Skip to content · ⁨コンテンツへスキップ⁩

Security · ⁨安否保障⁩

A-Level Computer Science · ⁨A-Level コンピューター科学⁩ · Topic 17 · ⁨トピック 17⁩

View Slides · ⁨查看幻灯片⁩ Train · ⁨練習する⁩
Video lesson for this topic · ⁨このトピックのビデオレッスン⁩ Open the video page · ⁨動画ページを開く⁩
13:19

暗号化の仕組み

ブラウザのアドレスバーにあるパッドロックを見てみてください。銀行名を入力すると、なぜかノートパソコンは実際に銀行と通信していることを確信します—そして…

English narration · English + 中文 subtitles burned in · ⁨英語ナレーション・英語+中文字幕 burning-in⁩

17.1

How encryption works · ⁨暗号化の仕組み⁩

Syllabus · ⁨シラバス⁩
English
Candidates should be able to: Notes and guidance
Show understanding of how encryption works Including the use of public key, private key, plain text, cipher text, encryption, symmetric key cryptography and asymmetric key cryptography How the keys can be used to send a private message from the public to an individual/organisation How the keys can be used to send a verified message to the public How data is encrypted and decrypted, using symmetric and asymmetric cryptography Purpose, benefits and drawbacks of quantum cryptography
Show awareness of the Secure Socket Layer (SSL) / Transport Layer Security (TLS) Purpose of SSL/TLS Use of SSL/TLS in client-server communication Situations where the use of SSL/TLS would be appropriate
Show understanding of digital certification How a digital certificate is acquired How a digital certificate is used to produce digital signatures
日本語
受験者は以下的能力を備えているべきである: メモおよびガイドライン
暗号化がどのように機能するかを理解する 公開鍵, 秘密鍵, 平明文, 暗号文, 暗号化, 対称鍵暗号, 非対称鍵暗号の使用を含む 公開から個人/組織へ秘密メッセージを送信するための鍵の使用方法 検証済みメッセージを一般に送信するための鍵の使用方法 対称および非対称暗号を用いてデータが暗号化・復号化される方法 量子暗号の目的、利点、欠点
Secure Socket Layer (SSL) / **Transport Layer Security (TLS)**への認識 SSL/TLSの目的 クライアント-サーバー通信におけるSSL/TLSの使用 SSL/TLSの使用が適切な場面
デジタル認証の理解 デジタル証明書を取得する方法 デジタル証明書がデジタル署名の生成にどのように使用されるか

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English

Encryption 加密 turns readable plaintext 明文 (plain text) into unreadable ciphertext 密文 (cipher text) using a maths operation that depends on a key. Only someone with the right key can reverse it — decryption 解密 — to get the plaintext back. An attacker who intercepts the ciphertext without the key sees only meaningless data, because trying every possible key would take far too long. A newer approach, quantum cryptography 量子密码学, uses quantum physics to share a key in a way that reveals any eavesdropper.

Symmetric encryption

Symmetric encryption 对称加密 (symmetric key cryptography) uses the same key for both encryption and decryption, so sender and receiver must both hold the secret key. It is fast and good for bulk data (a whole disk, a video stream). Its problem is key distribution 密钥分发: how do you share the key safely in the first place? Asymmetric encryption solves this.

"Describe what is meant by symmetric key encryption" (two marks). The same key is used to encrypt the plaintext and to decrypt the ciphertext, so the key must be shared between sender and receiver and kept secret from everyone else. Two drawbacks. The key has to be exchanged before the message can be sent, and if it is intercepted in transit the interceptor can read every message; a separate key is needed for every pair of correspondents; and it gives no proof of who sent the message, because both ends hold the same key. "Give two reasons for using key cryptography": so that data is unreadable by anyone who intercepts it (confidentiality); so that the receiver can be sure the data came from the claimed sender and was not altered (authenticity and integrity 完整性). The two methods are symmetric and asymmetric key cryptography.

Asymmetric encryption (public-key)

Asymmetric encryption 非对称加密 (asymmetric key cryptography) gives each user a pair of related keys: a public key 公钥 they publish, and a private key 私钥 they keep secret. Data encrypted with the public key can be decrypted only with the matching private key, and vice versa.

To send a secret message to Alice: get her published public key, encrypt with it, and send. Only Alice — holding the matching private key — can decrypt. No prior key exchange is needed. The trade-off is that it is much slower than symmetric, so it is not used for large data.

"State what is meant by a private key." A key known only to its owner (never transmitted), used to decrypt data that was encrypted with the matching public key, and to create digital signatures. "Describe the process of asymmetric encryption" (four marks): (1) the receiver generates a pair of keys, a public key and a private key, mathematically related; (2) the public key is made available to anyone who wants to send to them; (3) the sender encrypts the plaintext with the receiver's public key; (4) the ciphertext can only be decrypted with the receiver's private key, which never leaves the receiver, so nobody who intercepts the message can read it.

Worked example. Fred wants to send Sheila a confidential document. Explain how asymmetric encryption is used.

Sheila has a key pair; she sends Fred her public key (or he obtains it from her certificate). Fred encrypts the document with Sheila's public key and sends the ciphertext. Only Sheila's private key can decrypt it, and only Sheila holds that, so nobody else, including Fred once it is encrypted, can read the document. The keys are used the receiver's way round: her public key to lock, her private key to unlock. An organisation that holds a key pair "to receive secure transmissions" does exactly this: it publishes the public key, keeps the private key, and decrypts what arrives.

