Symmetric Encryption and Block Ciphers Questions

How symmetric-key primitives are constructed and why they work: block-cipher internals (Feistel networks vs substitution-permutation networks, the AES round structure and S-box design, key schedules and why a weak one degrades security), stream ciphers (ChaCha20 and CTR-mode keystream generation), and the internal mechanics of modes of operation (ECB, CBC, CTR, XTS, GCM), including why some are parallelizable, why ECB leaks structure, and why some require a unique nonce. Covers authenticated encryption construction internals (how GHASH and Poly1305 work, why nonce reuse breaks their security algebraically, formal security notions like IND-CPA and INT-CTXT), padding schemes and the mechanics of padding-oracle attacks, and cryptanalysis of block ciphers (differential and linear cryptanalysis, reduced-round attacks). This is the design and internals layer: how these primitives are built and proven secure, distinct from choosing which algorithm or mode to deploy, managing key lifecycle and rotation, or architecting data protection for a system, which belong to the applied cryptography layer.

HardTechnical
32 practiced

You observe microsecond-level timing differences in an otherwise uniform decryption API that correlate with padding validation steps, effectively providing a timing-based padding oracle even though error messages are unified. Describe how an attacker could exploit this channel, how you would measure and confirm the oracle in noisy networks, and practical countermeasures both at the API boundary and inside the crypto library.

EasyTechnical
28 practiced

Explain the role of Associated Data (AAD) in AEAD constructions. Provide two concrete examples where AAD is necessary (for example: network headers in TLS/QUIC, sequence numbers or frame metadata) and describe what can go wrong if AAD is omitted or handled incorrectly.

EasyTechnical
34 practiced

List and explain five common implementation pitfalls when using AEAD in real systems (for example: nonce reuse in GCM, verifying tag after parsing plaintext, truncated tags, improper AAD handling, non-constant-time comparisons). For each pitfall describe the practical security consequence and a mitigation.

EasyTechnical
28 practiced

Describe in detail the internal structure of AES-GCM: explain the role of CTR mode for confidentiality, GHASH for authentication (polynomial evaluation in GF(2^128)), how the IV/nonce is processed (96-bit optimized case vs general case), and how the authentication tag is computed and verified.

MediumTechnical
30 practiced

A messaging protocol encrypts payloads with AEAD but leaves the protocol version and sender ID in plaintext headers (not included in AAD). Describe concrete attacks that become possible due to this omission, such as downgrade, replay, or cross-user message mixup attacks. Propose a redesign of the message format and AAD usage to mitigate these vulnerabilities.

Unlock Full Question Bank

Get access to all 21 Symmetric Encryption and Block Ciphers interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.