CS 161, Lesson 28, in 50 slides. It explains why asymmetric cryptography solves the pre-shared-key problem, in section 11.1, then covers trapdoor one-way functions and the hard problems behind RSA and discrete log, in section 11.2. It covers RSA encryption and why textbook RSA is deterministic and therefore not IND-CPA without OAEP padding, in section 11.3, and El Gamal encryption built on Diffie-Hellman, with a fully worked toy example, in section 11.4. It is anchored to textbook sections 11.1 to 11.4.
Subject: Computer Security · 83 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 28 of 45
trapdoor one-way functions · RSA and the IND-CPA flaw of textbook RSA · El Gamal encryption built on Diffie-Hellman
Objectives
Warm-up
Discussion prompt
Before we open L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal: without looking back, what was the main idea of L27 · Diffie-Hellman Key Exchange, ECDH & MITM, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161, Lesson 27, in 54 slides. It states the key-exchange problem and gives the paint intuition, in sections 10 and 10.1, then covers one-way functions and the discrete-log problem in section 10.2 and the Diffie-Hellman protocol with a worked toy example in section 10.3. It goes on to elliptic-curve Diffie-Hellman and the equivalences in bit strength, in sections 10.4 and 10.5, and ends with the man-in-the-middle attack that forces authentication, in section 10.6. It is anchored to textbook sections 10.1 to 10.6.
Concept
L27 let two strangers agree on a key over a public channel — but only a key. This lesson asks how to encrypt an actual message to someone using only their public key, with no shared secret arranged in advance.
Matching
Match the pairs
From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.
Why: Why asymmetric?, What makes it possible?, Two real schemes are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §11.1 public and private keys
Concept
Every symmetric scheme — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. L27's Diffie-Hellman agreed on one over a public channel, but it took a live, two-way exchange.
What if Alice just wants to send Bob an encrypted message right now, with no prior contact and no live handshake? She needs a way to lock a message that only Bob can unlock — using something Bob has published in advance.
Concept
In public-key (asymmetric) encryption, Bob has a key pair. He publishes one half to the world and keeps the other half secret.
Public key (PK) — Bob's key that anyone may obtain and use to ENCRYPT a message intended for Bob. Public knowledge — Eve has it too.
Private key (SK) — Bob's secret key, held only by Bob, used to DECRYPT messages that were encrypted under his public key. Never shared.
Counterexample
Discussion prompt
In public-key (asymmetric) encryption, Bob has a key pair. He publishes one half to the world and keeps the other half secret.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Concept
Alice encrypts under Bob's public key; only Bob, holding the matching private key, can decrypt. The directions are fixed and not interchangeable.
\[ c = \mathrm{Enc}_{PK_{Bob}}(m), \qquad m = \mathrm{Dec}_{SK_{Bob}}(c) \]
Anyone can encrypt to Bob — there is nothing secret about doing so. The secrecy lives entirely in the private key that reverses it.
Analogy
Discussion prompt
Explain §11.1 Who uses which key by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Alice encrypts under Bob's public key; only Bob, holding the matching private key, can decrypt. The directions are fixed and not interchangeable.
Intuition
Think of Bob's public key as an open padlock he mails out by the thousands. Anyone can snap a box shut with one of his padlocks — that's encryption — and drop it in the post.
But only Bob has the key that opens those padlocks — that's his private key. Having the padlock (or watching it click shut) tells you nothing about how to open it.
Ask yourself: does handing out padlocks weaken Bob's secrecy? (No — locking and unlocking are different operations; the public half only locks.)
Explain it
Discussion prompt
Explain §11.1 The open padlock analogy to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Think of Bob's public key as an open padlock he mails out by the thousands. Anyone can snap a box shut with one of his padlocks — that's encryption — and drop it in the post.