Two differences between symmetric and asymmetric encryption. Symmetric uses one key for both directions; asymmetric uses two related keys, one to encrypt and the other to decrypt. In symmetric encryption the key must be kept secret by both parties and exchanged securely; in asymmetric encryption the public key can be published and only the private key is secret. Symmetric encryption is much faster and suits large amounts of data; asymmetric is slower, so it is used for keys and signatures rather than bulk data.

A private key must stay secret, so it is sometimes kept on a small hardware security key 硬件安全密钥. You plug it in or tap it to prove who you are, and the secret key never leaves the device.

Hybrid approach (used by almost every real system)

Use asymmetric encryption to exchange a fresh session key 会话密钥, then use that symmetric key for the data:

  1. the client makes a random session key.
  2. it encrypts the session key with the server's public key.
  3. the server decrypts it with its private key.
  4. both ends now share the session key and use fast symmetric encryption for the rest.

This is how HTTPS and SSH work.

The exam's version of the key-exchange problem. "A symmetric key is to be exchanged before the message is sent. Explain how the key can be exchanged securely." The sender encrypts the symmetric key with the receiver's public key and sends it; the receiver decrypts it with their private key; both now hold the symmetric key, which was never exposed in transit, and use it for the messages. Asymmetric encryption solves the distribution problem; symmetric encryption then does the fast work.

Hashing (related, not encryption)

A cryptographic hash 密码散列 function takes any input and gives a fixed-size digest 摘要 such that the same input always gives the same digest, it is infeasible to find two inputs with the same digest, and a tiny change in input changes the digest completely. Hashing is one-way — you cannot get the input back. It is used for storing password checks, integrity checks, and digital signatures.

Quantum cryptography

Quantum cryptography uses the physics of light to distribute keys: the bits of a key are sent as photons whose quantum states encode the values. "Describe its purpose": to transmit an encryption key securely, in such a way that any attempt to intercept it can be detected, because measuring a photon changes its state; an eavesdropper 窃听者 therefore leaves evidence, and the corrupted key is thrown away and a new one sent. Benefits: interception is always detectable; the key cannot be copied without being altered; it is secure against future advances in computing power (a mathematical key can eventually be cracked, a quantum one cannot be read without disturbing it). Drawbacks: it needs specialised, expensive equipment; it works only over limited distances on dedicated optical fibre (or line of sight), not across the existing internet; it distributes the key only, so ordinary encryption still protects the message; and it is a new technology with few suppliers and little experience.

日本語

暗号化 は、鍵 に依存する数学的演算を用いて、読み可能な 平文 (plain text)を読み取れない 暗号文 (cipher text)に変換します。正しい鍵を持つ者だけが逆転させる— 復号化 —ことで平文を取り戻せます。鍵なしに暗号文を傍受した攻撃者は、ありあらゆる可能な鍵を試すのにあまりにも長い時間がかかるため、意味のないデータしか見ることができません。新しいアプローチである 量子暗号 は、量子力学を利用して盗聴者が現れる way で鍵を共有します。

キーボードとローターを備えたエンigma暗号装置
エンigma装置は第二次世界大戦中にメッセージを暗号化しました—初期の機械式暗号デバイス
平文が暗号鍵付きの暗号アルゴリズムを経て暗号文となり、インターネットを介して渡り、復号鍵付きの復号アルゴリズムを経て平文に戻る
暗号化は鍵で平文を乱し、復号化はその逆を行う

対称暗号

対称暗号化(対称鍵暗号)は、同一の鍵を暗号化と復号の両方に使用するため、送信者と受信者の双方が秘密鍵を保持する必要があります。これは高速であり、大量データ(ハードディスク全体、動画ストリームなど)に適しています。しかし、鍵の配送という問題があります。最初の段階でどのように安全に鍵を共有するかです。非対称暗号化はこの問題を解決します。

「対称鍵暗号化とは何を意味するか説明せよ」(2点) 平文を暗号化し、暗号文を復号する際に同じ鍵が使用されるため、送信者と受信者の間で鍵が共有され、他者からは秘密に保たれる必要があります。2つの欠点。 メッセージを送信する前に鍵を交換する必要があり、通信中に盗聴された場合、盗聴者はすべてのメッセージを読むことができます;対応するすべてのペアごとに別の鍵が必要であり、誰がメッセージを送ったかの証明を提供しない点です。なぜなら、両端が同じ鍵を持っているからです。「鍵暗号化を用いる2つの理由を挙げよ」: 盗聴者がデータを読めないようにする(機密性)、受信者がデータが声称した送信者から来ていて改ざんされていないことを確信できるようにする(認証性と完全性)。2つの手法は対称鍵暗号化と非対称鍵暗号化です。

対称暗号化は両端で同じ鍵を使用し、これを秘密裡に共有する
対称暗号化は両端で同じ秘密鍵を使用

非対称暗号化(公開鍵暗号)

非対称暗号化(非対称鍵暗号)では、各ユーザーに関連する鍵のペアが割り当てられます:公開する公開鍵と、秘密に kept する秘密鍵です。公開鍵で暗号化されたデータは、対応する秘密鍵でのみ復号可能であり、その逆もまた然りです。

トムとミーラはそれぞれ共有するための公開鍵と、秘密に kept する秘密鍵を持っており、ミーラはトムに自身の公開键を送る
各ユーザーは共有するための公開鍵と、秘密に kept する秘密鍵を持っている

