브라우저 주소 표시줄의 자물쇠를 보세요. 은행 이름을 입력했는데, 어떻게든 노트북이 이제 정말로 은행과 대화하고 있다고 확신합니다—그리고…
English narration · English + 中文 subtitles burned in · 영어 내레이션 · 영어 + 중국어 자막 burned-in
17.1
How encryption works · 암호화의 원리
Syllabus
English
Candidates should be able to:
Notes and guidance
Show understanding of how encryption works
Including the use of public key, private key, plain text, cipher text, encryption, symmetric key cryptography and asymmetric key cryptography How the keys can be used to send a private message from the public to an individual/organisation How the keys can be used to send a verified message to the public How data is encrypted and decrypted, using symmetric and asymmetric cryptography Purpose, benefits and drawbacks of quantum cryptography
Show awareness of the Secure Socket Layer (SSL) / Transport Layer Security (TLS)
Purpose of SSL/TLS Use of SSL/TLS in client-server communication Situations where the use of SSL/TLS would be appropriate
Show understanding of digital certification
How a digital certificate is acquired How a digital certificate is used to produce digital signatures
한국어
응시자가 다음을 수행할 수 있어야 함:
참고 사항 및 가이드라인
암호화가 작동하는 원리에 대한 이해
공钥, 사钥, 평문, 암호문, 암호화, 대칭 키 암호화 및 비대칭 키 암호화의 사용 포함 공钥과 사钥을 사용하여 공개적으로 개인/기관에게 비私密 메시지를 보내는 방법 공钥과 사钥을 사용하여 검증된 메시지를 공개적으로 보내는 방법 대칭 및 비대칭 암호화를 사용하여 데이터를 암호화 및 복호화하는 방법 양자 암호학의 목적, 장점 및 단점
SSL/TLS의 목적 클라이언트-서버 통신에서의 SSL/TLS 사용 SSL/TLS 사용이 적절한 상황
디지털 인증에 대한 이해
디지털 인증서를 취득하는 방법 디지털 인증서를 사용하여 디지털 서명을 생성하는 방법
Source: Cambridge International syllabus · 출처: Cambridge International syllabus
English
Encryption 加密 turns readable plaintext 明文 (plain text) into unreadable ciphertext 密文 (cipher text) using a maths operation that depends on a key. Only someone with the right key can reverse it — decryption 解密 — to get the plaintext back. An attacker who intercepts the ciphertext without the key sees only meaningless data, because trying every possible key would take far too long. A newer approach, quantum cryptography 量子密码学, uses quantum physics to share a key in a way that reveals any eavesdropper.
Symmetric encryption
Symmetric encryption 对称加密 (symmetric key cryptography) uses the same key for both encryption and decryption, so sender and receiver must both hold the secret key. It is fast and good for bulk data (a whole disk, a video stream). Its problem is key distribution 密钥分发: how do you share the key safely in the first place? Asymmetric encryption solves this.
"Describe what is meant by symmetric key encryption" (two marks).The same key is used to encrypt the plaintext and to decrypt the ciphertext, so the key must be shared between sender and receiver and kept secret from everyone else. Two drawbacks. The key has to be exchanged before the message can be sent, and if it is intercepted in transit the interceptor can read every message; a separate key is needed for every pair of correspondents; and it gives no proof of who sent the message, because both ends hold the same key. "Give two reasons for using key cryptography": so that data is unreadable by anyone who intercepts it (confidentiality); so that the receiver can be sure the data came from the claimed sender and was not altered (authenticity and integrity 完整性). The two methods are symmetric and asymmetric key cryptography.
Asymmetric encryption (public-key)
Asymmetric encryption 非对称加密 (asymmetric key cryptography) gives each user a pair of related keys: a public key 公钥 they publish, and a private key 私钥 they keep secret. Data encrypted with the public key can be decrypted only with the matching private key, and vice versa.
To send a secret message to Alice: get her published public key, encrypt with it, and send. Only Alice — holding the matching private key — can decrypt. No prior key exchange is needed. The trade-off is that it is much slower than symmetric, so it is not used for large data.
"State what is meant by a private key."A key known only to its owner (never transmitted), used to decrypt data that was encrypted with the matching public key, and to create digital signatures."Describe the process of asymmetric encryption" (four marks): (1) the receiver generates a pair of keys, a public key and a private key, mathematically related; (2) the public key is made available to anyone who wants to send to them; (3) the sender encrypts the plaintext with the receiver's public key; (4) the ciphertext can only be decrypted with the receiver's private key, which never leaves the receiver, so nobody who intercepts the message can read it.
Worked example. Fred wants to send Sheila a confidential document. Explain how asymmetric encryption is used.
Sheila has a key pair; she sends Fred her public key (or he obtains it from her certificate). Fred encrypts the document with Sheila's public key and sends the ciphertext. Only Sheila's private key can decrypt it, and only Sheila holds that, so nobody else, including Fred once it is encrypted, can read the document. The keys are used the receiver's way round: her public key to lock, her private key to unlock. An organisation that holds a key pair "to receive secure transmissions" does exactly this: it publishes the public key, keeps the private key, and decrypts what arrives.
