Introduction
Cryptography is used to protect information when it is stored, transmitted, or exchanged between systems. In computer networks, it becomes especially important because data often travels across public and untrusted paths before reaching the destination.
The main security goals of cryptography are confidentiality, integrity, authentication, and non-repudiation. Each goal solves a different security problem, and together they form the foundation of secure communication.
Cryptography Security Goals
Confidentiality
Confidentiality ensures that only authorized parties can read the data. If an attacker captures the message while it is traveling through the network, the attacker should not be able to understand its actual content.
Encryption is commonly used to provide confidentiality. It converts readable data into unreadable ciphertext, and only someone with the correct key can convert it back into the original message.
Main idea: Unauthorized users should not be able to read the data.
Common mechanism: Encryption using cryptographic keys.
Example: A password sent over HTTPS should not be readable by someone monitoring the network.
Integrity
Integrity ensures that data has not been changed during transmission or storage. Even if an attacker cannot read the data, they may try to modify it before it reaches the receiver.
Cryptographic integrity checks help the receiver detect whether the message was altered. Hashing, message authentication codes, and digital signatures are commonly used for this purpose.
Main idea: Data should not be modified without detection.
Common mechanism: Hashes, MACs, and digital signatures.
Example: A payment request should not be changed from
Rs. 1000toRs. 100000.
Authentication
Authentication verifies the identity of the communicating party. It answers an important question: is this user, device, server, or application really who it claims to be?
In secure communication, authentication helps prevent impersonation attacks. For example, when a browser connects to a banking website, it must verify that it is communicating with the real bank server and not a fake server.
Main idea: The identity of the sender, receiver, or system should be verified.
Common mechanism: Certificates, digital signatures, passwords, tokens, and cryptographic protocols.
Example: HTTPS uses certificates to help verify that the website is genuine.
Non-Repudiation
Non-repudiation ensures that a sender cannot later deny sending or signing a message. It provides proof that a specific party performed a specific action.
Digital signatures are commonly used for non-repudiation. Since the signature is created using the sender’s private key, it can later be verified using the corresponding public key.
Main idea: The sender should not be able to deny the action later.
Common mechanism: Digital signatures and public-key cryptography.
Example: A digitally signed document can prove who signed it and whether it was changed after signing.
Security Goals at a Glance
Security Goal | What It Ensures | Simple Meaning |
|---|---|---|
Confidentiality | Data is hidden from unauthorized parties | Cannot read |
Integrity | Data changes can be detected | Cannot modify without detection |
Authentication | Identity is verified | Know who is communicating |
Non-Repudiation | Actions cannot be denied later | Cannot deny sending or signing |
Summary
The security goals of cryptography define what secure communication should achieve. Confidentiality keeps data private, integrity detects tampering, authentication verifies identity, and non-repudiation prevents denial of actions.
These goals are used in secure protocols and systems such as HTTPS, TLS, VPNs, SSH, digital signatures, and secure messaging. Cryptography does not replace all security controls, but it provides the core protection needed for trusted communication over modern networks.
Be the first to add a comment.