Asymmetric Encryption and Key Exchange Questions

The construction and mathematics-adjacent mechanics of public-key (asymmetric) cryptography: how RSA, Diffie-Hellman, and elliptic-curve schemes actually work, including the group law and point-arithmetic formulas, scalar-multiplication algorithms (double-and-add, Montgomery ladder, windowed methods, GLV, multi-scalar batching), curve models and coordinate systems, and the hardness assumptions (integer factorization, discrete log, ECDLP) each scheme rests on. Covers key-establishment and authenticated key-exchange protocol design: forward-secrecy mechanics, key confirmation, downgrade protection, key-derivation and context binding, group and multi-party key agreement, and hybrid classical/post-quantum key-exchange composition. Also covers implementation-level attacks against these primitives and their mitigations: timing and side-channel leakage in modular exponentiation and scalar multiplication, invalid-curve and small-subgroup attacks, fault attacks, and padding-oracle attacks. Distinct from selecting, deploying, and operating these primitives in production: PKI certificate lifecycle, CA hierarchy, revocation, and key storage and rotation belong to applied cryptography and key management.

EasyTechnical
73 practiced

What is key confirmation in a key-exchange protocol? Give two mechanisms for mutual key confirmation (for example, a MAC over the transcript using the derived key, and an explicit signature over the key material) and explain how key confirmation prevents certain active and reflection attacks.

EasyTechnical
73 practiced

Explain why RSA encryption requires padding and what OAEP (Optimal Asymmetric Encryption Padding) provides. Describe at a high level how OAEP encoding and decoding protect against chosen-ciphertext attacks and why deterministic RSA is dangerous.

HardTechnical
83 practiced

Describe in detail the classes of side-channel and fault-injection attacks that can extract private keys during scalar multiplication (simple power analysis, differential power analysis, injection of faults to induce incorrect curve operations). For each class, propose layered mitigations covering algorithmic changes, hardware features, detection, and protocol-level countermeasures.

MediumTechnical
74 practiced

A library you're reviewing computes an ECDH shared secret straight from whatever public key a peer sends, with no validation at all before use. Walk through the full set of checks you'd insist go in before that value is trusted, from confirming the point actually belongs to the curve through to how you'd handle its subgroup, and for each one, name the specific class of attack it closes off.

EasyTechnical
77 practiced

Explain step-by-step how RSA key generation works for a 2048-bit key. Include selecting strong primes p and q, computing modulus n = p * q, computing phi(n) (or lambda), choosing a public exponent e, computing the private exponent d as modular inverse, and producing the public/private key pair. Describe necessary checks for prime quality, randomness sources, CRT parameters, and common pitfalls such as low entropy or small primes.

Unlock Full Question Bank

Get access to all 15 Asymmetric Encryption and Key Exchange interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.