L19 · One-Time Pad, XOR & the IND-CPA Game

CS 161, Lesson 19, in 50 slides. It covers XOR and its algebra in section 6.2, the one-time pad and its perfect secrecy in section 6.3, and the fatal two-time-pad break that key reuse allows, as seen in VENONA. It then gives the formal IND-CPA game from section 6.1 and uses it to prove that a one-time pad with a reused key is not IND-CPA. It is anchored to textbook sections 6.1 to 6.3.

Subject: Computer Security · 90 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. The Perfect Cipher — And Its Fatal Flaw

Title

CS 161 · Lesson 19 of 45

XOR algebra · the one-time pad · perfect secrecy · the two-time-pad break · IND-CPA, now formal

2. By the end of this lesson you can…

Objectives

  1. Compute with XOR fluently and use its algebra — identity, self-inverse, commutativity, associativity — to solve bit equations.
  2. State the one-time pad scheme (KeyGen, Encrypt, Decrypt) and derive decryption from the encryption rule by XOR algebra.
  3. Explain why the one-time pad has perfect secrecy: the ciphertext is uniformly random regardless of the plaintext.
  4. Carry out the two-time-pad break — recover M⊕M′ (and the key) when one pad encrypts two messages — and connect it to VENONA.
  5. Run the formal IND-CPA game and prove that one-time pad with key reuse is not IND-CPA, while single-use OTP stays perfectly secure.

3. What survived from L18 · Kerckhoff's Principle, Attacker Models & IND-CPA?

Warm-up

Discussion prompt

Before we open L19 · One-Time Pad, XOR & the IND-CPA Game: without looking back, what was the main idea of L18 · Kerckhoff's Principle, Attacker Models & IND-CPA, and what could you do by the end of it that you could not do before?

Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.

Answer:

CS 161, Lesson 18, in 50 slides. It covers Kerckhoff's Principle, which holds that the key is the only secret, then the hierarchy of attacker models running from COA through KPA, replay, CPA, and CCA to CCA2, and an informal IND-CPA security game. Together these set the rules of the game for the whole cryptography unit. It is anchored to textbook sections 5.8 to 5.9 and to section 6.1.

4. Three questions this lesson answers

Concept

Last lesson set the rules of the game — Kerckhoff, the attacker models, and IND-CPA. Now we build the very first cipher and hold it to that bar.

What is the tool?
§6.2 XOR — one operation, four algebra laws
What is the cipher?
§6.3 the one-time pad and its perfect secrecy
Does it pass IND-CPA?
§6.1 yes once, NO if the key is reused

5. Which is which: Three questions this lesson answers

Matching

Match the pairs

From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.

  • c1. What is the tool?
  • c2. What is the cipher?
  • c3. Does it pass IND-CPA?
  • b1. §6.2 XOR — one operation, four algebra laws
  • b2. §6.3 the one-time pad and its perfect secrecy
  • b3. §6.1 yes once, NO if the key is reused

Why: What is the tool?, What is the cipher?, Does it pass IND-CPA? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.

6. One Operation: XOR

Section

Part 1 · §6.2 XOR and its algebra

7. §6.2 A scenario: combining a message with a secret

Concept

Imagine you want to scramble a string of bits using a secret string of bits, in a way you can perfectly undo later with the same secret. You need an operation that mixes two bits and is reversible.

That operation is XOR (exclusive or), written ⊕. It is the single building block under the one-time pad — and, later, under every stream cipher.

8. §6.2 XOR, by its truth table

Concept

XOR (⊕) — The exclusive-or of two bits: 1 when the bits differ, 0 when they are the same. Equivalently, addition modulo 2.

xyx ⊕ y
000
011
101
110

Read it as: 'output 1 exactly when the inputs disagree.' That single fact generates everything else.

9. Fill in: y for §6.2 XOR, by its truth table

Comparison

Comparison matrix

From §6.2 XOR, by its truth table: refill the y column from what you know. The rest of the table is as it appeared.

xyx ⊕ y
000
011
101
110

10. §6.2 The four algebra laws of XOR

Concept

XOR obeys four laws. Each one is just the truth table, written as an identity you can apply mechanically.

\[ x \oplus 0 = x \quad\text{(identity)} \]

\[ x \oplus x = 0 \quad\text{(self-inverse)} \]

\[ x \oplus y = y \oplus x \quad\text{(commutative)} \]

\[ (x \oplus y) \oplus z = x \oplus (y \oplus z) \quad\text{(associative)} \]

11. Break it if you can: §6.2 The four algebra laws of XOR

Counterexample

Discussion prompt

XOR obeys four laws. Each one is just the truth table, written as an identity you can apply mechanically.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

12. §6.2 Why XOR is its own undo button

Intuition

Most operations destroy information — once you AND two bits, you can't always recover the inputs. XOR is different: it never loses anything, because you can always run it backwards with the same value.

The reason is the self-inverse law: XOR-ing by the same thing twice cancels it out, returning you to where you started. The 'lock' and the 'key' are literally the same move.

Ask yourself: if I scramble a bit by flipping it whenever a secret bit is 1, how do I unscramble it? (Flip it again the same way — two flips return the original.)

13. By analogy: §6.2 Why XOR is its own undo button

Analogy

Discussion prompt

Explain §6.2 Why XOR is its own undo button by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

The reason is the self-inverse law: XOR-ing by the same thing twice cancels it out, returning you to where you started. The 'lock' and the 'key' are literally the same move.

14. What has to happen first: §6.2 Confirm two algebra laws on the truth table

Ranking

Put in order

Put the moves of §6.2 Confirm two algebra laws on the truth table into the order they have to happen.

  1. Check identity x ⊕ 0 = x for both values of x
  2. Check self-inverse x ⊕ x = 0 for both values of x
  3. Verify: both laws hold on every row, so they hold for all bits

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Read rows of the truth table where the second input is 0: the output equals the first input.

