All Topics  
Plaintext

 

   Email Print
   Bookmark   Link






 

Plaintext



 
 
In cryptography
Cryptography

Cryptography is the practice and study of hiding information. In modern times cryptography is considered a branch of both mathematics and computer science and is affiliated closely with information theory, computer security and engineering....
, plaintext is the information which the sender wishes to transmit to the receiver(s). Before the computer era, plaintext simply meant text in the language of the communicating parties. Since computers, the definition has been expanded to include not only the electronic representation of text, such as email and word processor documents, but also the computer representation of speech, music, pictures, videos, ATM and credit card transactions, sensor data, and so forth, basically any information which the communicating parties might wish to conceal from others.






Discussion
Ask a question about 'Plaintext'
Start a new discussion about 'Plaintext'
Answer questions from other users
Full Discussion Forum



Encyclopedia


In cryptography
Cryptography

Cryptography is the practice and study of hiding information. In modern times cryptography is considered a branch of both mathematics and computer science and is affiliated closely with information theory, computer security and engineering....
, plaintext is the information which the sender wishes to transmit to the receiver(s). Before the computer era, plaintext simply meant text in the language of the communicating parties. Since computers, the definition has been expanded to include not only the electronic representation of text, such as email and word processor documents, but also the computer representation of speech, music, pictures, videos, ATM and credit card transactions, sensor data, and so forth, basically any information which the communicating parties might wish to conceal from others. The plaintext is the normal representation of the data before any action has been taken to conceal it.

The plaintext is used as input to an encryption algorithm; the output is termed ciphertext
Encryption

In cryptography, encryption is the process of transforming information using an algorithm to make it unreadable to anyone except those possessing special knowledge, usually referred to as a key ....
. In some systems, however, multiple layers of encryption are used, in which case the ciphertext output of one encryption algorithm becomes the plaintext input to the next.

Secure handling of plaintext


In a cryptosystem
Cryptosystem

There are two different meanings of the word cryptosystem. One is used by the cryptographic community, while the other is the meaning understood by the public....
, weaknesses can be introduced through insecure handling of the plaintext, allowing an attacker to bypass the cryptography altogether. Plaintext is vulnerable in use and in storage, whether in electronic or paper format. Physical security
Physical security

Physical security describes both measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media and guidance on how to design structures to resist various hostile acts....
 deals with how media can be secured from local, physical, attacks. for instance, an attacker might enter a poorly secured building and attempt to open locked desk drawers or safe
Safe

A safe is a secure Lock box used for securing valuable objects against theft or damage. A safe is usually a hollow cuboid or cylinder, with one face removable or hinged to form a door....
s. An attacker can also engage in dumpster diving
Dumpster diving

Dumpster diving is the practice of sifting through commercial or residential Waste to find items that have been discarded by their owners, but which may be useful to the Dumpster diver....
, and may be able to reconstruct shredded information. One countermeasure is to burn or thoroughly crosscut shred discarded printed plaintexts. (See Paper shredder
Paper shredder

Paper shredders are used to cut paper into Chad , typically either strips or fine particles. Government organizations, businesses, and private individuals use shredders to destroy private, confidentiality, or otherwise sensitive documents....
 for specifications.) If plaintext is kept in a computer file
Computer file

A computer file is a block of arbitrary information, or resource for storing information, which is available to a computer program and is usually based on some kind of durable computer storage....
, the disk along with the entire computer and its components must be secure. Sensitive data is sometimes processed on computers whose mass storage is removable, in which case physical security of the removed disk is separately vital. In the case of securing a computer, that security must be physical (e.g., against burglary
Burglary

Burglary is a crime the essence of which is entry into a building for the purposes of committing an offence. Usually that offence will be theft, but most jurisdictions specify others which fall within the ambit of burglary....
, brazen removal under cover of a repair, installation of covert monitoring devices, etc.) as well as virtual (e.g., operating system
Operating system

An operating system is an interface between hardware and applications; it is responsible for the management and coordination of activities and the sharing of the limited resources of the computer....
 modification, illicit network access, Trojan
Trojan horse (computing)

The Trojan horse, also known as trojan, in the context of computer software, describes a class of computer threats that appears to perform a desirable function but in fact performs undisclosed malicious functions that allow unauthorized access to the host machine, giving them the ability to save their files on the user's computer...
 programs, ...). The wide availability of keydrives, which can plug into most modern computers and receive hundreds of megabytes of data, poses another severe security headache. A spy (perhaps posing as a cleaning person) could easily conceal one and even swallow it, if necessary.

