הסתכל על סמל המנעול בשורת הכתובת בדפדפן שלך. הקלטת את שם הבנק, וכך או אחרת המחשב הנייד שלך בטוח כעת שהוא באמת מתקשר עם הבנק — ו…
English narration · English + 中文 subtitles burned in · קריאת קול באנגלית · תרגום אנגלי + סינית שרוף בתוך הסרטון
17.1
How encryption works · כיצד הצפנה פועלת
Syllabus · סיילבוס
English
Candidates should be able to:
Notes and guidance
Show understanding of how encryption works
Including the use of public key, private key, plain text, cipher text, encryption, symmetric key cryptography and asymmetric key cryptography How the keys can be used to send a private message from the public to an individual/organisation How the keys can be used to send a verified message to the public How data is encrypted and decrypted, using symmetric and asymmetric cryptography Purpose, benefits and drawbacks of quantum cryptography
Show awareness of the Secure Socket Layer (SSL) / Transport Layer Security (TLS)
Purpose of SSL/TLS Use of SSL/TLS in client-server communication Situations where the use of SSL/TLS would be appropriate
Show understanding of digital certification
How a digital certificate is acquired How a digital certificate is used to produce digital signatures
עברית
המועמדים צריכים להיות מסוגלים:
הערות והנחיות
להראות הבנה כיצד הצפנה עובדת
כולל שימוש ב-public key, private key, plain text, cipher text, הצפנה, קריפטוגרפיה עם מפתח סימטרי ו-קריפטוגרפיה עם מפתח א-סימטרי. איך המפתחות משמשים לשליחת הודעה פרטית מהציבור לאדם/ארגון ספציפי. איך המפתחות משמשים לשליחת הודעה מאומתת לציבור. איך נתונים מצופנים ומפורקים, באמצעות קריפטוגרפיה סימטרית וא-סימטרית. מטרה, יתרונות וחסרונות של קריפטוגרפיה קוונטית
להראות מודעות ל-Secure Socket Layer (SSL) / Transport Layer Security (TLS)
מטרת SSL/TLS. שימוש ב-SSL/TLS בתקשורת לקוח-שרת. מצבים בהם שימוש ב-SSL/TLS יהיה מתאים
להראות הבנה של אישור דיגיטלי
איך תעודה דיגיטלית נרכשת. איך תעודה דיגיטלית משמשת ליצירת חתימות דיגיטליות
Source: Cambridge International syllabus · מקור: הסיילבוס הבינלאומי של קמבריד'ג'
English
Encryption 加密 turns readable plaintext 明文 (plain text) into unreadable ciphertext 密文 (cipher text) using a maths operation that depends on a key. Only someone with the right key can reverse it — decryption 解密 — to get the plaintext back. An attacker who intercepts the ciphertext without the key sees only meaningless data, because trying every possible key would take far too long. A newer approach, quantum cryptography 量子密码学, uses quantum physics to share a key in a way that reveals any eavesdropper.
Symmetric encryption
Symmetric encryption 对称加密 (symmetric key cryptography) uses the same key for both encryption and decryption, so sender and receiver must both hold the secret key. It is fast and good for bulk data (a whole disk, a video stream). Its problem is key distribution 密钥分发: how do you share the key safely in the first place? Asymmetric encryption solves this.
"Describe what is meant by symmetric key encryption" (two marks).The same key is used to encrypt the plaintext and to decrypt the ciphertext, so the key must be shared between sender and receiver and kept secret from everyone else. Two drawbacks. The key has to be exchanged before the message can be sent, and if it is intercepted in transit the interceptor can read every message; a separate key is needed for every pair of correspondents; and it gives no proof of who sent the message, because both ends hold the same key. "Give two reasons for using key cryptography": so that data is unreadable by anyone who intercepts it (confidentiality); so that the receiver can be sure the data came from the claimed sender and was not altered (authenticity and integrity 完整性). The two methods are symmetric and asymmetric key cryptography.
Asymmetric encryption (public-key)
Asymmetric encryption 非对称加密 (asymmetric key cryptography) gives each user a pair of related keys: a public key 公钥 they publish, and a private key 私钥 they keep secret. Data encrypted with the public key can be decrypted only with the matching private key, and vice versa.
To send a secret message to Alice: get her published public key, encrypt with it, and send. Only Alice — holding the matching private key — can decrypt. No prior key exchange is needed. The trade-off is that it is much slower than symmetric, so it is not used for large data.
"State what is meant by a private key."A key known only to its owner (never transmitted), used to decrypt data that was encrypted with the matching public key, and to create digital signatures."Describe the process of asymmetric encryption" (four marks): (1) the receiver generates a pair of keys, a public key and a private key, mathematically related; (2) the public key is made available to anyone who wants to send to them; (3) the sender encrypts the plaintext with the receiver's public key; (4) the ciphertext can only be decrypted with the receiver's private key, which never leaves the receiver, so nobody who intercepts the message can read it.
Worked example. Fred wants to send Sheila a confidential document. Explain how asymmetric encryption is used.
Sheila has a key pair; she sends Fred her public key (or he obtains it from her certificate). Fred encrypts the document with Sheila's public key and sends the ciphertext. Only Sheila's private key can decrypt it, and only Sheila holds that, so nobody else, including Fred once it is encrypted, can read the document. The keys are used the receiver's way round: her public key to lock, her private key to unlock. An organisation that holds a key pair "to receive secure transmissions" does exactly this: it publishes the public key, keeps the private key, and decrypts what arrives.
