Cryptography and Security Flashcards
6 cards from real CBCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Cryptography and Security flashcards as text
In public-key cryptography as used in blockchain, what is the primary function of the private key?
Answer: To encrypt the hash of a transaction, creating a digital signature.
The private key is used to create a digital signature by encrypting the hash of a transaction's data. This signature serves as proof that the transaction was authorized by the owner of the private key, ensuring authenticity and non-repudiation. Anyone with the corresponding public key can then verify this signature.
A malicious actor gains control of a large number of nodes on a blockchain network by creating multiple fake identities. They then use this influence to isolate a genuine node from the rest of the network, feeding it false information. What type of attack is this?
Answer: Sybil Attack
A Sybil attack involves a single entity creating and controlling numerous fake identities (nodes) within a peer-to-peer network to gain a disproportionately large influence. This control can then be used to carry out other attacks, such as an eclipse attack where a specific node is isolated from the true network.
Which cryptographic technique allows for computations to be performed on encrypted data without decrypting it first, offering enhanced privacy for smart contracts and blockchain analytics?
Answer: Homomorphic Encryption
Homomorphic encryption is a specific form of encryption that allows computations to be performed directly on ciphertext. The result of the computation, when decrypted, is the same as if the operations had been performed on the plaintext, making it ideal for privacy-preserving computations on a transparent ledger.
A user wants to prove they have a sufficient account balance to enter a decentralized lottery without revealing their actual balance or transaction history. Which cryptographic method is best suited for this scenario?
Answer: Zero-Knowledge Proof (ZKP)
A Zero-Knowledge Proof (ZKP) is a cryptographic protocol that allows a 'prover' to prove to a 'verifier' that a statement is true, without revealing any information beyond the validity of the statement itself. This is perfect for privacy-focused applications where specific facts need to be verified without disclosing the underlying sensitive data.
Compared to the RSA algorithm, what is the primary advantage of using Elliptic Curve Cryptography (ECC) for generating key pairs in blockchain systems like Bitcoin and Ethereum?
Answer: It provides the same level of security with significantly smaller key sizes.
The main advantage of ECC over RSA is its efficiency. ECC can provide the same level of cryptographic security as RSA but with much smaller key sizes. For example, a 256-bit ECC key offers comparable security to a 3072-bit RSA key, which leads to lower computational overhead and faster processing, crucial for blockchain performance.
A developer is building a decentralized application and needs to store user private keys. Which of the following represents the MOST secure storage practice?
Answer: Storing keys offline in a hardware wallet and requiring user interaction for signing.
The most secure practice is to keep private keys in 'cold storage,' completely offline and disconnected from the internet. A hardware wallet is a physical device that stores keys offline and requires physical interaction to sign transactions, which significantly reduces the risk of online threats like hacking and malware.