アリスへ秘密メッセージを送る場合:彼女の公開された公開鍵を取得し、それを使って暗号化して送信します。対応する秘密鍵を持っているアリスのみが復号できます。事前の鍵交換は不要です。代償として、対称暗号より遥かに遅いため、大容量データには使用されません。

"秘密鍵の概念を述べよ。" 所有者のみが知る鍵(伝送 never)、対応する公開鍵で暗号化されたデータを復号するために使用され、デジタル署名を作成するために使用される。「非対称暗号化のプロセスを説明しなさい」(4点): (1) 受信者がペアの鍵、すなわち公開鍵と秘密鍵を生成し、これらは数学的に関連しています;(2) 公開鍵は、彼らにメッセージを送りたい誰にでも提供されます;(3) 送信者は受信者の公開鍵を使って平文を暗号化します;(4) 暗号文は受信者の秘密鍵でのみ復号でき、それは常に受信者に留まるため、メッセージを intercept した誰一人として読むことはできません。

** worked example(例題)。** フレッドがシエラに機密文書を送りたいと考えています。非対称暗号化がどのように使われるかを説明しなさい。

シエラには鍵のペアがあります;彼女はフレッドに自身の公開鍵を送ります(または彼が彼女の証明書から取得します)。フレッドはシエラの公開鍵を使って文書を暗号化し、暗号文を送ります。シエラの秘密鍵のみで復号可能であり、それを保持しているのはシエラだけなので、フレッドを含む他の誰も、暗号化後では文書を読むことができません。鍵は受信者側の使い方をします:彼女の公開鍵でロックし、彼女の秘密鍵でアンロックします。「 secure transmission を受け取る」ために鍵のペアを保持する組織は、まさにこの動作を行います:公開鍵を published し、秘密鍵を kept して、到着したものを復号する。

対称暗号化と非対称暗号化の2つの違い。 対称暗号化は双方向に1つの鍵を使用します;非対称暗号化は2つの関連する鍵を使用し、一つで暗号化し、もう一つで復号します。対称暗号化では鍵を双方が秘密に kept 必要があり、 securely exchange する必要があります;非対称暗号化では公開鍵はpublishedでき、秘密鍵だけが secret です。対称暗号化は much faster であり、大量のデータに適しています;非対称暗号化は slower であるため、大量データではなく、鍵や署名のために使用されます。

秘密鍵は secret に keep する必要があるため、時折小さなハードウェアセキュリティキーに kept されることがあります。接続したりタッチしたりして自分自身であることを证明すると、秘密鍵はデバイスから never 離れません。

白い背景の上に黒いハードウェアセキュリティキーがあり、中央に丸い金色のタッチセンサー、片端に金色のUSBコネクタがある
ハードウェアセキュリティキーは、自分自身であることを証明するための秘密鍵を stored する

ハイブリッドアプローチ(ほぼ全ての実システムで使用)

新しいセッション鍵を exchange するために非対称暗号化を使用し、その後、その対称鍵を使ってデータを transfer する:

  1. クライアントがランダムなセッション鍵を生成する。
  2. セッション鍵をサーバーの公開鍵で暗号化する。
  3. サーバーは自身の秘密鍵で復号する。
  4. 両端は now share してセッション鍵を持ち、残りの部分では高速な対称暗号化を使用する。

これが HTTPS と SSH が動作する仕組みである。

試験における鍵交換問題のバージョン。 「メッセージを送信する前に対称鍵を exchange する必要がある。鍵を securely exchange する方法を説明しなさい。」 送信者は対称鍵を受信者の公開鍵で暗号化して送信します;受信者は自身の秘密鍵で復号します;双方 now hold して対称鍵を持ち、これは途中 transmission で never exposed であり、メッセージに use されます。非対称暗号化が distribution 問題を解決し、対称暗号化が subsequent fast work を行う。

クライアントはセッション鍵をサーバーの公開鍵で暗号化して送信し、サーバーの秘密鍵のみで開くことができ、その後双方は shared セッション鍵を使って高速な対称暗号化を使用する
ハイブリッドアプローチ:非対称暗号でセッションキーを一度共有し、その後高速な対称暗号でデータを保護する

ハッシュ関数(関連項目であり、暗号化ではない)

暗号ハッシュ関数は任意の入力を取り、同じ入力が常に同じダイジェストを与える固定サイズのダイジェストを出力します。また、同じダイジェストを持つ2つの入力を見つけることは不可能であり、入力のわずかな変更でもダイジェストが完全に変わります。ハッシュは一方向性を持ちます——元の入力に戻すことはできません。パスワードの検証保存、完全性チェック、デジタル署名に使用されます。

暗号化ハッシュ関数は入力 hello を1つのダイジェストにマッピングし、1文字だけ変更した hellp を全く異なるダイジェストにマッピングします;ハッシュ関数は逆変換できません
暗号ハッシュは固定されたダイジェストを与え、入力のわずかな変化で完全に変わり、逆変換もできません

量子暗号学

量子暗号学は光の物理学を利用して鍵を分配します:鍵のビットは量子状態が値をエンコードする光子として送信されます。「その目的を説明せよ」: 暗号化鍵を安全に伝送すること、かつ、それを盗聴しようとする試みはすべて検出可能であること、なぜなら光子を測定するとその状態が変わるからであるという点です。したがって、盗聴者は痕跡を残し、損なわれた鍵は破棄され新しいものが送信されます。利点: 盗聴は常に検出可能である;鍵は改変なくコピーすることはできない;計算能力の将来的な向上に対する耐性がある(数学的鍵は最終的に解読される可能性があるが、量子鍵は乱さずに読み取ることはできない)。欠点: 特殊で高価な機器が必要です;専用光ファイバー(または直進路)でのみ限られた距離で動作し、既存のインターネット上では動作しません;鍵のみを分配するため、メッセージ自体は通常の暗号化で保護されます;そして、これは供給者が少なく経験の少ない新しい技術です。

