Chapter 3: Basic Number Theory

Chapter 3 of Trappe & Washington: the Euclidean and extended Euclidean algorithms, congruences and modular inverses, the Chinese Remainder Theorem, square-and-multiply exponentiation, Fermat's and Euler's theorems with the totient, primitive roots, matrices and square roots mod n, the Legendre and Jacobi symbols, finite fields including the GF(2^8) of AES, and continued fractions. Every worked example is the book's own and is verified numerically.

Subject: Cryptography · 70 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Basic Number Theory

Title

Cryptography · Chapter 3

The twelve pieces of machinery that every later chapter uses without explanation

2. What you will be able to do

Objectives

The book says it plainly: except for this chapter, the chapters are fairly independent, and this one pervades the subject. Chapter 2 already leaned on it — gcd(α, 26) = 1 and φ(26) = 12 were both number theory. From Chapter 9 onwards it stops being a convenience and becomes the security itself.

Figure (svg): A map from each tool in this chapter to the chapter that consumes it.

Nothing in this chapter is here for its own sake — every section is consumed by a later one.

3. You have already used this chapter

Warm-up

Chapter 2 made two claims that were pure number theory, stated without proof.

Discussion prompt

Why does an affine cipher require gcd(α, 26) = 1, and why are there exactly 12 legal values of α?

Hint: One is about invertibility; the other is about counting the numbers coprime to 26.

Answer:

Invertibility. Decryption needs to undo multiplication by α, which needs an α* with αα* ≡ 1 (mod 26). Such an inverse exists exactly when gcd(α, 26) = 1 — and Section 3.2's extended Euclidean algorithm is what produces it.

Counting. 26 = 2 · 13, so the numbers coprime to 26 are the odd numbers other than 13. There are φ(26) = 12 of them, where φ is Euler's function from Section 3.6.

Both facts were used in Chapter 2 on trust. This chapter is where they get proved, and where the same two ideas — invertibility and φ — turn into RSA.

Figure (svg): A clock face for arithmetic modulo 12, showing 15 and 3 landing on the same mark.

Modular arithmetic is not a trick for keeping numbers small; it is arithmetic in a different set.

4. Basic Notions and the Euclidean Algorithm

Section

Section 3.1 · pp. 40-44

5. Divisibility, primes, and unique factorization

Concept

The vocabulary, stated once so it can be used freely afterwards.

a divides b — Written a | b: there is an integer k with b = ak. Note this is a statement about integers, so 3 | 12 but 5 does not divide 12.

Prime — An integer p > 1 whose only positive divisors are 1 and p. The primes are the multiplicative atoms.

gcd(a, b) — The largest integer dividing both. When gcd(a, b) = 1 we call a and b coprime — and coprimality, not primality, is what most of this book actually needs.

Unique factorization: every integer greater than 1 is a product of primes in exactly one way, up to order. This is why factoring is a well-posed problem with a single right answer — and why RSA can rest a whole system on the difficulty of finding it.

Figure (svg): A number factored into primes, with the factorization shown to be unique.

Multiplying primes is fast; recovering them is not. The whole of RSA lives in that asymmetry.

6. The Euclidean Algorithm on 12345 and 11111

Worked example

The oldest algorithm still in daily use, and the fastest way to a gcd. At each step, replace the pair (a, b) by (b, a mod b).

12345 = 1 · 11111 + 1234

Why: Divide the larger by the smaller and keep the remainder.

11111 = 9 · 1234 + 5

Why: Now repeat on (11111, 1234). The numbers shrink fast.

1234 = 246 · 5 + 4, then 5 = 1 · 4 + 1

Why: Two more lines and we are down to single digits.

4 = 4 · 1 + 0 — the remainder is zero, so stop

Why: The last non-zero remainder is the gcd.

\[ \gcd(12345,\; 11111) = 1 \]

Verify: check the claim of speed: five lines for five-digit inputs

Why: The number of steps is O(log of the smaller input) — Lamé's theorem bounds it by five times the number of decimal digits. This is why gcd is cheap even on the 600-digit numbers of Chapter 9, and it is the reason RSA key generation is practical at all.

Figure (svg): The Euclidean algorithm on 12345 and 11111, each line replacing a pair by a smaller pair until the remainder is zero.

Each line divides and keeps the remainder. Five lines for five-digit numbers — the algorithm is logarithmic.

7. How many steps does the algorithm take?

Prediction

The inputs are two numbers of about 300 digits each — the size RSA uses.

Predict first

Roughly how many division steps will the Euclidean algorithm need?

  • About 300
  • About 1500
  • About 10³⁰⁰
  • It depends entirely on the numbers

Correct: About 1500

The worst case is consecutive Fibonacci numbers, which is where the bound is tight.

