{"product_id":"139201","title":"Real-World Cryptography ","description":"\u003ccenter\u003e\u003cdiv style=\"text-align:center\"\u003e\u003cimg src=\"https:\/\/tmgdisk01.cafe24.com\/images\/vs\/4172\/sv\/uOonlWT5WUA8xLFYurHB0eU5BOS.png?v=1765073827\" style=\"max-width:100%;max-height:10px\"\u003e\u003c\/div\u003e\u003c\/center\u003e\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\u003ccenter\u003e\n\n\u003cdiv style=\"width:95%\"\u003e\n\n\u003cdiv style=\"text-align:center;font-size:30px;font-weight:bolder;line-height:1.6em\"\u003e Real-World Cryptography \u003c\/div\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003cdiv style=\"border-bottom:1px;border-bottom-style:dotted;border-color:;padding-bottom:20px\"\u003e\u003ccenter\u003e\u003ctable align=\"center\" width=\"100%\"\u003e\u003ctbody style=\"border:0px\"\u003e\n\n\u003ctr\u003e\u003ctd align=\"center\" style=\"line-height:1.2em;text-align:center;font-size:18px;color:black;font-weight:bold;padding-bottom:20px;\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\n\n\u003ctr\u003e\u003ctd style=\"text-align:center\"\u003e\u003cimg src=\"https:\/\/image.yes24.com\/goods\/116788103\/XL\" style=\"max-width:100%;height:auto\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\u003c\/table\u003e\u003c\/center\u003e\u003c\/div\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003cdiv style=\"width:95%;{split_style6}padding-top:20px;padding-bottom:20px\"\u003e\n\n\u003cdiv style=\"text-align:left;font-size:16px;font-weight:bold;padding-bottom:20px\"\u003e Description \u003c\/div\u003e\n\n\u003cdiv style=\"text-align:left;word-break:break-all;font-size:14px;line-height:1.6em;\"\u003e\n\n\u003cdiv\u003e\u003ch5\u003e \u003cb\u003eBook Introduction\u003c\/b\u003e\n\u003c\/h5\u003e\u003c\/div\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\u003cdiv\u003e \u003cb\u003eThe world's most practical cryptography guidebook\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e Cryptography is an essential foundation of IT security.\u003cbr\u003e To stay ahead of system attackers, you need to understand the tools, frameworks, and protocols that secure your networks and applications.\u003cbr\u003e This book teaches practical skills for developers, system administrators, and security practitioners.\u003cbr\u003e Instead of complex mathematics or technical terms, modern cryptography techniques are explained using various illustrations and real-world examples. \u003cbr\u003eYou can learn everything from fundamentals to cutting-edge technologies, including hash functions, signatures, HTTPS, secure messaging, quantum-resistant cryptography, and cryptocurrencies. Written by a cryptography engineer actively contributing to Internet standards, including TLS, this book is accessible even to practitioners new to the field.\u003cbr\u003e\n\n\u003c\/div\u003e\u003c\/div\u003e\n\u003cdiv\u003e\u003cul\u003e\u003cli\u003e You can preview some of the book's contents.\u003cbr\u003e \u003cspan\u003ePreview\u003c\/span\u003e\n\n\u003c\/li\u003e\u003c\/ul\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cbr\u003e\u003cdiv\u003e\u003ch5\u003e \u003cb\u003eindex\u003c\/b\u003e\n\u003c\/h5\u003e\u003c\/div\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e Translator's Preface xii\u003cbr\u003e Recommendation xiii\u003cbr\u003e Beta Reader Review xv\u003cbr\u003e Beginning with xvii\u003cbr\u003e Acknowledgments xxii\u003cbr\u003e About this book xxiii\u003cbr\u003e About the cover xxvii\u003cbr\u003e\u003cbr\u003e \u003cb\u003ePART I Primitives: The Stuff of Cryptography\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e CHAPTER 1 Getting Started 3\u003cbr\u003e 1.1 Cryptography Protects Protocols 4\u003cbr\u003e 1.2 Symmetric Cryptography: What is Symmetric Encryption? 