210
12 Cryptocurrencies
key, and finally encrypts again with the third key. In order to decode cipher text, we
have to undo this sequence in the reverse order. We first decrypt with the third key,
encrypt with the second, and decrypt with the first key.
The presently up-to-date encryption standard is the Advanced Encryption Standard (AES), which was announced 2001. It uses symmetric keys and operates on
128-bit long blocks of data. Encryption keys with a length between 128 and 512
bits are supported. The 128 bits of each block are assembled in a 4 × 4 array of
bytes, which is subsequently scrambled in ten to fourteen rounds with sub-keys that
are derived from the primary key. In order to reduce the load on the processors, in
particular those used in desktop computers, the processors support AES in hardware,
which allows to efficiently encrypt data, either locally on the harddisk, or in transit
when viewing websites with https.
Sometimes we do not really want to hide the communication from others, but
only want to ensure that the integrity of a message is not compromised, either unintentionally due to transmission errors, or intentionally by a third party falsifying the
messages. For this purpose we use a special fingerprint of a message, called a hash
or a message digest. One of the simplest hashes of a message m = (b 1 , b 2 , b 3 ) consisting of, for example, three bytes b 3 , b 2 , and b 1 is the checksum c where all bytes
are successively xor’ed, such as c = xor(b 3 , xor(b 2 , b 1 )). This checksum c can be
calculated before and after a transmission in order to ensure that the integrity of the
message remains intact. Using a one-byte long fingerprint only permits to distinguish
between 256 different cases and collisions—finding the same c for different messages m 1 and m 2 —are likely. Moreover, testing only 256 different messages suffices
to find one that produces a given checksum c. In a cryptographic context, where we
use the hash value to guarantee the integrity of the message, this is called a pre-image
attack. And finally, the calculation of the hash must be deterministic in the sense that
calculating it on different computer systems yields equal hashes. Thus, we need to
find deterministic functions that calculate long hashes and ensure that even rather
similar messages produce vastly different hash values c, such that moving a decimal
point in a financial transaction changes c drastically.
The MD5 message digest function, first introduced in 1992, calculates a 128-bit
long hash value from an input message that can have any length. The message can be a
text string, a binary quantity, or the contents of an arbitrary file. For a discussion of the
inner workings of the MD5 hash and other hash functions we refer to the specialized
literature [12]. During the past decade, however, it was shown that collisions in the
sense discussed above can be constructed with moderate computing power, which
makes MD5 unsuitable for cryptographic applications. On the other hand, MD5 is
still used to verify that downloaded files were not corrupted in transit.
In 2001, the SHA-2 family of hashing algorithms was published. It supports
several lengths of the hashes, including the 256-bit version SHA-256, which is used
by the Bitcoin cryptocurrency. The algorithm is based on breaking the message into
512-bit chunks and then subdiving each chunk further into sixteen 32-bit blocks
that are thoroughly scrambled by bit-shifting and xor’ing to obtain a total of 64
blocks, each 32 bits long. These 64 blocks undergo a second round of scrambling,
which includes xor’ing with pre-determined pseudo-random numbers and are finally
12 Cryptocurrencies
key, and finally encrypts again with the third key. In order to decode cipher text, we
have to undo this sequence in the reverse order. We first decrypt with the third key,
encrypt with the second, and decrypt with the first key.
The presently up-to-date encryption standard is the Advanced Encryption Standard (AES), which was announced 2001. It uses symmetric keys and operates on
128-bit long blocks of data. Encryption keys with a length between 128 and 512
bits are supported. The 128 bits of each block are assembled in a 4 × 4 array of
bytes, which is subsequently scrambled in ten to fourteen rounds with sub-keys that
are derived from the primary key. In order to reduce the load on the processors, in
particular those used in desktop computers, the processors support AES in hardware,
which allows to efficiently encrypt data, either locally on the harddisk, or in transit
when viewing websites with https.
Sometimes we do not really want to hide the communication from others, but
only want to ensure that the integrity of a message is not compromised, either unintentionally due to transmission errors, or intentionally by a third party falsifying the
messages. For this purpose we use a special fingerprint of a message, called a hash
or a message digest. One of the simplest hashes of a message m = (b 1 , b 2 , b 3 ) consisting of, for example, three bytes b 3 , b 2 , and b 1 is the checksum c where all bytes
are successively xor’ed, such as c = xor(b 3 , xor(b 2 , b 1 )). This checksum c can be
calculated before and after a transmission in order to ensure that the integrity of the
message remains intact. Using a one-byte long fingerprint only permits to distinguish
between 256 different cases and collisions—finding the same c for different messages m 1 and m 2 —are likely. Moreover, testing only 256 different messages suffices
to find one that produces a given checksum c. In a cryptographic context, where we
use the hash value to guarantee the integrity of the message, this is called a pre-image
attack. And finally, the calculation of the hash must be deterministic in the sense that
calculating it on different computer systems yields equal hashes. Thus, we need to
find deterministic functions that calculate long hashes and ensure that even rather
similar messages produce vastly different hash values c, such that moving a decimal
point in a financial transaction changes c drastically.
The MD5 message digest function, first introduced in 1992, calculates a 128-bit
long hash value from an input message that can have any length. The message can be a
text string, a binary quantity, or the contents of an arbitrary file. For a discussion of the
inner workings of the MD5 hash and other hash functions we refer to the specialized
literature [12]. During the past decade, however, it was shown that collisions in the
sense discussed above can be constructed with moderate computing power, which
makes MD5 unsuitable for cryptographic applications. On the other hand, MD5 is
still used to verify that downloaded files were not corrupted in transit.
In 2001, the SHA-2 family of hashing algorithms was published. It supports
several lengths of the hashes, including the 256-bit version SHA-256, which is used
by the Bitcoin cryptocurrency. The algorithm is based on breaking the message into
512-bit chunks and then subdiving each chunk further into sixteen 32-bit blocks
that are thoroughly scrambled by bit-shifting and xor’ing to obtain a total of 64
blocks, each 32 bits long. These 64 blocks undergo a second round of scrambling,
which includes xor’ing with pre-determined pseudo-random numbers and are finally
