L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal

CS 161, Lesson 28, in 50 slides. It explains why asymmetric cryptography solves the pre-shared-key problem, in section 11.1, then covers trapdoor one-way functions and the hard problems behind RSA and discrete log, in section 11.2. It covers RSA encryption and why textbook RSA is deterministic and therefore not IND-CPA without OAEP padding, in section 11.3, and El Gamal encryption built on Diffie-Hellman, with a fully worked toy example, in section 11.4. It is anchored to textbook sections 11.1 to 11.4.

Subject: Computer Security · 83 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. Encrypting With a Public Key

Title

CS 161 · Lesson 28 of 45

trapdoor one-way functions · RSA and the IND-CPA flaw of textbook RSA · El Gamal encryption built on Diffie-Hellman

2. By the end of this lesson you can…

Objectives

  1. Explain why public-key encryption solves the pre-shared-key problem symmetric crypto and L27 left open.
  2. Define a trapdoor one-way function and map encrypt/decrypt onto f and f⁻¹ with the secret key as the trapdoor.
  3. State RSA at a high level and explain why textbook RSA is deterministic and therefore not IND-CPA without OAEP padding.
  4. Run El Gamal encryption end to end and compute a ciphertext and its decryption on a concrete toy example.
  5. Explain why El Gamal is probabilistic (a fresh r per message) and how both schemes feed the hybrid model of L29.

3. What survived from L27 · Diffie-Hellman Key Exchange, ECDH & MITM?

Warm-up

Discussion prompt

Before we open L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal: without looking back, what was the main idea of L27 · Diffie-Hellman Key Exchange, ECDH & MITM, and what could you do by the end of it that you could not do before?

Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.

Answer:

CS 161, Lesson 27, in 54 slides. It states the key-exchange problem and gives the paint intuition, in sections 10 and 10.1, then covers one-way functions and the discrete-log problem in section 10.2 and the Diffie-Hellman protocol with a worked toy example in section 10.3. It goes on to elliptic-curve Diffie-Hellman and the equivalences in bit strength, in sections 10.4 and 10.5, and ends with the man-in-the-middle attack that forces authentication, in section 10.6. It is anchored to textbook sections 10.1 to 10.6.

4. Three questions this lesson answers

Concept

L27 let two strangers agree on a key over a public channel — but only a key. This lesson asks how to encrypt an actual message to someone using only their public key, with no shared secret arranged in advance.

Why asymmetric?
§11.1 a public key everyone can encrypt to; a private key only the owner has
What makes it possible?
§11.2 trapdoor one-way functions — RSA factoring, discrete log
Two real schemes
§11.3–11.4 RSA (with OAEP) and El Gamal (built on Diffie-Hellman)

5. Which is which: Three questions this lesson answers

Matching

Match the pairs

From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.

  • c1. Why asymmetric?
  • c2. What makes it possible?
  • c3. Two real schemes
  • b1. §11.1 a public key everyone can encrypt to; a private key only the owner has
  • b2. §11.2 trapdoor one-way functions — RSA factoring, discrete log
  • b3. §11.3–11.4 RSA (with OAEP) and El Gamal (built on Diffie-Hellman)

Why: Why asymmetric?, What makes it possible?, Two real schemes are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.

6. Why Asymmetric Crypto

Section

Part 1 · §11.1 public and private keys

7. §11.1 The problem symmetric crypto kept assuming

Concept

Every symmetric scheme — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. L27's Diffie-Hellman agreed on one over a public channel, but it took a live, two-way exchange.

What if Alice just wants to send Bob an encrypted message right now, with no prior contact and no live handshake? She needs a way to lock a message that only Bob can unlock — using something Bob has published in advance.

8. §11.1 Two keys: one public, one private

Concept

In public-key (asymmetric) encryption, Bob has a key pair. He publishes one half to the world and keeps the other half secret.

Public key (PK) — Bob's key that anyone may obtain and use to ENCRYPT a message intended for Bob. Public knowledge — Eve has it too.

Private key (SK) — Bob's secret key, held only by Bob, used to DECRYPT messages that were encrypted under his public key. Never shared.

9. Break it if you can: §11.1 Two keys: one public, one private

Counterexample

Discussion prompt

In public-key (asymmetric) encryption, Bob has a key pair. He publishes one half to the world and keeps the other half secret.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

10. §11.1 Who uses which key

Concept

Alice encrypts under Bob's public key; only Bob, holding the matching private key, can decrypt. The directions are fixed and not interchangeable.

\[ c = \mathrm{Enc}_{PK_{Bob}}(m), \qquad m = \mathrm{Dec}_{SK_{Bob}}(c) \]

Anyone can encrypt to Bob — there is nothing secret about doing so. The secrecy lives entirely in the private key that reverses it.

11. By analogy: §11.1 Who uses which key

Analogy

Discussion prompt

Explain §11.1 Who uses which key by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Alice encrypts under Bob's public key; only Bob, holding the matching private key, can decrypt. The directions are fixed and not interchangeable.

12. §11.1 The open padlock analogy

Intuition

Think of Bob's public key as an open padlock he mails out by the thousands. Anyone can snap a box shut with one of his padlocks — that's encryption — and drop it in the post.

But only Bob has the key that opens those padlocks — that's his private key. Having the padlock (or watching it click shut) tells you nothing about how to open it.

Ask yourself: does handing out padlocks weaken Bob's secrecy? (No — locking and unlocking are different operations; the public half only locks.)

13. Teach it back: §11.1 The open padlock analogy

Explain it

Discussion prompt

Explain §11.1 The open padlock analogy to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Think of Bob's public key as an open padlock he mails out by the thousands. Anyone can snap a box shut with one of his padlocks — that's encryption — and drop it in the post.

