← กลับบทอ่าน5.IT Security Defense against the digital dark arts
T0662 · ข้อความต้นทางภาษาอังกฤษ
ไฟล์ transcript ต้นทาง · subtitle (13).txt
หน้านี้แสดงข้อความจากไฟล์ต้นทางที่ผู้ใช้ให้ไว้เพื่อเทียบแนวคิด คำอธิบายภาษาไทยในหนังสือเป็นการเรียบเรียงใหม่ ไม่ได้แปลข้อความนี้ทั้งไฟล์
In this next lesson, we'll cover the second class of ciphers called asymmetric or public key ciphers. Remember why symmetric ciphers are referred to as symmetric? It's because the same key is used to encrypt as to decrypt. This is in contrast to asymmetric encryption systems because as the name implies, different keys are used to encrypt and decrypt. So how exactly does that work? Well, let's imagine here that there are two people who would like to communicate securely, we'll call them Suzanne and Darryl. Since they're using asymmetric encryption in this example, the first thing they each must do is generate a private key. Then, using this private key, a public key is derived. The strength of the asymmetric encryption system comes from the computational difficulty of figuring out the corresponding private key given a public key. Once Suzanne and Daryll have generated private and public key pairs, they exchange public keys. You might have guessed from the names that the public key is public and can be shared with anyone, while the private key must be kept secret. Once Suzanne and Daryll have exchanged public keys, they're ready to begin exchanging secure messages. When Suzanne wants to send Daryll an encrypted message, she uses Daryll's public key to encrypt the message and then send the cipher text. Darryl can then use his private key to decrypt the message and read it. Because of the relationship between private and public keys, only Daryll's private key can decrypt messages encrypted using Daryll's public key. The same is true of Suzanne's key pairs. So when Daryll is ready to reply to Suzanne's message, he'll use Suzanne's public key to encode his message, and Suzanne will use her private key to decrypt the message. Can you see why it's called asymmetric or public key cryptography? We just described encryption and decryption operations using an asymmetric crypto system. But there's one other very useful function the system can perform, public key signatures. Let's go back to our friends Suzanne and Darryl. Let's say Suzanne wants to send a message to Daryll and she wants to make sure that Daryll knows the message came from her and no one else, and that the message was not modified or tampered with. She could do this by composing the message and combining it with her private key to generate a digital signature. She then sends this message along with the associated digital signature to Daryll. We're assuming Suzanne and Daryll have already exchanged public keys previously in this scenario. Daryll can now verify the message's origin and authenticity by combining the message, the digital signature, and Suzanne's public key. If the message was actually signed using Suzanne's private key and not someone else's and the message wasn't modified at all, then a digital signature should validate. If the message was modified even by one whitespace character, the validation will fail and Daryll shouldn't trust the message. This is an important component of the asymmetric crypto system. Without message verification, anyone could use Daryll's public key and send him an encrypted message claiming to be from Suzanne. The three concepts that an asymmetric crypto system grants us are confidentiality, authenticity, and non-repudiation. Confidentiality is granted through the encryption-decryption mechanism, since our encrypted data is kept confidential and secret from unauthorized third parties. Authenticity is granted by the digital signature mechanism, as the message can be authenticated or verified that it wasn't tampered with. Non-repudiation means that the author of the message isn't able to dispute the origin of the message. In other words, this allows us to ensure that the message came from the person claiming to be the author.สารบัญบทอ่าน →