Two differences between symmetric and asymmetric encryption. Symmetric uses one key for both directions; asymmetric uses two related keys, one to encrypt and the other to decrypt. In symmetric encryption the key must be kept secret by both parties and exchanged securely; in asymmetric encryption the public key can be published and only the private key is secret. Symmetric encryption is much faster and suits large amounts of data; asymmetric is slower, so it is used for keys and signatures rather than bulk data.
A private key must stay secret, so it is sometimes kept on a small hardware security key 硬件安全密钥. You plug it in or tap it to prove who you are, and the secret key never leaves the device.
Hybrid approach (used by almost every real system)
Use asymmetric encryption to exchange a fresh session key 会话密钥, then use that symmetric key for the data:
the client makes a random session key.
it encrypts the session key with the server's public key.
the server decrypts it with its private key.
both ends now share the session key and use fast symmetric encryption for the rest.
This is how HTTPS and SSH work.
The exam's version of the key-exchange problem. "A symmetric key is to be exchanged before the message is sent. Explain how the key can be exchanged securely." The sender encrypts the symmetric key with the receiver's public key and sends it; the receiver decrypts it with their private key; both now hold the symmetric key, which was never exposed in transit, and use it for the messages. Asymmetric encryption solves the distribution problem; symmetric encryption then does the fast work.
Hashing (related, not encryption)
A cryptographic hash 密码散列 function takes any input and gives a fixed-size digest 摘要 such that the same input always gives the same digest, it is infeasible to find two inputs with the same digest, and a tiny change in input changes the digest completely. Hashing is one-way — you cannot get the input back. It is used for storing password checks, integrity checks, and digital signatures.
Quantum cryptography
Quantum cryptography uses the physics of light to distribute keys: the bits of a key are sent as photons whose quantum states encode the values. "Describe its purpose": to transmit an encryption key securely, in such a way that any attempt to intercept it can be detected, because measuring a photon changes its state; an eavesdropper 窃听者 therefore leaves evidence, and the corrupted key is thrown away and a new one sent. Benefits: interception is always detectable; the key cannot be copied without being altered; it is secure against future advances in computing power (a mathematical key can eventually be cracked, a quantum one cannot be read without disturbing it). Drawbacks: it needs specialised, expensive equipment; it works only over limited distances on dedicated optical fibre (or line of sight), not across the existing internet; it distributes the key only, so ordinary encryption still protects the message; and it is a new technology with few suppliers and little experience.
한국어
암호화는 키에 의존하는 수학 연산을 사용하여 가독성 있는 평문(plain text)을 가독 불가능한 암호문(cipher text)으로 변환합니다. 올바른 키를 가진 사람만이 이를 역행하여 평문으로 복원할 수 있는데, 이를 복호화라고 합니다. 키를 모른 채 암호문을 도청한 공격자는 무의미한 데이터만 보게 되는데, 가능한 모든 키를 시도하는 데에는 너무 많은 시간이 걸리기 때문입니다. 최신 방식인 양자 암호학은 양자 물리학을 활용하여 도청자의 존재를 드러낼 수 있는 방식으로 키를 공유합니다.
英格玛密码机在第二次世界大战期间用于加密信息——这是一种早期的机械式密码设备암호화는 키를 사용하여 평문을 섞어 놓으며, 복호화는 이를 역으로 undone합니다
대칭 암호화
대칭 암호화 (대칭 키 암호학)는 암호화와 복호화에 동일한 키를 사용하므로, 송신자와 수신자 모두에게 비밀 키가 공유되어야 합니다. 처리 속도가 빠르며 대용량 데이터(전체 디스크, 비디오 스트림 등)에 적합합니다. 그러나 키 분배 문제가 있습니다: 초기에 어떻게 안전하게 키를 공유할 것인가? 비대칭 암호화가 이를 해결합니다.
"대칭 키 암호화의 의미를 설명하시오 (2점)." 평문(plaintext)을 암호화하고 암호문(ciphertext)을 복호화하는 데 동일한 키가 사용되므로, 이 키는 송신자와 수신자 간에 공유되어야 하며 다른 모든 사람에게 비밀로 유지되어야 합니다. 두 가지 단점이 있습니다. 메시지가 전송되기 전에 키를 교환해야 하며, 전송 중 도청되면 도청자가 모든 메시지를 읽을 수 있습니다; 모든 쌍의 통신자에게마다 별도의 키가 필요하며, 양쪽 끝에서 동일한 키를 공유하므로 누가 메시지를 보냈는지 증명할 수 없습니다. "키 암호화를 사용하는 두 가지 이유를 제시하시오:": 도청자가 데이터를 읽지 못하게 하여(비밀성); 수신자가 데이터가声称한 sender에서 왔으며 변조되지 않았음을 확신할 수 있게 함(정체성 및 무결성). 두 방법은 대칭 키 암호학과 비대칭 키 암호학입니다.
