CS 161, Lesson 19, in 50 slides. It covers XOR and its algebra in section 6.2, the one-time pad and its perfect secrecy in section 6.3, and the fatal two-time-pad break that key reuse allows, as seen in VENONA. It then gives the formal IND-CPA game from section 6.1 and uses it to prove that a one-time pad with a reused key is not IND-CPA. It is anchored to textbook sections 6.1 to 6.3.
Subject: Computer Security · 90 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 19 of 45
XOR algebra · the one-time pad · perfect secrecy · the two-time-pad break · IND-CPA, now formal
Objectives
Warm-up
Discussion prompt
Before we open L19 · One-Time Pad, XOR & the IND-CPA Game: without looking back, what was the main idea of L18 · Kerckhoff's Principle, Attacker Models & IND-CPA, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161, Lesson 18, in 50 slides. It covers Kerckhoff's Principle, which holds that the key is the only secret, then the hierarchy of attacker models running from COA through KPA, replay, CPA, and CCA to CCA2, and an informal IND-CPA security game. Together these set the rules of the game for the whole cryptography unit. It is anchored to textbook sections 5.8 to 5.9 and to section 6.1.
Concept
Last lesson set the rules of the game — Kerckhoff, the attacker models, and IND-CPA. Now we build the very first cipher and hold it to that bar.
Matching
Match the pairs
From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.
Why: What is the tool?, What is the cipher?, Does it pass IND-CPA? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §6.2 XOR and its algebra
Concept
Imagine you want to scramble a string of bits using a secret string of bits, in a way you can perfectly undo later with the same secret. You need an operation that mixes two bits and is reversible.
That operation is XOR (exclusive or), written ⊕. It is the single building block under the one-time pad — and, later, under every stream cipher.
Concept
XOR (⊕) — The exclusive-or of two bits: 1 when the bits differ, 0 when they are the same. Equivalently, addition modulo 2.
| x | y | x ⊕ y |
|---|---|---|
| 0 | 0 | 0 |
| 0 | 1 | 1 |
| 1 | 0 | 1 |
| 1 | 1 | 0 |
Read it as: 'output 1 exactly when the inputs disagree.' That single fact generates everything else.
Comparison
Comparison matrix
From §6.2 XOR, by its truth table: refill the y column from what you know. The rest of the table is as it appeared.
| x | y | x ⊕ y |
|---|---|---|
| 0 | 0 | 0 |
| 0 | 1 | 1 |
| 1 | 0 | 1 |
| 1 | 1 | 0 |
Concept
XOR obeys four laws. Each one is just the truth table, written as an identity you can apply mechanically.
\[ x \oplus 0 = x \quad\text{(identity)} \]
\[ x \oplus x = 0 \quad\text{(self-inverse)} \]
\[ x \oplus y = y \oplus x \quad\text{(commutative)} \]
\[ (x \oplus y) \oplus z = x \oplus (y \oplus z) \quad\text{(associative)} \]
Counterexample
Discussion prompt
XOR obeys four laws. Each one is just the truth table, written as an identity you can apply mechanically.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Intuition
Most operations destroy information — once you AND two bits, you can't always recover the inputs. XOR is different: it never loses anything, because you can always run it backwards with the same value.
The reason is the self-inverse law: XOR-ing by the same thing twice cancels it out, returning you to where you started. The 'lock' and the 'key' are literally the same move.
Ask yourself: if I scramble a bit by flipping it whenever a secret bit is 1, how do I unscramble it? (Flip it again the same way — two flips return the original.)
Analogy
Discussion prompt
Explain §6.2 Why XOR is its own undo button by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
The reason is the self-inverse law: XOR-ing by the same thing twice cancels it out, returning you to where you started. The 'lock' and the 'key' are literally the same move.
Ranking
Put in order
Put the moves of §6.2 Confirm two algebra laws on the truth table into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Read rows of the truth table where the second input is 0: the output equals the first input.