14. §11.1 Symmetric vs asymmetric, side by side

Concept

The two worlds differ in one decisive place: whether the encrypt key and decrypt key are the same secret or a split pair. That split is what removes the prior-meeting requirement.

Symmetric (L19–24)Asymmetric (this lesson)
Keysone shared secret Kpublic PK + private SK
Encrypt withKBob's PK (anyone)
Decrypt withKBob's SK (only Bob)
Setup neededpre-shared keyjust publish PK
Speedfastslow (use for key transport)

15. Fill in: Symmetric (L19–24) for §11.1 Symmetric vs asymmetric, side by side

Comparison

Comparison matrix

From §11.1 Symmetric vs asymmetric, side by side: refill the Symmetric (L19–24) column from what you know. The rest of the table is as it appeared.

Symmetric (L19–24)Asymmetric (this lesson)
Keysone shared secret Kpublic PK + private SK
Encrypt withKBob's PK (anyone)
Decrypt withKBob's SK (only Bob)
Setup neededpre-shared keyjust publish PK
Speedfastslow (use for key transport)

16. §11.1 The payoff: key management at scale

Concept

Public-key crypto fixes key distribution. To talk to N people, Bob publishes ONE public key instead of pre-sharing N separate symmetric keys. Anyone can reach him without a prior secret meeting.

In practice Alice doesn't encrypt a long message directly. She encrypts a fresh symmetric key K under Bob's public key, then encrypts the bulk with fast AES under K — the hybrid model of L29.

17. Something is wrong here: 'the public key decrypts the message'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'The public key is the one everyone has, so it must be the one that opens — the public key decrypts the ciphertext.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: If the public key could decrypt, then Eve — who also has it — could read everything.

A student: which key reverses the encryption, and why must it be that one?

Why: If the public key could decrypt, then Eve — who also has it — could read everything. The public key only ENCRYPTS.

18. Trap: 'the public key decrypts the message'

Trap

The trap

A student: 'The public key is the one everyone has, so it must be the one that opens — the public key decrypts the ciphertext.'

\[ m \stackrel{?}{=} \mathrm{Dec}_{PK_{Bob}}(c) \]

Use Bob's PUBLIC key to recover the plaintext

Why: Wrong. If the public key could decrypt, then Eve — who also has it — could read everything. The public key only ENCRYPTS.

The fix

A student: which key reverses the encryption, and why must it be that one?

Decrypt with Bob's PRIVATE key, the only secret half

Why: §11.1: public encrypts, private decrypts. Only Bob holds SK, so only Bob can invert Enc — that asymmetry is the whole point.

19. Decode the notation: Trap: 'the public key decrypts the message'

Notation

Annotate

From Trap: 'the public key decrypts the message' — read this one piece at a time. What is each part doing?

On: \( m \stackrel{?}{=} \mathrm{Dec}_{PK_{Bob}}(c) \)

  • Wrong. If the public key could decrypt, then Eve — who also has it — could read everything. The public key only ENCRYPTS.
  • §11.1: public encrypts, private decrypts. Only Bob holds SK, so only Bob can invert Enc — that asymmetry is the whole point.

20. Trapdoor One-Way Functions

Section

Part 2 · §11.2 the math behind public keys

21. §11.2 From one-way to one-way-with-a-backdoor

Concept

L27 gave us one-way functions: easy forward, infeasible to invert. Public-key encryption needs more — a one-way function that the OWNER can secretly invert, while everyone else still cannot.

Trapdoor one-way function — A one-way function f with a secret 'trapdoor' SK: given x, f(x) is easy; given y = f(x), inverting is infeasible WITHOUT the trapdoor; but given y AND the trapdoor SK, inverting is easy.

22. §11.2 Three difficulty regimes, side by side

Concept

A trapdoor function lives in three worlds at once. The whole scheme depends on keeping these difficulties exactly where they are.

You are given…TaskDifficulty
xcompute y = f(x)easy (forward)
y, no trapdoorfind x with f(x) = yinfeasible
y and trapdoor SKfind x with f(x) = yeasy (invert)

23. What each one costs: §11.2 Three difficulty regimes, side by side

Trade off

Comparison matrix

From §11.2 Three difficulty regimes, side by side: every row here is a choice with a cost. Fill the Task column, then say which row you would actually pick and what you give up for it.

You are given…TaskDifficulty
xcompute y = f(x)easy (forward)
y, no trapdoorfind x with f(x) = yinfeasible
y and trapdoor SKfind x with f(x) = yeasy (invert)

24. §11.2 Map the trapdoor onto encryption

Concept

Now the dictionary is direct: f is 'encrypt with the public key', and f⁻¹ is 'decrypt with the private key.' The private key IS the trapdoor.

\[ f(m) = \mathrm{Enc}_{PK}(m), \qquad f^{-1}(c) = \mathrm{Dec}_{SK}(c) \]

Anyone can apply f (encrypt). Only the holder of SK can apply f⁻¹ (decrypt). 'Hard to invert without the trapdoor' is exactly 'hard to decrypt without the private key.'

25. §11.2 Why a plain one-way function isn't enough

Intuition

A plain one-way function (like a hash) is a one-way street with NO return lane — nobody can go back, not even its creator. That's perfect for fingerprints, useless for encryption: Bob needs to read his mail.

A trapdoor function adds a private return lane that only the key-holder can drive. Forward is open to all; backward is gated, and only SK opens the gate.

Ask yourself: what would happen if the trapdoor were public? (Then everyone could invert f, and the 'one-way' property would be gone for everyone — see the next trap.)