Concept
The two worlds differ in one decisive place: whether the encrypt key and decrypt key are the same secret or a split pair. That split is what removes the prior-meeting requirement.
| Symmetric (L19–24) | Asymmetric (this lesson) | |
|---|---|---|
| Keys | one shared secret K | public PK + private SK |
| Encrypt with | K | Bob's PK (anyone) |
| Decrypt with | K | Bob's SK (only Bob) |
| Setup needed | pre-shared key | just publish PK |
| Speed | fast | slow (use for key transport) |
Comparison
Comparison matrix
From §11.1 Symmetric vs asymmetric, side by side: refill the Symmetric (L19–24) column from what you know. The rest of the table is as it appeared.
| Symmetric (L19–24) | Asymmetric (this lesson) | |
|---|---|---|
| Keys | one shared secret K | public PK + private SK |
| Encrypt with | K | Bob's PK (anyone) |
| Decrypt with | K | Bob's SK (only Bob) |
| Setup needed | pre-shared key | just publish PK |
| Speed | fast | slow (use for key transport) |
Concept
Public-key crypto fixes key distribution. To talk to N people, Bob publishes ONE public key instead of pre-sharing N separate symmetric keys. Anyone can reach him without a prior secret meeting.
In practice Alice doesn't encrypt a long message directly. She encrypts a fresh symmetric key K under Bob's public key, then encrypts the bulk with fast AES under K — the hybrid model of L29.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'The public key is the one everyone has, so it must be the one that opens — the public key decrypts the ciphertext.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: If the public key could decrypt, then Eve — who also has it — could read everything.
A student: which key reverses the encryption, and why must it be that one?
Why: If the public key could decrypt, then Eve — who also has it — could read everything. The public key only ENCRYPTS.
Trap
A student: 'The public key is the one everyone has, so it must be the one that opens — the public key decrypts the ciphertext.'
\[ m \stackrel{?}{=} \mathrm{Dec}_{PK_{Bob}}(c) \]
Use Bob's PUBLIC key to recover the plaintext
Why: Wrong. If the public key could decrypt, then Eve — who also has it — could read everything. The public key only ENCRYPTS.
A student: which key reverses the encryption, and why must it be that one?
Decrypt with Bob's PRIVATE key, the only secret half
Why: §11.1: public encrypts, private decrypts. Only Bob holds SK, so only Bob can invert Enc — that asymmetry is the whole point.
Notation
Annotate
From Trap: 'the public key decrypts the message' — read this one piece at a time. What is each part doing?
On: \( m \stackrel{?}{=} \mathrm{Dec}_{PK_{Bob}}(c) \)
Section
Part 2 · §11.2 the math behind public keys
Concept
L27 gave us one-way functions: easy forward, infeasible to invert. Public-key encryption needs more — a one-way function that the OWNER can secretly invert, while everyone else still cannot.
Trapdoor one-way function — A one-way function f with a secret 'trapdoor' SK: given x, f(x) is easy; given y = f(x), inverting is infeasible WITHOUT the trapdoor; but given y AND the trapdoor SK, inverting is easy.
Concept
A trapdoor function lives in three worlds at once. The whole scheme depends on keeping these difficulties exactly where they are.
| You are given… | Task | Difficulty |
|---|---|---|
| x | compute y = f(x) | easy (forward) |
| y, no trapdoor | find x with f(x) = y | infeasible |
| y and trapdoor SK | find x with f(x) = y | easy (invert) |
Trade off
Comparison matrix
From §11.2 Three difficulty regimes, side by side: every row here is a choice with a cost. Fill the Task column, then say which row you would actually pick and what you give up for it.
| You are given… | Task | Difficulty |
|---|---|---|
| x | compute y = f(x) | easy (forward) |
| y, no trapdoor | find x with f(x) = y | infeasible |
| y and trapdoor SK | find x with f(x) = y | easy (invert) |
Concept
Now the dictionary is direct: f is 'encrypt with the public key', and f⁻¹ is 'decrypt with the private key.' The private key IS the trapdoor.
\[ f(m) = \mathrm{Enc}_{PK}(m), \qquad f^{-1}(c) = \mathrm{Dec}_{SK}(c) \]
Anyone can apply f (encrypt). Only the holder of SK can apply f⁻¹ (decrypt). 'Hard to invert without the trapdoor' is exactly 'hard to decrypt without the private key.'