15. §6.2 Confirm two algebra laws on the truth table

Worked example

Check identity x ⊕ 0 = x for both values of x

Why: Read rows of the truth table where the second input is 0: the output equals the first input.

x0x ⊕ 0
000
101

Check self-inverse x ⊕ x = 0 for both values of x

Why: Read the rows where both inputs are equal: equal bits always XOR to 0.

xxx ⊕ x
000
110

Verify: both laws hold on every row, so they hold for all bits

Why: §6.2: a one-bit law that holds on all rows of the truth table extends bitwise to whole strings — these are the laws decryption relies on.

16. What each one costs: §6.2 Confirm two algebra laws on the truth table

Trade off

Comparison matrix

From §6.2 Confirm two algebra laws on the truth table: every row here is a choice with a cost. Fill the 0 column, then say which row you would actually pick and what you give up for it.

x0x ⊕ 0
000
101

17. §6.2 The handy identity: cancel out the x

Concept

Combining commutativity, associativity, and self-inverse gives the one identity you'll use constantly in proofs:

\[ x \oplus y \oplus x = y \]

Any value XOR-ed in twice cancels itself out, leaving whatever is in between. This is the whole reason decryption works.

18. Teach it back: §6.2 The handy identity: cancel out the x

Explain it

Discussion prompt

Explain §6.2 The handy identity: cancel out the x to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Combining commutativity, associativity, and self-inverse gives the one identity you'll use constantly in proofs:

19. Plan first: §6.2 XOR algebra: solve a bit equation

Step zero

Discussion prompt

§6.2 XOR algebra: solve a bit equation — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Start from the equation to solve for y

Answer:

  1. Start from the equation to solve for y
  2. XOR both sides by 1
  3. Cancel the two 1's on the left and simplify the right
  4. Verify: substitute y = 1 back into y ⊕ 1

20. §6.2 XOR algebra: solve a bit equation

Worked example

Start from the equation to solve for y

Why: We are given a relationship between an unknown bit y and a known bit, and want y by itself.

\[ y \oplus 1 = 0 \]

XOR both sides by 1

Why: Just like adding the same number to both sides of an equation — XOR-ing both sides by the same value keeps them equal.

\[ y \oplus 1 \oplus 1 = 0 \oplus 1 \]

Cancel the two 1's on the left and simplify the right

Why: Self-inverse: 1 ⊕ 1 = 0, and identity: y ⊕ 0 = y. On the right, 0 ⊕ 1 = 1.

\[ y = 1 \]

Verify: substitute y = 1 back into y ⊕ 1

Why: 1 ⊕ 1 = 0, which matches the right-hand side, so y = 1 is correct.

21. Decode the notation: §6.2 XOR algebra: solve a bit equation

Notation

Annotate

From §6.2 XOR algebra: solve a bit equation — read this one piece at a time. What is each part doing?

On: \( y \oplus 1 \oplus 1 = 0 \oplus 1 \)

  • We are given a relationship between an unknown bit y and a known bit, and want y by itself.
  • Just like adding the same number to both sides of an equation — XOR-ing both sides by the same value keeps them equal.
  • Self-inverse: 1 ⊕ 1 = 0, and identity: y ⊕ 0 = y. On the right, 0 ⊕ 1 = 1.

22. Something is wrong here: treating XOR like AND or OR

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'XOR is basically OR, so 1 ⊕ 1 = 1, and a value XOR-ed with itself stays itself.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0.

A student: apply the XOR truth table exactly.

Why: OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.

23. Trap: treating XOR like AND or OR

Trap

The trap

A student: 'XOR is basically OR, so 1 ⊕ 1 = 1, and a value XOR-ed with itself stays itself.'

\[ 1 \oplus 1 \stackrel{?}{=} 1, \qquad x \oplus x \stackrel{?}{=} x \]

Borrow the rules of OR (or AND) for XOR

Why: Wrong. OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.

The fix

A student: apply the XOR truth table exactly.

\[ 1 \oplus 1 = 0, \qquad x \oplus x = 0 \]

Use the self-inverse law: equal inputs XOR to 0

Why: §6.2: XOR is 1 only when the inputs disagree. 1 ⊕ 1 = 0 and x ⊕ x = 0 — that cancellation is exactly what makes decryption possible.

24. Break it on purpose: treating XOR like AND or OR

Break the constraint

Discussion prompt

The rule this trap just fixed:

A student: apply the XOR truth table exactly.

Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?

Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.

Answer:

OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.

25. §6.2 XOR as bit-by-bit addition mod 2

Intuition

Another way to see XOR: it's addition where you only keep the last bit and throw away any carry. 1 + 1 = 10 in binary, but mod 2 you keep just the 0 — which is exactly 1 ⊕ 1 = 0.

That framing explains the algebra for free: addition mod 2 is commutative and associative, and every element is its own additive inverse. No new rules to memorize.

Ask yourself: in ordinary arithmetic, what undoes adding 5? (Subtracting 5.) In mod-2 arithmetic, what undoes XOR-ing by k? (XOR-ing by k again — it is its own inverse.)

26. The One-Time Pad

Section

Part 2 · §6.3 the scheme

27. §6.3 A scenario: Alice and Bob share a pad

Concept

Alice and Bob meet in advance and agree on a long secret string of random bits — a 'pad.' Later, apart and watched by Eve, Alice wants to send a message only Bob can read, using that shared pad.

The one-time pad does exactly this with one XOR: combine the message with the pad to send, combine again with the pad to recover. The catch is in the name — one-time.

28. §6.3 The one-time pad: three procedures

Concept

One-time pad (OTP) — Alice and Bob share an n-bit key K = k_1…k_n chosen uniformly at random (n independent fair coin flips). Encryption and decryption are a single XOR with that key.

\[ \textbf{KeyGen: } K = k_1 k_2 \cdots k_n, \quad k_i \xleftarrow{\$} \{0,1\} \]

\[ \textbf{Encrypt: } C = M \oplus K \]

\[ \textbf{Decrypt: } M = C \oplus K \]

29. Take the definitions apart: XOR (⊕) vs One-time pad (OTP)

Definition probe

Sort into buckets

Every line below is part of the definition of XOR (⊕) or of One-time pad (OTP) — one or the other, never both. Put each where it belongs.