Two differences between symmetric and asymmetric encryption. Symmetric uses one key for both directions; asymmetric uses two related keys, one to encrypt and the other to decrypt. In symmetric encryption the key must be kept secret by both parties and exchanged securely; in asymmetric encryption the public key can be published and only the private key is secret. Symmetric encryption is much faster and suits large amounts of data; asymmetric is slower, so it is used for keys and signatures rather than bulk data.
A private key must stay secret, so it is sometimes kept on a small hardware security key 硬件安全密钥. You plug it in or tap it to prove who you are, and the secret key never leaves the device.
Hybrid approach (used by almost every real system)
Use asymmetric encryption to exchange a fresh session key 会话密钥, then use that symmetric key for the data:
the client makes a random session key.
it encrypts the session key with the server's public key.
the server decrypts it with its private key.
both ends now share the session key and use fast symmetric encryption for the rest.
This is how HTTPS and SSH work.
The exam's version of the key-exchange problem. "A symmetric key is to be exchanged before the message is sent. Explain how the key can be exchanged securely." The sender encrypts the symmetric key with the receiver's public key and sends it; the receiver decrypts it with their private key; both now hold the symmetric key, which was never exposed in transit, and use it for the messages. Asymmetric encryption solves the distribution problem; symmetric encryption then does the fast work.
Hashing (related, not encryption)
A cryptographic hash 密码散列 function takes any input and gives a fixed-size digest 摘要 such that the same input always gives the same digest, it is infeasible to find two inputs with the same digest, and a tiny change in input changes the digest completely. Hashing is one-way — you cannot get the input back. It is used for storing password checks, integrity checks, and digital signatures.
Quantum cryptography
Quantum cryptography uses the physics of light to distribute keys: the bits of a key are sent as photons whose quantum states encode the values. "Describe its purpose": to transmit an encryption key securely, in such a way that any attempt to intercept it can be detected, because measuring a photon changes its state; an eavesdropper 窃听者 therefore leaves evidence, and the corrupted key is thrown away and a new one sent. Benefits: interception is always detectable; the key cannot be copied without being altered; it is secure against future advances in computing power (a mathematical key can eventually be cracked, a quantum one cannot be read without disturbing it). Drawbacks: it needs specialised, expensive equipment; it works only over limited distances on dedicated optical fibre (or line of sight), not across the existing internet; it distributes the key only, so ordinary encryption still protects the message; and it is a new technology with few suppliers and little experience.
עברית
הצפנה ממירה טקסט גלוי (plain text) לקריא לש טקסט מוצפן (cipher text) באמצעות פעולה מתמטית התלויה ב-מפתח. רק מי שיש לו את המפתח הנכון יכול לבצע את הפעולה ההפוכה – התאפנות – כדי לקבל בחזרה את הטקסט הגלוי. תקוק שחוקה החוסמת את הטקסט המוצפן ללא המפתח רואה רק נתונים חסרי משמעות, מכיוון שניסיון כל המפתחות האפשריים ייקח הרבה מדי זמן. גישה חדשה יותר, קריפטוגרפיה קוונטית, משתמשת בפזיקה קוונטית לשתף מפתח בצורה שתחשוף כל מאזין.
מכונת האנאגמה הצפנה הודעות במלחמת העולם השנייה — מכשיר הצפנה מכני מוקדםהצפנה מערבבת טקסט מקורי באמצעות מפתח; פיענוח מבטל את התהליך
הצפנה סימטרית
הצפנה סימטרית (קריפטוגרפיה עם מפתח סימטרי) משתמש במפתח זהה גם להצפנה וגם לפיענוח, ולכן שולח וקבלן צריכים לשמור על המפתח הסודי. היא מהירה ועדיפה לנתונים בכמות גדולה (כל דיסק, זרימת וידאו). הבעיה שלה היא חלוקת המפתח: כיצד משתפים את המפתח בבטיחות מראש? הצפנה א-סימטרית פותרת בעיה זו.
"ספק הגדרה של הצפנה סימטרית" (שתי נקודות). משתמשים באותו מפתח כדי להצפין את הטקסט המקורי ולהפענוח את קוד הטקסט, ולכן יש לשיתף את המפתח בין השולח לקבלן ולשמור אותו בסודיות מכל אחד אחר. שני חסרונות. יש להחליף את המפתח לפני שניתן לשלוח הודעה, ואם הוא יופעל בדרכו, החוטף יכול לקרוא כל הודעה; נדרש מפתח נפרד עבור כל זוג של שולחים וקבלנים; והוא אינו מספק הוכחה למי שלח את ההודעה, כיוון ששני הקצוות מחזיקים באותו מפתח. "תן שתי סיבות לשימוש בקריפטוגרפיה: כדי שהנתונים יהיו לא נגישים לכל מי שמפעיל אותם (סודיות); וכדי שקבלן יוכל להיות בטוח שהנתוניםGLA来自声称 השולח ולא שוינו (אותנטיות ושלמות). שתי השיטות הן קריפטוגרפיה סימטרית וא-סימטרית.
הצפנה סימטרית משתמשת באותו מפתח סודי בשני הקצוות
הצפנה א-סימטרית (מפתח ציבורי)
הצפנה א-סימטרית (קריפטוגרפיה עם מפתח א-סימטרי) מספקת למשתמש כלשהו זוג של מפתחות קשורים: מפתח ציבורי שהוא מפרסם, ומפתח פרטי שהוא שומר בסוד. נתונים המוצפנים במפתח הציבורי ניתן לפענח רק עם המפתח הפרטי המתאים, ולהפך.
לכל משתמש יש מפתח ציבורי לשיתוף ומפתח פרטי לשמירה בסודיות
כדי לשלוח הודעה סודית לאליס: לקחת את המפתח הציבורי המפורסם שלה, להצפין אותו, ולשלוח. רק אליס — שמחזיקה במפתח הפרטי המתאים — יכולה לפענח. אין צורך בהחלפת מפתח מראש. היתרון-חסרון הוא שהוא איטי הרבה יותר מהסימטרי, ולכן אינו משמש לנתונים גדולים.
