Document information
- University
- Politecnico di Milano
- Degree programme
- Computer Engineering
- Subject
- Cryptography and Architectures for Computer Security
- Classification
- Exam · Full exam
- Content
- Exam paper only
- Original format
- Text
- Searchable text
Full exam for Cryptography and Architectures for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2014–2015, Semester: 2 Prof. G. Pelosi July 1st, 2015 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . . . . .
Full exam for Cryptography and Architectures for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2014–2015, Semester: 2 Prof. G. Pelosi July 1st, 2015 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . . . . .
Import quality: text was extracted directly from the original document.
Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.
Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2014–2015, Semester: 2 Prof. G. Pelosi July 1st, 2015 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Student ID: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Signature: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Time: 2h:30’. Use of textbooks, notes, phones or Internet connected devices is not allowed. Prior to turn in your paper, write your name on any additional sheet and sign it. Question 1 [3 pts] Consider a TLS ciphersuite as a tuple (Akex,Aauth,Asym,Ahash) (a) Which choice between(Diffie-Hellman-2048, RSA-1024, AES-128-CBC, SHA-2-256) and (Diffie- Hellman-Ephemeral-512, RSA-2048, AES-128-CBC, SHA-2-256) is the one providing the highest security margin? (b) During the TLS key exchange, is it possible for an active attacker to alter the value of the session nonce, setting it to an arbitrary value decided by him? Does this action get detected before the end of the TLS handshake? (c) Is there any difference between picking (Diffie-Hellman-Ephemeral-2048, RSA-2048, None, SHA-2-256) and (Diffie-Hellman-2048, RSA-2048, None, SHA-2-256) as a TLS ciphersuite? Solution: (a) Despite providing perfect forward secrecy, the second ciphersuite is weaker than the first one, as it is possible to break DHE-512 with a relatively small computational effort, thus deriving the session key. The first choice, despite employing a suboptimal choice for key lenghts (the RSA keylength voids the effort of the 2048 bit DH key) (b) It is possible for an active attacker to tamper precisely with the value of the session…
First page of the document.