XOR (⊕)
The exclusive-or of two bits; 1 when the bits differ, 0 when they are the same.; Equivalently, addition modulo 2.
One-time pad (OTP)
Alice and Bob share an n-bit key K = k_1…k_n chosen uniformly at random (n independent fair coin flips).; Encryption and decryption are a single XOR with that key.
b1
The exclusive-or of two bits: 1 when the bits differ, 0 when they are the same. Equivalently, addition modulo 2.
b2
Alice and Bob share an n-bit key K = k_1…k_n chosen uniformly at random (n independent fair coin flips). Encryption and decryption are a single XOR with that key.

30. §6.3 Why the same key both locks and unlocks

Intuition

There's no separate 'decrypt key.' Bob uses the very same pad Alice used — because XOR is its own inverse, applying the pad a second time peels it right back off.

Think of the pad as a layer of random noise laid on top of the message. Adding the identical noise a second time cancels it (x ⊕ x = 0), and the message reappears untouched.

Ask yourself: what single XOR identity from Part 1 guarantees Bob gets M back? (The cancel-out identity: C ⊕ K = M ⊕ K ⊕ K = M.)

31. Complete the line: §6.3 Derive decryption from encryption

Fill the middle

Fill in the blanks

From §6.3 Derive decryption from encryption — finish the line. Write what belongs on the right of the equals sign before you look.

c_j = m_j \oplus k_j

Why: Producing the right-hand side unprompted is the difference between recognising this line and being able to use it. Encryption is defined bit-by-bit: the j-th ciphertext bit is the j-th message bit XOR the j-th key bit.

32. §6.3 Derive decryption from encryption

Worked example

Start from the per-bit encryption rule

Why: Encryption is defined bit-by-bit: the j-th ciphertext bit is the j-th message bit XOR the j-th key bit.

\[ c_j = m_j \oplus k_j \]

XOR both sides by k_j

Why: We want m_j alone; XOR-ing both sides by the same key bit keeps the equation balanced.

\[ c_j \oplus k_j = m_j \oplus k_j \oplus k_j \]

Cancel k_j ⊕ k_j on the right

Why: Self-inverse: k_j ⊕ k_j = 0, and identity: m_j ⊕ 0 = m_j. The key bit cancels itself out.

\[ c_j \oplus k_j = m_j \]

Verify: this says Decrypt = C ⊕ K recovers M exactly

Why: Holding for every bit j, the whole-string identity M = C ⊕ K follows — decryption is just encryption run again with the same pad.

33. Draw the shape of it: §6.3 Derive decryption from encryption

Blank canvas

Draw it

Draw what §6.3 Derive decryption from encryption just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

34. Predict the next row: §6.3 Encrypt and decrypt a 4-bit message

Pattern

Predict first

The table runs: 1 | 1 | 0 | 1 · 2 | 0 | 1 | 1 · 3 | 1 | 1 | 0

In §6.3 Encrypt and decrypt a 4-bit message, given the rows so far: what is the next one — the row where bit j is 4?

Correct: 4 | 1 | 0 | 1

bit jm_jk_jc_j = m_j ⊕ k_j
1101
2011
3110
4101

Why: The relationship between the columns, not the individual numbers, is what generates the next row. A concrete 4-bit message and a 4-bit pad; the pad was generated by fair coin flips and shared in advance.

35. §6.3 Encrypt and decrypt a 4-bit message

Worked example

Take M = 1011 and the shared random key K = 0110

Why: A concrete 4-bit message and a 4-bit pad; the pad was generated by fair coin flips and shared in advance.

Encrypt bit-by-bit: C = M ⊕ K

Why: XOR each message bit with the key bit below it; remember XOR outputs 1 only where the bits differ.

bit jm_jk_jc_j = m_j ⊕ k_j
1101
2011
3110
4101

\[ C = 1011 \oplus 0110 = 1101 \]

Decrypt: XOR the ciphertext with the same key, C ⊕ K

Why: Bob applies the identical pad; each key bit cancels the one used to encrypt.

bit jc_jk_jm_j = c_j ⊕ k_j
1101
2110
3011
4101

Verify: C ⊕ K = 1101 ⊕ 0110 = 1011, the original M

Why: The recovered bits 1011 match M exactly — encryption and decryption are the same XOR, so the round trip is lossless.

36. Fill in: m_j for §6.3 Encrypt and decrypt a 4-bit message

Comparison

Comparison matrix

From §6.3 Encrypt and decrypt a 4-bit message: refill the m_j column from what you know. The rest of the table is as it appeared.

bit jm_jk_jc_j = m_j ⊕ k_j
1101
2011
3110
4101

37. §6.3 Why the key must be uniformly random

Concept

KeyGen says each bit k_i is an independent fair coin flip — every n-bit key equally likely. This is not a detail you can relax; it is what makes the security proof go through.

A biased or predictable pad lets Eve guess key bits, and a guessed key bit directly exposes the matching plaintext bit (m_j = c_j ⊕ k_j). Randomness is the entire defense.

38. Something is wrong here: a 'pad' that isn't random

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'I'll save key bits — use a memorable phrase or a repeating pattern as the pad. It's still XOR, so it's still a one-time pad.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak.

A student: what makes a pad a real one-time pad?

Why: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak. Structure destroys perfect secrecy.

39. Trap: a 'pad' that isn't random

Trap

The trap

A student: 'I'll save key bits — use a memorable phrase or a repeating pattern as the pad. It's still XOR, so it's still a one-time pad.'

Swap the uniform random key for a structured one

Why: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak. Structure destroys perfect secrecy.

The fix

A student: what makes a pad a real one-time pad?

Use n independent fair coin flips — a fresh uniform random key, used once

Why: §6.3: perfect secrecy requires the key be uniformly random AND used a single time. 'XOR with something' is not enough; the something must be true randomness.