5\u003cbr\u003e 1.3 Kerkhoff's Principle: Keep Your Height a Secret 7\u003cbr\u003e 1.4 Asymmetric Cryptography: Two Keys Are Better Than One 10\u003cbr\u003e __1.4.1 How to share secrets, key exchange 10\u003cbr\u003e __1.4.2 Asymmetric encryption is different from symmetric encryption! 13 \u003cbr\u003e__1.4.3 Digital Signatures: Not So Different from Pen and Paper Signatures 15\u003cbr\u003e 1.5 Classification of Cryptography 17\u003cbr\u003e 1.6 Theoretical Cryptography vs. Real-World Cryptography 19\u003cbr\u003e 1.7 From Theory to Reality: Simulations for Making Cryptography a Reality 20\u003cbr\u003e 1.8 Warning 25\u003cbr\u003e Summary 26\u003cbr\u003e\u003cbr\u003e CHAPTER 2 Hash Functions 27\u003cbr\u003e 2.1 What is a hash function? 27\u003cbr\u003e 2.2 Security Properties of Hash Functions 30\u003cbr\u003e 2.3 Security Constraints of Hash Functions 32\u003cbr\u003e 2.4 Practical Uses of Hash Functions 34\u003cbr\u003e __2.4.1 commit 34\u003cbr\u003e __2.4.2 Subresource Integrity 35\u003cbr\u003e __2.4.3 BitTorrent 35\u003cbr\u003e __2.4.4 Thor 35\u003cbr\u003e 2.5 Standardized Hash Functions 36\u003cbr\u003e __2.5.1 SHA-2 Hash Function 37\u003cbr\u003e __2.5.2 SHA-3 Hash Function 41\u003cbr\u003e __2.5.3 Two XOFs, SHAKE and cSHAKE 44\u003cbr\u003e __2.5.4 Tuple Hash, Resolving Ambiguity 46\u003cbr\u003e 2.6 Password Hash 48\u003cbr\u003e Summary 50\u003cbr\u003e\u003cbr\u003e CHAPTER 3 Message Authentication Code 51\u003cbr\u003e 3.1 A representative example of MAC, stateless cookies 51\u003cbr\u003e 3.2 Code Example 54\u003cbr\u003e 3.3 Security Properties of MAC 56\u003cbr\u003e __3.3.1 Forgery of Authentication Tags 56\u003cbr\u003e __3.3.2 Authentication tag length 57\u003cbr\u003e __3.3.3 Replay Attack 58\u003cbr\u003e __3.3.4 Periodic Authentication Tag Verification 59\u003cbr\u003e 3.4 MAC 61 in the Real World \u003cbr\u003e__3.4.1 Message Authentication 61\u003cbr\u003e __3.4.2 Key Derivation 61\u003cbr\u003e __3.4.3 Cookie Integrity 61\u003cbr\u003e __3.4.4 Hash Table 62\u003cbr\u003e 3.5 MAC 62 in Practice\u003cbr\u003e __3.5.1 Hash-based MAC, HMAC 62\u003cbr\u003e __3.5.2 cSHAKE-based MAC, KMAC 63\u003cbr\u003e 3.6 SHA-2 and Variable-Length Attacks 64\u003cbr\u003e Summary 67\u003cbr\u003e\u003cbr\u003e CHAPTER 4: Authentication and Encryption 69\u003cbr\u003e 4.1 What is a ciphertext? 70\u003cbr\u003e 4.2 AES Block Encryption 71\u003cbr\u003e __4.2.1 Level of Security Provided by AES 72\u003cbr\u003e __4.2.2 AES Interface 73\u003cbr\u003e __4.2.3 Inside AES 74\u003cbr\u003e 4.3 Encrypted Penguin and CBC Mode 75\u003cbr\u003e 4.4 What if authentication is required? AES-CBC-HMAC 78\u003cbr\u003e 4.5 All-in-one architecture: Authentication and encryption 80\u003cbr\u003e __4.5.1 AEAD 80\u003cbr\u003e __4.5.2 AES-GCM AEAD 82\u003cbr\u003e __4.5.3 ChaCha20-Poly1305 86\u003cbr\u003e 4.6 Other Symmetric Encryption 90\u003cbr\u003e __4.6.1 Key Wrapping 91\u003cbr\u003e __4.6.2 Nonce Misuse Prevention Authentication Encryption 91\u003cbr\u003e __4.6.3 Disk Encryption 91\u003cbr\u003e __4.6.4 Database Encryption 92\u003cbr\u003e Summary 92\u003cbr\u003e\u003cbr\u003e CHAPTER 5 KEY EXCHANGE 95\u003cbr\u003e 5.1 What is Key Exchange? 