26. §11.2 Example trapdoor #1: RSA / factoring

Concept

Build a modulus from two large secret primes. Multiplying them is easy; un-multiplying (factoring) the product is believed hard.

\[ n = p \cdot q \quad (p, q \text{ large secret primes}) \]

\[ \text{Given } c = m^{e} \bmod n \text{ and } e:\ \text{find } m \text{ is hard} \]

But knowing the factorization (p or q) makes inverting easy — the factorization is the trapdoor. Security rests on factoring n being hard.

27. §11.2 Example trapdoor #2: discrete log

Concept

The L27 hard problem reappears. From the public values you can't combine your way to the shared exponentiated secret — that's the Diffie-Hellman gap.

\[ \text{Given } g,\ p,\ A = g^{a},\ B = g^{b}:\ \text{find } g^{ab} \text{ is hard} \]

But anyone who knows a or b computes g^{ab} instantly — the private exponent is the trapdoor. This is the engine under El Gamal (Part 4).

28. What has to happen first: §11.2 Read a trapdoor function as encrypt/decrypt

Ranking

Put in order

Put the moves of §11.2 Read a trapdoor function as encrypt/decrypt into the order they have to happen.

  1. Identify f for an RSA-style scheme: f(m) = m^e mod n, with PK = (n, e)
  2. Identify the trapdoor: the factorization of n (equivalently the private exponent d)
  3. Identify f⁻¹: f⁻¹(c) = c^d mod n, applied with the private key
  4. State who can do what: everyone applies f, only Bob applies f⁻¹
  5. Verify the mapping is consistent: PK ↔ f ↔ Enc, SK ↔ trapdoor ↔ Dec

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Encrypting is applying the public one-way map; anyone with (n, e) can do it, so anyone can send Bob ciphertext.

29. §11.2 Read a trapdoor function as encrypt/decrypt

Worked example

Identify f for an RSA-style scheme: f(m) = m^e mod n, with PK = (n, e)

Why: Encrypting is applying the public one-way map; anyone with (n, e) can do it, so anyone can send Bob ciphertext.

Identify the trapdoor: the factorization of n (equivalently the private exponent d)

Why: Without the factors, inverting m^e mod n is the hard RSA problem; with them you derive d and invert easily.

Identify f⁻¹: f⁻¹(c) = c^d mod n, applied with the private key

Why: Decryption is the gated return lane — it needs the trapdoor d that only Bob holds.

State who can do what: everyone applies f, only Bob applies f⁻¹

Why: The public half is the open padlock; the private half is the only key that opens it.

Verify the mapping is consistent: PK ↔ f ↔ Enc, SK ↔ trapdoor ↔ Dec

Why: §11.2: 'hard to invert without the trapdoor' is exactly 'hard to decrypt without the private key' — the encryption scheme IS the trapdoor function.

30. Draw the shape of it: §11.2 Read a trapdoor function as…

Blank canvas

Draw it

Draw what §11.2 Read a trapdoor function as encrypt/decrypt just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

31. Something is wrong here: 'the trapdoor is public knowledge'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'The trapdoor is part of the function's definition, so it's published along with the public key.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.

A student: what exactly is the trapdoor, and who is allowed to have it?

Why: If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.

32. Trap: 'the trapdoor is public knowledge'

Trap

The trap

A student: 'The trapdoor is part of the function's definition, so it's published along with the public key.'

Treat the trapdoor SK as part of the public parameters

Why: Wrong. If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.

The fix

A student: what exactly is the trapdoor, and who is allowed to have it?

Recognize the trapdoor IS the private key — held only by the owner

Why: §11.2: the public key defines f (easy forward, hard to invert). The trapdoor (factorization / private exponent) is the secret that makes f⁻¹ easy — and it must stay private.

33. RSA Encryption & the IND-CPA Flaw

Section

Part 3 · §11.3 why textbook RSA needs OAEP

34. §11.3 RSA at a high level

Concept

RSA (Rivest, Shamir, Adleman, 1978) is the classic trapdoor scheme. The public key encrypts, the private key decrypts, and security rests on factoring n = pq being hard.

\[ c = m^{e} \bmod n, \qquad m = c^{d} \bmod n \]

PK = (n, e) is published; SK = d is derived from the secret factors p, q. Recovering m from c without d means inverting a power mod n — the hard RSA problem.

35. §11.3 Why factoring is the trapdoor

Intuition

Multiplying two huge primes p and q to get n is a one-second operation. Going backward — splitting a 2048-bit n into its two prime factors — has no known efficient algorithm; it is the wall RSA leans on.

Bob built n himself, so he KNOWS p and q. That knowledge lets him compute the private exponent d and invert the encryption. Everyone else faces the factoring wall.

Ask yourself: why is knowing the factors the same as knowing the trapdoor? (From p and q you derive d; d is the secret return lane. No factors ⇒ no d ⇒ no decryption.)

36. §11.3 Do NOT implement RSA yourself

Concept

RSA is famously easy to get subtly, fatally wrong — bad padding, weak random primes, side channels. The textbook itself flags this section as 'under construction' and says to use a real, vetted library.

Use a vetted library — Never hand-roll RSA (or any primitive). Real deployments call audited implementations that handle padding, prime generation, and constant-time math correctly.

37. Term to definition: L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal

Matching

Match the pairs

Match each term to the definition this lesson gave it — not the one you would guess from the word.

  • t1. Public key (PK)
  • t2. Private key (SK)
  • t3. Use a vetted library
  • d1. Bob's key that anyone may obtain and use to ENCRYPT a message intended for Bob. Public knowledge — Eve has it too.
  • d2. Bob's secret key, held only by Bob, used to DECRYPT messages that were encrypted under his public key. Never shared.
  • d3. Never hand-roll RSA (or any primitive). Real deployments call audited implementations that handle padding, prime generation, and constant-time math correctly.