대칭 암호화는 양끝에서 동일한 비밀 키를 사용함
비대칭 암호화 (公开密钥)
비대칭 암호화 (비대칭 키 암호학)는 각 사용자에게 서로 관련된 키 쌍을 부여합니다: 공개하는 公开密钥와 비밀로 유지하는 사钥. 公开密钥로 암호화된 데이터는 오직 매칭되는 사钥으로만 복호화할 수 있으며, 그 반대로도 동일합니다.
각 사용자는 공유할 公开密钥와 비밀로 유지할 사钥을 가짐
앨리스에게 비밀 메시지를 보내려면: 그녀의 공개된 公开密钥를 얻어用它으로 암호화하여 전송합니다. 오직 매칭되는 사钥을 보유한 앨리스만이 복호화할 수 있습니다. 사전의 키 교환은 필요 없습니다. 대신 속도는 대칭 암호화보다 훨씬 느리므로 대용량 데이터에는 사용하지 않습니다.
"사钥의 의미를 서술하시오." 소유자만이 아는 키(전송되지 않음)로, 매칭되는 公开密钥로 암호화된 데이터를 복호화하고 디지털 서명을 생성하는 데 사용됩니다. "비대칭 암호화 과정을 설명하시오 (4점):" (1) 수신자가 수학적으로 연관된 키 쌍, 즉 公开密钥와 사钥을 생성합니다; (2) 公开密钥를 그들에게 메시지를 보내고 싶은modal에게 공개합니다; (3) sender가 수신자의 公开密钥로 평문을 암호화합니다; (4) 암호문은 수신자의 사钥으로만 복호화할 수 있으며, 이 키는 수신자를離脱하지 않으므로 메시지를 도청한modal은 읽을 수 없습니다.
해설 예제. 프레드가 시엘라에게 기밀 문서를 보내고 싶습니다. 비대칭 암호화가 어떻게 사용되는지 설명하십시오.
시엘라에는 키 쌍이 있으며, 그녀는 프레드에게 자신의 公开密钥를 전송하거나(또는 그의 인증서에서 얻습니다). 프레드는 시엘라의 公开密钥로 문서를 암호화하여 암호문을 전송합니다. 오직 시엘라의 사钥만이 이를 복호화할 수 있으며, 오직 시엘라만이 이를 보유하므로, 암호화 이후에는 프레드 포함modal은 문서를 읽을 수 없습니다. 키는 수신자의 방식(her public key to lock, her private key to unlock)으로 사용됩니다. "보안 전송을受领하기 위한" 키 쌍을 보유한 조직은 정확히 이 방식을 사용합니다: 公开密钥를 공개하고, 사钥을 보유하며, 도착한 데이터를 복호화합니다.
대칭 암호화와 비대칭 암호화의 두 가지 차이점. 대칭은 양방향 모두에 하나의 키를 사용하지만, 비대칭은 암호화에 하나와 복호화에 다른 하나를 사용하는 두 개의 관련 키를 사용합니다. 대칭 암호화에서는 키가 양측에 의해 비밀로 유지되어야 하며 안전하게交换됩니다; 비대칭 암호화에서는 公开密钥를 공개할 수 있고 오직 사钥만이 비밀입니다. 대칭 암호화가 훨씬 빠르며 대용량 데이터에 적합하지만, 비대칭은 느리므로 대용량 데이터보다는 키와 서명에 사용됩니다.
사钥은 비밀로 유지되어야 하므로, 때로는 작은 하드웨어 보안 키에 보관되기도 합니다. 이를 꽂거나 터치하여 신원을 입증하면, 비밀 키는 장치 밖으로 나가지 않습니다.
하드웨어 보안 키는 신원 확인을 위한 비밀 키를 저장함
하이브리드 방식 (거의 모든 실제 시스템에서 사용됨)
새로운 세션 키를交換하기 위해 비대칭 암호화를 사용하고, 이후 데이터에는 해당 대칭 키를 사용합니다:
클라이언트가 무작위 세션 키를 생성합니다.
서버의 公开密钥로 세션 키를 암호화합니다.
서버는 자신의 사钥로 이를 복호화합니다.
양측은 이제 세션 키를 공유하며 나머지 작업에는 빠른 대칭 암호화를 사용합니다.
이것이 HTTPS와 SSH의 작동 원리입니다.
시험 문제에서의 키交换 문제 버전. "메시지가 전송되기 전에 대칭키를 exchange해야 합니다. 이 키를 안전하게 exchange하는 방법을 설명하시오." sender가 대칭 키를 수신자의 公开密钥로 암호화하여 전송합니다; 수신자는 자신의 사钥으로 이를 복호화합니다; 양측은 이제 전송 중 노출되지 않은 대칭 키를 보유하고 메시지를 암호화합니다. 비대칭 암호화가 distribution 문제를 해결하고, 대칭 암호화가 이후 빠른 작업을 수행합니다.