"צין מה המשמעות של מפתח פרטי."מפתח הידוע רק לבעלו (מעולם אינו מועבר), המשמש לפענוח נתונים שהוצפנו במפתח הציבורי המתאים, וליצירת חתימות דיגיטליות. "ספק תיאור של תהליך ההצפנה הא-סימטרית" (ארבע נקודות): (1) הקבלן יוצר זוג של מפתחות, מפתח ציבורי ומפתח פרטי, הקשורים מתמטית; (2) המפתח הציבורי מוצב לרשות כל מי שרוצה לשלוח לו; (3) השולח מצפין את הטקסט המקורי במפתח הציבורי של הקבלן; (4) קוד הטקסט ניתן להפענוח רק עם מפתח הפרטי של הקבלן, שאינו עוזב לעולם את הקבלן, ולכן אף אחד שלא הפעיל את ההודעה לא יכול לקרוא אותה.
דוגמא פתורה. פريد רוצה לשלוח לשילה מסמך סודי. הסבר כיצד משתמשים בהצפנה א-סימטרית.
לשילה יש זוג מפתחות; היא שולחת לפريد את המפתח הציבורי שלה (או שהוא מקבל אותו מאישור שלה). פريد מצפין את המסמך במפתח הציבורי של שילה ושולח את קוד הטקסט. רק המפתח הפרטי של שילה יכול לפענח אותו, ורק שילה מחזיקה בו, ולכן אף אחד אחר, כולל פريد לאחר ההצפנה, לא יכול לקרוא את המסמך. המפתחות משמשים בדרך הקבלן: המפתח הציבורי שלה נעול, המפתח הפרטי שלה פותח. ארגון המחזיק בזוג מפתחות "לקבל שידורים מאובטחים" עושה בדיוק זאת: הוא מפרסם את המפתח הציבורי, שומר על המפתח הפרטי, ומפענח מה שמגיע.
שתי הבדלים בין הצפנה סימטרית לא-סימטרית. הסימטרית משתמש במפתח אחד לשני הכיוונים; הא-סימטרית משתמש בשני מפתחות קשורים, אחד להצפנה והשני לפיענוח. בהצפנה סימטרית יש לשמור על המפתח בסודיות על ידי שני הצדדים ולהחליפו בצורה מאובטחת; בהצפנה א-סימטרית ניתן לפרסם את המפתח הציבורי והמפתח הפרטי הוא הסודי. ההצפנה הסימטרית מהירה הרבה יותר ועדיפה לכמויות גדולות של נתונים; הא-סימטרית איטית, ולכן משמשת למפתחות וחתימות ולא לנתונים בכמות גדולה.
מפתח פרטי חייב להישאר בסוד, ולעיתים הוא מושחק על מפתח אבטחה חומרה קטן. מחברים אותו או מנגיעים בו כדי להוכיח את זהותך, והמפתח הסודי לעולם אינו עוזב את המכשיר.
מפתח אבטחה חומרית מאחסן מפתח סוד כדי לאמת את זהותך
גישה היברידית (משמשת כמעט כל מערכת אמיתית)
השתמש באנצריפטוריה א-סימטרית להחלפת מפתח סשן חדש, ולאחר מכן השתמש במפתח הסימטרי הזה עבור הנתונים:
המפעיל יוצר מפתח סשן מקרי.
הוא מצפין את מפתח הסשן עם המפתח הציבורי של השרת.
השרת פוענח אותו עם המפתח הפרטי שלו.
שני הקצוות משתפים עכשיו את מפתח הסשן ומשתמשים באנצריפטוריה סימטרית מהירה לשאר התהליך.
כך עובדים HTTPS ו-SSH.
הגרסה לבחינה של בעיית החלפת המפתחות. "יש להחליף מפתח סימטרי לפני שליחת ההודעה. הסבר כיצד ניתן להחליף את המפתח באופן בטוח." השולח מצפין את מפתח הסימטרי במפתח הציבורי של המקבל ושולח אותו; המקבע פוענח אותו עם המפתח הפרטי שלו; שני הצדדים מחזיקים עכשיו את מפתח הסימטרי, שהעולם לא נחשף במהלך העברה, ומשתמשים בו בהודעות. אנצריפטוריה א-סימטרית פותרת את בעיית ההפיצה; אנצריפטוריה סימטרית מבצעת לאחר מכן את העבודה המהירה.
הגישה ההיברידית: קריפטוגרפיה א-סימטרית משתפת מפתח סשן פעם אחת, ולאחר מכן אנצריפטוריה סימטרית מהירה מגנה על הנתונים
הפקטורייזציה (קשורה, אך אינה אנצריפטוריה)
פונקציית פקטורייזציה קריפטוגרפית לוקחת כל קלט ומניבה תמצית בגודל קבוע כך שקלט זהה תמיד מניב תמצית זהה, קשה למצוא שני קלטות שונות עם אותה תמצית, ושינוי קטן בקלט משנה את התמצית לחלוטין. הפקטורייזציה היא חד-כיוונית — לא ניתן לקבל את הקלט חזרה. היא משמשת לאחסון בדיקות סיסמאות, בדיקות אינטגריות, וחתימות דיגיטליות.