Worked example
Check identity x ⊕ 0 = x for both values of x
Why: Read rows of the truth table where the second input is 0: the output equals the first input.
| x | 0 | x ⊕ 0 |
|---|---|---|
| 0 | 0 | 0 |
| 1 | 0 | 1 |
Check self-inverse x ⊕ x = 0 for both values of x
Why: Read the rows where both inputs are equal: equal bits always XOR to 0.
| x | x | x ⊕ x |
|---|---|---|
| 0 | 0 | 0 |
| 1 | 1 | 0 |
Verify: both laws hold on every row, so they hold for all bits
Why: §6.2: a one-bit law that holds on all rows of the truth table extends bitwise to whole strings — these are the laws decryption relies on.
Trade off
Comparison matrix
From §6.2 Confirm two algebra laws on the truth table: every row here is a choice with a cost. Fill the 0 column, then say which row you would actually pick and what you give up for it.
| x | 0 | x ⊕ 0 |
|---|---|---|
| 0 | 0 | 0 |
| 1 | 0 | 1 |
Concept
Combining commutativity, associativity, and self-inverse gives the one identity you'll use constantly in proofs:
\[ x \oplus y \oplus x = y \]
Any value XOR-ed in twice cancels itself out, leaving whatever is in between. This is the whole reason decryption works.
Explain it
Discussion prompt
Explain §6.2 The handy identity: cancel out the x to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Combining commutativity, associativity, and self-inverse gives the one identity you'll use constantly in proofs:
Step zero
Discussion prompt
§6.2 XOR algebra: solve a bit equation — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Start from the equation to solve for y
Answer:
Worked example
Start from the equation to solve for y
Why: We are given a relationship between an unknown bit y and a known bit, and want y by itself.
\[ y \oplus 1 = 0 \]
XOR both sides by 1
Why: Just like adding the same number to both sides of an equation — XOR-ing both sides by the same value keeps them equal.
\[ y \oplus 1 \oplus 1 = 0 \oplus 1 \]
Cancel the two 1's on the left and simplify the right
Why: Self-inverse: 1 ⊕ 1 = 0, and identity: y ⊕ 0 = y. On the right, 0 ⊕ 1 = 1.
\[ y = 1 \]
Verify: substitute y = 1 back into y ⊕ 1
Why: 1 ⊕ 1 = 0, which matches the right-hand side, so y = 1 is correct.
Notation
Annotate
From §6.2 XOR algebra: solve a bit equation — read this one piece at a time. What is each part doing?
On: \( y \oplus 1 \oplus 1 = 0 \oplus 1 \)
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'XOR is basically OR, so 1 ⊕ 1 = 1, and a value XOR-ed with itself stays itself.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0.
A student: apply the XOR truth table exactly.
Why: OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.
Trap
A student: 'XOR is basically OR, so 1 ⊕ 1 = 1, and a value XOR-ed with itself stays itself.'
\[ 1 \oplus 1 \stackrel{?}{=} 1, \qquad x \oplus x \stackrel{?}{=} x \]
Borrow the rules of OR (or AND) for XOR
Why: Wrong. OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.
A student: apply the XOR truth table exactly.
\[ 1 \oplus 1 = 0, \qquad x \oplus x = 0 \]
Use the self-inverse law: equal inputs XOR to 0
Why: §6.2: XOR is 1 only when the inputs disagree. 1 ⊕ 1 = 0 and x ⊕ x = 0 — that cancellation is exactly what makes decryption possible.
Break the constraint
Discussion prompt
The rule this trap just fixed:
A student: apply the XOR truth table exactly.
Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?
Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.
Answer:
OR gives 1 ⊕ 1 = 1, but XOR outputs 1 only when bits DIFFER — equal bits give 0. Forgetting x ⊕ x = 0 destroys every OTP proof.
Intuition
Another way to see XOR: it's addition where you only keep the last bit and throw away any carry. 1 + 1 = 10 in binary, but mod 2 you keep just the 0 — which is exactly 1 ⊕ 1 = 0.
That framing explains the algebra for free: addition mod 2 is commutative and associative, and every element is its own additive inverse. No new rules to memorize.
Ask yourself: in ordinary arithmetic, what undoes adding 5? (Subtracting 5.) In mod-2 arithmetic, what undoes XOR-ing by k? (XOR-ing by k again — it is its own inverse.)
Section
Part 2 · §6.3 the scheme
Concept
Alice and Bob meet in advance and agree on a long secret string of random bits — a 'pad.' Later, apart and watched by Eve, Alice wants to send a message only Bob can read, using that shared pad.