혼합 방식: 비대칭 암호는 세션 키를 한 번만 공유한 후, 빠른 대칭 암호가 데이터를 보호합니다
해싱 (관련 개념, 암호화가 아님)
암호학적 해시 함수는 임의의 입력을 받아 고정된 크기의 **디제스트(digest)**를 생성합니다. 같은 입력은 항상 동일한 디제스트를 생성하며, 두 개의 다른 입력이 동일한 디제스트를 가지는 것을 찾는 것은 불가능에 가깝습니다. 또한 입력의 미세한 변화도 디제스트를 완전히 바꿉니다. 해시는 단방향(one-way) 이므로, 디제스트에서 원본 입력을 복원할 수 없습니다. 비밀번호 저장 및 검증, 무결성(integrity) 검증, 디지털 서명 등에 사용됩니다.
암호학적 해시는 고정된 디제스트를 제공하며, 미세한 입력 변화가 디제스트를 완전히 바꾸고, 이는 되돌릴 수 없습니다
양자 암호학
양자 암호학은 빛의 물리 법칙을 이용하여 키를 분배합니다: 키의 비트들은 그 양자 상태가 값을 인코딩하는 **광자(photon)**로 전송됩니다. “목적 설명”: 암호화 키를 보안적으로 전송하여, 도청 시도가 이루어지면 이를 검출할 수 있도록 합니다. 광자의 측정은 그 상태를 변경하기 때문입니다. 따라서 **도청자(eavesdropper)**는 흔적을 남기게 되며, 위조된 키는 폐기되고 새로운 키가 재전송됩니다. 장점: 도청은 항상 검출 가능하며, 키를 복제하려면 반드시 변조되어야 하므로 도용이 불가능합니다. 향후 컴퓨팅 파워의 발전에 대한 보안성이 있습니다(수학적 키는 결국 붕괴될 수 있으나, 양자 키는 교란 없이 읽을 수 없습니다). 단점: 전문적이고 비싼 장비가 필요합니다. 전용 광섬유(또는 직선 시야)에서만 제한된 거리 내에서 작동하며, 기존 인터넷 전체를 통해 작동하지 않습니다. 키만 분배하므로, 일반 암호화方式이 메시지 자체를 여전히 보호해야 합니다. 또한 새로운 기술로서 공급업체가 적고 경험이 부족합니다.
Explore · 탐색하기
Hashing and the avalanche effect · 해싱 및 폭풍 효과(Avalanche Effect)
A hash is one-way: easy to compute, practically impossible to reverse. A tiny change in the input flips a large, unpredictable part of the output — the avalanche effect that makes hashes good for passwords. · 해시는 일방향입니다: 계산하기 쉬우나 역산하는 것은 사실상 불가능합니다. 입력의 미세한 변화가 출력의 크고 예측 불가능한 부분을 완전히 바꿉니다 — 이것이 해시가 비밀번호에 적합한 이유인 폭풍 효과입니다.
Explore · 탐색하기
The Caesar cipher · Caesar 암호
Shift each letter to encrypt the message. A simple cipher shows the idea of a key — and why a small key is easy to break. · 각 문자를 이동시켜 메시지를 암호화합니다. 간단한 암호는 키의 개념을 보여주며, 왜 작은 키는 쉽게 깨질 수 있는지 설명합니다.
TLS 传输层安全 (Transport Layer Security, the successor to the Secure Socket Layer, SSL) is a protocol that gives encryption and authentication for data sent over a network. It encrypts the data in transit, authenticates the server with a certificate, and provides integrity (detecting tampering).
Outline of a TLS handshake:
the client connects and proposes cipher options.
the server picks one and sends its digital certificate (with its public key) — issuing and validating these certificates is digital certification.
the client checks the certificate.
the two ends exchange a fresh session key using asymmetric crypto.
all later traffic uses fast symmetric encryption with the session key.
The result is an encrypted, authenticated, integrity-checked tunnel for higher-level protocols (HTTP, SMTP). It is appropriate wherever sensitive information is sent: HTTPS web browsing, online banking and payments, secure email, and VPNs.
"Describe the purpose of SSL/TLS" and "state two functions." The purpose is to provide secure communication between a client and a server over a network. Its functions: it encrypts the data sent, so that it cannot be read if intercepted; it authenticates 认证 the server (and optionally the client) by means of a digital certificate, so the client knows it is talking to the genuine site; and it checks the integrity of the data, so that changes in transit are detected. Two examples of where it is appropriate: online banking and online shopping (card payments); also logins, private email, file transfer, VoIP and instant messaging: any transaction in which private data crosses the internet.
The two protocols that make up TLS. The handshake 握手 protocol sets up the session: it agrees the encryption algorithms (cipher suite), authenticates the server with its certificate, and exchanges the session key. The record protocol then carries the data: it encrypts each message with the session key, adds an integrity check, and passes it to the transport layer.
