12.5 Cryptography Fundamentals
211
concatenated to produce a 256-bit long hash value. The prominent use of of SHA256 in several cryptocurrencies has stimulated the development of special hardware,
based on field-programmable gate arrays (FPGA) and application specific integrated
circuits (ASIC). These devices calculate hashes at a rate of billions per second, and
are often used in parallel, which poses a threat against pre-image attacks that seek to
find an input to the hash function, which evaluates to a desired hash value and would
thus allow to tamper with the fingerprint.
In order to overcome this weakness against brute-force pre-image attacks, modern cryptocurrencies, such as Ethereum, use hashing algorithms that require large
amounts of memory for the calculation and therefore call for expensive hardware,
which precludes the high degree of parallelization that poses a threat to SHA-256.
The scrambling in ethash [15] hashes is based on first building a very large data
structure of pseudo-random numbers and then picking numbers from this structure
in a quasi-random fashion, which makes it impossible to keep only a small part of
the structure in memory. The calculation of the scrypt hash works similarly. The
high cost, both in hardware and computationally, accounts for the popularity of these
hashes in modern cryptocurrencies.
Occasionally, we need fingerprints of a large number of digital items, say n = 100
files. We can then either send n hashes to verify each file individually, or we can
assemble the hashes into a Merkle tree. It is based on first calculating the individual
hashes and then subsequently hash the bit-concatenation of two hashes to obtain
n/2 hashes. We then repeat the process until only one hash remains, which is called
the Merkle root. Note that unpaired hashes are hashed with themselves. In this way
we obtain a single hash value, the Merkle root, that is used to verify the integrity of
the entire group of n files, or any other digital item. We will encounter Merkle trees
again, because they are used to fingerprint large numbers of financial transactions
that are entered into a crytocurrency database in order to ensure their integrity.
By now, we have collected a number of cryptographic tools that allow us to encrypt
and fingerprint digital assets, but we still face the key-distribution problem, which
had to wait for a solution until the mid-1970s.
12.6 Early Public-Key Systems
In DES, AES, and many other encryption methods the key used to encrypt and to
decrypt is the same, which is thus called a symmetric key. Having only symmetric key systems available implies that the keys must be exchanged by some other
means. Prior to the mid-seventies, courier services shuttled attache cases with sheets
of paper containing the keys between the communicating partners, for example, the
state department and the embassies in foreign countries. This was expensive and
only possible when highly secret information needed to be exchanged, especially
during the cold war. In 1976, however, Diffie and Hellman published their landmark
report [13], in which they proposed to use asymmetric keys. Alice and Bob, the
parties of a two-way communication, each have their private secrets; Alice knows
Précédent

- 219/292

Suivant