96\u003cbr\u003e 5.2 DH Key Exchange 99\u003cbr\u003e __5.2.1 Group Theory 99\u003cbr\u003e __5.2.2 Diffie-Hellman Foundation, Discrete Logarithm Problem 103\u003cbr\u003e __5.2.3 Diffie-Hellman Standard 105\u003cbr\u003e 5.3 ECDH Key Exchange 106 \u003cbr\u003e__5.3.1 What is an Elliptic Curve? 107\u003cbr\u003e __5.3.2 How ECDH Key Exchange Works 110\u003cbr\u003e __5.3.3 Elliptic Curve Diffie-Hellman Standard 112\u003cbr\u003e 5.4 Small Subgroup Attacks and Other Security Considerations 114\u003cbr\u003e Summary 117\u003cbr\u003e\u003cbr\u003e CHAPTER 6 Asymmetric and Hybrid Encryption 119\u003cbr\u003e 6.1 What is Asymmetric Encryption? 120\u003cbr\u003e 6.2 Practical Asymmetric and Hybrid Encryption 122\u003cbr\u003e __6.2.1 Key Exchange and Key Encapsulation 122\u003cbr\u003e __6.2.2 Hybrid Encryption 123\u003cbr\u003e 6.3 RSA Asymmetric Cryptography: The Worst and the Less Worst 127\u003cbr\u003e __6.3.1 Textbook RSA 127\u003cbr\u003e __6.3.2 Why not use RSA PKCS#1 v1.5? 131\u003cbr\u003e __6.3.3 RSA-OAEP Asymmetric Encryption 133\u003cbr\u003e 6.4 ECIES Hybrid Encryption 136\u003cbr\u003e Summary 138\u003cbr\u003e\u003cbr\u003e CHAPTER 7 Signatures and Zero-Knowledge Proofs 139\u003cbr\u003e 7.1 What is a Signature? 140\u003cbr\u003e __7.1.1 How to Sign and Verify Signatures in Practice 141\u003cbr\u003e __7.1.2 Primary Use of Signatures: Authenticated Key Exchange 142\u003cbr\u003e __7.1.3 Real-World Use Case: Public Key Infrastructure 143\u003cbr\u003e 7.2 ZKP: The Origin of Signatures 144\u003cbr\u003e __7.2.1 Schnorr Identification Protocol: Interactive ZKP 145\u003cbr\u003e __7.2.2 Signatures as Non-Interactive ZKPs 148 \u003cbr\u003e7.3 Recommended Signature Algorithm 149\u003cbr\u003e __7.3.1 Insecure Standard, RSA PKCS#1 v1.5 150\u003cbr\u003e __7.3.2 Improved Standard, RSA-PSS 153\u003cbr\u003e __7.3.3 ECDSA 154\u003cbr\u003e __7.3.4 EdDSA 157\u003cbr\u003e 7.4 Subtle Properties of Signature Systems 160\u003cbr\u003e __7.4.1 Alternative Attack 160\u003cbr\u003e __7.4.2 Malleability of Signatures 162\u003cbr\u003e Summary 162\u003cbr\u003e\u003cbr\u003e CHAPTER 8 Randomness and Secrecy 165\u003cbr\u003e 8.1 What is randomness? 166\u003cbr\u003e 8.2 Slow Randomness? Use a PRNG 167\u003cbr\u003e 8.3 Ensuring Randomness in Practice 171\u003cbr\u003e 8.4 Random Number Generation and Security Considerations 173\u003cbr\u003e 8.5 Public Randomness 175\u003cbr\u003e 8.6 Key Derivation and HKDF 177\u003cbr\u003e 8.7 Key Management and Secret Management 181\u003cbr\u003e 8.8 Decentralizing Trust through Threshold Cryptography 183\u003cbr\u003e Summary 186\u003cbr\u003e\u003cbr\u003e \u003cb\u003ePART II Protocols: A Recipe for Cryptography\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e CHAPTER 9 SECURE TRANSMISSION 189\u003cbr\u003e 9.1 Secure Transport Protocols, SSL and TLS 190\u003cbr\u003e __9.1.1 SSL to TLS 190\u003cbr\u003e __9.1.2 Using TLS in Practice 191\u003cbr\u003e 9.2 How the TLS Protocol Works 193\u003cbr\u003e __9.2.1 TLS Handshake 194\u003cbr\u003e __9.2.2 How TLS 1.3 Encrypts Application Data 207\u003cbr\u003e 9.3 The Current State of the Encrypted Web 208 \u003cbr\u003e9.4 Other Transport Protocols 211\u003cbr\u003e 9.5 A Modern Alternative to TLS, the Noise Protocol Framework 211\u003cbr\u003e __9.5.1 Various Handshakes of Noise 212\u003cbr\u003e __9.5.2 Noise Handshake 213\u003cbr\u003e Summary 214\u003cbr\u003e\u003cbr\u003e CHAPTER 10 END-TO-END ENCRYPTION 215\u003cbr\u003e 10.1 Why is end-to-end encryption necessary? 