The one-time pad does exactly this with one XOR: combine the message with the pad to send, combine again with the pad to recover. The catch is in the name — one-time.
Concept
One-time pad (OTP) — Alice and Bob share an n-bit key K = k_1…k_n chosen uniformly at random (n independent fair coin flips). Encryption and decryption are a single XOR with that key.
\[ \textbf{KeyGen: } K = k_1 k_2 \cdots k_n, \quad k_i \xleftarrow{\$} \{0,1\} \]
\[ \textbf{Encrypt: } C = M \oplus K \]
\[ \textbf{Decrypt: } M = C \oplus K \]
Definition probe
Sort into buckets
Every line below is part of the definition of XOR (⊕) or of One-time pad (OTP) — one or the other, never both. Put each where it belongs.
Intuition
There's no separate 'decrypt key.' Bob uses the very same pad Alice used — because XOR is its own inverse, applying the pad a second time peels it right back off.
Think of the pad as a layer of random noise laid on top of the message. Adding the identical noise a second time cancels it (x ⊕ x = 0), and the message reappears untouched.
Ask yourself: what single XOR identity from Part 1 guarantees Bob gets M back? (The cancel-out identity: C ⊕ K = M ⊕ K ⊕ K = M.)
Fill the middle
Fill in the blanks
From §6.3 Derive decryption from encryption — finish the line. Write what belongs on the right of the equals sign before you look.
c_j = m_j \oplus k_j
Why: Producing the right-hand side unprompted is the difference between recognising this line and being able to use it. Encryption is defined bit-by-bit: the j-th ciphertext bit is the j-th message bit XOR the j-th key bit.
Worked example
Start from the per-bit encryption rule
Why: Encryption is defined bit-by-bit: the j-th ciphertext bit is the j-th message bit XOR the j-th key bit.
\[ c_j = m_j \oplus k_j \]
XOR both sides by k_j
Why: We want m_j alone; XOR-ing both sides by the same key bit keeps the equation balanced.
\[ c_j \oplus k_j = m_j \oplus k_j \oplus k_j \]
Cancel k_j ⊕ k_j on the right
Why: Self-inverse: k_j ⊕ k_j = 0, and identity: m_j ⊕ 0 = m_j. The key bit cancels itself out.
\[ c_j \oplus k_j = m_j \]
Verify: this says Decrypt = C ⊕ K recovers M exactly
Why: Holding for every bit j, the whole-string identity M = C ⊕ K follows — decryption is just encryption run again with the same pad.
Blank canvas
Draw it
Draw what §6.3 Derive decryption from encryption just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Pattern
Predict first
The table runs: 1 | 1 | 0 | 1 · 2 | 0 | 1 | 1 · 3 | 1 | 1 | 0
In §6.3 Encrypt and decrypt a 4-bit message, given the rows so far: what is the next one — the row where bit j is 4?
Correct: 4 | 1 | 0 | 1
| bit j | m_j | k_j | c_j = m_j ⊕ k_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 0 | 1 | 1 |
| 3 | 1 | 1 | 0 |
| 4 | 1 | 0 | 1 |
Why: The relationship between the columns, not the individual numbers, is what generates the next row. A concrete 4-bit message and a 4-bit pad; the pad was generated by fair coin flips and shared in advance.
Worked example
Take M = 1011 and the shared random key K = 0110
Why: A concrete 4-bit message and a 4-bit pad; the pad was generated by fair coin flips and shared in advance.
Encrypt bit-by-bit: C = M ⊕ K
Why: XOR each message bit with the key bit below it; remember XOR outputs 1 only where the bits differ.
| bit j | m_j | k_j | c_j = m_j ⊕ k_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 0 | 1 | 1 |
| 3 | 1 | 1 | 0 |
| 4 | 1 | 0 | 1 |
\[ C = 1011 \oplus 0110 = 1101 \]
Decrypt: XOR the ciphertext with the same key, C ⊕ K
Why: Bob applies the identical pad; each key bit cancels the one used to encrypt.
| bit j | c_j | k_j | m_j = c_j ⊕ k_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 1 | 1 | 0 |
| 3 | 0 | 1 | 1 |
| 4 | 1 | 0 | 1 |
Verify: C ⊕ K = 1101 ⊕ 0110 = 1011, the original M
Why: The recovered bits 1011 match M exactly — encryption and decryption are the same XOR, so the round trip is lossless.