פקטורייזציה קריפטוגרפית מניבה תמצית קבועה; שינוי קטן בקלט משנה אותה לחלוטין, ואינה ניתנת להפיכה
קריפטוגרפיה קוונטית
קריפטוגרפיה קוונטית משתמשת בפיזיקת האור להפיצת מפתחות: ביטים של מפתח נשלחים כ-פוטונים whose quantum states encode the values. "תיאור המטרה שלה": להעביר מפתח אנצריפטוריה בטוח, כך שכל ניסיון לחצוץ אותו ניתן לזיהוי, מכיוון שמדידת פוטון משנה את מצבו; לכן מאזין משאיר עקבות, והמפתח הפגום מושלך והמפתח החדש נשלח. יתרונות: חצילה נמצאת תמיד; המפתח לא ניתן להעתקה ללא שינוי; הוא בטוח בפני התקדמויות עתידיות בכוח מחשוב (מפתח מתמטי עשוי להיות פרוץ בסופו של דבר, אך מפתח קוונטי אינו ניתן לקריאה ללא הפרעה). חוסרונות: הוא דורש ציוד מיוחד, יקר; הוא פועל רק על מרחקים מוגבלים באופטיקה ייעודית (או בקו ראייה), ולא ברחבי האינטרנט הקיים; הוא מפיק את המפתח בלבד, ולכן אנצריפטוריה רגילה עדיין מגנה על ההודעה; והוא טכנולוגיה חדשה עם ספקים מעטים וניסיון מוגבל.
Explore · חקור
Hashing and the avalanche effect · השחזה ואפקט השלג
A hash is one-way: easy to compute, practically impossible to reverse. A tiny change in the input flips a large, unpredictable part of the output — the avalanche effect that makes hashes good for passwords. · השחזה היא חד-כיוונית: קל לחשב, כמע בלתי אפשרי להפוך. שינוי זעיר בקלט גורם לשינוי גדול ולא צפוי בחלק מהפלט — אפקט השלג שמפנה את השימוש בהשחזות כסיפורי מעבר.
Explore · חקור
The Caesar cipher · צופן קייסר
Shift each letter to encrypt the message. A simple cipher shows the idea of a key — and why a small key is easy to break. · הזז כל אות כדי להצפין את ההודעה. ציפר פשוט מציג את רעיון המפתח — ולמה מפתח קטן נשבר בקלות.
TLS 传输层安全 (Transport Layer Security, the successor to the Secure Socket Layer, SSL) is a protocol that gives encryption and authentication for data sent over a network. It encrypts the data in transit, authenticates the server with a certificate, and provides integrity (detecting tampering).
Outline of a TLS handshake:
the client connects and proposes cipher options.
the server picks one and sends its digital certificate (with its public key) — issuing and validating these certificates is digital certification.
the client checks the certificate.
the two ends exchange a fresh session key using asymmetric crypto.
all later traffic uses fast symmetric encryption with the session key.
The result is an encrypted, authenticated, integrity-checked tunnel for higher-level protocols (HTTP, SMTP). It is appropriate wherever sensitive information is sent: HTTPS web browsing, online banking and payments, secure email, and VPNs.
"Describe the purpose of SSL/TLS" and "state two functions." The purpose is to provide secure communication between a client and a server over a network. Its functions: it encrypts the data sent, so that it cannot be read if intercepted; it authenticates 认证 the server (and optionally the client) by means of a digital certificate, so the client knows it is talking to the genuine site; and it checks the integrity of the data, so that changes in transit are detected. Two examples of where it is appropriate: online banking and online shopping (card payments); also logins, private email, file transfer, VoIP and instant messaging: any transaction in which private data crosses the internet.
The two protocols that make up TLS. The handshake 握手 protocol sets up the session: it agrees the encryption algorithms (cipher suite), authenticates the server with its certificate, and exchanges the session key. The record protocol then carries the data: it encrypts each message with the session key, adds an integrity check, and passes it to the transport layer.
"Explain how SSL/TLS is used when client–server communication is initiated" (six marks). (1) The client (browser) sends a request to the server for a secure connection, saying which encryption methods it supports. (2) The server sends back its digital certificate, which contains its public key. (3) The client checks the certificate is valid (issued by a trusted Certificate Authority, not expired, for the right domain). (4) The client generates a session key, encrypts it with the server's public key and sends it. (5) The server decrypts the session key with its private key. (6) Both sides now hold the session key and all further data is sent using symmetric encryption with it. Give the steps in this order; the marks are for the certificate, the public key, the session key and the switch to symmetric encryption.
עברית
TLS (Transport Layer Security, ה延续者 של Secure Socket Layer, SSL) הוא פרוטוקול המספק אנצריפטוריה ואימות לנתונים הנשלחים ברשת. הוא מצפין את הנתונים בזמן העברה, מאמת את השרת באמצעות תעודה, ומספק אינטגריות (זיהוי התערבות).
סקיצה של ידית-בית TLS:
הלקוח מתחבר ומציע אפשרויות הצפנה.
השרת בוחר אחת ושולח את התעודה הדיגיטלית שלו (יחד עם המפתח הציבורי שלו) — הנפקת ואישור תעודות אלו נקראים אישור דיגיטלי.
הלקוח בודק את התעודה.
שני הקצוות מחליפים מפתח סשן חדש באמצעות קריפטוגרפיה לא סימטרית.
כל התנועה הבאה משתמשת בהצפנה סימטרית מהירה בעזרת מפתח הסשן.
התוצאה היא מנהרה מוצפנת, מאומתת ונבדקת שלמות עבור פרוטוקולים ברמה גבוהה יותר (HTTP, SMTP). זה מתאים בכל מקום שבו נשלחת מידע רגיש: גלישה באתרים באמצעות HTTPS, בנקאות ואישורים מקוונים, דוא"ל מאובטח ו-VPNs.
