2. Consider the following certificate mechanism. X.509 Certificate Structures Version Serial Number Algorithm identifier: Algorithm Parameters Issuer Period of Validity: Not before date Not after date Subject Subject's public key: Algorithm Parameters Public Key Signature Determines the format Given by CA Refers to signature algorithm Name of the CA Lifetime information Name of the user Refers to key's algorithm By the CA 69 a) The CA generates the signature but the message to be signed excludes the lifetime information. Describe how the security could be compromised in the real world. (3 marks) b) The CA generates the signature but the message to be signed excludes "Refer to Key's Algorithm". Describe how the security could be compromised in the real world. (3 marks)
Added by Gabriel S.
Close
Step 1
This could compromise security in the real world because an attacker could potentially use the signature beyond its intended validity period. For example, if a certificate is issued with a validity period of one year, but the signature does not include this Show more…
Show all steps
Your feedback will help us improve your experience
Aparna Shakti and 93 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
5. What is the main difference(s) between SET and SSL? a. SSL is not secure against breaking of any one form of encryption. b. SET is a payment protocol. c. SET requires all parties to have certificates d. SSL is a secure message protocol, not a payment protocol. e. All a, b and c above f. Items b, c and d above 6. Which of the following is associated with NAT? a. Switches b. SNMP c. Routers and firewalls d. Hubs 7. The following types of certificates are used in a Public-Key Infrastructure(PKI): a. No particular type is specified b. S/MIME c. X.509 d. SSL and SET e. Items (b), (c), (d) f. Items (b) and (c) 8. IPSec uses to implement data confidentiality a. Proprietary protocols b. Tunneling c. EAPOL d. IKE 9. An X.509v3 certificate has the following properties: a. It is used in conjunction with PKI platform. b. It does not allow for inclusion of extra information. c. It can be used with most network security protocols such as IPSec, SET, and SSL. d. It is an IETF standard for the use in the Internet. e. Items (a) and (c) only f. All of the above 10. What is Diffie-Hellman most commonly used for? a. Symmetric encryption key exchange b. Signing digital contracts c. Securing e-mail d. Storing encrypted passwords
Sri K.
A secure email system is expected to provide confidentiality, sender's non-repudiation, and message integrity. Alice uses three keys to achieve this goal. The three keys are Alice's private key (KA-), Bob's public key (Kg*), and a randomly generated symmetric key (Ks). The encryption procedure is shown below: How can Bob 1) decrypt the data, 2) verify the message's integrity, and 3) verify the sender's non-repudiation? Describe the detailed steps (including the formulas) and show your work.
Akash M.
(a) A Vigenere cipher with encryption key DELTA has been used to produce the ciphertext ZLPKEDQT. What was the plaintext? The following table is provided for your convenience: (bi) Alice wants to digitally sign the message [4,5] with the help of RSA. She uses the public key (91,29) and a private key 5. Compute the signed message. (bii) With the same RSA digital signature as in part (bi), Bob received the signed message [10] from Alice. What was the initial message? (c) Alice and Bob want to create a shared secret number with the help of the Diffie-Hellman protocol. Bob receives the triple (127,6,17) from Alice. Then he chooses the private key 3 and sends Alice the number 89. Compute.
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Watch the video solution with this free unlock.
EMAIL
PASSWORD