Why: These are the working definitions of Public key (PK), Private key (SK), Use a vetted library as L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.

38. §11.3 The flaw: textbook RSA is deterministic

Concept

Plain ('textbook') RSA encrypts m as m^e mod n with no randomness. The same message under the same key always produces the same ciphertext.

\[ \mathrm{Enc}(m) = m^{e} \bmod n \ \text{ is a fixed function of } m \]

A deterministic encryption scheme cannot be IND-CPA — exactly the L18 lesson again. Equal plaintexts give equal ciphertexts, so repeats leak.

39. §11.3 Why determinism leaks information

Intuition

Suppose a sensor sends either 'ARMED' or 'SAFE' each minute. Under deterministic RSA, 'ARMED' always encrypts to one fixed blob and 'SAFE' to another. Eve can't read the words — but she sees when the value repeats and when it flips.

For a two-message vote, login state, or yes/no flag, that's the whole secret. Leaking equality of plaintexts is leaking information — which IND-CPA forbids by definition.

Ask yourself: how can the SAME message ever produce DIFFERENT ciphertexts? (Mix in fresh randomness each time — that's what padding does.)

40. §11.3 The fix: a randomized padding mode

Concept

Make encryption probabilistic by mixing fresh randomness into m before exponentiating. In RSA this is done by a padding mode.

Despite the name, these padding modes act more like a block cipher's IV than like block-cipher length-padding: they inject randomness so the ciphertext 'looks random,' yet the receiver can still strip it off and recover m exactly.

41. §11.3 OAEP, in one breath

Concept

OAEP (Optimal Asymmetric Encryption Padding) — A randomized padding scheme (Bellare & Rogaway, 1994). Effectively it generates a random value, scrambles the message with it, and encrypts BOTH — so to recover m an attacker must recover both halves. This makes RSA semantically (IND-CPA) secure.

OAEP is randomization, not length-stuffing. The randomness is the point: it makes two encryptions of the same m look unrelated.

42. Plan first: §11.3 Same message, twice: plain RSA vs OAEP

Step zero

Discussion prompt

§11.3 Same message, twice: plain RSA vs OAEP — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Scenario: Alice encrypts the identical message m to Bob on Monday and…

Answer:

  1. Scenario: Alice encrypts the identical message m to Bob on Monday and again on Tuesday
  2. Under plain RSA, both sends compute m^e mod n — a fixed value
  3. Under OAEP, each send first mixes in a FRESH random value, then encrypts
  4. Verify: plain RSA reveals the repeat; OAEP hides it, yet both decrypt to m

43. §11.3 Same message, twice: plain RSA vs OAEP

Worked example

Scenario: Alice encrypts the identical message m to Bob on Monday and again on Tuesday

Why: We compare what an eavesdropper observes across two sends of the SAME plaintext — the exact IND-CPA test.

Under plain RSA, both sends compute m^e mod n — a fixed value

Why: No randomness enters, so the ciphertext is a deterministic function of m: Monday's and Tuesday's blobs are byte-for-byte identical.

Under OAEP, each send first mixes in a FRESH random value, then encrypts

Why: Different randomness each time scrambles m differently, so the two ciphertexts look unrelated even though m is the same.

SchemeCiphertext (Mon)Ciphertext (Tue)Eve learns
Plain RSAc₀c₀ (identical)the message repeated → LEAK
RSA-OAEPc₁c₂ (looks unrelated)nothing — IND-CPA

Verify: plain RSA reveals the repeat; OAEP hides it, yet both decrypt to m

Why: §11.3: determinism is the leak. OAEP's fresh randomness gives different ciphertexts for the same m, restoring IND-CPA — and Bob still strips the padding to recover m exactly.

44. Fill in: Eve learns for §11.3 Same message, twice: plain RSA vs OAEP

Comparison

Comparison matrix

From §11.3 Same message, twice: plain RSA vs OAEP: refill the Eve learns column from what you know. The rest of the table is as it appeared.

SchemeCiphertext (Mon)Ciphertext (Tue)Eve learns
Plain RSAc₀c₀ (identical)the message repeated → LEAK
RSA-OAEPc₁c₂ (looks unrelated)nothing — IND-CPA

45. Something is wrong here: 'textbook RSA is already IND-CPA secure'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'RSA is a respected public-key cipher, so c = m^e mod n is IND-CPA secure on its own.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts.

A student: what must be added to RSA to make it IND-CPA secure?

Why: Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts. Any deterministic scheme loses the IND-CPA game by encrypting the same message twice and spotting the match.

46. Trap: 'textbook RSA is already IND-CPA secure'

Trap

The trap

A student: 'RSA is a respected public-key cipher, so c = m^e mod n is IND-CPA secure on its own.'

Use plain m^e mod n and assume semantic security

Why: Wrong. Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts. Any deterministic scheme loses the IND-CPA game by encrypting the same message twice and spotting the match.

The fix

A student: what must be added to RSA to make it IND-CPA secure?

Add a randomized padding mode such as OAEP

Why: §11.3: OAEP mixes fresh randomness into each encryption, so the same m yields different ciphertexts. Randomized padding is what makes RSA semantically secure.

47. Something is wrong here: 'OAEP is just length padding'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Padding fills the message out to the block size — OAEP just pads m up to n's length.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats.

A student: what does OAEP actually add, and why does it matter?

Why: If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats. Fixed padding does NOT give IND-CPA.

48. Trap: 'OAEP is just length padding'

Trap

The trap

A student: 'Padding fills the message out to the block size — OAEP just pads m up to n's length.'