"תיאור המטרה של SSL/TLS ו"ציינו שתי פונקציות." המטרה היא לספק תקשורת מאובטחת בין לקוח לשרת דרך רשת. הפונקציות שלו: הוא מצפין את הנתונים שנשלחים, כך שלא ניתן יהיה לקרוא אותם אם ייתפסו; הוא מאמת את השרת (ופחות גם את הלקוח) באמצעות תעודה דיגיטלית, כך שהלקוח יודע שהוא מדבר עם האתר האמיתי; והוא בודק את השלמות של הנתונים, כך שינויים במהלך העברה יתגלו. שני דוגמאות למקומות שבהם זה מתאים: בנקאות מקוונות וקניות מקוונות (תשלום בכרטיס); כמו כן התחברויות, דוא"ל פרטי, העברת קבצים, VoIP ומסרים מידיים: כל עסקה שבה נתונים פרטיים חוצים את האינטרנט.
הפרוטוקולים השניים המרכיבים את TLS. פרוטוקול החיבור (Handshake) מגדיר את הסשן: הוא מסכים על אלגוריתמי ההצפנה (צמד הצפנה), מאמת את השרת בתעודה שלו, ומחליף את מפתח הסשן. לאחר מכן פרוטוקול הרשומה (Record) נושא את הנתונים: הוא מצפין כל הודעה עם מפתח הסשן, מוסיף בדיקת שלמות, ועובר אותה לשכבת ההעברה.
איך סשן מאובטח מתחיל: התעודה מוכיחה מי השרת, המפתח הציבורי של השרת מגן על מפתח הסשן בדרכו, ומפתח הסשן מגן על הכל שאחרי כן
"הסבר כיצד SSL/TLS משמש כאשר תקשורת לקוח-שרת מוזמנת (שישה נקודות). (1) הלקוח (דפדפן) שולח בקשה לשרת עבור חיבור מאובטח, ומציין אילו שיטות הצפנה הוא תומך. (2) השרת שולח בחזרה את התעודה הדיגיטלית שלו, המכילה את המפתח הציבורי שלו. (3) הלקוח בודק שהתעודה תקפה (הונפקה על רשות אישור אמינה, לא פגה, לתחום הנכון). (4) הלקוח יוצר מפתח סשן, מצפין אותו עם המפתח הציבורי של השרת ושולח אותו. (5) השרת פוענח את מפתח הסשן עם המפתח הפרטי שלו. (6) לשני הצדדים יש כעת את מפתח הסשן וכל הנתונים הבאים נשלחים באמצעות הצפנה סימטרית איתו. נתנו את השלבים בסדר זה; הנקודות הן עבור התעודה, המפתח הציבורי, מפתח הסשן והמעבר להצפנה סימטרית.
Explore · חקור
The TLS handshake · החילוף TLS
Step through what happens before a padlock appears. The slow public-key crypto is used only to agree a shared key; the actual page then travels under fast symmetric encryption. · עבור שלב אחר של מה שקורה לפני שהתליון מופיע. הקריפטוגרפיה האיטית עם המפתח הציבורי משמשת רק להסכמה על מפתח משותף; העמוד בפועל נעשה תחת הצפנה סימטרית מהירה.
A digital certificate 数字证书 binds an identity (a domain, an organisation) to a public key, and is signed by a trusted Certificate Authority 证书颁发机构 (CA). It contains the subject (who it identifies), the subject's public key, the issuer (the CA), a validity period, and the CA's signature over all of it.
To verify one, the client (which holds a list of trusted root CAs):
checks the expiry dates.
checks the subject name matches the URL.
checks it is signed by a trusted CA, using the CA's public key to verify the signature.
follows the certificate chain up to a trusted root.
If anything fails, the browser shows the "Your connection is not private" warning. When it verifies cleanly, the client knows the identity was vetted by a trusted CA, the public key really belongs to that identity, and the certificate is current.
"Describe what is meant by a digital certificate" (two marks).An electronic document, issued by a Certificate Authority, that verifies the identity of its owner (a person, organisation or website) and contains the owner's public key.Items found in one: the serial number; the name of the owner (subject) and, for a website, its domain; the owner's public key; the name of the issuing CA; the validity period (dates); the signature algorithm used; and the CA's digital signature of the whole certificate.
"Explain how an organisation acquires a digital certificate" (four marks). (1) The organisation generates its own key pair, a public key and a private key. (2) It sends a request containing its public key and its identity details to a Certificate Authority. (3) The CA verifies the identity (checks that the applicant really is the organisation or owns the domain). (4) The CA creates the certificate containing the public key and the identity, signs it with the CA's own private key, and returns it. (5) The organisation installs the certificate on its server so that it can be sent to clients. The private key never leaves the organisation.
"Explain why a digital certificate is required to validate a digital signature." To check a signature the receiver needs the sender's public key, and needs to be sure that the key really belongs to the claimed sender; the certificate supplies the public key together with the identity, and because the certificate is signed by a trusted CA the receiver can trust that binding. Without it an impostor could publish a public key in someone else's name and sign messages as them. The same reasoning answers "what should be included with a program downloaded from the internet to prove it is genuine": a digital signature, checked against the publisher's certificate.
עברית
תעודה דיגיטלית מקשרת זהות (תחום, ארגון) למפתח ציבורי, והיא חתומה על ידי רשות אישור (CA) אמינה. היא מכילה את הנושא (מי שהזהות שלו מזוהה), המפתח הציבורי של הנושא, המנפיק (רשות ה-A), תקופת תוקף, וחתימת ה-CA על כל אלו.