"Explain how SSL/TLS is used when client–server communication is initiated" (six marks). (1) The client (browser) sends a request to the server for a secure connection, saying which encryption methods it supports. (2) The server sends back its digital certificate, which contains its public key. (3) The client checks the certificate is valid (issued by a trusted Certificate Authority, not expired, for the right domain). (4) The client generates a session key, encrypts it with the server's public key and sends it. (5) The server decrypts the session key with its private key. (6) Both sides now hold the session key and all further data is sent using symmetric encryption with it. Give the steps in this order; the marks are for the certificate, the public key, the session key and the switch to symmetric encryption.
한국어
TLS(Transport Layer Security, Secure Socket Layer, SSL의 후속)은 네트워크를 통해 전송되는 데이터에 대해 암호화와 인증을 제공하는 프로토콜입니다.它是传输中的数据加密,使用证书验证服务器身份,并提供完整性(检测篡改)。
TLS 핸드쉐이크의 개요:
클라이언트가 연결하고 암호화 옵션을 제안합니다.
서버가 하나를 선택하여 디지털 인증서(공인-public key 포함)를发送 — 이러한 인증서의 발급 및 검증은 **디지털 인증(digital certification)**에 해당합니다.
클라이언트가 인증서를 확인합니다.
양측이 비대칭 암호를 사용하여 새로운 세션 키를 교환합니다.
이후 모든 트래픽은 세션 키를 사용한 빠른 대칭 암호로 처리됩니다.
이 결과는 HTTP, SMTP와 같은 고위 프로토콜을 위한 암호화, 인증, 무결성 검증이 적용된 터널을 만듭니다. **민감한 정보(sensitive information)**가 전송되는 곳이라면 어디든 적합합니다: HTTPS 웹 브라우징, 온라인 뱅킹 및 결제, 안전한 이메일, VPN 등.
“SSL/TLS의 목적”과 “두 가지 기능”을 설명하십시오. 목적은 네트워크 상에서 클라이언트와 서버 간 **안전한 통신(secure communication)**을 제공하는 것입니다. 기능: 전송되는 데이터를 암호화하여 도청당해 읽히지 않게 합니다; 디지털 인증서를 통해 서버(및 선택적 경우 클라이언트)를 인증하여, 클라이언트가 정품 사이트와 대화하고 있음을 알 수 있게 합니다; 데이터의 무결성을 검사하여 전송 중 변경 사항을 탐지합니다. 적용 가능한 두 가지 예: 온라인 킹 및 온라인 쇼핑(카드 결제); 또한 로그인, 개인 이메일, 파일 전송, VoIP 및 인스턴트 메시징: 사적 데이터가 인터넷을 가로질러 이동하는 모든 거래에 적합합니다.
TLS를 구성하는 두 가지 프로토콜.핸드쉐이크(handshake) 프로토콜은 세션을 설정합니다: 암호화 알고리즘(암호화 스위트, cipher suite)을 합의하고, 서버의 인증서로 인증하며, 세션 키를交換합니다. 레코드(record) 프로토콜은 이후 데이터를 전달합니다: 각 메시지를 세션 키로 암호화하고 무결성 검사를 추가한 뒤, 전송 계층으로 넘겨줍니다.
안전한 세션 시작 방법: 인증서가 서버임을 증명하고, 서버의 공인-key가 전송 중인 세션 키를 보호하며, 이후 모든 것을 세션 키가 보호합니다
“클라이언트-서버 통신이 시작될 때 SSL/TLS가 어떻게 사용되는지” 설명하시오 (6점). (1) 클라이언트(브라우저)가支持的哪些加密方法来说明它支持哪些加密方法。 (2) 서버는 공인-public key가 포함된 디지털 인증서를 회신합니다. (3) 클라이언트는 인증서가 유효한지 확인합니다(신뢰받는 인증 기관(Certificate Authority)에서 발급되었는지, 만료되지 않았는지, 올바른 도메인인지). (4) 클라이언트는 세션 키를 생성하고, 서버의 공인-key로 암호화하여 전송합니다. (5) 서버는 자신의 **비밀-key(private key)**로 세션 키를 복호화합니다. (6) 양측은 이제 세션 키를 보유하고 있으며, 모든 추가 데이터는 이를 사용한 **대칭 암호(symmetric encryption)**로 전송됩니다. 이 순서대로 단계를 제시하십시오; 점수는 인증서, 공인-key, 세션 키, 그리고 대칭 암호로의 전환에 부여됩니다.
Explore · 탐색하기
The TLS handshake · TLS 핸드셰이크
Step through what happens before a padlock appears. The slow public-key crypto is used only to agree a shared key; the actual page then travels under fast symmetric encryption. · 자물쇠 아이콘이 나타나기 전에 일어나는 과정을 설명하십시오. 느린 PUBLIC-KEY crypto는 공유 키에 대한 합의에만 사용되며, 실제 페이지 데이터는 빠른 대칭 암호 하에 전송됩니다.
