mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-25 05:50:57 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# Standards and References - End-to-End Encryption for Messaging
|
||||
|
||||
## Signal Protocol Specifications
|
||||
|
||||
### The Double Ratchet Algorithm
|
||||
- **URL**: https://signal.org/docs/specifications/doubleratchet/
|
||||
- **Description**: Core key management algorithm for E2EE messaging
|
||||
|
||||
### The X3DH Key Agreement Protocol
|
||||
- **URL**: https://signal.org/docs/specifications/x3dh/
|
||||
- **Description**: Initial key exchange using Extended Triple Diffie-Hellman
|
||||
|
||||
### The Sesame Algorithm
|
||||
- **URL**: https://signal.org/docs/specifications/sesame/
|
||||
- **Description**: Multi-device session management
|
||||
|
||||
## Cryptographic Standards
|
||||
|
||||
### RFC 7748 - Elliptic Curves for Security (X25519)
|
||||
- **URL**: https://www.rfc-editor.org/rfc/rfc7748
|
||||
- **Description**: X25519 Diffie-Hellman key exchange
|
||||
|
||||
### RFC 5869 - HKDF (HMAC-based Key Derivation Function)
|
||||
- **URL**: https://www.rfc-editor.org/rfc/rfc5869
|
||||
- **Description**: Key derivation for chain key updates
|
||||
|
||||
### RFC 8032 - Edwards-Curve Digital Signature Algorithm (Ed25519)
|
||||
- **URL**: https://www.rfc-editor.org/rfc/rfc8032
|
||||
- **Description**: Identity key signatures
|
||||
|
||||
### NIST SP 800-38D - AES-GCM
|
||||
- **URL**: https://csrc.nist.gov/publications/detail/sp/800-38d/final
|
||||
- **Description**: Authenticated encryption for messages
|
||||
|
||||
## Python Libraries
|
||||
|
||||
### cryptography
|
||||
- **X25519**: `cryptography.hazmat.primitives.asymmetric.x25519`
|
||||
- **HKDF**: `cryptography.hazmat.primitives.kdf.hkdf`
|
||||
- **AES-GCM**: `cryptography.hazmat.primitives.ciphers.aead.AESGCM`
|
||||
@@ -0,0 +1,87 @@
|
||||
# Workflows - End-to-End Encryption for Messaging
|
||||
|
||||
## Workflow 1: X3DH Key Agreement
|
||||
|
||||
```
|
||||
Alice (initiator) Server Bob (responder)
|
||||
| | |
|
||||
| |<-- Register: |
|
||||
| | Identity Key (IK_B) |
|
||||
| | Signed PreKey (SPK_B)|
|
||||
| | One-Time PreKeys |
|
||||
| | |
|
||||
|-- Fetch Bob's Keys ----------->| |
|
||||
|<-- IK_B, SPK_B, OPK_B --------| |
|
||||
| | |
|
||||
[Compute shared secret]: |
|
||||
DH1 = DH(IK_A, SPK_B) |
|
||||
DH2 = DH(EK_A, IK_B) |
|
||||
DH3 = DH(EK_A, SPK_B) |
|
||||
DH4 = DH(EK_A, OPK_B) |
|
||||
SK = HKDF(DH1 || DH2 || DH3 || DH4) |
|
||||
| | |
|
||||
|-- Send Initial Message ------->|-- Forward to Bob ------>|
|
||||
| (IK_A, EK_A, OPK_id, msg) | |
|
||||
| | [Bob computes same SK]|
|
||||
```
|
||||
|
||||
## Workflow 2: Double Ratchet (Sending)
|
||||
|
||||
```
|
||||
[Message to Send]
|
||||
|
|
||||
[Check: Do we have recipient's new DH public key?]
|
||||
YES --> [DH Ratchet Step]
|
||||
- Generate new DH key pair
|
||||
- Compute DH shared secret
|
||||
- Derive new root key + sending chain key via HKDF
|
||||
NO --> [Continue with current sending chain]
|
||||
|
|
||||
[Symmetric Ratchet: Derive message key from sending chain]
|
||||
(chain_key, message_key) = HMAC(chain_key, constants)
|
||||
|
|
||||
[Encrypt message with AES-256-GCM using message_key]
|
||||
|
|
||||
[Include header: DH public key, previous chain length, message number]
|
||||
|
|
||||
[Delete message_key from memory]
|
||||
```
|
||||
|
||||
## Workflow 3: Double Ratchet (Receiving)
|
||||
|
||||
```
|
||||
[Received Encrypted Message + Header]
|
||||
|
|
||||
[Check DH public key in header]
|
||||
[New key?]
|
||||
YES --> [DH Ratchet Step]
|
||||
- Compute DH shared secret
|
||||
- Derive new root key + receiving chain key
|
||||
NO --> [Use current receiving chain]
|
||||
|
|
||||
[Symmetric Ratchet: Derive message key]
|
||||
|
|
||||
[Decrypt message with AES-256-GCM]
|
||||
|
|
||||
[Verify authentication tag]
|
||||
FAIL --> Reject message
|
||||
PASS --> Return plaintext
|
||||
|
|
||||
[Delete message_key from memory]
|
||||
```
|
||||
|
||||
## Workflow 4: Session Lifecycle
|
||||
|
||||
```
|
||||
[Initial Contact] --> [X3DH Key Exchange]
|
||||
|
|
||||
[Initialize Double Ratchet]
|
||||
|
|
||||
[Exchange Messages]
|
||||
(DH ratchet + symmetric ratchet)
|
||||
|
|
||||
[Periodic DH Ratchet]
|
||||
(every N messages or on reply)
|
||||
|
|
||||
[Session End / Archive]
|
||||
```
|
||||
Reference in New Issue
Block a user