Explore · ⁨探索⁩

Hashing and the avalanche effect · ⁨ハッシングと雪崩効果⁩

A hash is one-way: easy to compute, practically impossible to reverse. A tiny change in the input flips a large, unpredictable part of the output — the avalanche effect that makes hashes good for passwords. · ⁨ハッシュは一方向性である:計算は容易だが、逆算は事実上不可能である。入力のわずかな変化が、出力の大きく予測不能な部分を変化させる — ハッシュがパスワードに適している理由である雪崩効果。⁩

Explore · ⁨探索⁩

The Caesar cipher · ⁨凯撒暗号(Caesar cipher)⁩

Shift each letter to encrypt the message. A simple cipher shows the idea of a key — and why a small key is easy to break. · ⁨文字をシフトしてメッセージを暗号化します。簡単な暗号は鍵という概念を示し、なぜ小さな鍵では破読しやすいかを理解できます。⁩

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
encryption/enˈkrɪpʃn/ 暗号化
plaintext/ˈpleɪntekst/ 平明文
ciphertext/ˈsaɪfətekst/ 暗号文
decryption/dɪˈkrɪpʃn/ 復号化
quantum cryptography/ˈkwɒntəm krɪpˈtɒɡrəfi/ 量子暗号
eavesdropper/ˈiːvzdrɒpə/ 盗聴者
symmetric encryption/sɪˈmetrɪk enˈkrɪpʃn/ 対称暗号化
key distribution/kiː ˌdɪstrɪˈbjuːʃn/ 鍵配分
asymmetric encryption/ˌeɪsɪˈmetrɪk enˈkrɪpʃn/ 非対称暗号化
integrity/ɪnˈteɡrɪti/ 完全性
public key/ˈpʌblɪk kiː/ 公開鍵
private key/ˈpraɪvət kiː/ 秘密鍵
17.1

SSL / TLS

English

TLS 传输层安全 (Transport Layer Security, the successor to the Secure Socket Layer, SSL) is a protocol that gives encryption and authentication for data sent over a network. It encrypts the data in transit, authenticates the server with a certificate, and provides integrity (detecting tampering).

Outline of a TLS handshake:

  1. the client connects and proposes cipher options.
  2. the server picks one and sends its digital certificate (with its public key) — issuing and validating these certificates is digital certification.
  3. the client checks the certificate.
  4. the two ends exchange a fresh session key using asymmetric crypto.
  5. all later traffic uses fast symmetric encryption with the session key.

The result is an encrypted, authenticated, integrity-checked tunnel for higher-level protocols (HTTP, SMTP). It is appropriate wherever sensitive information is sent: HTTPS web browsing, online banking and payments, secure email, and VPNs.

"Describe the purpose of SSL/TLS" and "state two functions." The purpose is to provide secure communication between a client and a server over a network. Its functions: it encrypts the data sent, so that it cannot be read if intercepted; it authenticates 认证 the server (and optionally the client) by means of a digital certificate, so the client knows it is talking to the genuine site; and it checks the integrity of the data, so that changes in transit are detected. Two examples of where it is appropriate: online banking and online shopping (card payments); also logins, private email, file transfer, VoIP and instant messaging: any transaction in which private data crosses the internet.

The two protocols that make up TLS. The handshake 握手 protocol sets up the session: it agrees the encryption algorithms (cipher suite), authenticates the server with its certificate, and exchanges the session key. The record protocol then carries the data: it encrypts each message with the session key, adds an integrity check, and passes it to the transport layer.

"Explain how SSL/TLS is used when client–server communication is initiated" (six marks). (1) The client (browser) sends a request to the server for a secure connection, saying which encryption methods it supports. (2) The server sends back its digital certificate, which contains its public key. (3) The client checks the certificate is valid (issued by a trusted Certificate Authority, not expired, for the right domain). (4) The client generates a session key, encrypts it with the server's public key and sends it. (5) The server decrypts the session key with its private key. (6) Both sides now hold the session key and all further data is sent using symmetric encryption with it. Give the steps in this order; the marks are for the certificate, the public key, the session key and the switch to symmetric encryption.

日本語

TLS(Transport Layer Security、Secure Socket Layer (SSL) の後継者)は、ネットワークを介して送信されるデータに対して暗号化と認証を提供するプロトコルです。它在途中的数据进行加密,对服务器进行证书认证,并提供完整性(检测篡改)。

TLSハンドシェイクの概要:

  1. クライアントが接続し、暗号化オプションを提案する。
  2. サーバーが1つ選択し、デジタル証明書(公開鍵付き)を送信する——これらの証明書の発行と検証はデジタル認証である。
  3. クライアントが証明書を確認する。
  4. 両端は非対称暗号を使って新しいセッションキーを交換する。
  5. その後のすべての通信は、セッションキーを用いた高速な対称暗号で行われる。

結果として、HTTPやSMTPなどの上位プロトコル用には、暗号化・認証済み・完全性チェック済みのトンネルが構築されます。敏感な情報が送信されるあらゆる場面で適切です:HTTPSウェブブラウジング、オンライン銀行取引と支払い、セキュアメール、VPNなど。

