Cryptanalysis and Security Proofs Questions

Evaluating the strength of cryptographic constructions: attack techniques, cryptanalysis of ciphers and protocols, reduction-based security proofs, and formal analysis. Covers reasoning about what an adversary can and cannot do and how security guarantees are argued rigorously. The offensive-and-verification counterpart to scheme design.

EasyTechnical
19 practiced

Estimate the time required to brute-force symmetric keys of length 56, 80, 112, and 128 bits on a machine that can test 1e9 keys per second. Provide results in seconds, days, and years, and briefly discuss how parallelization or specialized hardware changes these estimates.

EasyTechnical
17 practiced

Explain the birthday paradox and why generic collision search against an n-bit hash function requires about 2^{n/2} evaluations. Compute approximate expected work to find a collision for n=128 and n=256, and discuss practical implications for choosing hash output size in modern systems.

MediumTechnical
24 practiced

Estimate the practical feasibility of factoring a 1024-bit RSA modulus using current best classical algorithms. Compare Pollard rho, elliptic curve method (ECM) for small factors, and the general number field sieve (GNFS) asymptotics. Given a 1000-core cluster providing 1000 CPU-years per calendar year, argue whether 1024-bit factoring is within reach and provide a rough cost estimate and time-to-completion reasoning.

EasyTechnical
18 practiced

Explain the meet-in-the-middle attack on double-DES (ciphertext C = E_{k2}(E_{k1}(P))). Derive the time and memory complexity in terms of single-DES key size k=56 and show the numeric work factor and memory requirement. Explain why double-DES was not considered secure and how 3DES addresses the issue.

MediumTechnical
22 practiced

Explain how you would distinguish a theoretical cryptographic weakness (e.g., best-published attack complexity slightly below brute force) from a practically exploitable weakness in an in-use protocol. List at least five criteria or heuristics you would evaluate and describe one empirical test you could run to validate practical exploitability.

Unlock Full Question Bank

Get access to all 6 Cryptanalysis and Security Proofs interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.