216\u003cbr\u003e 10.2 The Source of Trust You Can't Find Anywhere 217\u003cbr\u003e 10.3 Email Encryption Failure 219\u003cbr\u003e __10.3.1. PGP? GPG? How Does It Work? 219\u003cbr\u003e __10.3.2 Web of Trust: Extending Trust Between Users 222\u003cbr\u003e __10.3.3 The real issue is finding the key 223\u003cbr\u003e __10.3.4 If not PGP, what are the alternatives? 224\u003cbr\u003e 10.4 Secure Messaging: Modern End-to-End Encryption with Signal 226\u003cbr\u003e __10.4.1 Trust, but verify. More user-friendly than WOT 227\u003cbr\u003e __10.4.2 Signal Protocol Handshake, X3DH 230\u003cbr\u003e __10.4.3 Post-handshake protocol for signals, double ratchet 233\u003cbr\u003e 10.5 Current End-to-End Encryption 238\u003cbr\u003e Summary 240\u003cbr\u003e\u003cbr\u003e CHAPTER 11 USER AUTHENTICATION 243\u003cbr\u003e 11.1 Reviewing Certification 243 \u003cbr\u003e11.2 User Authentication, the Journey to Eliminating Passwords 245\u003cbr\u003e __11.2.1 The Master of Passwords, SSO and Password Manager 248\u003cbr\u003e __11.2.2 Want to prevent password exposure? Use asymmetric password authentication key exchange. 249\u003cbr\u003e __11.2.3 O TP is not an actual password.\u003cbr\u003e Switching without a password using symmetric keys 253\u003cbr\u003e __11.2.4 Replacing Passwords with Asymmetric Keys 257\u003cbr\u003e 11.3 User-assisted authentication: Pairing devices with human assistance 260\u003cbr\u003e __11.3.1 Preshared Key 261\u003cbr\u003e __11.3.2 Symmetric Password Authentication Key Exchange Using CPace 263\u003cbr\u003e __11.3.3 Has My Key Exchange Been MITM-Attackered? Check SAS 264\u003cbr\u003e Summary 267\u003cbr\u003e\u003cbr\u003e CHAPTER 12: The \"Cryptocurrency\" in \"Cryptocurrency\"? 269\u003cbr\u003e 12.1 A Brief Introduction to BFT Consensus Algorithms 270\u003cbr\u003e __12.1.1 The Problem of Resilience: Distributed Protocols for Structure 270\u003cbr\u003e __12.1.2 Decentralization Solving the Problem of Trust 272\u003cbr\u003e __12.1.3 The Problem of Scale: Permissionless and Censorship-Resistant Networks 273 \u003cbr\u003e12.2 How Bitcoin Works 275\u003cbr\u003e __12.2.1 How Bitcoin Manages User Balances and Transactions 276\u003cbr\u003e __12.2.2 The Digital Gold Mine: Mining BTC 278\u003cbr\u003e __12.2.3 Fork Hell! Mining Dispute Resolution 281\u003cbr\u003e __12.2.4 Reducing Block Size Using Merkle Trees 284\u003cbr\u003e 12.3 Cryptocurrency Overview 286\u003cbr\u003e __12.3.1 Volatility 286\u003cbr\u003e __12.3.2 Delay time 286\u003cbr\u003e __12.3.3 Blockchain Size 287\u003cbr\u003e __12.3.4 Confidentiality 287\u003cbr\u003e __12.3.5 Energy Efficiency 288\u003cbr\u003e 12.4 DMBFT: BFT Consensus Protocol 288\u003cbr\u003e __12.4.1 Two Properties of BFT Consensus Protocols: Safety and Liveness 288\u003cbr\u003e __12.4.2 Round 289 of the DMBFT Protocol\u003cbr\u003e __12.4.3 How much dishonesty can a protocol tolerate? 290\u003cbr\u003e __12.4.4 DMBFT Voting Rules 291\u003cbr\u003e __12.4.5 When is a transaction confirmed? 292\u003cbr\u003e __12.4.6 The Hidden Intuition Behind DMBFM's Safety 293\u003cbr\u003e Summary 295\u003cbr\u003e\u003cbr\u003e CHAPTER 13 Hardware Cryptography 297\u003cbr\u003e 13.1 Attacker Models in Modern Cryptography 297\u003cbr\u003e 13.2 Hardware: The Savior of Untrusted Environments 299 \u003cbr\u003e__13.2.1 White-Box Cryptography 300\u003cbr\u003e __13.2.2 Smart Cards and Security Elements 300\u003cbr\u003e __13.2.3 HSM 303, Loved by Banks\u003cbr\u003e __13.2.4.