Comparison
Comparison matrix
From §6.3 Encrypt and decrypt a 4-bit message: refill the m_j column from what you know. The rest of the table is as it appeared.
| bit j | m_j | k_j | c_j = m_j ⊕ k_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 0 | 1 | 1 |
| 3 | 1 | 1 | 0 |
| 4 | 1 | 0 | 1 |
Concept
KeyGen says each bit k_i is an independent fair coin flip — every n-bit key equally likely. This is not a detail you can relax; it is what makes the security proof go through.
A biased or predictable pad lets Eve guess key bits, and a guessed key bit directly exposes the matching plaintext bit (m_j = c_j ⊕ k_j). Randomness is the entire defense.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'I'll save key bits — use a memorable phrase or a repeating pattern as the pad. It's still XOR, so it's still a one-time pad.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak.
A student: what makes a pad a real one-time pad?
Why: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak. Structure destroys perfect secrecy.
Trap
A student: 'I'll save key bits — use a memorable phrase or a repeating pattern as the pad. It's still XOR, so it's still a one-time pad.'
Swap the uniform random key for a structured one
Why: A predictable pad is guessable: Eve who suspects k_j leans on it, and any repetition reintroduces the reuse leak. Structure destroys perfect secrecy.
A student: what makes a pad a real one-time pad?
Use n independent fair coin flips — a fresh uniform random key, used once
Why: §6.3: perfect secrecy requires the key be uniformly random AND used a single time. 'XOR with something' is not enough; the something must be true randomness.
Section
Part 3 · §6.3 perfect secrecy
Concept
Used once with a random key, the one-time pad leaks precisely zero information about the plaintext. This is not 'hard to break' — it is impossible to break, even with infinite computing power.
Perfect (information-theoretic) secrecy — The ciphertext is statistically independent of the plaintext: seeing C tells Eve nothing about M she didn't already know. No amount of computation can change that.
Matching
Match the pairs
Match each term to the definition this lesson gave it — not the one you would guess from the word.
Why: These are the working definitions of XOR (⊕), One-time pad (OTP), Perfect (information-theoretic) secrecy as L19 · One-Time Pad, XOR & the IND-CPA Game uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.
Intuition
Fix any plaintext M. For every possible ciphertext C, there is exactly one key that would produce it: K = M ⊕ C. So each ciphertext is reachable, and by precisely one key.
Because every key is equally likely (fair coin flips), every ciphertext is equally likely too. From Eve's seat, C is a uniformly random n-bit string — and that's true no matter which M Alice sent.
Ask yourself: if the ciphertext distribution is identical for every plaintext, what can C reveal about M? (Nothing — that sameness IS perfect secrecy.)
Step zero
Discussion prompt
§6.3 Every ciphertext is achievable by one key — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Fix the plaintext M and pick ANY target ciphertext C
Answer:
Worked example
Fix the plaintext M and pick ANY target ciphertext C
Why: We want to show C could have come from this M — i.e. the mapping M → C hides nothing about M.
Solve C = M ⊕ K for the key K
Why: XOR both sides by M: the cancel-out identity isolates K.
\[ K = M \oplus C \]
Observe there is exactly ONE such key, and it has probability 1/2^n
Why: K = M ⊕ C is unique, and since K was uniform over all n-bit strings, this particular key is as likely as any other.
Verify: every C is equally likely given M, so the distribution of C does not depend on M
Why: §6.3: Eve sees a uniform random string whatever the plaintext — perfect secrecy, provided the key is random and used ONCE.
Translation
\( K = M \oplus C \)
Draw it
Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.
Hypothesis
Predict first
§6.3 Same ciphertext, two different plaintexts is about to be worked. State your hypothesis first: which rule or definition decides this one, and what is the first move it forces? Then watch whether the example agrees with you.
Correct: Suppose Eve sees the ciphertext C = 1101 and wonders if the message was 1011
Why: We test whether seeing C lets Eve rule any plaintext in or out — if not, C carries no information about M.