*רשות אישור מנפיקה תעודה דיגיטלית המקשרת זהות למפתח ציבורי
לבדוק תעודה כזו, הלקוח (שהוא מחזיק ברשימה של רשויות אישור שורש אמינות):
בודק את תאריכי הפגת התוקף.
בודק שהשם הנושא תואם את כתובת ה-URL.
בודק שהיא חתומה על ידי רשות אישור אמינה, באמצעות המפתח הציבורי של הרשות כדי לבדוק את החתימה.
עוקב אחר שרשרת התעודות כלפי מעלה עד לשורש אמין.
אם משהו נכשל, הדפדפן מציג את אזהרת "החיבור שלך אינו פרטי". כאשר האישור מתבצע בצורה תקינה, הלקוח יודע שהזהות נבדקה על ידי CA אמין, שהמפתח הציבורי באמת שייך לזהות זו, והתעודה עדכנית.
"תאר מה נדרש מזהות דיגיטלית" (שתי נקודות).מסמך אלקטרוני, המונפק על ידי רשות האישור, המאמת את זהות הבעלים שלה (אדם, ארגון או אתר) ומכיל את המפתח הציבורי של הבעל.פריטים הנמצאים בה:מספר הסידורי; שם הבעל (נושא) ו, עבור אתר, התחום שלו; המפתח הציבורי של הבעל; שם רשות האישור המנפיקה; תקופת התוקף (תאריכים); אלגוריתם החתימה ששימש; והחתימה הדיגיטלית של ה-CA על כלל התעודה.
"הסבר כיצד ארגון מקבל תעודה דיגיטלית" (ארבע נקודות). (1) הארגון יוצר זוג מפתחות משלו, מפתח ציבורי ומפתח פרטי. (2) הוא שולח בקשה המכילה את המפתח הציבורי ואת פרטי הזהות שלו לרשות האישור. (3) ה-CA בודק את הזהות (בודק שהמבקש באמת הארגון או שבעל התחום). (4) ה-CA יוצר את התעודה המכילה את המפתח הציבורי והזהות, חותם אותה במפתח הפרטי של ה-CA עצמו, ומחזירה אותה. (5) הארגון מתקין את התעודה על השרת שלו כדי שתוכל להישלח ללקוחות. המפתח הפרטי מעולם אינו עוזב את הארגון.
"הסבר מדוע נדרשת תעודה דיגיטלית כדי לאמת חתימה דיגיטלית." כדי לבדוק חתימה, המקבל זקוק למפתח הציבורי של השולח, וזקוק להיות בטוח שהמפתח באמת שייך לשולח הנטען; התעודה מספקת את המפתח הציבורי יחד עם הזהות, וכיוון שהתעודה חתומה על ידי CA אמין, המקבל יכול לסמוך על הקישור הזה. ללא זאת, מזייף could פרסם מפתח ציבורי בשם אחר וחתום הודעות בשמו. אותה סיבה משיבה גם על "מה צריך לכלול עם תוכנה המוטלת מאינטרנט כדי להוכיח שהיא מקורית": חתימה דיגיטלית, הנבדקת מול תעודת המפרסם.
A digital signature 数字签名 proves who signed a message and that it was not changed. To sign:
compute a cryptographic hash of the message.
encrypt the hash with the sender's private key — that is the signature.
send the message and the signature.
To verify: compute the hash of the received message; decrypt the signature with the sender's public key to get the sender's hash; compare. If they match, the message was signed by the holder of the private key (authentication 身份验证) and was not changed (integrity). A signature does not hide the message — for confidentiality as well, encrypt and sign.
"Explain the role of a digital certificate in creating a digital signature" (three marks). The sender's certificate was issued by a CA and contains the sender's public key together with the sender's identity; the sender produces the signature by hashing the message and encrypting the hash with their private key, the partner of the key in the certificate; the receiver uses the public key from the certificate to decrypt the hash and, because the certificate binds that key to the sender, the signature proves who signed.
"Explain how a digital signature is used to verify a message" (four marks). (1) The receiver decrypts the signature with the sender's public key (taken from the sender's certificate), which yields the hash that the sender computed. (2) The receiver hashes the received message with the same hash algorithm. (3) The two hashes are compared. (4) If they match, the message came from the holder of the private key (authentic) and has not been altered since it was signed (integrity); if they differ, the message is rejected. A banker receiving confidential data with a signature does exactly this before trusting it; the data itself may separately be encrypted with the banker's public key for confidentiality.
Putting it together
A secure request to https://www.bank.com: the server sends its certificate; the client verifies it against trusted CAs; the client uses the server's public key to exchange a session key; then data flows encrypted with that key. Encryption stops eavesdroppers, the certificate proves the server's identity, and integrity checks stop a man-in-the-middle 中间人攻击 altering the data.
Worked example. Alice sends Bob a contract. She wants Bob to be certain it came from her and was not altered, and she wants nobody else to be able to read it. Which keys does she use, and in which direction? These are two different jobs needing two different key pairs. For the signature (authentication and integrity): Alice hashes the contract and encrypts that hash with her own private key; Bob decrypts it with Alice's public key and compares it against his own hash of the message. Only Alice holds her private key, so only she could have produced it. For confidentiality: Alice encrypts the contract itself with Bob's public key, so only Bob's private key can open it. One rule keeps all four straight: you sign with your own private key and encrypt with the recipient's public key. A signature on its own does not hide the message.
עברית
חתימה דיגיטלית מוכיחה מי חתם על הודעה וגם שהיא לא שונתה. לחתימה:
חשב TODO קריפטוגרפי של ההודעה.
הצפן את ה-TODO בעזרת המפתח הפרטי של השולח — זהו החתימה.
שלח את ההודעה ואת החתימה.
