission for a transaction. Availability of the host system is important to the economic well-being of the merchant. A user may try again if the system is not available at times, while a merchant may lose business if the system is repeatedly not available. 1.3 a. The system will have to assure confidentiality, if it is being used to publish corporate financial data. b. The system will have to assure integrity, if it is being used to report financial details to the government for complying with tax regulations. c. The system will have to assure availability, if it is being used to publish hourly updates on selected stocks in the share market. 1.4 a. A student managing a blog to post public information implies that there is no potential impact from a loss of confidentiality (i.e., confidentiality requirements are not applicable), a moderate potential impact from a loss of integrity, and a low potential impact from a loss of availability. b. An examination section of University managing sensitive information about exam papers determines that the potential impact from a loss of confidentiality is high, the potential impact from a loss of integrity is also high, and the potential impact from a loss of availability is moderate. c. An information system in a pathological laboratory maintaining the patient’s data determines that the potential impact from a loss of confidentiality is moderate, the potential impact from a loss of integrity is high, and the potential impact from a loss of availability is moderate. d. (i) for the personal, academic information of a student, the potential impact from a loss of confidentiality is moderate, the potential impact from a loss of integrity is high, and the potential impact from a loss of availability is moderate; and (ii) for the routine administrative information (not privacy related), the potential impact from a loss of confidentiality is low, the potential impact from a loss of integrity is low, and the potential impact from a loss of availability is low. For the system as a whole: the potential impact from a loss of confidentiality is moderate, the potential impact from a loss of integrity is high and the potential impact from a loss of availability is moderate. e. (i) for the student data being acquired by the library management system, potential impact from a loss of confidentiality is moderate, the potential impact from a loss of integrity is moderate, and the potential impact from a loss of availability is high; and (ii) for the -7-


Turn static files into dynamic content formats.

Create a flipbook
Cryptography and Network Security Principles and Practice, Global Edition, 7th Edition William Stall by TBtutors - Issuu