A digital certificate 数字证书 binds an identity (a domain, an organisation) to a public key, and is signed by a trusted Certificate Authority 证书颁发机构 (CA). It contains the subject (who it identifies), the subject's public key, the issuer (the CA), a validity period, and the CA's signature over all of it.
To verify one, the client (which holds a list of trusted root CAs):
checks the expiry dates.
checks the subject name matches the URL.
checks it is signed by a trusted CA, using the CA's public key to verify the signature.
follows the certificate chain up to a trusted root.
If anything fails, the browser shows the "Your connection is not private" warning. When it verifies cleanly, the client knows the identity was vetted by a trusted CA, the public key really belongs to that identity, and the certificate is current.
"Describe what is meant by a digital certificate" (two marks).An electronic document, issued by a Certificate Authority, that verifies the identity of its owner (a person, organisation or website) and contains the owner's public key.Items found in one: the serial number; the name of the owner (subject) and, for a website, its domain; the owner's public key; the name of the issuing CA; the validity period (dates); the signature algorithm used; and the CA's digital signature of the whole certificate.
"Explain how an organisation acquires a digital certificate" (four marks). (1) The organisation generates its own key pair, a public key and a private key. (2) It sends a request containing its public key and its identity details to a Certificate Authority. (3) The CA verifies the identity (checks that the applicant really is the organisation or owns the domain). (4) The CA creates the certificate containing the public key and the identity, signs it with the CA's own private key, and returns it. (5) The organisation installs the certificate on its server so that it can be sent to clients. The private key never leaves the organisation.
"Explain why a digital certificate is required to validate a digital signature." To check a signature the receiver needs the sender's public key, and needs to be sure that the key really belongs to the claimed sender; the certificate supplies the public key together with the identity, and because the certificate is signed by a trusted CA the receiver can trust that binding. Without it an impostor could publish a public key in someone else's name and sign messages as them. The same reasoning answers "what should be included with a program downloaded from the internet to prove it is genuine": a digital signature, checked against the publisher's certificate.
한국어
디지털 인증서는 신원(도메인, 조직 등)을 공인-key에 묶으며, 신뢰받는 **인증 기관(Certificate Authority, CA)**에 의해 서명됩니다. 대상(신원을 식별하는 주체), 대상의 공인-key, 발급자(CA), 유효 기간, 그리고 모든 내용에 대한 CA의 서명이 포함되어 있습니다
인증 기관(CA)은 신원과 공개 키를 연결하는 디지털 인증서를 발급함
이 인증서를 검증하려면 클라이언트(신뢰할 수 있는 루트 CA 목록을 보유):
만료 날짜를 확인합니다.
주체 이름이 URL과 일치하는지 확인합니다.
신뢰할 수 있는 CA에 의해 서명되었는지 확인하며, CA의 공개 키를 사용하여 서명을 검증합니다.
신뢰할 수 있는 루트까지 인증서 체인을 따라 올라갑니다.
무엇인가 결여되면 브라우저는 "당신의 연결은 비공개가 아닙니다" 경고 표시합니다. 검증이 완벽하게 완료되면 클라이언트는 신원이 신뢰할 수 있는 CA에 의해 검토되었음을, 공개 키가 해당 신원에 정말 속함을, 그리고 인증서가 유효함을 알 수 있습니다.
"디지털 인증서의 의미를 설명하시오" (2점).인증 기관(CA)에서 발급한 전자 문서로, 소유자(개인, 조직 또는 웹사이트)의 신원을 검증하며 소유자의 공개 키를 포함합니다.발견되는 항목:일련 번호; 소유자 이름(주체) 및 웹사이트의 경우 도메인; 소유자의 공개 키; 발급 CA의 이름; 유효 기간(날짜); 사용된 서명 알고리즘; 그리고 전체 인증서에 대한 CA의 디지털 서명.
"조직이 디지털 인증서를 획득하는 방법을 설명하시오" (4점). (1) 조직은 자체적인 키 쌍, 즉 공개 키와 개인 키를 생성합니다. (2) 공개 키와 신원 정보가 포함된 요청을 인증 기관(CA)에 전송합니다. (3) CA는 신원을 검증합니다(신청인이真有 조직이거나 도메인을 소유했는지 확인). (4) CA는 공개 키와 신원을 포함한 인증서를 생성하여 CA 자신의 개인 키로 서명하고 반환합니다. (5)組織는 서버에 인증서를 설치하여 클라이언트에 전달할 수 있게 합니다. 개인 키는 조직 밖으로 절대 나가지 않습니다.
