Asymmetric Encryption and Key Exchange Questions

The construction and mathematics-adjacent mechanics of public-key (asymmetric) cryptography: how RSA, Diffie-Hellman, and elliptic-curve schemes actually work, including the group law and point-arithmetic formulas, scalar-multiplication algorithms (double-and-add, Montgomery ladder, windowed methods, GLV, multi-scalar batching), curve models and coordinate systems, and the hardness assumptions (integer factorization, discrete log, ECDLP) each scheme rests on. Covers key-establishment and authenticated key-exchange protocol design: forward-secrecy mechanics, key confirmation, downgrade protection, key-derivation and context binding, group and multi-party key agreement, and hybrid classical/post-quantum key-exchange composition. Also covers implementation-level attacks against these primitives and their mitigations: timing and side-channel leakage in modular exponentiation and scalar multiplication, invalid-curve and small-subgroup attacks, fault attacks, and padding-oracle attacks. Distinct from selecting, deploying, and operating these primitives in production: PKI certificate lifecycle, CA hierarchy, revocation, and key storage and rotation belong to applied cryptography and key management.

MediumTechnical
120 practiced

Implement an RSA key generation routine in Python (pseudocode acceptable) that produces a key pair of a specified bit length. Your implementation should use a secure random source, perform Miller-Rabin primality testing with sufficient rounds, select a standard public exponent, ensure gcd(e, phi(n)) = 1, compute d as modular inverse, and validate final key properties. Describe complexity and practical pitfalls.

HardTechnical
83 practiced

Provide code or detailed pseudocode (Python acceptable) to convert a point on an Edwards curve to an equivalent point on a short Weierstrass curve and vice versa using the birational maps between models. Ensure your implementation handles the identity element, checks for undefined mappings, and documents special cases that must be handled for correctness on curve parameters like Ed25519.

HardTechnical
70 practiced

Provide a detailed description of Bleichenbacher's adaptive chosen-ciphertext attack against RSA PKCS#1 v1.5 encryption. Explain how an oracle that reveals padding validity can be exploited to decrypt ciphertexts, the mathematical interval narrowing used, and practical server-side defenses including constant-time uniform error handling and migration to OAEP.

MediumTechnical
67 practiced

Explain why including explicit context and protocol identifiers (for example transcript hashes, ciphersuite IDs, or role labels) in KDF inputs is critical. Provide an example where missing context allowed two different protocols to derive the same symmetric key from different inputs and caused cross-protocol key reuse vulnerability.

HardTechnical
66 practiced

An implementation uses RSA with CRT optimization for decryption but omits result blinding. Describe the Bellcore fault attack that extracts RSA private key factors using a single faulty decryption or signature. Explain why CRT makes the attack easier and propose robust countermeasures, including blinding, integrity checks, and hardware defenses.

Unlock Full Question Bank

Get access to all Asymmetric Encryption and Key Exchange interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.