40. Why It's Perfectly Secret

Section

Part 3 · §6.3 perfect secrecy

41. §6.3 Perfect secrecy: zero information leaked

Concept

Used once with a random key, the one-time pad leaks precisely zero information about the plaintext. This is not 'hard to break' — it is impossible to break, even with infinite computing power.

Perfect (information-theoretic) secrecy — The ciphertext is statistically independent of the plaintext: seeing C tells Eve nothing about M she didn't already know. No amount of computation can change that.

42. Term to definition: L19 · One-Time Pad, XOR & the IND-CPA Game

Matching

Match the pairs

Match each term to the definition this lesson gave it — not the one you would guess from the word.

  • t1. XOR (⊕)
  • t2. One-time pad (OTP)
  • t3. Perfect (information-theoretic) secrecy
  • d1. The exclusive-or of two bits: 1 when the bits differ, 0 when they are the same. Equivalently, addition modulo 2.
  • d2. Alice and Bob share an n-bit key K = k_1…k_n chosen uniformly at random (n independent fair coin flips). Encryption and decryption are a single XOR with that key.
  • d3. The ciphertext is statistically independent of the plaintext: seeing C tells Eve nothing about M she didn't already know. No amount of computation can change that.

Why: These are the working definitions of XOR (⊕), One-time pad (OTP), Perfect (information-theoretic) secrecy as L19 · One-Time Pad, XOR & the IND-CPA Game uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.

43. §6.3 Why Eve just sees uniform random noise

Intuition

Fix any plaintext M. For every possible ciphertext C, there is exactly one key that would produce it: K = M ⊕ C. So each ciphertext is reachable, and by precisely one key.

Because every key is equally likely (fair coin flips), every ciphertext is equally likely too. From Eve's seat, C is a uniformly random n-bit string — and that's true no matter which M Alice sent.

Ask yourself: if the ciphertext distribution is identical for every plaintext, what can C reveal about M? (Nothing — that sameness IS perfect secrecy.)

44. Plan first: §6.3 Every ciphertext is achievable by one key

Step zero

Discussion prompt

§6.3 Every ciphertext is achievable by one key — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Fix the plaintext M and pick ANY target ciphertext C

Answer:

  1. Fix the plaintext M and pick ANY target ciphertext C
  2. Solve C = M ⊕ K for the key K
  3. Observe there is exactly ONE such key, and it has probability 1/2^n
  4. Verify: every C is equally likely given M, so the distribution of C does not depend on M

45. §6.3 Every ciphertext is achievable by one key

Worked example

Fix the plaintext M and pick ANY target ciphertext C

Why: We want to show C could have come from this M — i.e. the mapping M → C hides nothing about M.

Solve C = M ⊕ K for the key K

Why: XOR both sides by M: the cancel-out identity isolates K.

\[ K = M \oplus C \]

Observe there is exactly ONE such key, and it has probability 1/2^n

Why: K = M ⊕ C is unique, and since K was uniform over all n-bit strings, this particular key is as likely as any other.

Verify: every C is equally likely given M, so the distribution of C does not depend on M

Why: §6.3: Eve sees a uniform random string whatever the plaintext — perfect secrecy, provided the key is random and used ONCE.

46. Say it in words: §6.3 Every ciphertext is achievable by one key

Translation

\( K = M \oplus C \)

Draw it

Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.

47. State the rule before it runs: §6.3 Same ciphertext, two different…

Hypothesis

Predict first

§6.3 Same ciphertext, two different plaintexts is about to be worked. State your hypothesis first: which rule or definition decides this one, and what is the first move it forces? Then watch whether the example agrees with you.

Correct: Suppose Eve sees the ciphertext C = 1101 and wonders if the message was 1011

Why: We test whether seeing C lets Eve rule any plaintext in or out — if not, C carries no information about M.

A hypothesis you wrote down is falsifiable; a vague sense of how it will go is not. If the example opens somewhere else, that gap is the thing worth chasing.

48. §6.3 Same ciphertext, two different plaintexts

Worked example

Suppose Eve sees the ciphertext C = 1101 and wonders if the message was 1011

Why: We test whether seeing C lets Eve rule any plaintext in or out — if not, C carries no information about M.

Find the key that maps 1011 to 1101

Why: K = M ⊕ C = 1011 ⊕ 1101 = 0110 — a perfectly valid key, equally likely as any other.

Now suppose instead the message was 0000

Why: Find the key for that plaintext: K = 0000 ⊕ 1101 = 1101 — also a valid, equally likely key.

candidate Mkey K = M ⊕ Cproduces C?
10110110yes
00001101yes
any MM ⊕ 1101yes — exactly one key each

Verify: EVERY plaintext explains C with exactly one equally-likely key

Why: §6.3: since C is consistent with every M and all keys are equally likely, the ciphertext gives Eve no reason to prefer any plaintext — perfect secrecy.

49. What each one costs: §6.3 Same ciphertext, two different plaintexts

Trade off

Comparison matrix

From §6.3 Same ciphertext, two different plaintexts: every row here is a choice with a cost. Fill the key K = M ⊕ C column, then say which row you would actually pick and what you give up for it.

candidate Mkey K = M ⊕ Cproduces C?
10110110yes
00001101yes
any MM ⊕ 1101yes — exactly one key each

50. §6.3 Perfect secrecy is information-theoretic

Concept

Most ciphers (AES, RSA) are only computationally secure: safe because breaking them takes infeasibly long. The OTP is stronger — it leaks zero information even to an attacker with unlimited time and compute.

Shannon proved this in 1949: because C is uniform random independent of M, there is simply no information in the ciphertext to extract. There is nothing to compute, fast or slow.

51. The Fatal Flaw: Key Reuse

Section

Part 4 · §6.3 the two-time pad

52. §6.3 The one rule: never reuse the pad

Concept

Perfect secrecy came with fine print: the key must be random and used exactly once. Reuse the same pad on two messages and the whole guarantee collapses.