"왜 디지털 서명의 효성을 검증하기 위해 디지털 인증서가 필요한지 설명하시오." 서명을 확인하려면 수신자는 sender의 공개 키가 필요하며, 이 키가 진정 ** claimed sender에게 속함**을 확신해야 합니다; 인증서는 공개 키와 함께 신원을 제공하며, 인증서가 신뢰할 수 있는 CA에 의해 서명되었기 때문에 수신자는 이 연결을 신뢰할 수 있습니다. 이것이 없으면 위장자가 다른 사람의 이름으로 공개 키를 게시하고 그 사람처럼 메시지를 서명할 수 있습니다. 동일한 논리는 "인터넷에서 다운로드한 프로그램에 정품임을 증명하기 위해 무엇 포함되어야 하는가"라는 질문에 대한 답변입니다: 디지털 서명, 발행자의 인증서와 대조하여 검증됨.
A digital signature 数字签名 proves who signed a message and that it was not changed. To sign:
compute a cryptographic hash of the message.
encrypt the hash with the sender's private key — that is the signature.
send the message and the signature.
To verify: compute the hash of the received message; decrypt the signature with the sender's public key to get the sender's hash; compare. If they match, the message was signed by the holder of the private key (authentication 身份验证) and was not changed (integrity). A signature does not hide the message — for confidentiality as well, encrypt and sign.
"Explain the role of a digital certificate in creating a digital signature" (three marks). The sender's certificate was issued by a CA and contains the sender's public key together with the sender's identity; the sender produces the signature by hashing the message and encrypting the hash with their private key, the partner of the key in the certificate; the receiver uses the public key from the certificate to decrypt the hash and, because the certificate binds that key to the sender, the signature proves who signed.
"Explain how a digital signature is used to verify a message" (four marks). (1) The receiver decrypts the signature with the sender's public key (taken from the sender's certificate), which yields the hash that the sender computed. (2) The receiver hashes the received message with the same hash algorithm. (3) The two hashes are compared. (4) If they match, the message came from the holder of the private key (authentic) and has not been altered since it was signed (integrity); if they differ, the message is rejected. A banker receiving confidential data with a signature does exactly this before trusting it; the data itself may separately be encrypted with the banker's public key for confidentiality.
Putting it together
A secure request to https://www.bank.com: the server sends its certificate; the client verifies it against trusted CAs; the client uses the server's public key to exchange a session key; then data flows encrypted with that key. Encryption stops eavesdroppers, the certificate proves the server's identity, and integrity checks stop a man-in-the-middle 中间人攻击 altering the data.
Worked example. Alice sends Bob a contract. She wants Bob to be certain it came from her and was not altered, and she wants nobody else to be able to read it. Which keys does she use, and in which direction? These are two different jobs needing two different key pairs. For the signature (authentication and integrity): Alice hashes the contract and encrypts that hash with her own private key; Bob decrypts it with Alice's public key and compares it against his own hash of the message. Only Alice holds her private key, so only she could have produced it. For confidentiality: Alice encrypts the contract itself with Bob's public key, so only Bob's private key can open it. One rule keeps all four straight: you sign with your own private key and encrypt with the recipient's public key. A signature on its own does not hide the message.
한국어
디지털 서명은 메시지를 누가 서명했는지 그리고それが 변경되지 않았음을 증명합니다. 서명하기 위해:
메시지의 암호화 해시를 계산합니다.
해시 값을 sender의 개인 키로 암호화 — 이것이 서명입니다.
메시지 및 서명을 전송합니다.
검증하기 위해: 수신된 메시지의 해시를 계산합니다; sender의 공개 키로 서명을 복호화하여 sender의 해시를 얻습니다; 비교합니다. 일치하면, 메시지는 개인 키 소지자에 의해 서명되었음(인증) 및 변경되지 않았음(무결성)을 의미합니다. 서명은 메시지를 숨기지 않습니다 — 기밀성을 위해 암호화하고 서명해야 합니다.
서명은 메시지를 해싱하고 디지스트를 개인 키로 암호화하며, receiver는 공개 키로 이를 확인함
"디지털 서명 생성 시 디지털 인증서의 역할을 설명하시오" (3점). sender의 인증서는 CA에서 발급되었으며 sender의 공개 키와 sender의 신원을 포함합니다; sender는 메시지를 해싱하고 인증서의 키와 쌍을 이루는 개인 키로 해시를 암호화하여 서명을 생성합니다; receiver는 인증서에서 가져온 공개 키를 사용하여 해시를 복호화하며, 인증서가 해당 키를 sender에 연결하므로 서명은 누가 서명했는지 증명합니다.
"디지털 서명이 메시지를 검증하는 데 어떻게 사용되는지 설명하시오" (4점). (1) receiver는 sender의 공개 키(sender의 인증서에서 가져옴)로 서명을 복호화하여 sender가 계산한 해시를 얻습니다. (2) receiver는 같은 해시 알고리즘으로 수신된 메시지를 해싱합니다. (3) 두 해시는 비교됩니다. (4) 만약 일치하면, 메시지는 개인 키 소지자에게서 왔음(진정) 및 서명 이후 변경되지 않음(무결성)을 의미하며; 서로 다르면 메시지는 거절됩니다. 은행가는 기밀 데이터를 서명과 함께 받을 때 신뢰하기 전에 정확히 이 과정을 거칩니다; 데이터 자체는 별도로 은행가의 공개 키로 기밀성을 위해 암호화될 수 있습니다.
