← All CBCP Flashcard Decks

Cryptography and Hashing Flashcards

7 cards from real CBCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cryptography and Hashing flashcards as text
  1. What is the role of the generator point G in elliptic curve cryptography as used in blockchain systems?

    Answer: It is a publicly known fixed point on the curve used to compute public keys via scalar multiplication

    The generator point G is a standardized curve point; the public key is derived as k·G where k is the private key, and the discrete log problem makes reversing this infeasible.

  2. What does the term 'entropy' mean in the context of generating a blockchain private key or seed phrase?

    Answer: A measure of randomness indicating how unpredictable the generated value is

    Entropy quantifies the unpredictability of the random source; a 256-bit private key requires 256 bits of entropy from a cryptographically secure random number generator.

  3. Which BIP standard defines the mnemonic seed phrase (12–24 words) used to back up HD wallets?

    Answer: BIP-39

    BIP-39 specifies converting entropy into a human-readable mnemonic word list and then deriving a binary seed from those words via PBKDF2.

  4. How does a zero-knowledge proof allow one party to prove knowledge of a secret without revealing the secret itself?

    Answer: By demonstrating possession of information through a mathematical protocol that reveals no additional details

    Zero-knowledge proofs use mathematical protocols (e.g., zk-SNARKs, zk-STARKs) where a prover convinces a verifier of a statement's truth without exposing any underlying private data.

  5. In threshold cryptography, what does an (m, n) threshold signature scheme mean?

    Answer: Any m out of n keyholders can jointly produce a valid signature, but fewer than m cannot

    An (m, n) threshold scheme distributes a private key across n parties such that any m of them can collaborate to sign, improving security by eliminating single points of failure.

  6. What is the primary security risk of reusing the same ECDSA nonce (k) for two different signatures with the same private key?

    Answer: The private key can be mathematically extracted from the two signatures

    If k is reused, an attacker with two signatures and the known nonce can solve for the private key algebraically using the ECDSA signature equations.

  7. Which construction does SHA-256 use to process arbitrarily long messages through fixed-size compression rounds?

    Answer: Merkle-Damgård construction

    SHA-256 uses the Merkle-Damgård construction, which pads the message, splits it into fixed-size blocks, and iteratively applies a compression function to produce the final hash.