לבדיקה: חשב את TODO של ההודעה התקבלה; פרש את החתימה בעזרת המפתח הציבורי של השולח כדי לקבל את TODO השולח; השווה. אם הם תואמים, ההודעה נחתמה על ידי בעל המפתח הפרטי (אישור) ולא שונתה (אינטגריות). חתימה אינה מחבאת את ההודעה — לצורך פרטיות גם כן, יש להצפין וגם לחתום.
*חתירה חושבת את ההודעה ומצפיד את הגישה עם המפתח הפרטי; המקבל בודק זאת בשימוש המפתח הציבורי
"הסבר את תפקידו של תעודת דיגיטלית ביצירת חתימה דיגיטלית" (שלוש נקודות). התעודה של השולחן הונפקה על ידי רשות האישור (CA) ותכיל את מפתחו הציבורי של השולחן יחד עם זהותו; השולחן יוצר את החתימה על ידי חישוב גישה של ההודעה וצפיפת הגישה עם מפתחו הפרטי, שותף המפתח בתעודה; המקבל משתמש במפתח הציבורי מתוך התעודה לפתוח את הגישה, וכיוון שהתעודה מקשרת מפתח זה לזהות השולחן, החתימה מעידה על מי חתם.
"הסבר כיצד משתמשים בחתימה דיגיטלית לאישור הודעה" (ארבע נקודות). (1) המקבל פותח את החתימה בשימוש מפתחו הציבורי של השולחן (הלקוח מתעודת השולחן), מה שמניב את הגישה שחישב השולחן. (2) המקבל חושב גישה של ההודעה שהתקבלה באותו אלגוריתם גישה. (3) שתי הגישות מושווה. (4) אם הן מתאימות, ההודעה הגיעה ממחזיק המפתח הפרטי (אותנטית) ולא שונתה מאז חתימתה (אמינות); אם הן שונות, ההודעה נדחת. בנקאי המקבל נתונים סודיים עם חתימה עושה בדיוק זאת לפני שהוא מאמין בהם; הנתונים עצמם עשויים להיות מצופדים בנפרד בשימוש מפתחו הציבורי של הבנקאי למען סודיות.
סיכום הדברים
בקשת מאובטחת לhttps://www.bank.com: השרת שולחן את תעודתו; הלקוח בודק אותה מול רשויות האישור המוסמכות; הלקוח משתמש במפתח הציבורי של השרת להחלפת מפתח מסע; לאחר מכן הנתונים זורמים מצופדים בשימוש המפתח הזה. הצפנה מונעת ציתות, התעודה מעידה על זהות השרת, ובדיקות אמינות מונעות גנב במרכז משנה את הנתונים.
דוגמא פתורה. אליס שולחת לבוב חוזה. היא רוצה שבוב יהיה בטוח שהגיעה ממנה שלא שונתה, וגם she wants nobody else to be able to read it. Which keys does she use, and in which direction? These are two different jobs needing two different key pairs. For the signature (authentication and integrity): Alice hashes the contract and encrypts that hash with her own private key; Bob decrypts it with Alice's public key and compares it against his own hash of the message. Only Alice holds her private key, so only she could have produced it. For confidentiality: Alice encrypts the contract itself with Bob's public key, so only Bob's private key can open it. One rule keeps all four straight: you sign with your own private key and encrypt with the recipient's public key. A signature on its own does not hide the message.
Definitions the examiner accepts · הגדרות מקובלות בקורס
English
A definition question is marked against fixed wording. Learn these exactly, and give one answer only.
Term
Definition
encryption
converting plaintext into ciphertext using an algorithm and a key so that it cannot be understood if intercepted
plaintext / ciphertext
the original readable data / the encrypted, unreadable form of it
symmetric key cryptography
the same secret key is used to encrypt and to decrypt, so it must be shared securely by both parties
asymmetric key cryptography
a pair of related keys is used: the public key encrypts and only the matching private key decrypts
public key
a key made available to anyone, used to encrypt messages to its owner and to verify the owner's signatures
private key
a key known only to its owner, used to decrypt messages encrypted with the public key and to sign
SSL/TLS
protocols that provide secure (encrypted, authenticated, integrity-checked) communication between a client and a server
digital certificate
an electronic document issued by a Certificate Authority that verifies the owner's identity and contains their public key
digital signature
a hash of a message encrypted with the sender's private key, proving who sent it and that it is unaltered
Certificate Authority
a trusted organisation that verifies identities and issues and signs digital certificates
quantum cryptography
the use of quantum states of photons to distribute keys so that any interception is detected
עברית
שאלת הגדרה מוקדמת לפי טקסט קבוע. לימודן במדויק, ותן תשובה אחת בלבד.
מונח
הגדרה
הצפנה
המרת טקסט גלוי לקריפטוגרמה באמצעות אלגוריתם ומפתח כך שאינו ניתן להבנה במקרה של הסחת דעת
טקסט גלוי / טקסט מוצפן
הנתונים המקוריים הקריאים / הצורה המוצפנת, שאינה קריאה, שלהם
קריפטוגרפיה עם מפתח סימטרי
משתמשים באותו מפתח סודי כדי להצפין ולפרק, ולכן חייב להיות משותף בצורה מאובטחת על ידי שני הצדדים
קריפטוגרפיה עם מפתח א-סימטרי
משתמש בזוג של מפתחות קשורים: המפתח הציבורי מצפין והמפתח הפרטי המתאים בלבד מפרק
מפתח ציבורי
מפתח המועמד לכל אדם, משמש להצפנת הודעות למחזיקו ולאישור חתימותיו
מפתח פרטי
מפתח הידוע רק למחזיקו, משמש לפרוק הודעות שהוצפו במפתח הציבורי ולחתימה
SSL/TLS
פרוטוקולים המספק תקשורת מאובטחת (מוצפנת, מאומתת, נבדקת שלמות) בין לקוח ושרת
תעודה דיגיטלית
מסמך אלקטרוני המונפק על ידי רשות האישור המאמת זהות המחזיק ומכיל את המפתח הציבורי שלו
חתימה דיגיטלית
פלט של הודעה המוצפנת במפתח הפרטי של השולח, המוכיחה מי שלחה אותה ואילו לא שינוי בה
רשות האישור
ארגון אמין המאמת זהויות ומנפיק וחותם בתעודות דיגיטליות
קריפטוגרפיה כמותית
השימוש במצבי כמותיים של פוטונים להעברת מפתחים כך שכל מעקב יתגלה
17.1
Exam tips · טיפים לבחינות
English
Symmetric: one shared secret key, fast, key exchange is the weakness. Asymmetric: public key to encrypt, private key to decrypt, slow, no exchange problem. Two differences, two drawbacks, two reasons: the exam asks for them in pairs.