종합하기
https://www.bank.com에 대한 안전한 요청: 서버는 인증서를 전송합니다; 클라이언트는 신뢰할 수 있는 CA와 대조하여 이를 검증합니다; 클라이언트는 서버의 공개 키를 사용하여 세션 키를 교환합니다; 그런 다음 데이터는 해당 키로 암호화되어 전송됩니다. 암호화는 도청자를 차단하고, 인증서는 서버의 신원을 입증하며, 무결성 검사는 중간자 공격자가 데이터를 변경하는 것을 방지합니다.
풀이 예제. 앨리스가 보브에게 계약서를 보냅니다. 앨리스는 보브가 계약서가 herself에서 왔고 변조되지 않았음을 확신하기를 원하며, 또한 다른 누구도 읽지 못하게 하고 싶습니다. 그녀는 어떤 키를 사용하며, 어떤 방향으로? 이는 서로 다른 두 가지 작업으로, 각각 다른 키 쌍이 필요합니다. 서명(인증 및 무결성): 앨리스는 계약서를 해시하고 그 해시 값을 她自己의 비공개 키로 암호화합니다; 보브는 앨리스의 공개 키로 복호화하여 자신의 메시지 해시와 비교합니다. 비공개 키는 앨리스만이 보유하므로, 그녀만 생성할 수 있었습니다. 비밀유지: 앨리스는 계약서 자체를 보브의 공개 키로 암호화하므로, 오직 보브의 비공개 키만이 열 수 있습니다. 모든 것을 명확히 구분하는 한 가지 규칙: 본인의 비공개 키로 서명하고 수신자의 공개 키로 암호화하십시오. 서명만으로는 메시지를 숨길 수 없습니다.
Symmetric: one shared secret key, fast, key exchange is the weakness. Asymmetric: public key to encrypt, private key to decrypt, slow, no exchange problem. Two differences, two drawbacks, two reasons: the exam asks for them in pairs.
Confidentiality uses the receiver's keys (public to lock, private to unlock); a signature uses the sender's keys (private to sign, public to check). Say whose key every time.
The TLS start-up is six steps: request, certificate with public key, check, session key encrypted with the public key, decrypted with the private key, symmetric encryption from then on.
A certificate is identity plus public key, signed by a CA; acquisition is key pair, request, verification, signing, installation. It is needed to validate a signature because it proves whose public key it is.
A signature is a hash encrypted with the private key; verification is decrypt, re-hash, compare. Integrity and authenticity are the two things it proves.
Quantum cryptography distributes keys and detects eavesdropping; its limits are cost, distance and novelty.
Common mistakes
Saying a message is encrypted with the sender's public key; the receiver's public key encrypts, the receiver's private key decrypts.
Describing a signature as "encrypting the message with the private key" instead of encrypting its hash.
Claiming a certificate contains the private key; it holds the public key and the identity, signed by the CA.
Listing "the server sends its private key" in the TLS handshake; only the public key travels, inside the certificate.
Giving "SSL/TLS makes the connection faster" as a function; its functions are encryption, authentication and integrity.
Confusing hashing with encryption: a hash cannot be reversed and has no key; encryption is reversible with the key.
Answering "why is a certificate needed for a signature" with "to encrypt it"; it is needed to trust the public key.
한국어
대칭: 하나의 공유된 비밀 키, 빠름, 키 교환이 약점임. 비대칭: 공개키로 암호화, 비공개키로 복호화, 느림, 교환 문제 없음. 두 가지 차이점, 두 가지 단점, 두 가지 이유: 시험에서는 이를 쌍为单位로 묻습니다.
비밀보장은 수신자의 키를 사용함 (공개키로 잠금, 비공개키로 열기); 서명은 송신자의 키를 사용함 (비공개키로 서명, 공개키로 검증). 매번谁的의 키인지 명시하십시오.
TLS 초기화(start-up)는 여섯 단계입니다: 요청, 공개키가 포함된 인증서, 검증, 공개키로 암호화된 세션 키, 비공개키로 복호화, 이후부터는 대칭 암호화 사용.
인증서는 신원 plus 공개키이며, CA에 의해 서명됨; 발급 과정은 키 쌍 생성, 요청, 검증, 서명, 설치가 포함됩니다. 서명을 검증하기 위해 필요하며, 해당 공개키가谁的것임을 증명하기 때문입니다.
서명은 비공개키로 암호화된 해시값; 검증은 복호화, 재해시, 비교를 의미합니다. 무결성과 autentication(정체성)이 이것이 입증하는 두 가지 사항입니다.
양자 암호학은 키를 분배하고 도청을 감지하며, 그 한계는 비용, 거리 및 신규성입니다.
흔한 실수
메시지를 송신자의 공개키로 암호화했다고 말하는 것은 틀림; 수신자의 공개키로 암호화하고, 수신자의 비공개키로 복호화해야 합니다.