\u003cbr\u003e Great standardization of security elements, TPM 305\u003cbr\u003e __13.2.5 Secure Computing with TEE 308\u003cbr\u003e 13.3 Which solution should I choose? 309\u003cbr\u003e 13.4 Leak-Resistant Cryptography and Side-Channel Attack Defenses 311\u003cbr\u003e __13.4.1 Constant-Time Programming 313\u003cbr\u003e __13.4.2 Masking and Blinding 315\u003cbr\u003e __13.4.3 How to Deal with Flaw Attacks 316\u003cbr\u003e Summary 316\u003cbr\u003e\u003cbr\u003e CHAPTER 14 Cryptography in the Quantum Computer Age 319\u003cbr\u003e 14.1 What is a Quantum Computer? 320\u003cbr\u003e __14.1.1 Exploring the Small, Quantum Mechanics 320\u003cbr\u003e __14.1.2 From the Birth of Quantum Computers to Quantum Supremacy 323\u003cbr\u003e __14.1.3 Grover and Shor's Algorithm 324\u003cbr\u003e __14.1.4 Post-Quantum Cryptography Against Quantum Computers 326\u003cbr\u003e 14.2 All you need is a hash function! Hash-based signatures 326\u003cbr\u003e __14.2.1 OTS 327 via Lamport Signature\u003cbr\u003e __14.2.2 WOTS and Small Key 329\u003cbr\u003e __14.2.3 Multi-signature via XMSS and SPHINCS+ 330 \u003cbr\u003e14.3 Shorter Keys and Signatures Using Lattice-Based Cryptography 333\u003cbr\u003e __14.3.1 What is a Lattice? 333\u003cbr\u003e __14.3.2 Learning from Errors 335\u003cbr\u003e __14.3.3 Lattice-Based Key Exchange, Kyber 337\u003cbr\u003e __14.3.4 Lattice-Based Signature Scheme, Dilithium 339\u003cbr\u003e 14.4 Are Quantum Computers a Horror? 340\u003cbr\u003e Summary 342\u003cbr\u003e\u003cbr\u003e CHAPTER 15: Next-Generation Cryptography 345\u003cbr\u003e 15.1 MPC 346, the more you play together, the better\u003cbr\u003e __15.1.1 PSI 347\u003cbr\u003e __15.1.2 General Purpose MPC 348\u003cbr\u003e __15.1.3 MPC's current 350\u003cbr\u003e 15.2 FHE and the Future of the Encrypted Cloud 350\u003cbr\u003e __15.2.1 Example of RSA Encryption and Homomorphic Encryption 351\u003cbr\u003e __15.2.2 Various Homomorphic Encryption 351\u003cbr\u003e __15.2.3 The Key to FHE, Bootstrapping 352\u003cbr\u003e __15.2.4 Error-Based Learning-Based FHE System 354\u003cbr\u003e __15.2.5 Where to use it? 356\u003cbr\u003e 15.3 General Purpose ZKP 357\u003cbr\u003e __15.3.1 How zk-SNARKs Work 359\u003cbr\u003e __15.3.2 Isomorphic commit 360 that hides part of the evidence\u003cbr\u003e __15.3.3 Bilinear Pairing to Improve Isomorphic Commit 361\u003cbr\u003e __15.3.4 Where is the brevity? 361\u003cbr\u003e __15.3.5 Program to Polynomial 362\u003cbr\u003e __15.3.6 The program is for computers. \u003cbr\u003eWhat we need is an arithmetic circuit 363\u003cbr\u003e __15.3.7 R1CS Arithmetic Circuit 364\u003cbr\u003e __15.3.8 From R1CS to Polynomials 364\u003cbr\u003e __15.3.9 Computing the Hidden Polynomial in the Exponent 365\u003cbr\u003e Summary 367\u003cbr\u003e\u003cbr\u003e CHAPTER 16 The End of Cryptography 369\u003cbr\u003e 16.1 The tedious task of finding suitable cryptographic primitives or protocols 370\u003cbr\u003e 16.2 How to Use Cryptographic Primitives and Protocols? Standards and Format Verification 371\u003cbr\u003e 16.3 Where are the good libraries? 