Intuition
A plain one-way function (like a hash) is a one-way street with NO return lane — nobody can go back, not even its creator. That's perfect for fingerprints, useless for encryption: Bob needs to read his mail.
A trapdoor function adds a private return lane that only the key-holder can drive. Forward is open to all; backward is gated, and only SK opens the gate.
Ask yourself: what would happen if the trapdoor were public? (Then everyone could invert f, and the 'one-way' property would be gone for everyone — see the next trap.)
Concept
Build a modulus from two large secret primes. Multiplying them is easy; un-multiplying (factoring) the product is believed hard.
\[ n = p \cdot q \quad (p, q \text{ large secret primes}) \]
\[ \text{Given } c = m^{e} \bmod n \text{ and } e:\ \text{find } m \text{ is hard} \]
But knowing the factorization (p or q) makes inverting easy — the factorization is the trapdoor. Security rests on factoring n being hard.
Concept
The L27 hard problem reappears. From the public values you can't combine your way to the shared exponentiated secret — that's the Diffie-Hellman gap.
\[ \text{Given } g,\ p,\ A = g^{a},\ B = g^{b}:\ \text{find } g^{ab} \text{ is hard} \]
But anyone who knows a or b computes g^{ab} instantly — the private exponent is the trapdoor. This is the engine under El Gamal (Part 4).
Ranking
Put in order
Put the moves of §11.2 Read a trapdoor function as encrypt/decrypt into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Encrypting is applying the public one-way map; anyone with (n, e) can do it, so anyone can send Bob ciphertext.
Worked example
Identify f for an RSA-style scheme: f(m) = m^e mod n, with PK = (n, e)
Why: Encrypting is applying the public one-way map; anyone with (n, e) can do it, so anyone can send Bob ciphertext.
Identify the trapdoor: the factorization of n (equivalently the private exponent d)
Why: Without the factors, inverting m^e mod n is the hard RSA problem; with them you derive d and invert easily.
Identify f⁻¹: f⁻¹(c) = c^d mod n, applied with the private key
Why: Decryption is the gated return lane — it needs the trapdoor d that only Bob holds.
State who can do what: everyone applies f, only Bob applies f⁻¹
Why: The public half is the open padlock; the private half is the only key that opens it.
Verify the mapping is consistent: PK ↔ f ↔ Enc, SK ↔ trapdoor ↔ Dec
Why: §11.2: 'hard to invert without the trapdoor' is exactly 'hard to decrypt without the private key' — the encryption scheme IS the trapdoor function.
Blank canvas
Draw it
Draw what §11.2 Read a trapdoor function as encrypt/decrypt just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'The trapdoor is part of the function's definition, so it's published along with the public key.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.
A student: what exactly is the trapdoor, and who is allowed to have it?
Why: If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.
Trap
A student: 'The trapdoor is part of the function's definition, so it's published along with the public key.'
Treat the trapdoor SK as part of the public parameters
Why: Wrong. If the trapdoor were public, anyone could invert f and decrypt — the function would no longer be one-way to attackers, and secrecy would collapse.
A student: what exactly is the trapdoor, and who is allowed to have it?
Recognize the trapdoor IS the private key — held only by the owner
Why: §11.2: the public key defines f (easy forward, hard to invert). The trapdoor (factorization / private exponent) is the secret that makes f⁻¹ easy — and it must stay private.
Section
Part 3 · §11.3 why textbook RSA needs OAEP
Concept
RSA (Rivest, Shamir, Adleman, 1978) is the classic trapdoor scheme. The public key encrypts, the private key decrypts, and security rests on factoring n = pq being hard.
\[ c = m^{e} \bmod n, \qquad m = c^{d} \bmod n \]
PK = (n, e) is published; SK = d is derived from the secret factors p, q. Recovering m from c without d means inverting a power mod n — the hard RSA problem.
