Book Image

Modern Cryptography for Cybersecurity Professionals

By : Lisa Bock
Book Image

Modern Cryptography for Cybersecurity Professionals

By: Lisa Bock

Overview of this book

In today's world, it is important to have confidence in your data storage and transmission strategy. Cryptography can provide you with this confidentiality, integrity, authentication, and non-repudiation. But are you aware of just what exactly is involved in using cryptographic techniques? Modern Cryptography for Cybersecurity Professionals helps you to gain a better understanding of the cryptographic elements necessary to secure your data. The book begins by helping you to understand why we need to secure data and how encryption can provide protection, whether it be in motion or at rest. You'll then delve into symmetric and asymmetric encryption and discover how a hash is used. As you advance, you'll see how the public key infrastructure (PKI) and certificates build trust between parties, so that we can confidently encrypt and exchange data. Finally, you'll explore the practical applications of cryptographic techniques, including passwords, email, and blockchain technology, along with securely transmitting data using a virtual private network (VPN). By the end of this cryptography book, you'll have gained a solid understanding of cryptographic techniques and terms, learned how symmetric and asymmetric encryption and hashed are used, and recognized the importance of key management and the PKI.
Table of Contents (16 chapters)
1
Section 1: Securing Our Data
5
Section 2: Understanding Cryptographic Techniques
9
Section 3: Applying Cryptography in Today's World

Managing public keys

A PKI is responsible for securely delivering verified public keys, which provides assurance or trust that you are communicating securely with a verified entity. A PKI achieves this goal by using a digitally signed certificate.

In this section, we'll discuss what's involved when creating a certificate. We'll see how malicious actors can intercept and spoof certificates, along with how pinning can help prevent this from happening. Finally, we'll compare trusted root certificates with self-signed certificates and see the steps to take to create a self-signed certificate on a Windows machine.

First, let's step through creating a certificate.

Creating a certificate

When a company wants to create a digital certificate that links a public key with their organization, they will go through a formal process. The first step is to create a certificate signing request (CSR) that is sent to the CA.

Let's see what's involved...