374\u003cbr\u003e 16.4 Developers Are the Enemy? Cryptography Misuse 376\u003cbr\u003e 16.5 Easy-to-Use Security 377\u003cbr\u003e 16.6 Cryptography is Not an Island 378\u003cbr\u003e 16.7 Cryptography Practitioners' Responsibilities: Don't Test Your Own Cryptography 379\u003cbr\u003e\u003cbr\u003e Summary 381\u003cbr\u003e Practice Problem Answer 383\u003cbr\u003e Search 388\u003c\/div\u003e\n\u003cdiv\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cbr\u003e\u003cdiv\u003e\u003ch5\u003e \u003cb\u003eDetailed image\u003c\/b\u003e \u003c\/h5\u003e\u003c\/div\u003e\n\u003cdiv\u003e\u003cdiv\u003e\u003cimg src=\"https:\/\/image.yes24.com\/momo\/TopCate4071\/MidCate005\/407047429(1).jpg\" border=\"0\" alt=\"Detailed Image 1\"\u003e\u003c\/div\u003e\u003c\/div\u003e\n\u003cbr\u003e\u003cdiv\u003e\u003ch5\u003e \u003cb\u003eInto the book\u003c\/b\u003e\n\u003c\/h5\u003e\u003c\/div\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e Let's say Queen Alice needs to send a letter to Sir Bob, who lives in a castle far away. \u003cbr\u003eQueen Alice asks her loyal messenger to ride his trusty horse across the perilous lands to deliver a precious message to Sir Bob.\u003cbr\u003e But she doesn't completely trust the messenger.\u003cbr\u003e (…) What Queen Alice needs is a protocol that mimics the act of transmitting a message to Sir Bob without an intermediary.\u003cbr\u003e This is a practically unsolvable problem unless you introduce cryptography (or teleportation).\u003cbr\u003e The cryptographic algorithm invented long ago to solve this problem is the symmetric encryption algorithm (also called a cipher).\u003cbr\u003e\u003cbr\u003e --- p.5\u003cbr\u003e\u003cbr\u003e This issue is also a vulnerability that I have discovered several times during my technical audits.\u003cbr\u003e When verifying an authentication tag, the comparison between the received authentication tag and the calculated authentication tag must be performed within a constant time. \u003cbr\u003eThat is, assuming the received tags are of the correct size, the comparison should always take the same amount of time.\u003cbr\u003e The inconsistent time taken to compare two authentication tags may be due to the two tags reflecting different moments during the comparison.\u003cbr\u003e This would allow an attack to measure the time taken for verification and then regenerate a valid authentication tag byte by byte.\u003cbr\u003e This type of attack is called a timing attack.\u003cbr\u003e The following page explains this through a metaphor.\u003cbr\u003e \/ Fortunately, cryptography libraries that implement MACs also provide convenient functions that allow you to verify authentication tags in constant time.\u003cbr\u003e As a practical example, Example 3.3 shows how to implement constant-time comparison of authentication tags in Golang.\u003cbr\u003e\u003cbr\u003e --- p.59\u003cbr\u003e \u003cbr\u003eFirst, to encrypt the message to Alice, we use (EC)DH-based key exchange with Alice's public key and a key pair generated from it (called an ephemeral key pair).\u003cbr\u003e You can then use the shared secret obtained with an authenticated symmetric encryption algorithm such as AES-GCM to encrypt a longer message to send to Alice (Figure 6.19).\u003cbr\u003e \/ Then you can send the temporary public key and ciphertext to Alice.\u003cbr\u003e Alice performs a key exchange with her own key pair using the temporary public key.\u003cbr\u003e You can then use the result to decrypt the ciphertext and get the original message.\u003cbr\u003e\u003cbr\u003e --- p.136\u003cbr\u003e\u003cbr\u003e There are countless places outside of cryptography where randomness is needed. \u003cbr\u003eEven simple Unix programs like ls require randomness! Exploiting bugs in programs can lead to fatal consequences, so binaries employ various tricks to defend against low-level attacks.