This Course will have 5 to 6 assignments. They will be put up as soon as they are discussed in the class. For group assignments, the groups will also be put with the assignments.
Assignments Submission Instructions
- Please DO NOT copy the assignments.
- Adhere to deadlines strictly. Assignments submitted after deadline will not be considered.
- Assignments SHOULD be in the following format:
- All the assignments must be within a single directory named "your_register_number"_"assignment_no" .
eg., 03329012_1 for a person with register number 03329029 and submitting the first assignment.
- There should be a README file in text format in this directory, containing your name, roll number and anything you want to tell about your assignment.
- tar zip this directory into a single file as follows:
tar -zcvf dirname.tgz directory
eg., tar -zcvf 03329029_1.tgz 03329029_1/
- Assigment file (the .tgz file) must be mailed to it653-assignments[at]it.iitb.ac.in
List of Assignments (In Chronological Order)
-
Assignment I
1.1)  Design an experiment to estimate the amount of time to
a) Generate key Pair (RSA)
b) Encrypt n bit message (RSA)
c) Decrypt n bit message (RSA)
as function of Keysize.
Experiment with different n-bit messages. Summarize your conclusion.
Deadline for 1.1 is 20/08/2004
Here is the source code of the java program demonstrated in the class for implementation of RSA.
Here is a link to the local copy of Java 2 Platform API doccumentation.
Here is a link directly to the page containing the documentation for BigInteger class.
1.2)   The first step in generating encrypt/decrypt keys in RSA is to generate two prime numbers p & q. Now suppose p is not
prime but rather the product of two primes p1 & p2.
a) Will this pose a problem in any way?
b) if so,how/why and how often?
Deadline for 1.2 is 16/08/2004
1.3) Search the web/text books to obtain the following definitions.
a) Cookie (abut half page).
b) Salt (few lines).
c) Nonce (few lines).
d) Stream cipher
Deadline for 1.3 is 16/08/2004
- Assignment II
2.1)  A wishes to initiate a session with B which will include a sequence of message exchanges with B.
Assume that
A is not known to B.
A knows of B but has never communicated with B before.
Only B (but not A) has a digital certificate.
Both parties wish to maintain the confidentiality and integrity of each message.A must make sure it is communicating with B and not someone posing as B.
Design a protocol to ensure the requirements above. The protocol should not be susceptible to the kinds of hacker attacks discussed in class.
Now suppose that B wishes to ensure it is communicating with A and not someone posing as A. Is this possible without A having a certificate? Explain.
Deadline for 2.1 is 3/09/2004
2.2)   Investigate the certification authorities that exist in India. Whom or which class of people do they issue certificates to? Can you receive a certificate from any of them? If so, under what conditions? In what domain areas are these certificates valid? What mechanisms are provided for certificate revocation?
2.3)   Investigate the use of smart cards globally including in India. What applications are they most used for? (For example, Transportation 30%, E-Purse 15% or whatever). How many of these have 8, 16, 32 bit processors or none at all? And run at what clock speeds? What are the RAM, ROM and EEPROM capacities? How many have a crypto accelerator? How many are loaded with MultOS, or Java cards, Microsoft OS, etc.?
For each of the above what are the projections2, 3, 5 years down the line?
Deadline for 2.2 and 2.3 is 8/09/2004