「SSL/TLSの目的を説明し、2つの機能を述べよ」。目的は、ネットワークを介してクライアントとサーバー間で** secure communication を提供することです。機能:送信されたデータを暗号化するため、盗聴されても読み取ることができない;デジタル証明書によってサーバー(およびオプションでクライアント)を認証するため、クライアントが正規のサイトと通信していることを確認できる;データの完全性をチェックするため、途中での変更を検知できる。適切な例:オンライン銀行取引とオンラインショッピング**(カード決済);さらにログイン、プライベートメール、ファイル転送、VoIP、インスタントメッセージングなど、プライベートデータがインターネットを横断するあらゆる取引。

TLSを構成する2つのプロトコル。 ハンドシェイクプロトコルはセッションを設定する:暗号アルゴリズム(暗号スイート)の合意、サーバーの証明書による認証、およびセッションキーの交換を行う。レコードプロトコルはその後データ运送を行う:各メッセージをセッションキーで暗号化し、完全性チェックを追加し、トランスポート層に渡す。

クライアントとサーバー間のシーケンス図:クライアントは安全な接続を要求し、サーバーはデジタル証明書と公開鍵で応答し、クライアントは証明書を確認し、セッションキーを作成してサーバーの公開鍵で暗号化して送信し、サーバーは自身の秘密鍵で復号し、両側はその後対称暗号で通信する
安全なセッションの開始方法:証明書がサーバーの正体证明了,サーバーの公開鍵がセッションキーの送信中を保護し、セッションキーがそれ以降の全てを保護する

「クライアント-サーバー通信が開始される際、SSL/TLSがどのように使われるかを説明せよ」(6点) (1)クライアント(ブラウザ)はサポートする暗号化方法を明言して、サーバーへ安全な接続の要求を送信する。(2)サーバーは自身の公開鍵を含むデジタル証明書を返信する。(3)クライアントは証明書が有効であることを確認する(信頼できる証明書発行者(CA)が発行した、期限切れでない、正しいドメインのもの)。 (4)クライアントはセッションキーを生成し、サーバーの公開鍵で暗号化して送信する。(5)サーバーは自身の秘密鍵でセッションキーを復号する。(6)両側はこれでセッションキーを保持しており、それ以降のデータはすべてこれを用いた対称暗号で送信される。この順序で手順を記述すること。採点ポイントは、証明書、公開鍵、セッションキー、対称暗号への切り替えにある。

Explore · ⁨探索⁩

The TLS handshake · ⁨TLS ハンデシェイク⁩

Step through what happens before a padlock appears. The slow public-key crypto is used only to agree a shared key; the actual page then travels under fast symmetric encryption. · ⁨ロックアイコンが表示される前に何が起こるかを確認します。スローな公開鍵暗号は共有鍵の合意にのみ使われ、実際のページデータは高速な対称暗号によって保護されます。⁩

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
TLS/ˌtiː el ˈes/ TLS
authentication/ɔːˌθentɪˈkeɪʃn/ 認証
authenticates/ɔːˈθentɪkeɪts/ 認証する
handshake/ˈhændʃeɪk/ ハンドシェイク
17.1

Digital certificates · ⁨デジタル証明書⁩

English

A digital certificate 数字证书 binds an identity (a domain, an organisation) to a public key, and is signed by a trusted Certificate Authority 证书颁发机构 (CA). It contains the subject (who it identifies), the subject's public key, the issuer (the CA), a validity period, and the CA's signature over all of it.

To verify one, the client (which holds a list of trusted root CAs):

  1. checks the expiry dates.
  2. checks the subject name matches the URL.
  3. checks it is signed by a trusted CA, using the CA's public key to verify the signature.
  4. follows the certificate chain up to a trusted root.

If anything fails, the browser shows the "Your connection is not private" warning. When it verifies cleanly, the client knows the identity was vetted by a trusted CA, the public key really belongs to that identity, and the certificate is current.

"Describe what is meant by a digital certificate" (two marks). An electronic document, issued by a Certificate Authority, that verifies the identity of its owner (a person, organisation or website) and contains the owner's public key. Items found in one: the serial number; the name of the owner (subject) and, for a website, its domain; the owner's public key; the name of the issuing CA; the validity period (dates); the signature algorithm used; and the CA's digital signature of the whole certificate.

"Explain how an organisation acquires a digital certificate" (four marks). (1) The organisation generates its own key pair, a public key and a private key. (2) It sends a request containing its public key and its identity details to a Certificate Authority. (3) The CA verifies the identity (checks that the applicant really is the organisation or owns the domain). (4) The CA creates the certificate containing the public key and the identity, signs it with the CA's own private key, and returns it. (5) The organisation installs the certificate on its server so that it can be sent to clients. The private key never leaves the organisation.

"Explain why a digital certificate is required to validate a digital signature." To check a signature the receiver needs the sender's public key, and needs to be sure that the key really belongs to the claimed sender; the certificate supplies the public key together with the identity, and because the certificate is signed by a trusted CA the receiver can trust that binding. Without it an impostor could publish a public key in someone else's name and sign messages as them. The same reasoning answers "what should be included with a program downloaded from the internet to prove it is genuine": a digital signature, checked against the publisher's certificate.