A hypothesis you wrote down is falsifiable; a vague sense of how it will go is not. If the example opens somewhere else, that gap is the thing worth chasing.
Worked example
Suppose Eve sees the ciphertext C = 1101 and wonders if the message was 1011
Why: We test whether seeing C lets Eve rule any plaintext in or out — if not, C carries no information about M.
Find the key that maps 1011 to 1101
Why: K = M ⊕ C = 1011 ⊕ 1101 = 0110 — a perfectly valid key, equally likely as any other.
Now suppose instead the message was 0000
Why: Find the key for that plaintext: K = 0000 ⊕ 1101 = 1101 — also a valid, equally likely key.
| candidate M | key K = M ⊕ C | produces C? |
|---|---|---|
| 1011 | 0110 | yes |
| 0000 | 1101 | yes |
| any M | M ⊕ 1101 | yes — exactly one key each |
Verify: EVERY plaintext explains C with exactly one equally-likely key
Why: §6.3: since C is consistent with every M and all keys are equally likely, the ciphertext gives Eve no reason to prefer any plaintext — perfect secrecy.
Trade off
Comparison matrix
From §6.3 Same ciphertext, two different plaintexts: every row here is a choice with a cost. Fill the key K = M ⊕ C column, then say which row you would actually pick and what you give up for it.
| candidate M | key K = M ⊕ C | produces C? |
|---|---|---|
| 1011 | 0110 | yes |
| 0000 | 1101 | yes |
| any M | M ⊕ 1101 | yes — exactly one key each |
Concept
Most ciphers (AES, RSA) are only computationally secure: safe because breaking them takes infeasibly long. The OTP is stronger — it leaks zero information even to an attacker with unlimited time and compute.
Shannon proved this in 1949: because C is uniform random independent of M, there is simply no information in the ciphertext to extract. There is nothing to compute, fast or slow.
Section
Part 4 · §6.3 the two-time pad
Concept
Perfect secrecy came with fine print: the key must be random and used exactly once. Reuse the same pad on two messages and the whole guarantee collapses.
Reusing the pad once is called a two-time pad — and it is one of the most famous self-inflicted wounds in cryptographic history.
Ranking
Put in order
Put the moves of §6.3 The key cancels: C ⊕ C′ = M ⊕ M′ into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. C = M ⊕ K and C′ = M′ ⊕ K — Eve intercepts both ciphertexts off the wire.
Worked example
Suppose the SAME key K encrypts two messages M and M′
Why: C = M ⊕ K and C′ = M′ ⊕ K — Eve intercepts both ciphertexts off the wire.
Eve XORs the two ciphertexts together
Why: She controls neither M nor K, but she can always XOR two strings she has seen.
\[ C \oplus C' = (M \oplus K) \oplus (M' \oplus K) \]
Reorder and cancel the two copies of K
Why: Commutativity and associativity let Eve group the keys together; K ⊕ K = 0 by self-inverse, so the key vanishes.
\[ C \oplus C' = M \oplus M' \]
Verify the leak: Eve now holds M ⊕ M′ with no key needed
Why: §6.3: reuse turns two ciphertexts into the XOR of the two plaintexts — a real leak that destroys perfect secrecy.
Step zero
Discussion prompt
§6.3 Compute C ⊕ C′ from two intercepted ciphertexts — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Eve intercepts two ciphertexts made with the same pad: C = 1101 and…
Answer:
Worked example
Eve intercepts two ciphertexts made with the same pad: C = 1101 and C′ = 0111
Why: Both came from one reused key K; Eve knows neither K nor the plaintexts, only these bits off the wire.
XOR them bit-by-bit to get M ⊕ M′
Why: C ⊕ C′ = M ⊕ M′ because the shared K cancels — Eve does not need the key at all.
| bit j | c_j | c′_j | c_j ⊕ c′_j = m_j ⊕ m′_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 1 | 1 | 0 |
| 3 | 0 | 1 | 1 |
| 4 | 1 | 1 | 0 |
\[ C \oplus C' = 1101 \oplus 0111 = 1010 = M \oplus M' \]
Verify the leak: 1010 tells Eve every bit where the two plaintexts DIFFER
Why: §6.3: a 1 marks a position where M and M′ disagree, a 0 where they match — real, key-free information that perfect secrecy was supposed to forbid.