Reusing the pad once is called a two-time pad — and it is one of the most famous self-inflicted wounds in cryptographic history.

53. What has to happen first: §6.3 The key cancels: C ⊕ C′ = M ⊕ M′

Ranking

Put in order

Put the moves of §6.3 The key cancels: C ⊕ C′ = M ⊕ M′ into the order they have to happen.

  1. Suppose the SAME key K encrypts two messages M and M′
  2. Eve XORs the two ciphertexts together
  3. Reorder and cancel the two copies of K
  4. Verify the leak: Eve now holds M ⊕ M′ with no key needed

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. C = M ⊕ K and C′ = M′ ⊕ K — Eve intercepts both ciphertexts off the wire.

54. §6.3 The key cancels: C ⊕ C′ = M ⊕ M′

Worked example

Suppose the SAME key K encrypts two messages M and M′

Why: C = M ⊕ K and C′ = M′ ⊕ K — Eve intercepts both ciphertexts off the wire.

Eve XORs the two ciphertexts together

Why: She controls neither M nor K, but she can always XOR two strings she has seen.

\[ C \oplus C' = (M \oplus K) \oplus (M' \oplus K) \]

Reorder and cancel the two copies of K

Why: Commutativity and associativity let Eve group the keys together; K ⊕ K = 0 by self-inverse, so the key vanishes.

\[ C \oplus C' = M \oplus M' \]

Verify the leak: Eve now holds M ⊕ M′ with no key needed

Why: §6.3: reuse turns two ciphertexts into the XOR of the two plaintexts — a real leak that destroys perfect secrecy.

55. Plan first: §6.3 Compute C ⊕ C′ from two intercepted ciphertexts

Step zero

Discussion prompt

§6.3 Compute C ⊕ C′ from two intercepted ciphertexts — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Eve intercepts two ciphertexts made with the same pad: C = 1101 and…

Answer:

  1. Eve intercepts two ciphertexts made with the same pad: C = 1101 and C′ = 0111
  2. XOR them bit-by-bit to get M ⊕ M′
  3. Verify the leak: 1010 tells Eve every bit where the two plaintexts DIFFER

56. §6.3 Compute C ⊕ C′ from two intercepted ciphertexts

Worked example

Eve intercepts two ciphertexts made with the same pad: C = 1101 and C′ = 0111

Why: Both came from one reused key K; Eve knows neither K nor the plaintexts, only these bits off the wire.

XOR them bit-by-bit to get M ⊕ M′

Why: C ⊕ C′ = M ⊕ M′ because the shared K cancels — Eve does not need the key at all.

bit jc_jc′_jc_j ⊕ c′_j = m_j ⊕ m′_j
1101
2110
3011
4110

\[ C \oplus C' = 1101 \oplus 0111 = 1010 = M \oplus M' \]

Verify the leak: 1010 tells Eve every bit where the two plaintexts DIFFER

Why: §6.3: a 1 marks a position where M and M′ disagree, a 0 where they match — real, key-free information that perfect secrecy was supposed to forbid.

57. Fill in: c_j for §6.3 Compute C ⊕ C′ from two intercepted…

Comparison

Comparison matrix

From §6.3 Compute C ⊕ C′ from two intercepted ciphertexts: refill the c_j column from what you know. The rest of the table is as it appeared.

bit jc_jc′_jc_j ⊕ c′_j = m_j ⊕ m′_j
1101
2110
3011
4110

58. §6.3 If Eve knows one message, she gets the other — and K

Worked example

Start from what the reuse already leaked: M ⊕ M′

Why: From the previous slide, Eve computed C ⊕ C′ = M ⊕ M′ with no key.

Suppose Eve also learns M (a guessed header, a known field, crib-dragging)

Why: Known-plaintext is realistic — predictable structure hands Eve M for free, as in Lesson 18.

Recover the other message by XOR-ing M back in

Why: (M ⊕ M′) ⊕ M = M′ by the cancel-out identity — the known message cancels itself, exposing M′.

\[ M' = (M \oplus M') \oplus M \]

Recover the key itself from M and its ciphertext C

Why: Since C = M ⊕ K, XOR-ing gives K = M ⊕ C — and now Eve can read every message ever sent under this pad.

\[ K = M \oplus C \]

59. §6.3 VENONA: when a superpower reused the pad

Worked example

Recall that a true one-time pad is unbreakable — IF the key is never reused

Why: Soviet intelligence used one-time pads precisely because, used correctly, they cannot be broken.

Note the operational failure: Soviet key generators got lazy and reused key material

Why: Manufacturing fresh random pads at scale is hard; duplicate pages of key material went into the field — creating two-time pads.

Predict what U.S. codebreakers could then do

Why: Reused key means C ⊕ C′ = M ⊕ M′; with cribs and known plaintext the analysts could peel apart the underlying messages — exactly the break we just derived.

Observe the outcome: the VENONA project read reused-key Soviet traffic, kept secret until the early 1980s

Why: §6.3: a real superpower's 'unbreakable' cipher fell to a single rule violation — reuse. The math, not the spies, did the damage.

60. Something is wrong here: 'reuse is fine if the messages differ'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'I can safely reuse a one-time pad as long as I encrypt two DIFFERENT messages with it.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.

A student: when is a pad safe to use a second time?

Why: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.

61. Trap: 'reuse is fine if the messages differ'

Trap

The trap

A student: 'I can safely reuse a one-time pad as long as I encrypt two DIFFERENT messages with it.'

Assume different plaintexts make reuse safe

Why: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.

The fix

A student: when is a pad safe to use a second time?

Never reuse a pad — generate fresh random key bits for every message

Why: §6.3: perfect secrecy holds only for a single use. The instant a key covers two messages, the key cancels and the plaintexts' XOR leaks.

62. Holding OTP to the IND-CPA Bar

Section

Part 5 · §6.1 the game, now formal

63. §6.1 The IND-CPA game, stated formally

Concept

Lesson 18 sketched the indistinguishability game. Here it is precisely, as a contest between a challenger and an adversary Eve.