Treat OAEP as deterministic length-stuffing like a fixed pad byte

Why: Wrong. If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats. Fixed padding does NOT give IND-CPA.

The fix

A student: what does OAEP actually add, and why does it matter?

Recognize OAEP injects fresh RANDOMNESS (more like an IV than like length padding)

Why: §11.3: OAEP scrambles m with a random value and encrypts both, so the same m maps to different ciphertexts. The randomization — not the length — is what buys IND-CPA.

49. El Gamal Encryption

Section

Part 4 · §11.4 public-key encryption on Diffie-Hellman

50. §11.4 El Gamal: Diffie-Hellman, turned into encryption

Concept

El Gamal (Taher Elgamal, 1985) builds public-key encryption directly on Diffie-Hellman. Where DH agreed on a key interactively, El Gamal lets Alice encrypt to Bob's published DH value with no round-trip.

Its security rests on the discrete-log / Diffie-Hellman hardness from L27 — the second trapdoor family from §11.2.

51. §11.4 Public parameters and key generation

Concept

Public parameters, fixed and standardized: a large prime p (≈ 2048 bits) and a generator g with 1 < g < p−1. Bob generates his key pair from them.

\[ \text{Public: } p\ (\approx 2048\text{-bit prime}),\quad g \ \text{with } 1 < g < p-1 \]

\[ \text{Bob picks private } b \in \{0,\dots,p-2\},\ \ B = g^{b} \bmod p \]

B is Bob's public key (his long-term DH value); b is his private key. This is exactly a DH key, published once.

52. §11.4 Encryption: a fresh ephemeral per message

Concept

To encrypt m ∈ {1, …, p−1}, Alice picks a fresh random r ∈ {0, …, p−2} — her one-time ephemeral DH secret — and sends a pair.

\[ \text{ciphertext } (R, S) = \big(\, g^{r} \bmod p,\ \ m \cdot B^{r} \bmod p \,\big) \]

R = g^r is Alice's ephemeral public value; S = m·B^r hides m by multiplying it by the shared DH secret B^r. The fresh r is what makes El Gamal probabilistic.

53. §11.4 Decryption: undo the masking

Concept

Bob receives (R, S). Using his private b, he reconstructs the shared secret from R and divides it out of S.

\[ m = R^{-b} \cdot S \bmod p \]

R^{-b} is the modular inverse of R^b. Multiplying S by it cancels the B^r mask and leaves m — only Bob can do this, because only he knows b.

54. What has to happen first: §11.4 Correctness: why R^{-b}·S returns m

Ranking

Put in order

Put the moves of §11.4 Correctness: why R^{-b}·S returns m into the order they have to happen.

  1. Substitute the ciphertext: R = g^r and S = m·B^r, with B = g^b
  2. Replace B^r with g^{br} since B = g^b
  3. Verify: the exponents br and rb cancel, leaving m exactly

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Decryption acts on exactly the values Alice sent, so we expand them in terms of g, r, b, m.

55. §11.4 Correctness: why R^{-b}·S returns m

Worked example

Substitute the ciphertext: R = g^r and S = m·B^r, with B = g^b

Why: Decryption acts on exactly the values Alice sent, so we expand them in terms of g, r, b, m.

\[ R^{-b} \cdot S = (g^{r})^{-b} \cdot (m \cdot B^{r}) \]

Replace B^r with g^{br} since B = g^b

Why: Bob's public key is g^b, so B^r = (g^b)^r = g^{br} — the shared DH secret Alice multiplied in.

\[ = g^{-rb} \cdot m \cdot g^{br} = m \cdot g^{br - rb} = m \cdot g^{0} = m \pmod p \]

Verify: the exponents br and rb cancel, leaving m exactly

Why: §11.4: because exponents multiply and br = rb, the mask g^{br} and its inverse g^{-rb} annihilate — decryption recovers m for every valid ciphertext.

56. Draw the shape of it: §11.4 Correctness: why R^{-b}·S returns m

Blank canvas

Draw it

Draw what §11.4 Correctness: why R^{-b}·S returns m just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

57. §11.4 El Gamal is a one-time pad over multiplication

Intuition

Read it as Diffie-Hellman: Bob's long-term value is B = g^b; Alice's fresh ephemeral is R = g^r. The shared key is K = g^{rb} = B^r = R^b — a DH secret both sides can form.

Then S = m·K is a one-time pad — but using modular MULTIPLICATION instead of XOR. The 'pad' is the fresh DH secret K; Bob divides it back out to unmask m.

Ask yourself: why must r be fresh every message? (A reused r reuses the pad K — the same one-time-pad rule as L17. Fresh r ⇒ key used once ⇒ probabilistic ⇒ IND-CPA-friendly, unlike plain RSA.)

58. Teach it back: §11.4 El Gamal is a one-time pad over multiplication

Explain it

Discussion prompt

Explain §11.4 El Gamal is a one-time pad over multiplication to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Read it as Diffie-Hellman: Bob's long-term value is B = g^b; Alice's fresh ephemeral is R = g^r. The shared key is K = g^{rb} = B^r = R^b — a DH secret both sides can form.

59. Plan first: §11.4 Toy El Gamal: keygen and encrypt (p = 23, g = 5)

Step zero

Discussion prompt

§11.4 Toy El Gamal: keygen and encrypt (p = 23, g = 5) — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Fix public parameters p = 23, g = 5 (tiny, for hand computation)

Answer:

  1. Fix public parameters p = 23, g = 5 (tiny, for hand computation)
  2. Bob's keygen: private b = 6, public B = 5^6 mod 23 = 8
  3. Alice encrypts m = 4 with fresh ephemeral r = 3
  4. Alice sends the ciphertext pair (R, S) = (10, 1)

60. §11.4 Toy El Gamal: keygen and encrypt (p = 23, g = 5)

Worked example

Fix public parameters p = 23, g = 5 (tiny, for hand computation)

Why: Real El Gamal uses a 2048-bit prime; a small prime lets us check every step by hand. Eve also knows p and g.