日本語

デジタル証明書は、ID(ドメイン、組織)と公開鍵を結び付け、信頼できる証明書発行者(CA)によって署名されています。対象者(誰を識別するか)、対象者の公開鍵、発行者(CA)、有効期間、およびこれら全体に対するCAの署名を含みます。

ユーザーが自身の識別情報と公開鍵を証明書発行者(CA)に送信し、CAは識別情報を検証して、公開鍵、CAの識別情報、ユーザーID、デジタル署名その他の情報を含む署名付きデジタル証明書を発行する
証明書発行者は、識別情報と公開鍵を結びつけたデジタル証明書を発行する

これらを検証するには、クライアント(信頼されたルートCAの一覧を保持している)は以下を行う:

  1. 有効期限を確認する。
  2. 対象者名がURLと一致するか確認する。
  3. CAの公開鍵を使用して署名を検証し、信頼できるCAによって署名されているか確認する。
  4. 信頼されるルートまで証明書チェーンをたどる。

何らかのチェックに失敗した場合、ブラウザは「この接続は非私密です」という警告を表示する。すべての検証が正常に行われた場合、クライアントはその識別情報が信頼できるCAによって審査され、公開鍵が確かにその識別情報のものであり、証明書が有効であることを知ることができる。

「デジタル証明書とは何かを説明せよ」(2点) 証明書発行者が発行した電子文書であり、所有者(個人、組織、またはウェブサイト)の識別情報を検証し、所有者の公開键を含んでいる。 含まれる項目: シリアル番号;所有者の名前(対象者)および、ウェブサイトの場合そのドメイン;所有者の公開鍵;発行CAの名前;有効期間(日付);使用されている署名アルゴリズム;そして証明書の全体に対するCAのデジタル署名。

「組織がデジタル証明書を入手する方法を説明せよ」(4点) (1) 組織は独自のキーペア(公開鍵と秘密鍵)を生成する。(2) 公開鍵と識別情報詳細を含む申請を証明書発行者に送信する。(3) CAは識別情報を検証する(申請者が実際にその組織である、またはドメインを所有していることを確認する)。(4) CAは公開鍵と識別情報を含む証明書を作成し、CA自身の秘密鍵で署名して返送する。(5) 組織はサーバーに証明書をインストールし、クライアントに送信できるようにする。秘密鍵が組織の外に出ることはない。

「なぜデジタル署名を検証するためにデジタル証明書が必要かを説明せよ。 署名を検査するには、受信者は送信者の公開鍵が必要であり、その鍵が本当に宣言された送信者のものであることを确信する必要があります。証明書は公開鍵と識別情報を併せて提供しており、証明書が信頼できるCAによって署名されているため、受信者はこの結合を信頼できます。これがない場合、騙しは他人の名前で公開鍵を公開し、その人物になりすましてメッセージに署名することが可能です。同じ論理は「インターネットからダウンロードしたプログラムに、本物であることを証明するために何が含まれるべきか」への回答にも当てはまります:デジタル署名であり、発行者の証明書に対して検証されます。

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
digital certificate/ˈdɪdʒɪtl səˈtɪfɪkət/ デジタル証明書
17.1

Digital signatures · ⁨デジタル署名⁩

English

A digital signature 数字签名 proves who signed a message and that it was not changed. To sign:

  1. compute a cryptographic hash of the message.
  2. encrypt the hash with the sender's private key — that is the signature.
  3. send the message and the signature.

To verify: compute the hash of the received message; decrypt the signature with the sender's public key to get the sender's hash; compare. If they match, the message was signed by the holder of the private key (authentication 身份验证) and was not changed (integrity). A signature does not hide the message — for confidentiality as well, encrypt and sign.

"Explain the role of a digital certificate in creating a digital signature" (three marks). The sender's certificate was issued by a CA and contains the sender's public key together with the sender's identity; the sender produces the signature by hashing the message and encrypting the hash with their private key, the partner of the key in the certificate; the receiver uses the public key from the certificate to decrypt the hash and, because the certificate binds that key to the sender, the signature proves who signed.

"Explain how a digital signature is used to verify a message" (four marks). (1) The receiver decrypts the signature with the sender's public key (taken from the sender's certificate), which yields the hash that the sender computed. (2) The receiver hashes the received message with the same hash algorithm. (3) The two hashes are compared. (4) If they match, the message came from the holder of the private key (authentic) and has not been altered since it was signed (integrity); if they differ, the message is rejected. A banker receiving confidential data with a signature does exactly this before trusting it; the data itself may separately be encrypted with the banker's public key for confidentiality.

Putting it together

A secure request to https://www.bank.com: the server sends its certificate; the client verifies it against trusted CAs; the client uses the server's public key to exchange a session key; then data flows encrypted with that key. Encryption stops eavesdroppers, the certificate proves the server's identity, and integrity checks stop a man-in-the-middle 中间人攻击 altering the data.

Worked example. Alice sends Bob a contract. She wants Bob to be certain it came from her and was not altered, and she wants nobody else to be able to read it. Which keys does she use, and in which direction? These are two different jobs needing two different key pairs. For the signature (authentication and integrity): Alice hashes the contract and encrypts that hash with her own private key; Bob decrypts it with Alice's public key and compares it against his own hash of the message. Only Alice holds her private key, so only she could have produced it. For confidentiality: Alice encrypts the contract itself with Bob's public key, so only Bob's private key can open it. One rule keeps all four straight: you sign with your own private key and encrypt with the recipient's public key. A signature on its own does not hide the message.