  1. Eve submits two equal-length messages M_0 and M_1.
  2. The challenger flips a secret bit b and returns C = Enc(K, M_b).
  3. Eve may also query encryptions of chosen messages (the chosen-plaintext power).
  4. Eve outputs a guess b′; she wins if b′ = b.

64. §6.1 The two-worlds reading of the game

Intuition

Picture two parallel worlds. In World 0 the challenger always encrypts M_0; in World 1 it always encrypts M_1. Eve is dropped into one and must say which world she's in.

If the ciphertexts (and oracle answers) look indistinguishable across the two worlds, Eve is stuck guessing — that's where IND, indistinguishability, gets its name.

Ask yourself: for single-use OTP, do the two worlds look different? (No — C is uniform random in both, so they're identical and Eve must guess.)

65. §6.1 Advantage: how far above a coin flip

Concept

Eve already knows M_0 and M_1 — she chose them. The only secret is b. Her advantage measures how much the ciphertext helps her recover that one bit.

\[ \mathrm{Adv}(\text{Eve}) = \left| \Pr[b' = b] - \tfrac{1}{2} \right| \]

IND-CPA secure means this advantage is negligibly small for every efficient Eve. Any non-negligible edge above 1/2 is leaked information.

66. Teach it back: §6.1 Advantage: how far above a coin flip

Explain it

Discussion prompt

Explain §6.1 Advantage: how far above a coin flip to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Eve already knows M_0 and M_1 — she chose them. The only secret is b. Her advantage measures how much the ciphertext helps her recover that one bit.

67. §6.1 Single-use OTP would WIN this game

Intuition

Used once, the one-time pad has perfect secrecy — the ciphertext is uniform random whatever the plaintext. So C looks identical whether Alice encrypted M_0 or M_1.

With nothing to distinguish the two worlds, Eve can only guess: Pr[b′ = b] = 1/2 exactly, advantage 0. Single-use OTP doesn't just pass IND-CPA, it passes the strongest possible bar.

Ask yourself: so where could an OTP-based scheme possibly fail the game? (Only if the SAME key is used more than once — the chosen-plaintext oracle is itself a second use.)

68. By analogy: §6.1 Single-use OTP would WIN this game

Analogy

Discussion prompt

Explain §6.1 Single-use OTP would WIN this game by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Used once, the one-time pad has perfect secrecy — the ciphertext is uniform random whatever the plaintext. So C looks identical whether Alice encrypted M_0 or M_1.

69. Plan first: §6.1 Prove OTP-with-key-reuse is NOT IND-CPA

Step zero

Discussion prompt

§6.1 Prove OTP-with-key-reuse is NOT IND-CPA — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Setup: the scheme uses a FIXED key K for both the oracle and the…

Answer:

  1. Setup: the scheme uses a FIXED key K for both the oracle and the challenge
  2. Eve picks two distinct messages M_0 ≠ M_1 and submits them; the challenger returns C = M_b ⊕ K
  3. Eve uses her chosen-plaintext query: ask the oracle to encrypt M_0, receiving M_0 ⊕ K
  4. Eve compares the challenge C with the oracle's answer M_0 ⊕ K
  5. Verify Eve wins with probability 1, so advantage = 1/2 > 0

70. §6.1 Prove OTP-with-key-reuse is NOT IND-CPA

Worked example

Setup: the scheme uses a FIXED key K for both the oracle and the challenge

Why: This is the broken variant — the same pad K encrypts every message, including Eve's chosen queries. (A correct OTP would never do this.)

Eve picks two distinct messages M_0 ≠ M_1 and submits them; the challenger returns C = M_b ⊕ K

Why: Standard first move of the game; b is hidden, and Eve wants to decide whether C hides M_0 or M_1.

Eve uses her chosen-plaintext query: ask the oracle to encrypt M_0, receiving M_0 ⊕ K

Why: CPA power lets Eve get the exact ciphertext M_0 produces under the SAME key K — that reuse is the fatal opening.

Eve compares the challenge C with the oracle's answer M_0 ⊕ K

Why: If b = 0 then C = M_0 ⊕ K, identical to the oracle output; if b = 1 then C = M_1 ⊕ K ≠ M_0 ⊕ K since M_0 ≠ M_1.

\[ b' = \begin{cases} 0 & \text{if } C = M_0 \oplus K \\ 1 & \text{otherwise} \end{cases} \]

Verify Eve wins with probability 1, so advantage = 1/2 > 0

Why: §6.1: the guess is always correct, Pr[b′ = b] = 1, advantage |1 − 1/2| = 1/2. OTP-with-key-reuse is decisively NOT IND-CPA.

71. Decode the notation: §6.1 Prove OTP-with-key-reuse is NOT IND-CPA

Notation

Annotate

From §6.1 Prove OTP-with-key-reuse is NOT IND-CPA — read this one piece at a time. What is each part doing?

On: \( b' = \begin{cases} 0 & \text{if } C = M_0 \oplus K \\ 1 & \text{otherwise} \end{cases} \)

  • This is the broken variant — the same pad K encrypts every message, including Eve's chosen queries. (A correct OTP would never do this.)
  • Standard first move of the game; b is hidden, and Eve wants to decide whether C hides M_0 or M_1.
  • CPA power lets Eve get the exact ciphertext M_0 produces under the SAME key K — that reuse is the fatal opening.

72. What has to happen first: §6.1 The break, with concrete bits

Ranking

Put in order

Put the moves of §6.1 The break, with concrete bits into the order they have to happen.

  1. Eve submits M_0 = 1011 and M_1 = 0000 to the reused-key challenger
  2. The challenger flips b and returns C = M_b ⊕ K
  3. Eve queries the oracle on M_0 = 1011 and gets back M_0 ⊕ K = 1101
  4. Eve outputs b′ = 0 if C = 1101, else b′ = 1
  5. Verify Eve is always right: advantage |1 − 1/2| = 1/2

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Two distinct equal-length messages; the challenger holds a fixed K, say 0110, hidden from Eve.