Bob's keygen: private b = 6, public B = 5^6 mod 23 = 8

Why: From the L27 repeated-squaring result, 5^6 mod 23 = 8, so Bob publishes B = 8 and keeps b = 6.

\[ B = g^{b} \bmod p = 5^{6} \bmod 23 = 8 \]

Alice encrypts m = 4 with fresh ephemeral r = 3

Why: She computes R = g^r and S = m·B^r mod p; r = 3 is her one-time secret for this message.

\[ R = g^{r} \bmod p = 5^{3} \bmod 23 = 10 \]

\[ B^{r} \bmod p = 8^{3} \bmod 23 = 6 \ \ (=K,\ \text{the shared secret}) \]

\[ S = m \cdot B^{r} \bmod p = 4 \cdot 6 \bmod 23 = 24 \bmod 23 = 1 \]

Alice sends the ciphertext pair (R, S) = (10, 1)

Why: Eve sees (10, 1) plus public 23, 5, 8 — but not b, r, or m. The message never crosses the wire in the clear.

61. Say it in words: §11.4 Toy El Gamal: keygen and encrypt (p = 23, g…

Translation

\( R = g^{r} \bmod p = 5^{3} \bmod 23 = 10 \)

Draw it

Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.

62. What has to happen first: §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m

Ranking

Put in order

Put the moves of §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m into the order they have to happen.

  1. Bob receives (R, S) = (10, 1) and uses his private b = 6
  2. Compute the shared secret R^b = 10^6 mod 23 = 6
  3. Invert it: R^{-b} = 10^{-6} mod 23 = 4 (the modular inverse of 6 mod 23)
  4. Verify: decryption returns m = 4, the message Alice encrypted

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. He reconstructs the shared secret from R and divides it out of S to recover m.

63. §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m

Worked example

Bob receives (R, S) = (10, 1) and uses his private b = 6

Why: He reconstructs the shared secret from R and divides it out of S to recover m.

Compute the shared secret R^b = 10^6 mod 23 = 6

Why: R^b = (g^r)^b = g^{rb} = K = 6 — the same shared secret Alice formed as B^r, confirming both sides agree.

\[ R^{b} \bmod p = 10^{6} \bmod 23 = 6 = B^{r} \]

Invert it: R^{-b} = 10^{-6} mod 23 = 4 (the modular inverse of 6 mod 23)

Why: 6 · 4 = 24 ≡ 1 (mod 23), so 4 is the inverse of the shared secret — multiplying by it cancels the mask.

\[ m = R^{-b} \cdot S \bmod p = 4 \cdot 1 \bmod 23 = 4 \]

Verify: decryption returns m = 4, the message Alice encrypted

Why: §11.4: R^{-b}·S = 4·1 = 4 = m. The exponents cancelled exactly as the correctness proof predicted — Bob recovers the plaintext using only his private key.

64. Decode the notation: §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m

Notation

Annotate

From §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m — read this one piece at a time. What is each part doing?

On: \( m = R^{-b} \cdot S \bmod p = 4 \cdot 1 \bmod 23 = 4 \)

  • He reconstructs the shared secret from R and divides it out of S to recover m.
  • R^b = (g^r)^b = g^{rb} = K = 6 — the same shared secret Alice formed as B^r, confirming both sides agree.
  • 6 · 4 = 24 ≡ 1 (mod 23), so 4 is the inverse of the shared secret — multiplying by it cancels the mask.

65. §11.4 El Gamal at a glance

Concept

The whole scheme on one card — parameters, keys, and the two operations. Notice the ciphertext is a PAIR, twice the length of the message (the ephemeral R rides along).

StageWhat happensFormula
Paramspublic prime and generatorp, g with 1 < g < p−1
KeyGenBob's private / public keyb secret; B = g^b mod p
Encryptfresh r per message; send a pair(R, S) = (g^r, m·B^r) mod p
Decryptundo the mask with private bm = R^{-b}·S mod p

66. Fill in: Formula for §11.4 El Gamal at a glance

Comparison

Comparison matrix

From §11.4 El Gamal at a glance: refill the Formula column from what you know. The rest of the table is as it appeared.

StageWhat happensFormula
Paramspublic prime and generatorp, g with 1 < g < p−1
KeyGenBob's private / public keyb secret; B = g^b mod p
Encryptfresh r per message; send a pair(R, S) = (g^r, m·B^r) mod p
Decryptundo the mask with private bm = R^{-b}·S mod p

67. §11.4 What Eve sees, and why she's stuck

Concept

Eve has the public p, g, B = g^b and the ciphertext (R, S) = (g^r, m·B^r). To strip the mask B^r off S she would need the shared secret g^{rb} from g^b and g^r alone.

\[ \text{Eve has } g^{b},\ g^{r}\ \Rightarrow\ \text{needs } g^{rb}\ \text{(the CDH problem)} \]

That is exactly the L27 Computational Diffie-Hellman problem — believed infeasible for 2048-bit p. Without g^{rb} the mask stays on, so m is hidden.

68. By analogy: §11.4 What Eve sees, and why she's stuck

Analogy

Discussion prompt

Explain §11.4 What Eve sees, and why she's stuck by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Eve has the public p, g, B = g^b and the ciphertext (R, S) = (g^r, m·B^r). To strip the mask B^r off S she would need the shared secret g^{rb} from g^b and g^r alone.

