AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/5/5-3)
Unit 5 · Topic 5.3
5.3 Protecting Stored Data with Cryptography
Encryption scrambles data so that only someone with the right key can read it, which protects stored files even if a drive is stolen. This topic covers the core vocabulary of cryptography, how keyspace relates to security, symmetric versus asymmetric and block versus stream ciphers, and how to encrypt a file with AES.
Key terms
- plaintext and ciphertext
- keyspace
- symmetric encryption
- block vs. stream cipher
- AES
- OpenSSL
Core vocabulary
Cryptography is about hiding information. A cryptographic algorithm defines how to encrypt (hide) information and how to decrypt it (reverse the process to get the original back). The information you start with is the plaintext; the scrambled output is the ciphertext. The algorithm combines the plaintext with a key, a secret value, and without the right key the ciphertext is useless.
The keyspace is the number of possible keys. The bigger the keyspace, the longer an adversary needs to find the right key by guessing. A 4-digit PIN has a keyspace of 10⁴ = 10,000, so a determined guesser gets through it fast. A 128-bit key has 2¹²⁸ ≈ 3.40 × 10³⁸ possibilities.
Ways to classify algorithms
Symmetric encryption is fast, which makes it ideal for files and disks. Its challenge is that everyone who needs to decrypt must already share the secret key. Asymmetric encryption (Topic 5.4) solves that sharing problem.
| Classification | Option | How it works |
|---|---|---|
| Number of keys | Symmetric | The same key encrypts and decrypts |
| Number of keys | Asymmetric | Two different keys: one encrypts, the other decrypts |
| How data is processed | Block | Works on fixed-size chunks (blocks), one output block per input block |
| How data is processed | Stream | Works on a continuous flow, one element at a time |
AES, the workhorse
Computer encryption works on binary data. The most common symmetric algorithm is the Advanced Encryption Standard (AES). It protects Wi-Fi traffic, web browsing, encrypted disks and even encryption built into processors.
AES is a symmetric block cipher: it encrypts data in 128-bit (16-byte) blocks. It can use keys of different lengths: 128, 192 or 256 bits. Longer keys are more secure but take more time to encrypt and decrypt.
Encrypting a file
You can run symmetric encryption from a command line, with specialized software like AES Crypt (a free, open-source tool) or with web-based tools. On the command line, OpenSSL does the job. To encrypt a file named notes.txt with 128-bit AES:
openssl enc -aes-128-cbc -e -in notes.txt -k mypassphrase -out notes.enc
Read it piece by piece: enc means encrypt or decrypt with a cipher; -aes-128-cbc picks AES with a 128-bit key (cbc is the mode, how blocks are chained together); -e means encrypt; -in and -out name the input and output files; -k gives the password the key is derived from. To decrypt, use the same command with -d instead of -e, the encrypted file as input and the same password:
openssl enc -aes-128-cbc -d -in notes.enc -k mypassphrase -out notes.txt
Current versions of OpenSSL print a warning with these exact commands and suggest adding -pbkdf2, which turns the password into a key in a much slower, harder-to-guess way. The commands still work, and the course uses this form.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Reading an OpenSSL command
A student runs openssl enc -aes-256-cbc -e -in plans.docx -k bluefinch42 -out plans.enc and emails plans.enc to a teammate. (a) What algorithm and key length were used? (b) What exact command should the teammate run to get plans.docx back? (c) What must the teammate already know?
Show the solutionHide the solution
- Step 1: (a) -aes-256-cbc means AES with a 256-bit key, in CBC mode.
- Step 2: (b) Decryption uses the same cipher and password, with -d and the files swapped: openssl enc -aes-256-cbc -d -in plans.enc -k bluefinch42 -out plans.docx.
- Step 3: (c) AES is symmetric, so the teammate needs the same password (bluefinch42) the key was made from. It should be shared some other way than the email that carried the file, or anyone who sees the email gets both.
Answer: (a) AES with a 256-bit key. (b)
openssl enc -aes-256-cbc -d -in plans.enc -k bluefinch42 -out plans.docx. (c) The same password, shared through a separate, secure channel. - Example 2
Comparing keyspaces
Compare the keyspaces of a 4-digit PIN, an AES 128-bit key and an AES 256-bit key.
Show the solutionHide the solution
- Step 1: PIN: 10 choices per digit, 4 digits: 10⁴ = 10,000.
- Step 2: AES-128: 2 choices per bit, 128 bits: 2¹²⁸ ≈ 3.40 × 10³⁸.
- Step 3: AES-256: 2²⁵⁶ ≈ 1.16 × 10⁷⁷.
- Step 4: Each added bit doubles the keyspace, so going from 128 to 256 bits multiplies it by 2¹²⁸, not by 2.
Answer: PIN: 10,000. AES-128: about 3.40 × 10³⁸. AES-256: about 1.16 × 10⁷⁷, which is 2¹²⁸ times the AES-128 keyspace.
Common mistakes
- Saying AES-256 is twice as strong as AES-128. Each extra bit doubles the keyspace, so 128 more bits multiplies it by 2¹²⁸.
- Mixing up block size and key size. AES always uses 128-bit blocks; the key can be 128, 192 or 256 bits.
- Forgetting that symmetric encryption needs a shared key. Whoever decrypts needs the same key or password.
- Confusing encryption with hashing. Encryption is meant to be reversed with the key; a hash is one-way.
On the exam
- You may need to read or complete an OpenSSL command, so know what -e, -d, -in, -out and -k do and how the cipher name shows the key length.
- For "why is this more secure" questions, tie key length to keyspace: more bits, more possible keys, longer to guess.
Connected topics
Videos
Check yourself: 5.3 Protecting Stored Data with Cryptography
4 questions on 5.3 Protecting Stored Data with Cryptography. Pick an answer to see if you got it, and why.
In encryption, what is the ciphertext?
Why does a larger keyspace make encrypted data more secure?
Which statement correctly compares symmetric and asymmetric encryption?
A cipher takes input in fixed-size chunks of 128 bits and produces one output chunk for each input chunk. What kind of cipher is this?
0 of 4 answered