Cryptography Tutor

Cryptography is where number theory stops being abstract. The trouble is that most courses present the algorithms without the reasoning — so RSA becomes four formulas to memorise instead of one idea you can rebuild from scratch. We fix that, working from your textbook and your problem sets.

25 chapter slide decks 13 interactive cipher tools Trappe & Washington aligned Proofs and implementation
Free, no sign-up

Run the ciphers before you book anything.

Thirteen working tools: encrypt with a Caesar or Vigenère cipher and then break it, build an RSA keypair and factor it, watch ECB mode leak an image, or split a secret with Shamir’s scheme. Everything runs in your browser and shows its working.

Who This Page Is For

The cryptography course student

You are in an undergraduate or master’s crypto course — often Trappe & Washington, Stinson or Katz & Lindell — and the number theory arrived faster than the intuition. We rebuild it in order.

The security student

You need cryptography for a security, networking or CISSP-style course. You care less about proofs and more about which primitive to use, why padding matters, and what actually breaks in practice.

The self-learner

You can implement AES from a tutorial but could not say why it is secure. We connect the code you can already write to the mathematics underneath it.

What We Cover

Classical Ciphers

  • Shift, affine and substitution
  • Vigenère and the Kasiski attack
  • Index of coincidence
  • Hill cipher and known-plaintext
  • Frequency analysis by hand

Number Theory

  • Euclid and extended Euclid
  • Modular inverses, Euler’s φ
  • Fermat and Euler theorems
  • Chinese Remainder Theorem
  • Primality testing and factoring

Symmetric Cryptography

  • One-time pad and perfect secrecy
  • Stream ciphers and LFSRs
  • DES, Feistel networks
  • AES structure and the S-box
  • Modes: ECB, CBC, CTR, GCM

Public Key

  • RSA: keygen, signing, attacks
  • Diffie-Hellman key exchange
  • ElGamal and discrete logs
  • Elliptic curves and ECDH
  • Pairings and identity-based crypto

Hashing & Protocols

  • Collision and preimage resistance
  • Birthday bound, MD5 and SHA-1 breaks
  • Digital signatures and DSA
  • Zero-knowledge proofs
  • Secret sharing and digital cash

Modern Topics

  • Information theory and entropy
  • Lattices, LLL and NTRU
  • Error-correcting codes, McEliece
  • Shor’s algorithm
  • Post-quantum migration

How I’d Walk You Through Why RSA Actually Works

Most students can recite that c = me mod n and m = cd mod n. Far fewer can say why the second one undoes the first. That gap is the whole subject, and it closes in four steps:

  1. Start with Euler’s theorem. If gcd(a, n) = 1 then aφ(n) ≡ 1 (mod n). Nothing about cryptography yet — just a fact about modular arithmetic.
  2. Choose d so that ed ≡ 1 (mod φ(n)). That is exactly what the extended Euclidean algorithm gives you, which is why gcd(e, φ(n)) = 1 is required rather than arbitrary.
  3. Write ed = 1 + kφ(n). Then cd = med = m1 + kφ(n) = m · (mφ(n))k ≡ m · 1k = m.
  4. Now ask what an attacker needs. To find d they need φ(n), and to find φ(n) = (p−1)(q−1) they need p and q. The security is not that RSA is complicated — it is that multiplying is easy and factoring is not.

Once you have built it that way, the attacks stop being a separate list to memorise. Small exponents, shared primes and missing padding all become obvious consequences of the same structure — and you can try each of them yourself in the RSA explorer.

Where Students Usually Get Stuck

Modular inverses

The first genuine wall. Division does not exist mod n, so everything routes through the extended Euclidean algorithm — and it reappears in affine ciphers, RSA, Hill ciphers and elliptic curves.

Why key length is not security

A substitution cipher has 26! keys and falls to a newspaper solver. Understanding why is what separates counting keys from thinking about attacks.

Proof versus practice

The one-time pad is provably unbreakable and almost never used. RSA is unproven and everywhere. Knowing which guarantee you actually have is the skill the exams test.

Frequently Asked Questions

Which textbook do you follow?

The slide course here follows Trappe & Washington, Introduction to Cryptography with Coding Theory (3rd edition), one deck per chapter. But we work from whatever your course uses — Stinson, Katz & Lindell and Paar & Pelzl are all familiar territory.

How much number theory do I need first?

Less than you think, and we build it as we go. If you are comfortable with remainders and can follow an algebraic argument, that is enough to start. The modular arithmetic toolkit shows every routine with its full working.

Can you help with the implementation side?

Yes. Writing a working cipher and understanding why it is secure are different skills, and courses often grade both. We can work in Python, Java, C or whatever your assignment requires.

Do you cover post-quantum cryptography?

Yes — lattices, NTRU, code-based systems like McEliece, and Shor’s algorithm. It is increasingly on syllabi, and the last three decks of the course cover it.

Are the tools and slides free?

Completely, with no sign-up. The 25 slide decks and 13 interactive tools are all on this site.

Related Free Tools

Related Tutoring

Bring me the chapter you are stuck on.

First 30-minute consultation is free. Whether it is a proof you cannot finish, an implementation that will not decrypt, or an exam next week — we start where you are.