Confidentiality uses the receiver's keys (public to lock, private to unlock); a signature uses the sender's keys (private to sign, public to check). Say whose key every time.
The TLS start-up is six steps: request, certificate with public key, check, session key encrypted with the public key, decrypted with the private key, symmetric encryption from then on.
A certificate is identity plus public key, signed by a CA; acquisition is key pair, request, verification, signing, installation. It is needed to validate a signature because it proves whose public key it is.
A signature is a hash encrypted with the private key; verification is decrypt, re-hash, compare. Integrity and authenticity are the two things it proves.
Quantum cryptography distributes keys and detects eavesdropping; its limits are cost, distance and novelty.
Common mistakes
Saying a message is encrypted with the sender's public key; the receiver's public key encrypts, the receiver's private key decrypts.
Describing a signature as "encrypting the message with the private key" instead of encrypting its hash.
Claiming a certificate contains the private key; it holds the public key and the identity, signed by the CA.
Listing "the server sends its private key" in the TLS handshake; only the public key travels, inside the certificate.
Giving "SSL/TLS makes the connection faster" as a function; its functions are encryption, authentication and integrity.
Confusing hashing with encryption: a hash cannot be reversed and has no key; encryption is reversible with the key.
Answering "why is a certificate needed for a signature" with "to encrypt it"; it is needed to trust the public key.
עברית
סימטרי: מפתח סודי משותק אחד, מהיר, החלפת המפתחות היא הנקודה החלשה. א-סימטרי: מפתח ציבורי להצפנה, מפתח פרטי לפרוק, איטי, אין בעיית החלפה. שתי הבדלים, שני חסרונות, שתי סיבות: השאלון דורש אותם זוגות.
סודיות משתמשת במפתחות של המקבל (ציבורי לסגירה, פרטי לפתיחה); חתימה משתמשת במפתחות של השולח (פרטי לחתימה, ציבורי לבדיקה). יש לציין בכל פעם למי השייך המפתח.
התחלת TLS היא שישה שלבים: בקשה, תעודה עם מפתח ציבורי, בדיקה, מפתח סשיין מוצפן במפתח הציבורי, פרוק במפתח הפרטי, הצפנה סימטרית ממנו והלאה.
תעודה היא זהות בפלוס מפתח ציבורי, חתומה על ידי רשות האישור; רכישתה כוללת יצירת זוג מפתחות, בקשה, אימות, חתימה והתקנה. היא נדרשת לאישור חתימה כי היא מוכיחה למי השייך המפתח הציבורי.
חתימה היא פלט מוצפן במפתח הפרטי; בדיקה היא פרוק, פלט מחדש, השוואה. שלמות ואותנטיות הם שני הדברים שהיא מוכיחה.
קריפטוגרפיה כמותית מעבירה מפתחות וגוררת עקבת; הגבולות שלה הם עלות, מרחק וחדשות.
טעויות נפוצות
אמירת שהודעה הוצפנה במפתח הציבורי של השולח; מפתח הציבורי של המקבל מצפין, ומפתח הפרטי של המקבל מפרק.
תיאור חתימה כ"הצפנת ההודעה במפתח הפרטי" במקום הצפנת הפלט שלה.
טענה שתעודה מכילה את המפתח הפרטי; היא מכילה את המפתח הציבורי והזהות, חתומה על ידי הרשות.
פירוט "השרת שולחן את המפתח הפרטי שלו" במהלך הטק היחס; רק המפתח הציבורי עובר, בתוך התעודה.
מתן "ה-SSL/TLS הופך את הקישור למהיר יותר" כפונקציה; הפונקציות שלו הן הצפנה, אימות ושלמות.
בלבול בין גיבוב (hashing) להצפנה: גיבוב אינו ניתן להפוך ואינו מכיל מפתח; ההצפנה ניתנת להפכה באמצעות המפתח.
מענה על השאלה "מדוע נדרש תעודה לחתימה" עם "כדי להצפין אותה"; היא נדרשת כדי לסמוך על המפתח הציבורי.
Interactive lessons on this topic · שיעורים אינטראקטיביים בנושא זה
Work through it step by step, with instant-check exercises. · לעבור על הדברים צעד אחר צעד, עם תרגילים לבדיקה מיידית.
Pick one and the site follows you — notes, papers, videos and practice all open on it. · בחרו נושא אחד והאתר יעקוב אחריו — הערות, מסמכים, וידאו ותרגולים פתוחים בו.
Type to search notes, lessons, code, vocabulary and past-paper questions across every subject. · הקלד כדי לחפש הערות, שיעורים, קוד, אוצר מילים ושאלות מבחנים בכל הנושאים.