73. §6.1 The break, with concrete bits

Worked example

Eve submits M_0 = 1011 and M_1 = 0000 to the reused-key challenger

Why: Two distinct equal-length messages; the challenger holds a fixed K, say 0110, hidden from Eve.

The challenger flips b and returns C = M_b ⊕ K

Why: If b = 0: C = 1011 ⊕ 0110 = 1101. If b = 1: C = 0000 ⊕ 0110 = 0110. Eve sees only C, not b.

Eve queries the oracle on M_0 = 1011 and gets back M_0 ⊕ K = 1101

Why: The chosen-plaintext oracle uses the SAME K, so it hands Eve exactly the ciphertext M_0 would produce.

Eve outputs b′ = 0 if C = 1101, else b′ = 1

Why: C = 1101 means the challenge was M_0; anything else (here 0110) means it was M_1. The comparison is exact.

Verify Eve is always right: advantage |1 − 1/2| = 1/2

Why: §6.1: with the concrete bits the distinguisher never errs, confirming OTP-with-key-reuse is not IND-CPA.

74. Draw the shape of it: §6.1 The break, with concrete bits

Blank canvas

Draw it

Draw what §6.1 The break, with concrete bits just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

75. Something is wrong here: 'the one-time pad is broken'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'VENONA and the reuse attack prove the one-time pad is insecure — don't use it.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation.

A student: what exactly failed in the two-time-pad attacks?

Why: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation. It was REUSE that broke.

76. Trap: 'the one-time pad is broken'

Trap

The trap

A student: 'VENONA and the reuse attack prove the one-time pad is insecure — don't use it.'

Blame the cipher instead of the misuse

Why: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation. It was REUSE that broke.

The fix

A student: what exactly failed in the two-time-pad attacks?

Pin the failure on key reuse, not on the OTP itself

Why: §6.3: single-use OTP is perfectly secure; the chosen-plaintext break and VENONA both exploit a key used MORE THAN ONCE. The rule is the security.

77. Which of these survive contact with L19 · One-Time Pad, XOR & the IND-CPA Game?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
Last lesson set the rules of the game — Kerckhoff, the attacker models, and IND-CPA. Now we build the very first cipher and hold it to that bar.; Read it as: 'output 1 exactly when the inputs disagree.' That single fact generates everything else.; XOR obeys four laws. Each one is just the truth table, written as an identity you can apply mechanically.
Breaks
A student: 'XOR is basically OR, so 1 ⊕ 1 = 1, and a value XOR-ed with itself stays itself.'; A student: 'I'll save key bits — use a memorable phrase or a repeating pattern as the pad. It's still XOR, so it's still a one-time pad.'
sound
These are stated as this lesson states them — each one survives the edge cases L19 · One-Time Pad, XOR & the IND-CPA Game puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

78. §6.1 Why the oracle query is really a 'second use'

Intuition

The break feels almost too easy — but notice what the chosen-plaintext oracle actually is: a second encryption under the SAME key K. That is precisely the situation OTP forbids.

So OTP failing IND-CPA isn't a contradiction of its perfect secrecy. IND-CPA hands Eve an encryption oracle, and any reusable-key scheme that answers oracle queries is, by definition, reusing its key.

Ask yourself: does a TRUE one-time pad (fresh key per message) even have a meaningful encryption oracle? (No — each message gets its own independent key, so there's nothing to reuse.)

79. Break it if you can: §6.1 Why the oracle query is really a 'second use'

Counterexample

Discussion prompt

The break feels almost too easy — but notice what the chosen-plaintext oracle actually is: a second encryption under the SAME key K. That is precisely the situation OTP forbids.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

Answer:

Ask yourself: does a TRUE one-time pad (fresh key per message) even have a meaningful encryption oracle? (No — each message gets its own independent key, so there's nothing to reuse.)

80. §6.3 The catch that makes OTP impractical

Concept

Even used correctly, the one-time pad is rarely practical. The key must be as long as the message and can never be reused — so to send n bits you must first securely share n fresh random key bits.

But if you already have a secure channel to share an n-bit key, you could have just sent the n-bit message over it. That circularity is why real systems use short, reusable keys with computational ciphers instead.

81. Without one step: The one-time-pad playbook

Constraint

Discussion prompt

Run The one-time-pad playbook with this step confiscated:

Never reuse: two messages under one key give C⊕C′ = M⊕M′; known M ⇒ M′ = (M⊕M′)⊕M and K = M⊕C (VENONA).

Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.

Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.

Answer:

  1. XOR algebra: identity x⊕0=x, self-inverse x⊕x=0, commutative, associative — and the cancel identity x⊕y⊕x=y.
  2. The scheme: KeyGen a uniform random n-bit K; Encrypt C = M⊕K; Decrypt M = C⊕K (same pad both ways).
  3. Perfect secrecy: for fixed M, every C comes from exactly one key K = M⊕C, so C is uniform random — information-theoretic, not just 'hard'.
  4. Never reuse: two messages under one key give C⊕C′ = M⊕M′; known M ⇒ M′ = (M⊕M′)⊕M and K = M⊕C (VENONA).
  5. IND-CPA: single-use OTP wins (advantage 0); OTP-with-key-reuse loses — Eve's oracle query M_0⊕K matches the challenge iff b=0, advantage 1/2.
  6. Practicality: key as long as the message and one-time-use ⇒ OTP is mostly impractical; real ciphers reuse short keys.

82. The one-time-pad playbook

Pattern

  1. XOR algebra: identity x⊕0=x, self-inverse x⊕x=0, commutative, associative — and the cancel identity x⊕y⊕x=y.
  2. The scheme: KeyGen a uniform random n-bit K; Encrypt C = M⊕K; Decrypt M = C⊕K (same pad both ways).
  3. Perfect secrecy: for fixed M, every C comes from exactly one key K = M⊕C, so C is uniform random — information-theoretic, not just 'hard'.
  4. Never reuse: two messages under one key give C⊕C′ = M⊕M′; known M ⇒ M′ = (M⊕M′)⊕M and K = M⊕C (VENONA).
  5. IND-CPA: single-use OTP wins (advantage 0); OTP-with-key-reuse loses — Eve's oracle query M_0⊕K matches the challenge iff b=0, advantage 1/2.
  6. Practicality: key as long as the message and one-time-use ⇒ OTP is mostly impractical; real ciphers reuse short keys.