Discarded computers, disk drives and media are also a potential source of plaintexts. Most operating systems do not actually erase anything — they simply mark the disk space occupied by a deleted file as 'available for use', and remove its entry from the file system directory
Directory (file systems)

In computing, a directory, folder, catalog, or drawer is a virtual container within a digital file system, in which groups of files and other directories can be kept and organized....
. The information in a file deleted in this way remains fully present until overwritten at some later time when the operating system reuses the disk space. With even low-end computers commonly sold with many Gigabytes of disk space and rising monthly, this 'later time' may be months, or never. Even overwriting the portion of a disk surface occupied by a deleted file is insufficient in many cases. Peter Gutmann
Peter Gutmann (computer scientist)

Peter Gutmann is a computer science in the Department of Computer Science at the University of Auckland, Auckland, New Zealand. He has a Ph.D. in computer science from the University of Auckland....
 of the University of Auckland
University of Auckland

File:University Of Auckland Tamaki Campus.jpgThe University of Auckland is New Zealand's largest university and the top-ranked New Zealand university in the THES - QS World University Rankings....
 wrote a celebrated paper about 1996 on the recovery of overwritten information from magnetic disks (though since drive densities have got much higher since then, this type of recovery is now much harder). Also, modern hard drives automatically remap sectors that are starting to fail; those sectors no longer in use will contain information that is invisible to the file system software but is nonetheless still there on the physical platter. It may be sensitive data. Some government agencies (e.g., NSA) require that all disk drives be physically pulverized when they are discarded, and in some cases, chemically treated with corrosives before or after. This practice is not widespread outside of the government, however. For example, Garfinkel and Shelat (2003) analysed 158 second-hand hard drives acquired at garage sales and the like and found that less than 10% had been sufficiently sanitised. A wide variety of personal and confidential information was found readable from the others. See data remanence
Data remanence

Data remanence is the residual representation of data that has been in some way nominally erased or removed. This residue may be due to data being left intact by a nominal file deletion operation, or through physical properties of the data storage device....
.

Laptop computers are a special problem. The US State Department, the British Secret Service, and the US Department of Defense have all had laptops containing secret information, presumably in readable text form, 'vanish' in recent years. Announcements of similar losses are becoming a common item in news reports. Disk encryption
Disk encryption

Disk encryption is a special case of data at rest protection when the storage media is a sector-addressable device . This article presents cryptographic aspects of the problem....
 techniques can provide protection if they are used properly.

On occasion, even when the data on the host systems is itself encrypted, the media used to transfer data between such systems is still left as plaintext because of bad data policy. An incident in October 2007 where the English HM Revenue and Customs lost CDs containing no less then 25m records of child benefit recipients in the United Kingdom — the data on the CDs apparently being entirely unencrypted — is a case in point.

Modern cryptographic systems are designed to resist attacks based on known plaintext or even chosen plaintext. Older systems used techniques such as padding
Padding (cryptography)

In cryptography, padding refers to a number of distinct practices....
 and Russian copulation
Russian copulation

In cryptography, Russian copulation is a method of rearranging plaintext before encryption so as to conceal stereotyped headers, salutations, introductions, endings, signatures, etc....
 to obscure information in plaintext that would be known or easily guessed.

See also

  • cleartext
    Cleartext

    In data communications, cleartext is the form of a message or data which is in a form that is immediately comprehensible to a human being without additional processing....
  • RED/BLACK concept
    RED/BLACK concept

    The RED/BLACK concept refers to the careful segregation in cryptographic systems of signals that contain sensitive or classified plaintext information from those that carry encrypted information, or ciphertext ....