Comparison
Comparison matrix
From §6.3 Compute C ⊕ C′ from two intercepted ciphertexts: refill the c_j column from what you know. The rest of the table is as it appeared.
| bit j | c_j | c′_j | c_j ⊕ c′_j = m_j ⊕ m′_j |
|---|---|---|---|
| 1 | 1 | 0 | 1 |
| 2 | 1 | 1 | 0 |
| 3 | 0 | 1 | 1 |
| 4 | 1 | 1 | 0 |
Worked example
Start from what the reuse already leaked: M ⊕ M′
Why: From the previous slide, Eve computed C ⊕ C′ = M ⊕ M′ with no key.
Suppose Eve also learns M (a guessed header, a known field, crib-dragging)
Why: Known-plaintext is realistic — predictable structure hands Eve M for free, as in Lesson 18.
Recover the other message by XOR-ing M back in
Why: (M ⊕ M′) ⊕ M = M′ by the cancel-out identity — the known message cancels itself, exposing M′.
\[ M' = (M \oplus M') \oplus M \]
Recover the key itself from M and its ciphertext C
Why: Since C = M ⊕ K, XOR-ing gives K = M ⊕ C — and now Eve can read every message ever sent under this pad.
\[ K = M \oplus C \]
Worked example
Recall that a true one-time pad is unbreakable — IF the key is never reused
Why: Soviet intelligence used one-time pads precisely because, used correctly, they cannot be broken.
Note the operational failure: Soviet key generators got lazy and reused key material
Why: Manufacturing fresh random pads at scale is hard; duplicate pages of key material went into the field — creating two-time pads.
Predict what U.S. codebreakers could then do
Why: Reused key means C ⊕ C′ = M ⊕ M′; with cribs and known plaintext the analysts could peel apart the underlying messages — exactly the break we just derived.
Observe the outcome: the VENONA project read reused-key Soviet traffic, kept secret until the early 1980s
Why: §6.3: a real superpower's 'unbreakable' cipher fell to a single rule violation — reuse. The math, not the spies, did the damage.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'I can safely reuse a one-time pad as long as I encrypt two DIFFERENT messages with it.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.
A student: when is a pad safe to use a second time?
Why: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.
Trap
A student: 'I can safely reuse a one-time pad as long as I encrypt two DIFFERENT messages with it.'
Assume different plaintexts make reuse safe
Why: Backwards. Different plaintexts are exactly the break: C ⊕ C′ = M ⊕ M′ leaks information about how the two messages relate — and with one known, the other falls.
A student: when is a pad safe to use a second time?
Never reuse a pad — generate fresh random key bits for every message
Why: §6.3: perfect secrecy holds only for a single use. The instant a key covers two messages, the key cancels and the plaintexts' XOR leaks.
Section
Part 5 · §6.1 the game, now formal
Concept
Lesson 18 sketched the indistinguishability game. Here it is precisely, as a contest between a challenger and an adversary Eve.
Intuition
Picture two parallel worlds. In World 0 the challenger always encrypts M_0; in World 1 it always encrypts M_1. Eve is dropped into one and must say which world she's in.
If the ciphertexts (and oracle answers) look indistinguishable across the two worlds, Eve is stuck guessing — that's where IND, indistinguishability, gets its name.
Ask yourself: for single-use OTP, do the two worlds look different? (No — C is uniform random in both, so they're identical and Eve must guess.)
Concept
Eve already knows M_0 and M_1 — she chose them. The only secret is b. Her advantage measures how much the ciphertext helps her recover that one bit.
\[ \mathrm{Adv}(\text{Eve}) = \left| \Pr[b' = b] - \tfrac{1}{2} \right| \]
IND-CPA secure means this advantage is negligibly small for every efficient Eve. Any non-negligible edge above 1/2 is leaked information.
Explain it
Discussion prompt
Explain §6.1 Advantage: how far above a coin flip to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Eve already knows M_0 and M_1 — she chose them. The only secret is b. Her advantage measures how much the ciphertext helps her recover that one bit.
Intuition
Used once, the one-time pad has perfect secrecy — the ciphertext is uniform random whatever the plaintext. So C looks identical whether Alice encrypted M_0 or M_1.