83. Where does it stop working: The one-time-pad playbook

Edge cases

Discussion prompt

The one-time-pad playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

  1. XOR algebra: identity x⊕0=x, self-inverse x⊕x=0, commutative, associative — and the cancel identity x⊕y⊕x=y.
  2. The scheme: KeyGen a uniform random n-bit K; Encrypt C = M⊕K; Decrypt M = C⊕K (same pad both ways).
  3. Perfect secrecy: for fixed M, every C comes from exactly one key K = M⊕C, so C is uniform random — information-theoretic, not just 'hard'.
  4. Never reuse: two messages under one key give C⊕C′ = M⊕M′; known M ⇒ M′ = (M⊕M′)⊕M and K = M⊕C (VENONA).
  5. IND-CPA: single-use OTP wins (advantage 0); OTP-with-key-reuse loses — Eve's oracle query M_0⊕K matches the challenge iff b=0, advantage 1/2.
  6. Practicality: key as long as the message and one-time-use ⇒ OTP is mostly impractical; real ciphers reuse short keys.

84. Rule out three: Checkpoint — what can Eve compute?

Elimination

Eliminate the wrong options

From C and C′ alone (same key K reused), what can Eve compute with certainty?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. M ⊕ M′, the XOR of the two plaintexts — the key cancels out.
  • B. Nothing at all; reusing the key still gives perfect secrecy for each message.
  • C. Both M and M′ directly, in full, with no further information.
  • D. The key K, but not M ⊕ M′.

Survives elimination: A

Why: §6.3: C = M ⊕ K and C′ = M′ ⊕ K, so C ⊕ C′ = (M ⊕ K) ⊕ (M′ ⊕ K) = M ⊕ M′ because K ⊕ K = 0. Eve gets the XOR of the two plaintexts with no key. She cannot separate M from M′ without extra information (e.g. a known message or crib), but the reuse has already broken perfect secrecy.

85. Checkpoint — what can Eve compute?

Check

Alice carelessly encrypts two different messages M and M′ with the SAME one-time-pad key K, producing ciphertexts C and C′. Eve intercepts both C and C′ but does not know K, M, or M′. Work it out on paper first.

Check your understanding

From C and C′ alone (same key K reused), what can Eve compute with certainty?

  • A. M ⊕ M′, the XOR of the two plaintexts — the key cancels out. (correct)
  • B. Nothing at all; reusing the key still gives perfect secrecy for each message.
  • C. Both M and M′ directly, in full, with no further information.
  • D. The key K, but not M ⊕ M′.

Answer: A

Why: §6.3: C = M ⊕ K and C′ = M′ ⊕ K, so C ⊕ C′ = (M ⊕ K) ⊕ (M′ ⊕ K) = M ⊕ M′ because K ⊕ K = 0. Eve gets the XOR of the two plaintexts with no key. She cannot separate M from M′ without extra information (e.g. a known message or crib), but the reuse has already broken perfect secrecy.

Why B tempts people
Perfect secrecy holds only for a SINGLE use of the key. The moment one key covers two messages, XOR-ing the ciphertexts cancels K and leaks M ⊕ M′ — the guarantee is gone.
Why C tempts people
Eve gets only the combined M ⊕ M′, not the individual plaintexts. Recovering M and M′ separately requires additional info such as a known message or predictable structure (crib-dragging).
Why D tempts people
The key does not drop out by itself: C ⊕ C′ cancels K and yields M ⊕ M′. Eve can only recover K if she additionally learns one plaintext (then K = M ⊕ C) — not from C and C′ alone.

86. Misconceptions to retire

Concept

87. Synthesis — XOR and the pad underpin the unit

Concept

88. Primary sources & where to read more

Concept

89. Connect it up: L19 · One-Time Pad, XOR & the IND-CPA Game

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — One Operation: XOR · The One-Time Pad · Why It's Perfectly Secret · The Fatal Flaw: Key Reuse · Holding OTP to the IND-CPA Bar. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

90. Recap — Lesson 19

Recap

You can now compute with XOR and its algebra, run the one-time pad both directions, explain its perfect secrecy, carry out the two-time-pad break and tie it to VENONA, and prove OTP-with-key-reuse fails IND-CPA while single-use OTP passes perfectly.

Idea§The one-line version
XOR algebra6.2x⊕x=0, x⊕0=x, and x⊕y⊕x=y cancel out
One-time pad6.3C = M⊕K to send, M = C⊕K to read
Perfect secrecy6.3C is uniform random; one key per ciphertext
Two-time pad6.3Reuse ⇒ C⊕C′ = M⊕M′ leaks the plaintexts' XOR
VENONA6.3Soviet reuse let the U.S. read 'unbreakable' OTP traffic
OTP & IND-CPA6.1Single use wins; key reuse loses with advantage 1/2
Impracticality6.3Key as long as the message, never reused

Sources

  1. CS 161 Computer Security Textbook §6.1–6.3 — Wagner, Weaver, Kao, Shakir, Law & Ngai, UC Berkeley — XOR and its properties (§6.2), the one-time pad and its information-theoretic perfect secrecy plus the key-reuse (two-time-pad) break (§6.3), and the formal IND-CPA security game (§6.1)
  2. Communication Theory of Secrecy Systems — C. E. Shannon, Bell System Technical Journal 28(4), pp. 656–715 (1949) — proves the perfect (information-theoretic) secrecy of the one-time pad
  3. VENONA Project (declassified release) — U.S. National Security Agency — historical decryption of Soviet one-time-pad traffic that reused key material; kept secret until the early 1980s, publicly released beginning 1995

Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108