\u003cbr\u003e One of them is address space layout randomization (ASLR), which randomizes the memory layout of a process each time it runs, requiring random numbers.\u003cbr\u003e Another example is the network protocol TCP, which uses random numbers each time a connection is created to generate an unpredictable sequence of numbers, preventing attacks that attempt to hijack the connection.\u003cbr\u003e (…) NIST, wanting to be different (as always), calls its PRNG a deterministic random bit generator (DRBG).\u003cbr\u003e\u003cbr\u003e --- pp.167~168\u003cbr\u003e \u003cbr\u003eSome attackers have free access to the device, while others have a limited amount of time to execute their attack.\u003cbr\u003e Let's imagine the following scenario:\u003cbr\u003e You left your smartphone or laptop in your hotel room, and a 'malicious' maid came in, opened the device, used low-budget tools to modify the system, and then put the device back where it was.\u003cbr\u003e When you return to your room, the device is in its original place and appears untouched.\u003cbr\u003e This is known as an evil maid attack and can be generalized to many situations (e.g. carrying a device in checked luggage during a flight, storing sensitive keys in an insecure data center, etc.).\u003cbr\u003e\u003cbr\u003e --- p.299\u003cbr\u003e\u003cbr\u003e Since most asymmetric algorithms used today rely on discrete logarithms or factoring problems, Shor's algorithm is fatal to asymmetric cryptography. \u003cbr\u003eOf course, discrete logarithms and factorization remain difficult mathematical problems, and algorithm parameters can be increased in size to improve defense against quantum computers.\u003cbr\u003e Unfortunately, however, in 2017, Bernstein et al. showed that parameter expansion, while effective, is highly impractical.\u003cbr\u003e The study estimated that increasing the parameters of RSA to 1 terabyte would be necessary to achieve quantum resistance.\u003cbr\u003e Parameter sizes of this magnitude are unrealistic.\u003cbr\u003e\n\n\u003c\/div\u003e\n\u003cdiv\u003e --- p.325\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cdiv\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cbr\u003e\u003cdiv\u003e\u003ch5\u003e \u003cb\u003ePublisher's Review\u003c\/b\u003e\n\u003c\/h5\u003e\u003c\/div\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e \u003cb\u003eThe present and future of cryptography: learning through pictures instead of formulas, examples instead of history, and applications instead of theory.\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e Cryptography is the foundation of IT security, including web APIs, user services, and blockchain, but there aren't many books on it worth reading.\u003cbr\u003e Books that start with history, like the Caesar cipher or the Vigenère cipher, are boring. \u003cbr\u003eWhat elements make up modern cryptography, what protocols are commonly used, what attacks have occurred, and what does the future of cryptography hold with the advent of quantum computers?\u003cbr\u003e What practitioners are curious about is this.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e Instead of delving into the history of cryptography or legacy algorithms, the author fills the book with real-world, large-scale use cases today, including TLS, the Noise Protocol framework, the Signal Protocol, cryptocurrencies (the author claims this is the first cryptography book with a full chapter on cryptocurrencies!), HSMs, and threshold cryptography.