Intuition
Multiplying two huge primes p and q to get n is a one-second operation. Going backward — splitting a 2048-bit n into its two prime factors — has no known efficient algorithm; it is the wall RSA leans on.
Bob built n himself, so he KNOWS p and q. That knowledge lets him compute the private exponent d and invert the encryption. Everyone else faces the factoring wall.
Ask yourself: why is knowing the factors the same as knowing the trapdoor? (From p and q you derive d; d is the secret return lane. No factors ⇒ no d ⇒ no decryption.)
Concept
RSA is famously easy to get subtly, fatally wrong — bad padding, weak random primes, side channels. The textbook itself flags this section as 'under construction' and says to use a real, vetted library.
Use a vetted library — Never hand-roll RSA (or any primitive). Real deployments call audited implementations that handle padding, prime generation, and constant-time math correctly.
Matching
Match the pairs
Match each term to the definition this lesson gave it — not the one you would guess from the word.
Why: These are the working definitions of Public key (PK), Private key (SK), Use a vetted library as L28 · Public-Key Encryption: Trapdoor Functions, RSA & El Gamal uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.
Concept
Plain ('textbook') RSA encrypts m as m^e mod n with no randomness. The same message under the same key always produces the same ciphertext.
\[ \mathrm{Enc}(m) = m^{e} \bmod n \ \text{ is a fixed function of } m \]
A deterministic encryption scheme cannot be IND-CPA — exactly the L18 lesson again. Equal plaintexts give equal ciphertexts, so repeats leak.
Intuition
Suppose a sensor sends either 'ARMED' or 'SAFE' each minute. Under deterministic RSA, 'ARMED' always encrypts to one fixed blob and 'SAFE' to another. Eve can't read the words — but she sees when the value repeats and when it flips.
For a two-message vote, login state, or yes/no flag, that's the whole secret. Leaking equality of plaintexts is leaking information — which IND-CPA forbids by definition.
Ask yourself: how can the SAME message ever produce DIFFERENT ciphertexts? (Mix in fresh randomness each time — that's what padding does.)
Concept
Make encryption probabilistic by mixing fresh randomness into m before exponentiating. In RSA this is done by a padding mode.
Despite the name, these padding modes act more like a block cipher's IV than like block-cipher length-padding: they inject randomness so the ciphertext 'looks random,' yet the receiver can still strip it off and recover m exactly.
Concept
OAEP (Optimal Asymmetric Encryption Padding) — A randomized padding scheme (Bellare & Rogaway, 1994). Effectively it generates a random value, scrambles the message with it, and encrypts BOTH — so to recover m an attacker must recover both halves. This makes RSA semantically (IND-CPA) secure.
OAEP is randomization, not length-stuffing. The randomness is the point: it makes two encryptions of the same m look unrelated.
Step zero
Discussion prompt
§11.3 Same message, twice: plain RSA vs OAEP — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Scenario: Alice encrypts the identical message m to Bob on Monday and…
Answer:
Worked example
Scenario: Alice encrypts the identical message m to Bob on Monday and again on Tuesday
Why: We compare what an eavesdropper observes across two sends of the SAME plaintext — the exact IND-CPA test.
Under plain RSA, both sends compute m^e mod n — a fixed value
Why: No randomness enters, so the ciphertext is a deterministic function of m: Monday's and Tuesday's blobs are byte-for-byte identical.
Under OAEP, each send first mixes in a FRESH random value, then encrypts
Why: Different randomness each time scrambles m differently, so the two ciphertexts look unrelated even though m is the same.
| Scheme | Ciphertext (Mon) | Ciphertext (Tue) | Eve learns |
|---|---|---|---|
| Plain RSA | c₀ | c₀ (identical) | the message repeated → LEAK |
| RSA-OAEP | c₁ | c₂ (looks unrelated) | nothing — IND-CPA |
Verify: plain RSA reveals the repeat; OAEP hides it, yet both decrypt to m
Why: §11.3: determinism is the leak. OAEP's fresh randomness gives different ciphertexts for the same m, restoring IND-CPA — and Bob still strips the padding to recover m exactly.
