pk.org: Computer Security/Lecture Notes

Authentication and Secure Communication

Terms we covered

Paul Krzyzanowski – 2026-09-24

Secure Communication

Security protocol
A sequence of messages exchanged to achieve a security goal.
Key establishment
Getting a shared secret key to the parties that need it, and only them.
Pre-shared key
A secret distributed out of band before communication begins.
Trusted third party
A party that participants rely on to vouch for keys or identities.
Public key transport
One party generating a key and sending it encrypted under the other’s public key.
Diffie-Hellman key agreement
Two parties computing a shared secret from values exchanged in the open.
Long-term key
A key that identifies a party across many connections.
Session key
A key that protects one conversation and is then discarded.
Adversary in the middle (AiTM)
An attacker relaying traffic between two parties who believe they are talking directly. Also called man in the middle (MITM).
Replay attack
Reusing a valid message outside the context in which it was sent.
Freshness
Evidence that a message belongs to the current exchange or a recent period.
Nonce
A value intended for one use.
Timestamp
The sending time, included in a protected message so the receiver can judge recency.
Sequence number
An increasing counter that lets a receiver reject duplicated or reordered messages.
Challenge-response authentication
Proving knowledge of a key by computing a response to a fresh challenge.
One-way authentication
One party authenticating the other, but not the reverse.
Mutual authentication
Each party authenticating the other.
Reflection attack
Sending a party’s own challenge back so that it answers itself.
Session hijacking
Taking over a session after authentication has finished.
Authenticated key exchange
A protocol that establishes shared keys and authenticates one or both participants.

Key Distribution with a Trusted Third Party

Key distribution center (KDC)
A trusted server that shares a key with every participant and issues session keys.
Ticket
A credential created by a trusted third party that only the recipient can decrypt.
Needham-Schroeder protocol
A 1978 protocol for obtaining a session key from a trusted server.
Denning-Sacco attack
Replaying an old Needham-Schroeder ticket whose session key was compromised.
Otway-Rees protocol
A key distribution protocol that uses nonces from both parties instead of clocks.
Kerberos
A ticket-based authentication system built around a key distribution center.
Authentication server (AS)
The Kerberos service that verifies a user at login.
Ticket-granting server (TGS)
The Kerberos service that issues tickets for individual services.
Ticket-granting ticket (TGT)
A Kerberos ticket used to request service tickets without the password.
Service ticket
A ticket for one service, encrypted under that service’s key.
Authenticator
The client’s name and current time, encrypted under a ticket’s session key.
Single sign-on
One login giving access to many services.

Public Key Authentication and TLS

Elliptic-curve Diffie-Hellman (ECDH)
Diffie-Hellman key agreement using elliptic curves, with smaller public values.
Hybrid cryptosystem
Establishing a key with public-key cryptography and protecting data with symmetric encryption.
Hybrid key establishment
Combining a classical and a post-quantum method to derive one key.
Ephemeral key
A key-agreement value used for one handshake and then erased.
Forward secrecy
Keeping recorded sessions secret after a long-term key is compromised. Also called perfect forward secrecy.
Transport Layer Security (TLS)
The protocol that authenticates servers and protects HTTPS connections.
TLS handshake
The messages that negotiate algorithms, authenticate the server, and establish keys.
Record
A chunk of the TLS data stream, encrypted and authenticated as a unit.
Transcript hash
A hash of the handshake messages exchanged so far.
Downgrade attack
Forcing parties to negotiate a weaker protocol version or algorithm.
Mutual TLS (mTLS)
TLS with certificates authenticating both the client and the server.
0-RTT
Early TLS application data sent before the server replies, which can be replayed and lacks forward secrecy.

Passwords

Identification
Claiming an identity.
Authentication
Verifying a claimed identity.
Authorization
Determining what an authenticated party is allowed to do.
Authentication factor
A category of evidence: something you know, have, or are.
Multi-factor authentication (MFA)
Requiring evidence from two or more different factor categories.
Password Authentication Protocol (PAP)
Sending the password to the server, which compares it with its records.
Challenge-Handshake Authentication Protocol (CHAP)
Proving password knowledge by hashing it with a challenge from the server.
Online guessing
Submitting password guesses to the login service.
Offline guessing
Testing password guesses against stolen or captured data.
Dictionary attack
Guessing likely passwords and their common variations first.
Rainbow table
A compact precomputed table for reversing unsalted hashes of likely passwords.
Salt
A random value stored with each password hash to make it unique.
Password hashing function
A deliberately slow hash with a tunable cost, used to store passwords.
bcrypt
A password hashing function with an adjustable cost parameter.
scrypt
A password hashing function that requires a large amount of memory per hash.
Argon2
A password hashing function with adjustable time and memory costs, recommended for new systems.
PBKDF2
A password hashing function that repeats HMAC many times.
Credential stuffing
Trying username and password pairs leaked from one site on other sites.
Password spraying
Trying a few common passwords against many accounts.
Password manager
Software that generates and stores a unique password for each site.

Beyond Passwords

One-time password (OTP)
A code accepted for at most one successful authentication.
Hash chain
A sequence of values produced by repeatedly hashing a seed.
HMAC-based one-time password (HOTP)
A one-time code computed from a shared key and a counter.
Time-based one-time password (TOTP)
A one-time code computed from a shared key and the current time.
SIM swap
Moving a victim’s phone number to a SIM card the attacker controls.
Push fatigue
Sending repeated login prompts until the user approves one. Also called MFA fatigue.
Number matching
Requiring the user to enter a number from the login screen into the app.
Session cookie
A token the browser sends to show it has already authenticated.
Passkey
A public-key credential bound to one site, whose private key stays with the user.
Synced passkey
A passkey copied to a user’s approved devices through a sync provider.
Device-bound passkey
A passkey whose private key never leaves one authenticator.
Security key
A USB or NFC device that holds keys and answers login challenges.
WebAuthn
The browser interface for creating and using public-key credentials.
FIDO2
The standards for public-key authentication to websites, including WebAuthn.
Origin
A web page’s scheme, host, and port.

Biometric Authentication

Biometric authentication
Verifying identity from physical or behavioral characteristics.
Template
The stored biometric features created at enrollment.
Enrollment
Capturing samples and building a user’s biometric template.
Threshold
The similarity cutoff for accepting a biometric match.
False accept rate (FAR)
The probability that the system accepts an impostor.
False reject rate (FRR)
The probability that the system rejects the legitimate user.
Receiver operating characteristic (ROC) curve
A plot of correct acceptances against false acceptances across thresholds.
Operating point
The threshold a deployment chooses, and its resulting error rates.
Biometric verification
Comparing a sample with the template of one claimed identity.
Biometric identification
Searching every template to find whom a sample belongs to.
Minutiae
Points where fingerprint ridges end or split.
Presentation attack
Fooling a biometric sensor with a substitute, such as a photograph or mold.
Liveness detection
Checking that a sample comes from a live person at the sensor.