Encryption and hashing · 加密与哈希
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| symmetric/sɪˈmetrɪk/ | 对称 | duì chèn |
| encryption/enˈkrɪpʃn/ | 加密 | jiā mì |
| asymmetric/ˌeɪsɪˈmetrɪk/ | 非对称 | fēi duì chèn |
| plaintext/ˈpleɪntekst/ | 明文 | míng wén |
| ciphertext/ˈsaɪfətekst/ | 密文 | mì wén |
| decrypt/dɪˈkrɪpt/ | 解密 | jiě mì |
| key pair/kiː peə/ | 密钥对 | mì yào duì |
| public key/ˈpʌblɪk kiː/ | 公钥 | gōng yào |
| private key/ˈpraɪvət kiː/ | 私钥 | sī yào |
| session key/ˈseʃn kiː/ | 会话密钥 | huì huà mì yào |
| cryptographic hash/ˌkrɪptəˈɡræfɪk hæʃ/ | 密码散列 | mì mǎ sàn liè |
| digest/ˈdaɪdʒest/ | 摘要 | zhāi yào |
Two strangers agreeing a secret in public
- Here is a problem that sounds impossible. You and a shop have never met and share nothing. Everything you say to each other is overheard by everyone. Agree a secret key.
- Until 1976 the answer was that you cannot: symmetric encryption needs the key delivered in advance, by courier or in person, which is why wartime codebooks were printed and shipped.
- Then Diffie, Hellman and later Rivest, Shamir and Adleman showed it can be done, using a key that only locks and a different key that only unlocks. Every purchase you have ever made online rests on it.
- This lesson is symmetric 对称 and asymmetric 非对称 encryption, why real systems use both, and the one-way function called hashing.
两个陌生人当众约定一个秘密
- 这里有个听起来不可能的问题。你和一家商店素未谋面、毫无共同之处。你们之间说的每一句话都被所有人听到。请约定一个密钥。
- 直到 1976 年,答案都是做不到:对称加密需要事先送达密钥,靠信使或当面交接,这就是战时密码本要印刷并运送的原因。
- 后来 Diffie、Hellman,以及之后的 Rivest、Shamir 和 Adleman 证明这可以做到:用一把只能上锁的钥匙和另一把只能开锁的钥匙。你在网上做过的每一笔交易都建立在它之上。
- 这一课讲对称(symmetric)加密和非对称(asymmetric)加密、真实系统为什么两者都用,以及叫做散列的那个单向函数。
The vocabulary
- Encryption 加密 turns readable plaintext 明文 into unreadable ciphertext 密文 using a key; to decrypt 解密 is to reverse it with the appropriate key.
- Encryption protects confidentiality: an intercepted copy cannot be understood. It does not stop the data being intercepted, delayed or deleted.
- The strength lies in the key, not in keeping the algorithm secret. The algorithms are published and studied precisely so that weaknesses are found by friends rather than enemies.
术语
- 加密(encryption)用密钥把可读的明文(plaintext)变成不可读的密文(ciphertext);解密(decrypt)就是用相应的密钥把它还原。
- 加密保护保密性:被截获的副本无法被理解。它不阻止数据被截获、被延迟或被删除。
- 强度在于密钥,而不在于把算法保密。算法被公开并被研究,正是为了让弱点由朋友而不是敌人发现。
Symmetric encryption
- Symmetric encryption uses the same key to encrypt and to decrypt. AES is the standard example.
- It is fast, so it suits bulk data: a whole disk, a video stream, a large file.
- Its weakness is key distribution: the key must reach the other party without being intercepted, and if it is intercepted the whole scheme is broken. With $n$ people who all wish to talk privately in pairs, the number of keys needed grows with the square of $n$.
对称加密
- 对称加密用同一把密钥加密和解密。AES 是标准例子。
- 它快,所以适合大量数据:整块磁盘、一路视频流、一个大文件。
- 它的弱点是密钥分发:密钥必须在不被截获的情况下送到对方手里,一旦被截获整个方案就破了。若有 $n$ 个人都想两两私密通话,所需密钥数随 $n$ 的平方增长。
A shift cipher (symmetric key) · 一个移位密码(对称密钥)
Caesar's cipher shifts every letter forward by a fixed key. The SAME key both encrypts and decrypts — that is what symmetric means. Try to read the ciphertext without knowing the shift. · 凯撒密码把每个字母按一个固定的密钥向前移。同一个密钥既加密又解密——那就是对称的意思。试试在不知道偏移量的情况下读密文。
Symmetric encryption uses: · 对称加密用:
Symmetric encryption shares one secret key — fast, but it must be distributed securely. · 对称加密共享一个秘密密钥——快,但它必须被安全地分发。
Asymmetric encryption
- Asymmetric encryption gives each user a key pair 密钥对: a public key 公钥 they publish to the world, and a private key 私钥 they never reveal.
- Anything encrypted with the public key can be decrypted only with the matching private key. So to send Alice a confidential message you encrypt with Alice's public key, and only Alice can read it.
