Cryptanalysis and Security Proofs Questions

Evaluating the strength of cryptographic constructions: attack techniques, cryptanalysis of ciphers and protocols, reduction-based security proofs, and formal analysis. Covers reasoning about what an adversary can and cannot do and how security guarantees are argued rigorously. The offensive-and-verification counterpart to scheme design.

MediumTechnical
37 practiced

Given a toy 3-round Feistel cipher with 32-bit block size, independent 32-bit round keys, and a known S-box-based round function whose S-box differential probabilities are provided, outline a differential cryptanalysis strategy to recover round key bits. Specify how to select input differences, build characteristics across rounds, estimate the number of chosen plaintext pairs needed, and indicate computational steps to rank key candidates.

MediumTechnical
17 practiced

Explain sequential and parallel composition theorems for cryptographic primitives. Using a concrete example, analyze how composing two IND-CPA encryption instances in parallel affects the reduction strategy and the security bound, and explain subtle issues that may arise such as shared randomness, correlated keys, or information leakage across components.

HardTechnical
32 practiced

Describe in detail how you would mechanize an IND-CCA proof of a hybrid encryption protocol using a proof assistant of your choice (EasyCrypt, CryptoVerif, Tamarin, or ProVerif). For your chosen tool explain modeling choices (programs, oracles, ideal functionalities), which lemmas require manual proofs, how to represent probabilistic advantage bounds, and common obstacles such as modeling programmable random oracles or adaptive decryption oracles.

MediumTechnical
19 practiced

For deterministic signature schemes (signer uses no randomness), explain why standard UF-CMA proofs require care. Define strong unforgeability and message-replay concerns unique to deterministic schemes, and sketch a reduction that relates forging such a deterministic signature to breaking collision resistance or one-wayness of an underlying hash/primitive.

MediumTechnical
25 practiced

Describe algebraic attacks on ciphers: how cipher components (S-boxes, linear layers, LFSRs) are modeled as polynomial equations over GF(2), which solving techniques are commonly used (SAT solvers, Groebner bases, XL), and what properties of a primitive make it vulnerable to algebraic attacks.

Unlock Full Question Bank

Get access to all Cryptanalysis and Security Proofs interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.