With nothing to distinguish the two worlds, Eve can only guess: Pr[b′ = b] = 1/2 exactly, advantage 0. Single-use OTP doesn't just pass IND-CPA, it passes the strongest possible bar.
Ask yourself: so where could an OTP-based scheme possibly fail the game? (Only if the SAME key is used more than once — the chosen-plaintext oracle is itself a second use.)
Analogy
Discussion prompt
Explain §6.1 Single-use OTP would WIN this game by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Used once, the one-time pad has perfect secrecy — the ciphertext is uniform random whatever the plaintext. So C looks identical whether Alice encrypted M_0 or M_1.
Step zero
Discussion prompt
§6.1 Prove OTP-with-key-reuse is NOT IND-CPA — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Setup: the scheme uses a FIXED key K for both the oracle and the…
Answer:
Worked example
Setup: the scheme uses a FIXED key K for both the oracle and the challenge
Why: This is the broken variant — the same pad K encrypts every message, including Eve's chosen queries. (A correct OTP would never do this.)
Eve picks two distinct messages M_0 ≠ M_1 and submits them; the challenger returns C = M_b ⊕ K
Why: Standard first move of the game; b is hidden, and Eve wants to decide whether C hides M_0 or M_1.
Eve uses her chosen-plaintext query: ask the oracle to encrypt M_0, receiving M_0 ⊕ K
Why: CPA power lets Eve get the exact ciphertext M_0 produces under the SAME key K — that reuse is the fatal opening.
Eve compares the challenge C with the oracle's answer M_0 ⊕ K
Why: If b = 0 then C = M_0 ⊕ K, identical to the oracle output; if b = 1 then C = M_1 ⊕ K ≠ M_0 ⊕ K since M_0 ≠ M_1.
\[ b' = \begin{cases} 0 & \text{if } C = M_0 \oplus K \\ 1 & \text{otherwise} \end{cases} \]
Verify Eve wins with probability 1, so advantage = 1/2 > 0
Why: §6.1: the guess is always correct, Pr[b′ = b] = 1, advantage |1 − 1/2| = 1/2. OTP-with-key-reuse is decisively NOT IND-CPA.
Notation
Annotate
From §6.1 Prove OTP-with-key-reuse is NOT IND-CPA — read this one piece at a time. What is each part doing?
On: \( b' = \begin{cases} 0 & \text{if } C = M_0 \oplus K \\ 1 & \text{otherwise} \end{cases} \)
Ranking
Put in order
Put the moves of §6.1 The break, with concrete bits into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Two distinct equal-length messages; the challenger holds a fixed K, say 0110, hidden from Eve.
Worked example
Eve submits M_0 = 1011 and M_1 = 0000 to the reused-key challenger
Why: Two distinct equal-length messages; the challenger holds a fixed K, say 0110, hidden from Eve.
The challenger flips b and returns C = M_b ⊕ K
Why: If b = 0: C = 1011 ⊕ 0110 = 1101. If b = 1: C = 0000 ⊕ 0110 = 0110. Eve sees only C, not b.
Eve queries the oracle on M_0 = 1011 and gets back M_0 ⊕ K = 1101
Why: The chosen-plaintext oracle uses the SAME K, so it hands Eve exactly the ciphertext M_0 would produce.
Eve outputs b′ = 0 if C = 1101, else b′ = 1
Why: C = 1101 means the challenge was M_0; anything else (here 0110) means it was M_1. The comparison is exact.
Verify Eve is always right: advantage |1 − 1/2| = 1/2
Why: §6.1: with the concrete bits the distinguisher never errs, confirming OTP-with-key-reuse is not IND-CPA.
Blank canvas
Draw it
Draw what §6.1 The break, with concrete bits just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'VENONA and the reuse attack prove the one-time pad is insecure — don't use it.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation.
A student: what exactly failed in the two-time-pad attacks?
Why: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation. It was REUSE that broke.
Trap
A student: 'VENONA and the reuse attack prove the one-time pad is insecure — don't use it.'
Blame the cipher instead of the misuse
Why: Wrong target. Used correctly — random key, used ONCE — the OTP has perfect secrecy and cannot be broken by any amount of computation. It was REUSE that broke.
