← All Cryptocurrency Flashcard Decks

Core Cryptographic Principles Flashcards

7 cards from real Cryptocurrency practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Core Cryptographic Principles flashcards as text
  1. What is a 'padding oracle attack' and which cipher mode is most vulnerable to it?

    Answer: An attack that exploits error messages about invalid padding in CBC mode to decrypt ciphertext

    In a padding oracle attack, an attacker queries a system that reveals whether decrypted padding is valid, allowing CBC-mode ciphertext to be decrypted block-by-block.

  2. In the context of digital signatures, what does 'non-repudiation' mean?

    Answer: The signer cannot later deny having signed the message because only they hold the private key

    Non-repudiation means the signer cannot plausibly deny signing a message, since only the holder of the private key could have produced the valid signature.

  3. Which of the following is a post-quantum cryptographic algorithm standardized by NIST in 2024?

    Answer: CRYSTALS-Kyber (ML-KEM)

    CRYSTALS-Kyber, standardized as ML-KEM by NIST in 2024, is a lattice-based key encapsulation mechanism designed to resist quantum computer attacks.

  4. What is 'key stretching' and which algorithms are commonly used for it?

    Answer: Deliberately slowing down hash computation to make brute-force attacks more expensive; used in bcrypt, scrypt, and Argon2

    Key stretching algorithms like bcrypt, scrypt, and Argon2 apply thousands of hash iterations and memory requirements to make password cracking computationally expensive.

  5. What is the primary cryptographic purpose of a Merkle tree in Bitcoin?

    Answer: To efficiently verify that a specific transaction is included in a block without downloading all transactions

    Merkle trees allow Simplified Payment Verification (SPV) clients to verify transaction inclusion by checking a logarithmic-length proof path rather than all transactions.

  6. What vulnerability is introduced when the same private key is used to sign two different messages with the same nonce in ECDSA?

    Answer: The private key can be algebraically recovered from the two signatures

    If the same nonce k is reused in two ECDSA signatures, a simple algebraic equation allows anyone to compute the signer's private key — this famously compromised PlayStation 3.

  7. What is the purpose of 'key derivation functions' (KDFs) like HKDF in cryptographic protocols?

    Answer: To derive multiple cryptographically strong keys from a single shared secret or master key

    KDFs like HKDF take a shared secret or master key and derive multiple independent, cryptographically strong subkeys for different purposes (encryption, authentication, etc.).