Cryptography and Security Flashcards
7 cards from real CBCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cryptography and Security flashcards as text
Which elliptic curve is used by Bitcoin for its digital signature scheme?
Answer: secp256k1
Bitcoin uses the secp256k1 elliptic curve, defined by SECG, for its ECDSA signature scheme.
What is the primary purpose of a Merkle tree in blockchain cryptography?
Answer: Providing efficient and tamper-evident summarization of transaction sets
Merkle trees allow efficient, tamper-evident verification of large transaction sets by hashing pairs of hashes up to a single root.
In a threshold signature scheme (TSS), what does a (t, n) configuration mean?
Answer: n total keys exist, any t of them must sign to produce a valid signature
A (t, n) TSS means there are n shares distributed, and any t of those shareholders must cooperate to produce a valid signature.
What cryptographic property ensures that a blockchain transaction cannot be denied by its sender?
Answer: Non-repudiation
Non-repudiation, achieved via digital signatures, ensures a sender cannot later deny having signed and sent a transaction.
Which attack exploits the birthday paradox to find collisions in hash functions?
Answer: Birthday attack
A birthday attack leverages the birthday paradox to find two inputs that hash to the same output far faster than brute force.
What does 'key derivation' accomplish in a hierarchical deterministic (HD) wallet?
Answer: It derives multiple child key pairs from a single master seed deterministically
HD wallets use key derivation (BIP-32) to generate a tree of child key pairs from one master seed, enabling backup with a single phrase.
What is a length extension attack, and which hash functions are vulnerable?
Answer: An attack that computes H(m || extra) from H(m) without knowing m; MD5 and SHA-1 are vulnerable
Length extension attacks allow computing H(m || extra) from H(m) alone using Merkle-Damgård construction; MD5, SHA-1, and SHA-2 are vulnerable.