日本語

デジタル署名は、誰がメッセージに署名したかを示すだけでなく、変更されていないことも証明します。署名するには:

  1. メッセージの暗号化ハッシュを計算する。
  2. ハッシュを送信者の秘密鍵で暗号化する — これが署名である。
  3. メッセージと署名を送信する。

検証するには:受信メッセージのハッシュを計算する;送信者の公開鍵で署名を復号化して送信者のハッシュを取得する;比較する。一致すれば、メッセージは秘密鍵の保有者によって署名されており(認証)、変更されていない(完全性)。署名はメッセージを隠さない。機密性を確保するためには、暗号化と署名の両方を行う必要がある。

送信者はメッセージをダイジェストにハッシュ化し、自身の秘密鍵で暗号化して署名を形成します;受信者はメッセージを再ハッシュ化し、送信者の公開鍵で署名を復号化して、2つのダイジェストを比較します
署名はメッセージをハッシュ化し、ダイジェストを秘密鍵で暗号化します;受信者は公開鍵を使ってそれを検証する

「デジタル署名を作成する際、デジタル証明書の役割について説明せよ」(3点) 送信者の証明書はCAによって発行され、送信者の公開鍵と送信者の識別情報を含んでいます。送信者はメッセージをハッシュ化し、証明書内の鍵の対となる秘密鍵でハッシュを暗号化することで署名を作成します。受信者は証明書からの公開鍵を用いてハッシュを復号化し、その鍵が送信者に紐付けられているため、署名は誰が署名したか證明します。

「デジタル署名がメッセージの検証にどのように使われるかを説明せよ」(4点) (1) 受信者は送信者の公開鍵(送信者の証明書から取得)で署名を復号化し、送信者が計算したハッシュを得る。(2) 受信者は同じハッシュアルゴリズムで受信メッセージをハッシュ化する。(3) 2つのハッシュは比較される。(4) 一致すれば、メッセージは秘密鍵の保有者から来たもの(正規)であり、署名後改変されていない(完全性);不一致であればメッセージは却下される。銀行が署名付きの機密データを受け取る際、これを信頼する前に同様の操作を行う;データ自体は機密性のために別個に銀行の公開鍵で暗号化される場合がある。

統合

https://www.bank.comへの安全なリクエスト:サーバーは証明書を送信し、クライアントは信頼できるCAに対してそれを検証する;クライアントはサーバーの公開鍵を使用してセッション鍵を交換し、その後、その鍵で暗号化されたデータが流れる。暗号化は盗聴者を遮断し、証明書はサーバーの識別情報を証明し、完全性チェックはミドルマン攻撃によるデータ改変を防ぐ。

** worked example.** アリスがボブに契約書を送る。アリスは、この文書が自分から送られたことと改ざんされていないことをボブに確信させたい。さらに、第三者には読まれないようにしたい。アリスはどの鍵を、どのような方向で使うべきか。これらは2つの異なるタスクであり、2つの異なる鍵ペアが必要である。署名(認証と完全性)のために:アリスは契約書のハッシュを取り、それを自身の秘密鍵で暗号化する;ボブはアリスの公開鍵で復号し、自分のメッセージに対するハッシュと比較する。アリス自身が秘密鍵を持っているのは彼だけなので、彼だけが生成した可能性がある。機密性のために:アリスは契約書そのものをボブの公開鍵で暗号化するため、ボブの秘密鍵のみで開くことができる。4つを区別するための1つのルールがある:「署名は自身の秘密鍵で行い、暗号化は相手の公開鍵で行う」。署名だけではメッセージは隠されない。

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
digital signature/ˈdɪdʒɪtl ˈsɪɡnɪtʃə/ デジタルサイネチャ
hardware security key/ˈhɑːdweə sɪˈkjʊərɪti kiː/ ハードウェアセキュリティキー
session key/ˈseʃn kiː/ セッションキー
cryptographic hash/ˌkrɪptəˈɡræfɪk hæʃ/ 暗号ハッシュ
digest/ˈdaɪdʒest/ ダイジェスト
17.1

Definitions the examiner accepts · ⁨出題者が認める定義⁩

English

A definition question is marked against fixed wording. Learn these exactly, and give one answer only.

Term Definition
encryption converting plaintext into ciphertext using an algorithm and a key so that it cannot be understood if intercepted
plaintext / ciphertext the original readable data / the encrypted, unreadable form of it
symmetric key cryptography the same secret key is used to encrypt and to decrypt, so it must be shared securely by both parties
asymmetric key cryptography a pair of related keys is used: the public key encrypts and only the matching private key decrypts
public key a key made available to anyone, used to encrypt messages to its owner and to verify the owner's signatures
private key a key known only to its owner, used to decrypt messages encrypted with the public key and to sign
SSL/TLS protocols that provide secure (encrypted, authenticated, integrity-checked) communication between a client and a server
digital certificate an electronic document issued by a Certificate Authority that verifies the owner's identity and contains their public key
digital signature a hash of a message encrypted with the sender's private key, proving who sent it and that it is unaltered
Certificate Authority a trusted organisation that verifies identities and issues and signs digital certificates
quantum cryptography the use of quantum states of photons to distribute keys so that any interception is detected
日本語