69. §11.4 A caveat: the simple scheme is malleable

Concept

Fresh r makes El Gamal probabilistic and IND-CPA-friendly — but this textbook form is not fully semantically secure in the stronger sense. It is malleable.

\[ (R,\ 2S) \ \text{decrypts to } 2m: \ R^{-b}\cdot(2S) = 2\,(R^{-b} S) = 2m \]

An attacker who doubles S turns an encryption of m into an encryption of 2m without knowing m. Real deployments add integrity / stronger constructions to close this — the same 'need authenticity' theme as L27.

70. Break it if you can: §11.4 A caveat: the simple scheme is malleable

Counterexample

Discussion prompt

Fresh r makes El Gamal probabilistic and IND-CPA-friendly — but this textbook form is not fully semantically secure in the stronger sense. It is malleable.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

71. Something is wrong here: 'El Gamal is deterministic, like textbook RSA'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Encryption maps a message to a ciphertext, so encrypting m twice gives the same (R, S) — El Gamal is deterministic.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change.

A student: what makes El Gamal probabilistic where textbook RSA is not?

Why: Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change. The same m gives different ciphertexts every time.

72. Trap: 'El Gamal is deterministic, like textbook RSA'

Trap

The trap

A student: 'Encryption maps a message to a ciphertext, so encrypting m twice gives the same (R, S) — El Gamal is deterministic.'

Assume (R, S) is a fixed function of m

Why: Wrong. Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change. The same m gives different ciphertexts every time.

The fix

A student: what makes El Gamal probabilistic where textbook RSA is not?

Recognize the fresh ephemeral r randomizes every ciphertext

Why: §11.4: r is chosen anew per message, so the shared secret B^r and the pair (R, S) differ each time. That built-in randomness is exactly what plain RSA lacks.

73. Which of these survive contact with L28 · Public-Key Encryption: Trapdoor…?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
In public-key (asymmetric) encryption, Bob has a key pair. He publishes one half to the world and keeps the other half secret.; Alice encrypts under Bob's public key; only Bob, holding the matching private key, can decrypt. The directions are fixed and not interchangeable.; Ask yourself: does handing out padlocks weaken Bob's secrecy? (No — locking and unlocking are different operations; the public half only locks.)
Breaks
A student: 'The public key is the one everyone has, so it must be the one that opens — the public key decrypts the ciphertext.'; A student: 'The trapdoor is part of the function's definition, so it's published along with the public key.'
sound
These are stated as this lesson states them — each one survives the edge cases L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

74. Without one step: The public-key encryption playbook

Constraint

Discussion prompt

Run The public-key encryption playbook with this step confiscated:

Fix RSA with OAEP: a randomized padding mode (more like an IV than length padding) makes the same m encrypt differently → IND-CPA.

Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.

Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.

Answer:

  1. Two keys: publish a public key (anyone encrypts), keep a private key (only you decrypt). Public encrypts, private decrypts — never the reverse.
  2. Trapdoor core: encryption is a one-way function f; the private key is the trapdoor that makes f⁻¹ (decryption) easy. Keep the trapdoor secret.
  3. RSA: PK = (n, e), SK = d; c = m^e mod n; security = factoring n is hard. Textbook RSA is DETERMINISTIC → not IND-CPA.
  4. Fix RSA with OAEP: a randomized padding mode (more like an IV than length padding) makes the same m encrypt differently → IND-CPA.
  5. El Gamal: DH-based; B = g^b public; encrypt with fresh r as (R, S) = (g^r, m·B^r); decrypt m = R^{-b}·S. A one-time pad over multiplication.
  6. Probabilistic by design: fresh r per message makes El Gamal IND-CPA-friendly; never implement RSA yourself — use a vetted library.

75. The public-key encryption playbook

Pattern

  1. Two keys: publish a public key (anyone encrypts), keep a private key (only you decrypt). Public encrypts, private decrypts — never the reverse.
  2. Trapdoor core: encryption is a one-way function f; the private key is the trapdoor that makes f⁻¹ (decryption) easy. Keep the trapdoor secret.
  3. RSA: PK = (n, e), SK = d; c = m^e mod n; security = factoring n is hard. Textbook RSA is DETERMINISTIC → not IND-CPA.
  4. Fix RSA with OAEP: a randomized padding mode (more like an IV than length padding) makes the same m encrypt differently → IND-CPA.
  5. El Gamal: DH-based; B = g^b public; encrypt with fresh r as (R, S) = (g^r, m·B^r); decrypt m = R^{-b}·S. A one-time pad over multiplication.
  6. Probabilistic by design: fresh r per message makes El Gamal IND-CPA-friendly; never implement RSA yourself — use a vetted library.

76. Where does it stop working: The public-key encryption playbook

Edge cases

Discussion prompt

The public-key encryption playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

  1. Two keys: publish a public key (anyone encrypts), keep a private key (only you decrypt). Public encrypts, private decrypts — never the reverse.
  2. Trapdoor core: encryption is a one-way function f; the private key is the trapdoor that makes f⁻¹ (decryption) easy. Keep the trapdoor secret.
  3. RSA: PK = (n, e), SK = d; c = m^e mod n; security = factoring n is hard. Textbook RSA is DETERMINISTIC → not IND-CPA.
  4. Fix RSA with OAEP: a randomized padding mode (more like an IV than length padding) makes the same m encrypt differently → IND-CPA.
  5. El Gamal: DH-based; B = g^b public; encrypt with fresh r as (R, S) = (g^r, m·B^r); decrypt m = R^{-b}·S. A one-time pad over multiplication.
  6. Probabilistic by design: fresh r per message makes El Gamal IND-CPA-friendly; never implement RSA yourself — use a vetted library.

