Subject » BMEVIHIA030
Applied Cryptography
Alkalmazott kriptográfia
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
—
| Subject name (Hungarian, English) |
Alkalmazott kriptográfia
Applied Cryptography
|
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Subject code | BMEVIHIA030 | ||||||||||||
| Subject type | — | ||||||||||||
| Training Level | — | ||||||||||||
| Course types and hours (weekly/semester) |
|
||||||||||||
| Assessment type | vizsga | ||||||||||||
| Credits | 4 | ||||||||||||
| Subject coordinator |
DR. Buttyán Levente
position: egyetemi tanár
contact:
buttyan.levente@vik.bme.hu
|
||||||||||||
| Responsible department |
Hálózati Rendszerek és Szolgáltatások Tanszék
|
||||||||||||
| Faculty | Villamosmérnöki és Informatikai Kar | ||||||||||||
| Subject website | — | ||||||||||||
| Primary curriculum type | — | ||||||||||||
| Direct prerequisites – Strong prerequisite | none | ||||||||||||
| Direct prerequisites – Weak prerequisite | none | ||||||||||||
| Direct prerequisites – Parallel prerequisite | none | ||||||||||||
| Direct prerequisites – Milestone prerequisite | none | ||||||||||||
| Direct prerequisites – Exclusion | none |
Objectives
Programme
Week 1: Motivation and basic concepts. Examples for cyber attacks, attacker models, security objectives. History of Cryptography. Symmetric and asymmetric ciphers, digital signature schemes, cryptographic hash functions. Construction examples and parameter sizes.
Exercise: operation and properties of cryptographic building blocks.
Week 2: Block encryption modes, MAC functions, PKCS formatting for public key algorithms.
Week 3: Random number generation, attacks against PRNG-s, secure PRNG constructions. Key exchange protocols: attacker model and main design principles, illustrative examples (Needham-Schroeder, Wide Mouth Frog, Diffie-Hellman, ...). Manual and automated security verification of key exchange protocols.
Exercise: usage of cryptographic libraries (eg. OpenSSL).
Week 4: Introduction to Public Key Infrastructures (PKI): certificate, certification authority (CA), trust, key pair management, verification of digital signatures.
Week 5: Digital vs. electronic signature: digital signature, authentication with public key cryptography; legal background of electronic signatures, related laws in the EU and in the US, qualified electronic signature; requirements for electronic signatures, the process of creating and verifying electronic signatures, certificate revocation, electronic signature archive formats.
Exercise: establishment of a certification authority.
Week 6: PKI and secure communications on the web. Security of and trust in CAs. Audit frameworks. Practical examples for security issues in CAs. Business models for PKI.
Week 7: Secure communcation protocols: TLS/SSL (operation and analysis).
Exercise: attacks of communication and key exchange protocols.
Week 8: Security in wireless networks: WiFi security protocols (WEP, WPA, WPA2) (operation and analysis).
Week 9: Other topics: cryptography in resource constrained environments (embedded systems, RFID systems). Privacy protection with cryptographic solutions: anonim communication systems and private authentication protocols.
Exercise: measuring privacy in anonymous communication systems.
Week 10: Password based authentication: cryptographic protection of passwords in applications, and password based key derivation. Two factor authentication, one-time passwords. Authentication and authorization in practice (Kerberos, OAuth, OpenID, SAML).
Week 11: Applications: Disk encryption and secure electronic mail (PGP and SMIME).
Exercise: use of PGP and SMIME in practice.
Week 12: Client side encryption in the Tresorit cloud based data storage system.
Week 13: DRM and secure file sharing in the Tresorit system.
Exercise: Tresorit setup for a virtual business environment
Week 14: Summary and outlook to other application areas of cryptography.
Exercise: operation and properties of cryptographic building blocks.
Week 2: Block encryption modes, MAC functions, PKCS formatting for public key algorithms.
Week 3: Random number generation, attacks against PRNG-s, secure PRNG constructions. Key exchange protocols: attacker model and main design principles, illustrative examples (Needham-Schroeder, Wide Mouth Frog, Diffie-Hellman, ...). Manual and automated security verification of key exchange protocols.
Exercise: usage of cryptographic libraries (eg. OpenSSL).
Week 4: Introduction to Public Key Infrastructures (PKI): certificate, certification authority (CA), trust, key pair management, verification of digital signatures.
Week 5: Digital vs. electronic signature: digital signature, authentication with public key cryptography; legal background of electronic signatures, related laws in the EU and in the US, qualified electronic signature; requirements for electronic signatures, the process of creating and verifying electronic signatures, certificate revocation, electronic signature archive formats.
Exercise: establishment of a certification authority.
Week 6: PKI and secure communications on the web. Security of and trust in CAs. Audit frameworks. Practical examples for security issues in CAs. Business models for PKI.
Week 7: Secure communcation protocols: TLS/SSL (operation and analysis).
Exercise: attacks of communication and key exchange protocols.
Week 8: Security in wireless networks: WiFi security protocols (WEP, WPA, WPA2) (operation and analysis).
Week 9: Other topics: cryptography in resource constrained environments (embedded systems, RFID systems). Privacy protection with cryptographic solutions: anonim communication systems and private authentication protocols.
Exercise: measuring privacy in anonymous communication systems.
Week 10: Password based authentication: cryptographic protection of passwords in applications, and password based key derivation. Two factor authentication, one-time passwords. Authentication and authorization in practice (Kerberos, OAuth, OpenID, SAML).
Week 11: Applications: Disk encryption and secure electronic mail (PGP and SMIME).
Exercise: use of PGP and SMIME in practice.
Week 12: Client side encryption in the Tresorit cloud based data storage system.
Week 13: DRM and secure file sharing in the Tresorit system.
Exercise: Tresorit setup for a virtual business environment
Week 14: Summary and outlook to other application areas of cryptography.
The objective of the course is to give an introduction to the basics of cryptography, to explain how basic building blocks work, and to demonstrate how secure systems can be engineered by properly using them. Besides the theoretical background, we use lot of illustrative examples and show practical applications. In addition, besides the technical details, we give an outlook to the legal and business aspects of using cryptography.
Learning outcomes
Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:
Knowledge
No learning outcomes recorded.
Skills
No learning outcomes recorded.
Attitudes
No learning outcomes recorded.
Autonomy and responsibility
No learning outcomes recorded.
Oktatási módszertan
Lecture and classroom exercise.
Tanulástámogató anyagok
Online források
William Stallings, Cryptography and Network Security – Principles and Practices, 4th Edition, Prentice Hall, 2006.; On-line lecture slides.
Recommended preliminary knowledge for completing the subject
Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
No special prerequisites are needed.
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
No special prerequisites are needed.
General rules
Requirements:
In the semester:
3 homework sucessfully delivered. Homeworks are given on the 5th, 8th, and 11th week.
Homeworks are due on the 8th, 11th and last week of the semester.
In the exam period:
Oral exam.
Additional possibilities:
In case of late delivery of homeworks, the official faculty rules apply.
Assessment methods
In-term assessments
No detailed assessments provided.
Weight of in-term assessments
No weights provided.
Exam-period assessments
No detailed assessments provided.
Weight of exam elements
No weights provided.
Grade calculation
No grade thresholds provided.
Attendance requirements
No attendance requirements provided.
Rules for retake and resubmission
Not provided.
Short description
Not provided.
Detailed description
Not provided.
Recommended courses
None.
Workload to complete the subject
No workload breakdown provided.
Validity of subject requirements
Requirements valid from:
—
Requirements valid until:
—
Curriculum placement
No curriculum placements recorded for this subject version.