Comparison
Comparison matrix
From §11.3 Same message, twice: plain RSA vs OAEP: refill the Eve learns column from what you know. The rest of the table is as it appeared.
| Scheme | Ciphertext (Mon) | Ciphertext (Tue) | Eve learns |
|---|---|---|---|
| Plain RSA | c₀ | c₀ (identical) | the message repeated → LEAK |
| RSA-OAEP | c₁ | c₂ (looks unrelated) | nothing — IND-CPA |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'RSA is a respected public-key cipher, so c = m^e mod n is IND-CPA secure on its own.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts.
A student: what must be added to RSA to make it IND-CPA secure?
Why: Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts. Any deterministic scheme loses the IND-CPA game by encrypting the same message twice and spotting the match.
Trap
A student: 'RSA is a respected public-key cipher, so c = m^e mod n is IND-CPA secure on its own.'
Use plain m^e mod n and assume semantic security
Why: Wrong. Plain RSA is DETERMINISTIC — equal plaintexts give equal ciphertexts. Any deterministic scheme loses the IND-CPA game by encrypting the same message twice and spotting the match.
A student: what must be added to RSA to make it IND-CPA secure?
Add a randomized padding mode such as OAEP
Why: §11.3: OAEP mixes fresh randomness into each encryption, so the same m yields different ciphertexts. Randomized padding is what makes RSA semantically secure.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Padding fills the message out to the block size — OAEP just pads m up to n's length.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats.
A student: what does OAEP actually add, and why does it matter?
Why: If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats. Fixed padding does NOT give IND-CPA.
Trap
A student: 'Padding fills the message out to the block size — OAEP just pads m up to n's length.'
Treat OAEP as deterministic length-stuffing like a fixed pad byte
Why: Wrong. If the padding were a fixed pattern, encryption would stay deterministic and still leak repeats. Fixed padding does NOT give IND-CPA.
A student: what does OAEP actually add, and why does it matter?
Recognize OAEP injects fresh RANDOMNESS (more like an IV than like length padding)
Why: §11.3: OAEP scrambles m with a random value and encrypts both, so the same m maps to different ciphertexts. The randomization — not the length — is what buys IND-CPA.
Section
Part 4 · §11.4 public-key encryption on Diffie-Hellman
Concept
El Gamal (Taher Elgamal, 1985) builds public-key encryption directly on Diffie-Hellman. Where DH agreed on a key interactively, El Gamal lets Alice encrypt to Bob's published DH value with no round-trip.
Its security rests on the discrete-log / Diffie-Hellman hardness from L27 — the second trapdoor family from §11.2.
Concept
Public parameters, fixed and standardized: a large prime p (≈ 2048 bits) and a generator g with 1 < g < p−1. Bob generates his key pair from them.
\[ \text{Public: } p\ (\approx 2048\text{-bit prime}),\quad g \ \text{with } 1 < g < p-1 \]
\[ \text{Bob picks private } b \in \{0,\dots,p-2\},\ \ B = g^{b} \bmod p \]
B is Bob's public key (his long-term DH value); b is his private key. This is exactly a DH key, published once.
Concept
To encrypt m ∈ {1, …, p−1}, Alice picks a fresh random r ∈ {0, …, p−2} — her one-time ephemeral DH secret — and sends a pair.
\[ \text{ciphertext } (R, S) = \big(\, g^{r} \bmod p,\ \ m \cdot B^{r} \bmod p \,\big) \]
R = g^r is Alice's ephemeral public value; S = m·B^r hides m by multiplying it by the shared DH secret B^r. The fresh r is what makes El Gamal probabilistic.