定義問題は固定された用語に基づいて採点されます。これらを正確に暗記し、一つの答えのみを答えてください。

用語 定義
暗号化 アルゴリズムと鍵を使って平明文を暗号文に変換し、傍受された場合に理解できないようにすること
平明文 / 暗号文 元の読み可能なデータ / その暗号化され、読み取れない形
対称鍵暗号化 暗号化と復号に同じ秘密鍵が使われるため、両者によって安全に共有される必要がある
非対称鍵暗号化 関連する鍵のペアが使われる:公開鍵で暗号化し、対応する秘密鍵のみで復号する
公開鍵 誰でも利用可能にするための鍵。所有者へのメッセージの暗号化や、所有者の署名の検証に使用される
秘密鍵 所有者のみに知られている鍵。公開鍵で暗号化されたメッセージの復号や、署名作成に使用される
SSL/TLS クライアントとサーバー間の安全な(暗号化済み、認証済み、完全性確認済み)通信を提供するプロトコル
デジタル証明書 証明機関が発行する電子文書。所有者の身份を確認し、公開键を含む
デジタル署名 送信者の秘密鍵で暗号化されたメッセージのハッシュ。誰が送信したか、かつ改ざんされていないことを証明する
証明機関 (Certificate Authority) 信頼できる組織。 identities を検証し、デジタル証明書を発行・署名する
量子暗号化 光子の量子状態を用いて鍵を分配し、傍受を検知する
Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
Certificate Authority/səˈtɪfɪkət əˈθɒrɪti/ 証明機関
man-in-the-middle/mæn ɪnðə ˈmɪdl/ 真ん中の男
17.1

Exam tips · ⁨試験対策⁩

English
  • Symmetric: one shared secret key, fast, key exchange is the weakness. Asymmetric: public key to encrypt, private key to decrypt, slow, no exchange problem. Two differences, two drawbacks, two reasons: the exam asks for them in pairs.
  • Confidentiality uses the receiver's keys (public to lock, private to unlock); a signature uses the sender's keys (private to sign, public to check). Say whose key every time.
  • The TLS start-up is six steps: request, certificate with public key, check, session key encrypted with the public key, decrypted with the private key, symmetric encryption from then on.
  • A certificate is identity plus public key, signed by a CA; acquisition is key pair, request, verification, signing, installation. It is needed to validate a signature because it proves whose public key it is.
  • A signature is a hash encrypted with the private key; verification is decrypt, re-hash, compare. Integrity and authenticity are the two things it proves.
  • Quantum cryptography distributes keys and detects eavesdropping; its limits are cost, distance and novelty.

Common mistakes

  • Saying a message is encrypted with the sender's public key; the receiver's public key encrypts, the receiver's private key decrypts.
  • Describing a signature as "encrypting the message with the private key" instead of encrypting its hash.
  • Claiming a certificate contains the private key; it holds the public key and the identity, signed by the CA.
  • Listing "the server sends its private key" in the TLS handshake; only the public key travels, inside the certificate.
  • Giving "SSL/TLS makes the connection faster" as a function; its functions are encryption, authentication and integrity.
  • Confusing hashing with encryption: a hash cannot be reversed and has no key; encryption is reversible with the key.
  • Answering "why is a certificate needed for a signature" with "to encrypt it"; it is needed to trust the public key.
日本語
  • 対称:1つの共有秘密鍵、高速だが、鍵交換が弱点。非対称:公開鍵で暗号化、秘密鍵で復号、低速だが交換問題なし。2つの違い、2つの欠点、2つの理由:試験ではこれらをペアで問われる。
  • 機密性は受信者の鍵(公開鍵でロック、秘密鍵でアンロック)を使用;署名は送信者の鍵(秘密鍵で署名、公開鍵でチェック)を使用。毎回「だれの鍵か」を明言すること。
  • TLSの初期化は6ステップ:リクエスト、公開鍵付き証明書、チェック、公開鍵で暗号化されたセッション鍵、秘密鍵で復号、それ以降は対称暗号化。
  • 証明書は「identity+公開鍵」であり、CAによって署名されている;取得プロセスは「鍵ペア生成→リクエスト→検証→署名→インストール」。署名を検証するために必要なのは、それが「だれの公開鍵か」を示すからである。
  • 署名とは「秘密鍵で暗号化されたハッシュ」であり、検証は「復号→再ハッシュ→比較」である。完結性と真正性は、証明する2つの要素である。
  • 量子暗号化は鍵の分配と盗聴検出を行う;その限界はコスト、距離、および新しさである。

一般的なミス

  • メッセージが「送信者の公開鍵で暗号化されている」と言うのは間違い。「受信者の公開鍵で暗号化され、受信者の秘密鍵で復号される」のが正しい。
  • 「メッセージそのものを秘密鍵で暗号化している」と署名を説明するのは誤り。「ハッシュを暗号化している」のが正しい。
  • 証明書に秘密鍵が含まれると主張するのは誤り。「公開鍵とidentityを含み、CAによって署名されている」のが正しい。
  • TLSハンドシェイクで「サーバーが秘密鍵を送る」と並べるのは誤り。「公開鍵のみが移動し、証明書の中に含まれる」のが正しい。
  • 「SSL/TLSは接続を速くする」を機能として挙げるのは誤り。「暗号化、認証、完全性の提供」が正しい機能である。
  • ハッシングと暗号化を混同する:ハッシュは逆転できず鍵も持たない;暗号化は鍵で逆転可能である。
  • 「なぜ証明書の必要性があるか」に対して「暗号化するため」と答えるのは誤り。「公開鍵を信頼するため」が必要である。

Interactive lessons on this topic · ⁨このトピックのインタラクティブ授業⁩

Work through it step by step, with instant-check exercises. · ⁨一歩ずつ進め、即時チェック付きの問題で学習します。⁩

Past Papers · ⁨過去問⁩

More topics in A-Level Computer Science · ⁨A-Level コンピューター科学⁩ · ⁨A-Level Computer Science · ⁨A-Level コンピューター科学⁩ の他のトピック⁩

Log in or create account · ⁨ログインまたはアカウント作成⁩

IGCSE, A-Level & AP