Monash University · FACULTY OF CYBERSECURITY

FIT1093 Chap.3 Block Ciphers and Modes of Operation

- one subject, every graph, every model, every mark
6 Chapters4-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 3 of 10 · FIT1093

Block Ciphers and Modes of Operation

The second part of Week 2 moves from letter-by-letter ciphers to modern block ciphers, which encrypt a fixed-size block of bits, such as 64 or 128, under a secret key. The design splits into two layers: a block cipher that handles exactly one block, and a mode of operation that applies it to messages of any length.

A block cipher must decrypt correctly and must be a secure pseudorandom function, meaning that with a random key its outputs cannot be told apart from random strings, even by an attacker who knows the inputs.

Two standards anchor the topic.

DES, adopted in the United States in 1977, uses a 64-bit block, a 56-bit key and a Feistel structure in which each round changes one half of the block by XORing it with a function of the other half; it was withdrawn in 2005, with Triple DES as a stronger successor.

AES, selected in 2000 and standardised in 2001, uses a 128-bit block, keys of 128, 192 or 256 bits, and rounds built from SubBytes, ShiftRows, MixColumns and AddRoundKey. Longer keys, larger blocks and more rounds all raise security, and for a well designed cipher brute force over the key space remains the fastest known attack.

The modes decide how much a ciphertext reveals and how a system behaves in practice.

ECB encrypts every block independently, so identical blocks produce identical ciphertext and patterns leak. CBC chains each block to the previous ciphertext through a random initial vector, hiding patterns but preventing parallel encryption and spreading a transmission error across two blocks.

Counter mode turns the cipher into a keystream, allowing parallel work and random access with no padding, provided a counter value is never reused under the same key.

In this chapter

What this chapter covers

  • 01

    Blocks, keys and the two-layer design of modern encryption

  • 02

    Correct decryption and pseudorandom function security

  • 03

    The Feistel round inside DES and why XOR makes it reversible

  • 04

    AES parameters and its four round operations

  • 05

    Key length, brute force and side-channel warnings

  • 06

    ECB, CBC and counter mode compared

Worked example · free

See why chaining hides a repeated block

Q [6 marks]. The marks shown here are a practice weighting for this guide, not an official university scheme. Use a deliberately insecure toy block cipher E(x) = x XOR 0011 on 4-bit blocks. Encrypt two identical plaintext blocks 1010 and 1010 in ECB mode and in CBC mode with IV = 0110, and compare the results.
  • 2ECB: each block is encrypted alone, 1010 XOR 0011 = 1001, so both ciphertext blocks are 1001.
  • 2CBC, first block: XOR with the IV, 1010 XOR 0110 = 1100, then encrypt, 1100 XOR 0011 = 1111.
  • 2CBC, second block: XOR with the previous ciphertext, 1010 XOR 1111 = 0101, then encrypt, 0101 XOR 0011 = 0110.
ECB outputs 1001 1001, exposing the repetition, while CBC outputs 1111 0110, so an observer cannot tell that the two plaintext blocks were equal. The toy cipher itself is far too weak for real use.
Sia tip — In CBC, the value XORed into each block before encryption is always the previous ciphertext block, and the IV only for the first block.
Glossary

Key terms

Feistel Structure
A round design that splits the block into halves and updates one half with a keyed function of the other, so every round can be reversed.
Initial Vector
A random, non-secret starting value that makes encryptions of the same message under the same key look different.
Electronic Code Book
The mode that encrypts every block independently, so equal plaintext blocks give equal ciphertext blocks.
Counter Mode
The mode that encrypts successive counter values to make a keystream, which is XORed with the plaintext blocks.
FAQ

Block Ciphers and Modes of Operation FAQ

Why should ECB mode be avoided?

Because it encrypts each block on its own, identical plaintext blocks produce identical ciphertext blocks. Patterns such as the outline of an image or repeated record fields stay visible, which the lecture illustrates with a videoconference product that used it.

Which mode spreads a transmission error into two blocks?

CBC. A corrupted ciphertext block decrypts to garbage and also corrupts the next plaintext block, because each block's decryption is XORed with the previous ciphertext block. Counter mode keeps errors inside one block.

Why does the lecture warn against coding AES yourself?

Straightforward implementations can leak information through side channels such as timing, even when the algorithm is sound. The advice is to use a well known library written by experts rather than a home-made implementation.

How long would brute force take against a 56-bit key?

There are about 7.2 × 10^16 keys, so on average half of them must be tried. At a billion guesses per second that is roughly a year on one machine and much less on many, which is why DES is now obsolete.

What must never repeat in counter mode?

A counter value under the same key. Reusing one produces the same keystream twice, and XORing the two ciphertexts then cancels the keystream, exactly like reusing a one-time pad.

Study strategy

Assessment move

Start by drawing the encryption and decryption diagrams for ECB, CBC and counter mode from memory, since Workshop 2 asks students to complete the decryption diagrams and the comparison table of parallelism, pattern hiding, random access and padding.

Next, practise one-round calculations on small states: XOR with a key byte, a rotation across the whole state, and an S-box lookup, writing each intermediate state in binary and hex. Keep a one-line justification ready for each mode's main weakness and each parameter's effect on security. Finally, estimate brute-force times for a few key lengths so that the jump from 56 to 128 bits feels as large as it is.

Working through Block Ciphers and Modes of Operation in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Block Ciphers and Modes of Operation question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 111 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT1093 tutor, unlimited, worked the way the exam marks it
The full 4-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
FIT1093 · Cybersecurity Tools and Techniques - independent study guide on the AskSia Library. More Monash University subjects · Microeconomics across all universities