Concept
Bob receives (R, S). Using his private b, he reconstructs the shared secret from R and divides it out of S.
\[ m = R^{-b} \cdot S \bmod p \]
R^{-b} is the modular inverse of R^b. Multiplying S by it cancels the B^r mask and leaves m — only Bob can do this, because only he knows b.
Ranking
Put in order
Put the moves of §11.4 Correctness: why R^{-b}·S returns m into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Decryption acts on exactly the values Alice sent, so we expand them in terms of g, r, b, m.
Worked example
Substitute the ciphertext: R = g^r and S = m·B^r, with B = g^b
Why: Decryption acts on exactly the values Alice sent, so we expand them in terms of g, r, b, m.
\[ R^{-b} \cdot S = (g^{r})^{-b} \cdot (m \cdot B^{r}) \]
Replace B^r with g^{br} since B = g^b
Why: Bob's public key is g^b, so B^r = (g^b)^r = g^{br} — the shared DH secret Alice multiplied in.
\[ = g^{-rb} \cdot m \cdot g^{br} = m \cdot g^{br - rb} = m \cdot g^{0} = m \pmod p \]
Verify: the exponents br and rb cancel, leaving m exactly
Why: §11.4: because exponents multiply and br = rb, the mask g^{br} and its inverse g^{-rb} annihilate — decryption recovers m for every valid ciphertext.
Blank canvas
Draw it
Draw what §11.4 Correctness: why R^{-b}·S returns m just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Intuition
Read it as Diffie-Hellman: Bob's long-term value is B = g^b; Alice's fresh ephemeral is R = g^r. The shared key is K = g^{rb} = B^r = R^b — a DH secret both sides can form.
Then S = m·K is a one-time pad — but using modular MULTIPLICATION instead of XOR. The 'pad' is the fresh DH secret K; Bob divides it back out to unmask m.
Ask yourself: why must r be fresh every message? (A reused r reuses the pad K — the same one-time-pad rule as L17. Fresh r ⇒ key used once ⇒ probabilistic ⇒ IND-CPA-friendly, unlike plain RSA.)
Explain it
Discussion prompt
Explain §11.4 El Gamal is a one-time pad over multiplication to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Read it as Diffie-Hellman: Bob's long-term value is B = g^b; Alice's fresh ephemeral is R = g^r. The shared key is K = g^{rb} = B^r = R^b — a DH secret both sides can form.
Step zero
Discussion prompt
§11.4 Toy El Gamal: keygen and encrypt (p = 23, g = 5) — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Fix public parameters p = 23, g = 5 (tiny, for hand computation)
Answer:
Worked example
Fix public parameters p = 23, g = 5 (tiny, for hand computation)
Why: Real El Gamal uses a 2048-bit prime; a small prime lets us check every step by hand. Eve also knows p and g.
Bob's keygen: private b = 6, public B = 5^6 mod 23 = 8
Why: From the L27 repeated-squaring result, 5^6 mod 23 = 8, so Bob publishes B = 8 and keeps b = 6.
\[ B = g^{b} \bmod p = 5^{6} \bmod 23 = 8 \]
Alice encrypts m = 4 with fresh ephemeral r = 3
Why: She computes R = g^r and S = m·B^r mod p; r = 3 is her one-time secret for this message.
\[ R = g^{r} \bmod p = 5^{3} \bmod 23 = 10 \]
\[ B^{r} \bmod p = 8^{3} \bmod 23 = 6 \ \ (=K,\ \text{the shared secret}) \]
\[ S = m \cdot B^{r} \bmod p = 4 \cdot 6 \bmod 23 = 24 \bmod 23 = 1 \]
Alice sends the ciphertext pair (R, S) = (10, 1)
Why: Eve sees (10, 1) plus public 23, 5, 8 — but not b, r, or m. The message never crosses the wire in the clear.
Translation
\( R = g^{r} \bmod p = 5^{3} \bmod 23 = 10 \)
Draw it
Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.