- No prior key exchange is needed, which solves the problem the lesson opened with. The cost is that it is much slower, so it is not used for large amounts of data.
One key locks, the other unlocks, and only one of them is secret
非对称加密
- 非对称加密给每个用户一对密钥对(key pair):向全世界公开的公钥(public key),和绝不透露的私钥(private key)。
- 用公钥加密的东西只能用配对的私钥解密。所以要给 Alice 发一条保密消息,你用 Alice 的公钥加密,而只有 Alice 能读它。
- 不需要事先交换密钥,这解决了本课开头的问题。代价是它慢得多,所以不用于大量数据。

一把上锁,另一把开锁,而只有其中一把是秘密
Match each cryptographic tool to what it uses. · 把每个密码工具与它使用的东西配对。
Symmetric is fast but needs key sharing; asymmetric solves that with a key pair; hashing is one-way; HTTPS combines them. · 对称快但需要密钥共享;非对称用一个密钥对解决那个;哈希是单向的;HTTPS 结合它们。
To send a confidential message to Alice using asymmetric encryption, you encrypt with: · 要用非对称加密给 Alice 发一条机密消息,你用以下加密:
Encrypting with the recipient's public key means only their matching private key can decrypt it. · 用接收者的公钥加密意味着只有他们匹配的私钥能解密它。
Match each kind of encryption to its main weakness. · 把每种加密与它的主要弱点配对。
The hybrid scheme uses each to cover the other's weakness: asymmetric to deliver the key, symmetric to carry the data. · 混合方案用它们互相弥补弱点:非对称送密钥,对称载数据。
Worked example: send a confidential message
- Explain how asymmetric encryption lets Bob send a confidential message to Alice, even if they have never met. [3]
- Alice publishes her public key, which anyone may have, including an eavesdropper.
- Bob encrypts the message with Alice's public key. The ciphertext can only be decrypted by the matching private key.
- Alice decrypts it with her private key, which she has never shared. An eavesdropper holding the public key and the ciphertext cannot recover the message.
- The commonest error is saying Bob encrypts with his own key. Trace whose key is used at each step.
例题:发送一条保密消息
- 解释非对称加密怎样让 Bob 给 Alice 发送一条保密消息,即使他们素未谋面。[3]
- Alice 公开她的公钥,任何人都可以拿到,包括窃听者。
- Bob 用 Alice 的公钥加密消息。这段密文只能被配对的私钥解密。
- Alice 用她从未分享过的私钥解密它。持有公钥和密文的窃听者无法恢复消息。
- 最常见的错误是说 Bob 用他自己的密钥加密。每一步都要追踪用的是谁的密钥。
Bob sends Alice a confidential message using asymmetric encryption. Which key does he encrypt with? · Bob 用非对称加密给 Alice 发一条保密消息。他用哪把密钥加密?
Only Alice's private key can undo what her public key did, and only Alice has it. Bob never sees Alice's private key at all. · 只有 Alice 的私钥能解开她的公钥所做的事,而只有 Alice 拥有它。Bob 根本看不到 Alice 的私钥。
The hybrid approach, which is what really happens
- Symmetric is fast but cannot share its key; asymmetric can share a key but is slow. Real systems use each for what it is good at.
- The client generates a random session key 会话密钥, encrypts that small key with the server's public key, and sends it. The server decrypts it with its private key, and now both sides hold the same session key.
- Every byte of the actual conversation is then encrypted symmetrically with that session key: fast, and the slow asymmetric step happened only once, on a few bytes.
- This is exactly how HTTPS and SSH work.
Asymmetric to agree the key, symmetric to carry the data
混合方案,也就是实际发生的事
- 对称快但无法分享密钥;非对称能分享密钥但慢。真实系统各取所长。
- 客户端生成一个随机的会话密钥(session key),用服务器的公钥加密这把小小的密钥并发送。服务器用自己的私钥解密它,于是双方现在持有同一把会话密钥。
- 之后真正对话的每一个字节都用那把会话密钥对称加密:快,而且慢的非对称那一步只在几个字节上做了一次。
- HTTPS 和 SSH 正是这样工作的。

非对称用来约定密钥,对称用来承载数据
In the hybrid approach used by HTTPS, asymmetric encryption is used to: · 在 HTTPS 用的混合方法中,非对称加密用来:
Slow asymmetric crypto just shares a session key; the bulk data then uses fast symmetric encryption. · 慢的非对称密码学只共享一个会话密钥;大量的数据然后用快速的对称加密。
Put the steps of the hybrid scheme used by HTTPS in order. · 把 HTTPS 使用的混合方案的步骤按顺序排列。
The slow asymmetric step runs once, on a few bytes; everything after it is fast symmetric encryption. · 慢的非对称步骤只在几个字节上做一次;之后的一切都是快速的对称加密。
Hashing
- A cryptographic hash 密码散列 turns an input of any size into a fixed-size digest 摘要. The same input always gives the same digest, and a tiny change to the input changes the digest completely.
- It is one-way: the input cannot be recovered from the digest. That is the whole point, and it is what makes it different from encryption, which is designed to be reversed.
