Skip to main content

Unit 5 · Topic 5.3

5.3 Protecting Stored Data with Cryptography

Encryption scrambles data so that only someone with the right key can read it, which protects stored files even if a drive is stolen. This topic covers the core vocabulary of cryptography, how keyspace relates to security, symmetric versus asymmetric and block versus stream ciphers, and how to encrypt a file with AES.

Key terms

  • plaintext and ciphertext
  • keyspace
  • symmetric encryption
  • block vs. stream cipher
  • AES
  • OpenSSL

Core vocabulary

Cryptography is about hiding information. A cryptographic algorithm defines how to encrypt (hide) information and how to decrypt it (reverse the process to get the original back). The information you start with is the plaintext; the scrambled output is the ciphertext. The algorithm combines the plaintext with a key, a secret value, and without the right key the ciphertext is useless.

The keyspace is the number of possible keys. The bigger the keyspace, the longer an adversary needs to find the right key by guessing. A 4-digit PIN has a keyspace of 10⁴ = 10,000, so a determined guesser gets through it fast. A 128-bit key has 2¹²⁸ ≈ 3.40 × 10³⁸ possibilities.

Ways to classify algorithms

Symmetric encryption is fast, which makes it ideal for files and disks. Its challenge is that everyone who needs to decrypt must already share the secret key. Asymmetric encryption (Topic 5.4) solves that sharing problem.

ClassificationOptionHow it works
Number of keysSymmetricThe same key encrypts and decrypts
Number of keysAsymmetricTwo different keys: one encrypts, the other decrypts
How data is processedBlockWorks on fixed-size chunks (blocks), one output block per input block
How data is processedStreamWorks on a continuous flow, one element at a time

AES, the workhorse

Computer encryption works on binary data. The most common symmetric algorithm is the Advanced Encryption Standard (AES). It protects Wi-Fi traffic, web browsing, encrypted disks and even encryption built into processors.

AES is a symmetric block cipher: it encrypts data in 128-bit (16-byte) blocks. It can use keys of different lengths: 128, 192 or 256 bits. Longer keys are more secure but take more time to encrypt and decrypt.

Encrypting a file

You can run symmetric encryption from a command line, with specialized software like AES Crypt (a free, open-source tool) or with web-based tools. On the command line, OpenSSL does the job. To encrypt a file named notes.txt with 128-bit AES:

openssl enc -aes-128-cbc -e -in notes.txt -k mypassphrase -out notes.enc

Read it piece by piece: enc means encrypt or decrypt with a cipher; -aes-128-cbc picks AES with a 128-bit key (cbc is the mode, how blocks are chained together); -e means encrypt; -in and -out name the input and output files; -k gives the password the key is derived from. To decrypt, use the same command with -d instead of -e, the encrypted file as input and the same password:

openssl enc -aes-128-cbc -d -in notes.enc -k mypassphrase -out notes.txt

Current versions of OpenSSL print a warning with these exact commands and suggest adding -pbkdf2, which turns the password into a key in a much slower, harder-to-guess way. The commands still work, and the course uses this form.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Reading an OpenSSL command

    A student runs openssl enc -aes-256-cbc -e -in plans.docx -k bluefinch42 -out plans.enc and emails plans.enc to a teammate. (a) What algorithm and key length were used? (b) What exact command should the teammate run to get plans.docx back? (c) What must the teammate already know?

    Show the solution
    1. Step 1: (a) -aes-256-cbc means AES with a 256-bit key, in CBC mode.
    2. Step 2: (b) Decryption uses the same cipher and password, with -d and the files swapped: openssl enc -aes-256-cbc -d -in plans.enc -k bluefinch42 -out plans.docx.
    3. Step 3: (c) AES is symmetric, so the teammate needs the same password (bluefinch42) the key was made from. It should be shared some other way than the email that carried the file, or anyone who sees the email gets both.

    Answer: (a) AES with a 256-bit key. (b) openssl enc -aes-256-cbc -d -in plans.enc -k bluefinch42 -out plans.docx. (c) The same password, shared through a separate, secure channel.

  2. Example 2

    Comparing keyspaces

    Compare the keyspaces of a 4-digit PIN, an AES 128-bit key and an AES 256-bit key.

    Show the solution
    1. Step 1: PIN: 10 choices per digit, 4 digits: 10⁴ = 10,000.
    2. Step 2: AES-128: 2 choices per bit, 128 bits: 2¹²⁸ ≈ 3.40 × 10³⁸.
    3. Step 3: AES-256: 2²⁵⁶ ≈ 1.16 × 10⁷⁷.
    4. Step 4: Each added bit doubles the keyspace, so going from 128 to 256 bits multiplies it by 2¹²⁸, not by 2.

    Answer: PIN: 10,000. AES-128: about 3.40 × 10³⁸. AES-256: about 1.16 × 10⁷⁷, which is 2¹²⁸ times the AES-128 keyspace.

Common mistakes

  • Saying AES-256 is twice as strong as AES-128. Each extra bit doubles the keyspace, so 128 more bits multiplies it by 2¹²⁸.
  • Mixing up block size and key size. AES always uses 128-bit blocks; the key can be 128, 192 or 256 bits.
  • Forgetting that symmetric encryption needs a shared key. Whoever decrypts needs the same key or password.
  • Confusing encryption with hashing. Encryption is meant to be reversed with the key; a hash is one-way.

On the exam

  • You may need to read or complete an OpenSSL command, so know what -e, -d, -in, -out and -k do and how the cipher name shows the key length.
  • For "why is this more secure" questions, tie key length to keyspace: more bits, more possible keys, longer to guess.

Connected topics

Videos

  • Cryptography: Crash Course Computer Science #33

    CrashCourseWatch on YouTube (opens in a new tab)

  • Encryption - Symmetric Encryption vs Asymmetric Encryption - Cryptography - Practical TLS

    Practical NetworkingWatch on YouTube (opens in a new tab)

  • Stream and Block Ciphers - SY0-601 CompTIA Security+ : 2.8

    Professor MesserWatch on YouTube (opens in a new tab)

  • AES Explained (Advanced Encryption Standard) - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Encrypting Data - CompTIA Security+ SY0-701 - 1.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • Symmetric Encryption With OpenSSL

    NeuralNineWatch on YouTube (opens in a new tab)

Check yourself: 5.3 Protecting Stored Data with Cryptography

4 questions on 5.3 Protecting Stored Data with Cryptography. Pick an answer to see if you got it, and why.

Question 1 of 4

In encryption, what is the ciphertext?

Question 2 of 4

Why does a larger keyspace make encrypted data more secure?

Question 3 of 4

Which statement correctly compares symmetric and asymmetric encryption?

Question 4 of 4

A cipher takes input in fixed-size chunks of 128 bits and produces one output chunk for each input chunk. What kind of cipher is this?

0 of 4 answered