Ranking
Put in order
Put the moves of §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. He reconstructs the shared secret from R and divides it out of S to recover m.
Worked example
Bob receives (R, S) = (10, 1) and uses his private b = 6
Why: He reconstructs the shared secret from R and divides it out of S to recover m.
Compute the shared secret R^b = 10^6 mod 23 = 6
Why: R^b = (g^r)^b = g^{rb} = K = 6 — the same shared secret Alice formed as B^r, confirming both sides agree.
\[ R^{b} \bmod p = 10^{6} \bmod 23 = 6 = B^{r} \]
Invert it: R^{-b} = 10^{-6} mod 23 = 4 (the modular inverse of 6 mod 23)
Why: 6 · 4 = 24 ≡ 1 (mod 23), so 4 is the inverse of the shared secret — multiplying by it cancels the mask.
\[ m = R^{-b} \cdot S \bmod p = 4 \cdot 1 \bmod 23 = 4 \]
Verify: decryption returns m = 4, the message Alice encrypted
Why: §11.4: R^{-b}·S = 4·1 = 4 = m. The exponents cancelled exactly as the correctness proof predicted — Bob recovers the plaintext using only his private key.
Notation
Annotate
From §11.4 Toy El Gamal: Bob decrypts (10, 1) back to m — read this one piece at a time. What is each part doing?
On: \( m = R^{-b} \cdot S \bmod p = 4 \cdot 1 \bmod 23 = 4 \)
Concept
The whole scheme on one card — parameters, keys, and the two operations. Notice the ciphertext is a PAIR, twice the length of the message (the ephemeral R rides along).
| Stage | What happens | Formula |
|---|---|---|
| Params | public prime and generator | p, g with 1 < g < p−1 |
| KeyGen | Bob's private / public key | b secret; B = g^b mod p |
| Encrypt | fresh r per message; send a pair | (R, S) = (g^r, m·B^r) mod p |
| Decrypt | undo the mask with private b | m = R^{-b}·S mod p |
Comparison
Comparison matrix
From §11.4 El Gamal at a glance: refill the Formula column from what you know. The rest of the table is as it appeared.
| Stage | What happens | Formula |
|---|---|---|
| Params | public prime and generator | p, g with 1 < g < p−1 |
| KeyGen | Bob's private / public key | b secret; B = g^b mod p |
| Encrypt | fresh r per message; send a pair | (R, S) = (g^r, m·B^r) mod p |
| Decrypt | undo the mask with private b | m = R^{-b}·S mod p |
Concept
Eve has the public p, g, B = g^b and the ciphertext (R, S) = (g^r, m·B^r). To strip the mask B^r off S she would need the shared secret g^{rb} from g^b and g^r alone.
\[ \text{Eve has } g^{b},\ g^{r}\ \Rightarrow\ \text{needs } g^{rb}\ \text{(the CDH problem)} \]
That is exactly the L27 Computational Diffie-Hellman problem — believed infeasible for 2048-bit p. Without g^{rb} the mask stays on, so m is hidden.
Analogy
Discussion prompt
Explain §11.4 What Eve sees, and why she's stuck by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Eve has the public p, g, B = g^b and the ciphertext (R, S) = (g^r, m·B^r). To strip the mask B^r off S she would need the shared secret g^{rb} from g^b and g^r alone.
Concept
Fresh r makes El Gamal probabilistic and IND-CPA-friendly — but this textbook form is not fully semantically secure in the stronger sense. It is malleable.
\[ (R,\ 2S) \ \text{decrypts to } 2m: \ R^{-b}\cdot(2S) = 2\,(R^{-b} S) = 2m \]
An attacker who doubles S turns an encryption of m into an encryption of 2m without knowing m. Real deployments add integrity / stronger constructions to close this — the same 'need authenticity' theme as L27.