A student: what exactly failed in the two-time-pad attacks?
Pin the failure on key reuse, not on the OTP itself
Why: §6.3: single-use OTP is perfectly secure; the chosen-plaintext break and VENONA both exploit a key used MORE THAN ONCE. The rule is the security.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Intuition
The break feels almost too easy — but notice what the chosen-plaintext oracle actually is: a second encryption under the SAME key K. That is precisely the situation OTP forbids.
So OTP failing IND-CPA isn't a contradiction of its perfect secrecy. IND-CPA hands Eve an encryption oracle, and any reusable-key scheme that answers oracle queries is, by definition, reusing its key.
Ask yourself: does a TRUE one-time pad (fresh key per message) even have a meaningful encryption oracle? (No — each message gets its own independent key, so there's nothing to reuse.)
Counterexample
Discussion prompt
The break feels almost too easy — but notice what the chosen-plaintext oracle actually is: a second encryption under the SAME key K. That is precisely the situation OTP forbids.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Answer:
Ask yourself: does a TRUE one-time pad (fresh key per message) even have a meaningful encryption oracle? (No — each message gets its own independent key, so there's nothing to reuse.)
Concept
Even used correctly, the one-time pad is rarely practical. The key must be as long as the message and can never be reused — so to send n bits you must first securely share n fresh random key bits.
But if you already have a secure channel to share an n-bit key, you could have just sent the n-bit message over it. That circularity is why real systems use short, reusable keys with computational ciphers instead.
Constraint
Discussion prompt
Run The one-time-pad playbook with this step confiscated:
Never reuse: two messages under one key give C⊕C′ = M⊕M′; known M ⇒ M′ = (M⊕M′)⊕M and K = M⊕C (VENONA).
Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.
Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.
Answer:
Pattern
Edge cases
Discussion prompt
The one-time-pad playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Elimination
Eliminate the wrong options
From C and C′ alone (same key K reused), what can Eve compute with certainty?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: §6.3: C = M ⊕ K and C′ = M′ ⊕ K, so C ⊕ C′ = (M ⊕ K) ⊕ (M′ ⊕ K) = M ⊕ M′ because K ⊕ K = 0. Eve gets the XOR of the two plaintexts with no key. She cannot separate M from M′ without extra information (e.g. a known message or crib), but the reuse has already broken perfect secrecy.
Check
Alice carelessly encrypts two different messages M and M′ with the SAME one-time-pad key K, producing ciphertexts C and C′. Eve intercepts both C and C′ but does not know K, M, or M′. Work it out on paper first.
Check your understanding
From C and C′ alone (same key K reused), what can Eve compute with certainty?
Answer: A
Why: §6.3: C = M ⊕ K and C′ = M′ ⊕ K, so C ⊕ C′ = (M ⊕ K) ⊕ (M′ ⊕ K) = M ⊕ M′ because K ⊕ K = 0. Eve gets the XOR of the two plaintexts with no key. She cannot separate M from M′ without extra information (e.g. a known message or crib), but the reuse has already broken perfect secrecy.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — One Operation: XOR · The One-Time Pad · Why It's Perfectly Secret · The Fatal Flaw: Key Reuse · Holding OTP to the IND-CPA Bar. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now compute with XOR and its algebra, run the one-time pad both directions, explain its perfect secrecy, carry out the two-time-pad break and tie it to VENONA, and prove OTP-with-key-reuse fails IND-CPA while single-use OTP passes perfectly.
| Idea | § | The one-line version |
|---|---|---|
| XOR algebra | 6.2 | x⊕x=0, x⊕0=x, and x⊕y⊕x=y cancel out |
| One-time pad | 6.3 | C = M⊕K to send, M = C⊕K to read |
| Perfect secrecy | 6.3 | C is uniform random; one key per ciphertext |
| Two-time pad | 6.3 | Reuse ⇒ C⊕C′ = M⊕M′ leaks the plaintexts' XOR |
| VENONA | 6.3 | Soviet reuse let the U.S. read 'unbreakable' OTP traffic |
| OTP & IND-CPA | 6.1 | Single use wins; key reuse loses with advantage 1/2 |
| Impracticality | 6.3 | Key as long as the message, never reused |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.