77. Rule out three: Checkpoint — why isn't textbook RSA IND-CPA?

Elimination

Eliminate the wrong options

Why is plain (textbook) RSA NOT IND-CPA secure, and what fixes it?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. It is deterministic — the same message always yields the same ciphertext, leaking repeats; a randomized padding mode like OAEP fixes it.
  • B. The public key can decrypt ciphertexts, so any eavesdropper with (n, e) reads the message directly.
  • C. Textbook RSA is already IND-CPA secure; no padding or randomness is needed.
  • D. Like El Gamal, RSA reuses a fresh random r each time, and reusing r breaks semantic security.

Survives elimination: A

Why: §11.3: textbook RSA computes c = m^e mod n with no randomness, so it is deterministic — encrypting the same m twice produces the identical ciphertext. Any deterministic scheme loses the IND-CPA game: the adversary submits the same message twice (or two equal challenge messages) and detects the matching ciphertexts. The fix is a randomized padding mode such as OAEP, which mixes fresh randomness into each encryption (acting more like an IV than like length padding), so the same m encrypts to different-looking ciphertexts while still decrypting correctly.

78. Checkpoint — why isn't textbook RSA IND-CPA?

Check

Bob publishes an RSA public key (n, e). Alice encrypts messages with plain 'textbook' RSA, c = m^e mod n, with no padding. Reason it through before choosing.

Check your understanding

Why is plain (textbook) RSA NOT IND-CPA secure, and what fixes it?

  • A. It is deterministic — the same message always yields the same ciphertext, leaking repeats; a randomized padding mode like OAEP fixes it. (correct)
  • B. The public key can decrypt ciphertexts, so any eavesdropper with (n, e) reads the message directly.
  • C. Textbook RSA is already IND-CPA secure; no padding or randomness is needed.
  • D. Like El Gamal, RSA reuses a fresh random r each time, and reusing r breaks semantic security.

Answer: A

Why: §11.3: textbook RSA computes c = m^e mod n with no randomness, so it is deterministic — encrypting the same m twice produces the identical ciphertext. Any deterministic scheme loses the IND-CPA game: the adversary submits the same message twice (or two equal challenge messages) and detects the matching ciphertexts. The fix is a randomized padding mode such as OAEP, which mixes fresh randomness into each encryption (acting more like an IV than like length padding), so the same m encrypts to different-looking ciphertexts while still decrypting correctly.

Why B tempts people
The public key only ENCRYPTS; decryption requires the private key d (derived from the secret factors of n). An eavesdropper with (n, e) cannot decrypt — that is the whole point of the trapdoor. RSA's IND-CPA failure is determinism, not a decrypting public key.
Why C tempts people
Textbook RSA is NOT IND-CPA: with no randomness it is deterministic, and deterministic encryption always loses the IND-CPA game because equal plaintexts produce equal ciphertexts. It needs randomized padding (OAEP) to become semantically secure.
Why D tempts people
Textbook RSA uses NO random r at all — that absence of randomness is precisely why it is deterministic and not IND-CPA. The fresh ephemeral r belongs to El Gamal, where it MAKES the scheme probabilistic rather than breaking it.

79. Misconceptions to retire

Concept

80. Synthesis — trapdoors turn one-way functions into encryption

Concept

81. Primary sources & where to read more

Concept

82. Connect it up: L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — Why Asymmetric Crypto · Trapdoor One-Way Functions · RSA Encryption & the IND-CPA Flaw · El Gamal Encryption. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

83. Recap — Lesson 28

Recap

You can now explain why public-key encryption solves the pre-shared-key problem, define a trapdoor one-way function and map encrypt/decrypt onto f and f⁻¹, explain why textbook RSA is deterministic and needs OAEP to be IND-CPA, and run El Gamal end to end — encrypting and decrypting a message on a concrete toy example.

Idea§The one-line version
Why asymmetric11.1Public key encrypts; private key decrypts; one key reaches everyone
Trapdoor function11.2One-way f; private key is the trapdoor that makes f⁻¹ easy
Two hard problems11.2RSA = factoring n=pq; El Gamal = discrete log / DH
RSA11.3c = m^e mod n; deterministic ⇒ NOT IND-CPA without OAEP
OAEP11.3Randomized padding (like an IV) ⇒ same m, different ciphertexts
El Gamal11.4(R,S)=(g^r, m·B^r); decrypt m=R^{-b}·S; fresh r ⇒ probabilistic
Big picture11.1–11.4Slow trapdoors distribute session keys (hybrid, L29); reverse ⇒ signatures (L30)

Sources

  1. CS 161 Computer Security Textbook §11.1–11.4 — Wagner, Weaver, Kao, Shakir, Law & Ngai, UC Berkeley — why asymmetric / public-key encryption (§11.1), trapdoor one-way functions (§11.2), RSA encryption and the need for OAEP padding (§11.3), and El Gamal encryption built on Diffie-Hellman (§11.4)
  2. A Method for Obtaining Digital Signatures and Public-Key Cryptosystems — R. L. Rivest, A. Shamir & L. Adleman, Communications of the ACM 21(2), pp. 120–126 (1978) — introduces the RSA public-key cryptosystem whose security rests on the difficulty of factoring
  3. A Public-Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms — T. ElGamal, IEEE Transactions on Information Theory 31(4), pp. 469–472 (1985) — the El Gamal encryption and signature schemes built on the discrete-logarithm / Diffie-Hellman problem
  4. Optimal Asymmetric Encryption — How to Encrypt with RSA — M. Bellare & P. Rogaway, EUROCRYPT '94, LNCS 950, pp. 92–111 (1995) — introduces OAEP, the randomized padding that makes RSA encryption semantically (IND-CPA) secure

Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108