\u003cbr\u003e Although there are no formulas, we have tried to make the explanation easy to understand by inserting numerous pictures, including Alice and Bob, who are familiar to us. \u003cbr\u003eThe author himself did not know how the elliptic curve mathematics he learned in college was used in real-world algorithms, and many developers are causing security failures by making 'implementation' mistakes. Therefore, for each chapter, he included example snippets written in various languages ​​such as Java, JavaScript, Golang, and Rust, using 'good' libraries.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e Rich diagrams and case studies help developers, system administrators, and security practitioners learn cryptographic concepts like authentication, encryption, and confidentiality, as well as tools, frameworks, and protocols to stay ahead of attackers.\u003cbr\u003e This is the most practical and modern cryptography book, covering everything from the basics like hash functions and signatures to cryptographic protocols like HTTPS and secure messaging, and cutting-edge technologies like post-quantum cryptography (quantum-resistant cryptography) and cryptocurrencies.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e \u003cb\u003eKey Contents\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e Best practices when using cryptography \u003cbr\u003eㆍ Illustrations and explanations of cryptographic algorithms\u003cbr\u003e ㆍ Implementation of digital signatures and zero-knowledge proofs\u003cbr\u003e ㆍ Hardware solutions to prepare for attacks, etc.\u003cbr\u003e How to identify and fix bad practices\u003cbr\u003e ㆍ Selecting the appropriate cryptographic tool for each problem \u003c\/div\u003e\n\u003cdiv\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003cdiv style=\"width:95%;padding-top:20px;padding-bottom:20px\"\u003e\n\n\u003cdiv style=\"text-align:left;font-size:16px;font-weight:bold;padding-bottom:20px\"\u003e GOODS SPECIFICS \u003c\/div\u003e\n\n\u003cdiv style=\"text-align:left;font-size:14px;line-height:1.6em;\"\u003e\n\n\u003cdiv style=\"width:100%;margin-bottom:5px;line-height:1.6em;font-size:14px\"\u003e - \u003cstrong\u003eDate of issue:\u003c\/strong\u003e January 20, 2023\u003c\/div\u003e\n\n\u003cdiv style=\"width:100%;margin-bottom:5px;line-height:1.6em;font-size:14px\"\u003e - \u003cstrong\u003ePage count, weight, size:\u003c\/strong\u003e 424 pages | 806g | 188*245*22mm\u003c\/div\u003e\n\n\u003cdiv style=\"width:100%;margin-bottom:5px;line-height:1.6em;font-size:14px\"\u003e - \u003cstrong\u003eISBN13:\u003c\/strong\u003e 9791192469539\u003c\/div\u003e\n\n\u003cdiv style=\"width:100%;margin-bottom:5px;line-height:1.6em;font-size:14px\"\u003e - \u003cstrong\u003eISBN10:\u003c\/strong\u003e 1192469534 \u003c\/div\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e\n\n\u003ccenter\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003ccenter\u003e\u003ctable\u003e\u003ctr\u003e\u003ctd style=\"height:10px\"\u003e\u003c\/td\u003e\u003c\/tr\u003e\u003c\/table\u003e\u003c\/center\u003e\n\n\u003cspan\u003e\u003c\/span\u003e\n\n\u003c\/center\u003e\n\n\n\u003c\/center\u003e","brand":"LIBRAIRIE COREENNE","offers":[{"title":"Default Title","offer_id":43893345779754,"sku":"139201","price":44.0,"currency_code":"EUR","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0683\/2750\/5962\/files\/fc306e7cca2b398337e377946690888e.jpg?v=1765397549","url":"https:\/\/librairie.coreenne.fr\/en\/products\/139201","provider":"LIBRAIRIE COREENNE","version":"1.0","type":"link"}