- Uses: storing passwords, where the system keeps only the digest and compares digests at login, so a stolen database yields no passwords; and checking integrity, where a file's digest is recomputed and compared to detect any change.
散列
- 密码散列(cryptographic hash)把任意大小的输入变成固定大小的摘要(digest)。同样的输入总是给出同样的摘要,而输入哪怕改动一点点,摘要就完全不同。
- 它是单向的:无法从摘要恢复输入。这正是关键所在,也是它与加密不同的地方——加密的设计目的就是可逆。
- 用途:存储密码,系统只保留摘要并在登录时比对摘要,于是被盗的数据库交不出任何密码;以及检查完整性,重新计算文件的摘要并比对,以发现任何改动。
A cryptographic hash produces a fixed-size ____ from an input of any size. · 密码散列从任意大小的输入产生一个固定大小的____。
The same input always gives the same digest, a small change gives a completely different one, and the input cannot be recovered from it. · 同样的输入总给出同样的摘要,微小改动会给出完全不同的摘要,而且无法从它恢复输入。
Worked example: why hash a password instead of encrypting it
- A website stores users' passwords as hashes rather than as encrypted text. Explain why.
- Encryption is reversible: a key exists somewhere that turns the stored value back into the password, and an attacker who obtains the database may also obtain the key.
- Hashing is one-way, so a stolen database of digests does not yield the passwords, and even the site's own staff cannot read them.
- Login still works because the system hashes what the user typed and compares digests, never the passwords themselves.
例题:密码为什么散列而不是加密
- 一个网站把用户密码存成散列而不是加密后的文本。解释为什么。
- 加密是可逆的:某处存在一把密钥,能把存储的值变回密码,而拿到数据库的攻击者也可能拿到那把密钥。
- 散列是单向的,所以被盗的摘要数据库交不出密码,连网站自己的员工也读不到。
- 登录仍然可行,因为系统对用户输入的内容做散列并比对摘要,从不比对密码本身。
Hashing and the avalanche effect · 哈希与雪崩效应
A hash is one-way: easy to compute, practically impossible to reverse. A tiny change in the input flips a large, unpredictable part of the output — the avalanche effect that makes hashes good for passwords. · 一个哈希是单向的:容易计算,实际上不可能逆转。输入中的一个微小改变翻转输出的一大部分、不可预测的部分——使哈希对密码有用的雪崩效应。
A cryptographic hash is one-way (you cannot recover the input from the digest) and shows the avalanche effect — a tiny change in the input flips a large, unpredictable part of the output. · 一个密码哈希是单向的(你不能从摘要恢复输入)并表现出雪崩效应——输入中的一个微小改变翻转输出的一大部分、不可预测的部分。
One-wayness plus avalanche is what makes hashes good for storing passwords and checking integrity. · 单向性加上雪崩是使哈希对存储密码和检查完整性有用的原因。
Why store passwords as hashes rather than encrypted? Select all · 所有 that apply. · 为什么把密码存成散列而不是加密?选出所有适用的。
A fixed-size digest may indeed be shorter, but that is not the security reason. Irreversibility is. · 固定大小的摘要确实可能更短,但那不是安全上的理由。不可逆才是。
Marks that slip away
- To send someone a confidential message you use their public key, not yours. Say whose key at every step.
- Symmetric's weakness is key distribution; asymmetric's weakness is speed. The hybrid uses each to cover the other's.
- Hashing is one-way and is not encryption: there is no key and nothing to decrypt.
- Encryption protects confidentiality only. It does not stop interception, deletion, or a message being altered undetectably: for that you need a hash.
容易丢掉的分
- 要给某人发保密消息,用的是他的公钥,不是你的。每一步都要说清用谁的密钥。
- 对称的弱点是密钥分发;非对称的弱点是速度。混合方案让它们互相弥补。
- 散列是单向的,而且不是加密:没有密钥,也没有什么可解密的。
- 加密只保护保密性。它不阻止截获、删除,也不阻止消息被改动而不被察觉:那需要散列。
You've got it
- encryption turns plaintext into ciphertext with a key and protects confidentiality only; the strength is in the key, not in hiding the algorithm
- symmetric: one shared key, fast, good for bulk data, weak on key distribution · asymmetric: a public key to encrypt and a private key to decrypt, needs no prior exchange, but slow
- the hybrid used by HTTPS and SSH sends a random session key encrypted asymmetrically, then carries the data symmetrically
- a cryptographic hash makes a fixed-size digest, is one-way, and is used for passwords and integrity checks
你掌握了
- 加密用密钥把明文变成密文,只保护保密性;强度在密钥,不在隐藏算法
- 对称:一把共享密钥,快,适合大量数据,弱在密钥分发 · 非对称:公钥加密、私钥解密,不需要事先交换,但慢
- HTTPS 和 SSH 使用的混合方案先用非对称加密送出一把随机会话密钥,再用对称加密承载数据
- 密码散列产生固定大小的摘要,是单向的,用于密码和完整性校验