Counterexample
Discussion prompt
Fresh r makes El Gamal probabilistic and IND-CPA-friendly — but this textbook form is not fully semantically secure in the stronger sense. It is malleable.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Encryption maps a message to a ciphertext, so encrypting m twice gives the same (R, S) — El Gamal is deterministic.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change.
A student: what makes El Gamal probabilistic where textbook RSA is not?
Why: Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change. The same m gives different ciphertexts every time.
Trap
A student: 'Encryption maps a message to a ciphertext, so encrypting m twice gives the same (R, S) — El Gamal is deterministic.'
Assume (R, S) is a fixed function of m
Why: Wrong. Each encryption draws a FRESH random r, so R = g^r and S = m·B^r both change. The same m gives different ciphertexts every time.
A student: what makes El Gamal probabilistic where textbook RSA is not?
Recognize the fresh ephemeral r randomizes every ciphertext
Why: §11.4: r is chosen anew per message, so the shared secret B^r and the pair (R, S) differ each time. That built-in randomness is exactly what plain RSA lacks.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Constraint
Discussion prompt
Run The public-key encryption playbook with this step confiscated:
Fix RSA with OAEP: a randomized padding mode (more like an IV than length padding) makes the same m encrypt differently → IND-CPA.
Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.
Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.
Answer:
Pattern
Edge cases
Discussion prompt
The public-key encryption playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Elimination
Eliminate the wrong options
Why is plain (textbook) RSA NOT IND-CPA secure, and what fixes it?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: §11.3: textbook RSA computes c = m^e mod n with no randomness, so it is deterministic — encrypting the same m twice produces the identical ciphertext. Any deterministic scheme loses the IND-CPA game: the adversary submits the same message twice (or two equal challenge messages) and detects the matching ciphertexts. The fix is a randomized padding mode such as OAEP, which mixes fresh randomness into each encryption (acting more like an IV than like length padding), so the same m encrypts to different-looking ciphertexts while still decrypting correctly.
Check
Bob publishes an RSA public key (n, e). Alice encrypts messages with plain 'textbook' RSA, c = m^e mod n, with no padding. Reason it through before choosing.
Check your understanding
Why is plain (textbook) RSA NOT IND-CPA secure, and what fixes it?
Answer: A
Why: §11.3: textbook RSA computes c = m^e mod n with no randomness, so it is deterministic — encrypting the same m twice produces the identical ciphertext. Any deterministic scheme loses the IND-CPA game: the adversary submits the same message twice (or two equal challenge messages) and detects the matching ciphertexts. The fix is a randomized padding mode such as OAEP, which mixes fresh randomness into each encryption (acting more like an IV than like length padding), so the same m encrypts to different-looking ciphertexts while still decrypting correctly.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — Why Asymmetric Crypto · Trapdoor One-Way Functions · RSA Encryption & the IND-CPA Flaw · El Gamal Encryption. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now explain why public-key encryption solves the pre-shared-key problem, define a trapdoor one-way function and map encrypt/decrypt onto f and f⁻¹, explain why textbook RSA is deterministic and needs OAEP to be IND-CPA, and run El Gamal end to end — encrypting and decrypting a message on a concrete toy example.
| Idea | § | The one-line version |
|---|---|---|
| Why asymmetric | 11.1 | Public key encrypts; private key decrypts; one key reaches everyone |
| Trapdoor function | 11.2 | One-way f; private key is the trapdoor that makes f⁻¹ easy |
| Two hard problems | 11.2 | RSA = factoring n=pq; El Gamal = discrete log / DH |
| RSA | 11.3 | c = m^e mod n; deterministic ⇒ NOT IND-CPA without OAEP |
| OAEP | 11.3 | Randomized padding (like an IV) ⇒ same m, different ciphertexts |
| El Gamal | 11.4 | (R,S)=(g^r, m·B^r); decrypt m=R^{-b}·S; fresh r ⇒ probabilistic |
| Big picture | 11.1–11.4 | Slow trapdoors distribute session keys (hybrid, L29); reverse ⇒ signatures (L30) |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.