Hold this next to Chapter 1's scale argument: gcd of two 300-digit numbers is instant, and factoring one 600-digit number is beyond the universe's resources. Two operations on the same objects, and the entire subject lives in the gap between them.

Why: The step count is O(log of the smaller number), and Lamé's theorem gives a bound of about five times the number of decimal digits — so roughly 1500 divisions for 300-digit inputs. That is nothing. The contrast with factoring is the point: both take a number as input, and one is logarithmic while the other has no known polynomial algorithm at all.

8. Coprime, prime, or neither?

Definition probe

The distinction matters because almost every condition in this book asks for coprimality, not primality.

Sort into buckets

Sort each statement.

A coprimality fact
gcd(9, 26) = 1; gcd(8, 15) = 1, though neither is prime; gcd(6, 35) = 1
A primality fact
13 has only 1 and itself as positive divisors
Neither — the numbers share a factor
gcd(13, 26) = 13
cop
Coprime means sharing no factor above 1. It is a property of a pair, and it does not require either number to be prime — 8 and 15 are both composite and still coprime. This is the condition that makes modular inverses exist.
pri
Primality is a property of one number. It is a much stronger and much rarer condition, and most of the theorems in this chapter do not need it.
not
13 divides 26, so they are not coprime and 13 has no inverse mod 26. This is exactly why α = 13 was an illegal affine key in Chapter 2.

9. The Extended Euclidean Algorithm

Section

Section 3.2 · pp. 44-47

10. The Extended Euclidean Algorithm: gcd as a combination

Concept

The Euclidean algorithm computes the gcd. With slightly more bookkeeping it also produces integers x and y expressing that gcd as a linear combination — a fact called Bézout's identity.

\[ \gcd(a, b) = ax + by \]

The book's small examples:

\[ 1 = \gcd(45, 13) = 45 \cdot (-2) + 13 \cdot 7, \qquad 7 = \gcd(259, 119) = 259 \cdot 6 - 119 \cdot 13 \]

This is not a curiosity. When gcd(a, n) = 1 the identity reads ax + ny = 1, so ax ≡ 1 (mod n) — and x is the inverse of a mod n. Every modular inverse in this book comes from here.

Figure (svg): The extended Euclidean algorithm as a three-column table, each row a linear combination of the two starting numbers.

The last row is Bézout's identity, and its x is the modular inverse the rest of the book needs.

11. Running it on 12345 and 11111

Worked example

Keep a table whose every row records value = 12345·x + 11111·y. The first two rows are free.

Row 1: 12345 = 1 · 12345 + 0 · 11111. Row 2: 11111 = 0 · 12345 + 1 · 11111

Why: Trivially true, and they seed everything else.

The gcd's first line said 12345 = 1 · 11111 + 1234, so 1234 = row 1 − 1 · row 2

Why: Subtract whole rows, coefficients included: 1234 gets x = 1, y = −1.

Next line: 11111 = 9 · 1234 + 5, so row for 5 = row 2 − 9 · row(1234)

Why: Giving 5 = 12345 · (−9) + 11111 · 10.

Continue with 4 = row(1234) − 246 · row(5), then 1 = row(5) − 1 · row(4)

Why: The values run down the same sequence as the plain Euclidean algorithm; only the coefficients are new work.

\[ 1 = 12345 \cdot (-2224) + 11111 \cdot 2471 \]

Verify: 12345 · (−2224) = −27 455 280 and 11111 · 2471 = 27 455 281, and these differ by 1

Why: So the identity holds. And reading it mod 11111 gives 12345 · (−2224) ≡ 1, so −2224 ≡ 8887 is the inverse of 12345 mod 11111.

Figure (svg): The extended Euclidean algorithm as a three-column table, each row a linear combination of the two starting numbers.

The last row is Bézout's identity, and its x is the modular inverse the rest of the book needs.

12. From Bézout to an inverse

Fill the middle

This one step is used in every RSA key generation. Complete it.

Fill in the blanks

ax + ny = 1 \;\Longrightarrow\; ax \equiv 1 \pmodx \;\Longrightarrow\; ___ \equiv a^___ \pmod___

Why: Reducing ax + ny = 1 modulo n kills the ny term, leaving ax ≡ 1 (mod n) — which is the definition of x being the inverse of a. So the extended Euclidean algorithm is a modular-inverse algorithm, and it runs in logarithmic time. In RSA this is how d is computed from e: d ≡ e⁻¹ (mod φ(n)), and it is the single step that turns a public exponent into a private one.

13. Why does the algorithm terminate at all?

Socratic

The Euclidean algorithm replaces (a, b) with (b, a mod b) and repeats.

Discussion prompt

Why must this stop, and why is the last non-zero remainder the gcd rather than merely a common divisor?

Hint: For termination, watch the second component. For correctness, ask which numbers divide both members of a pair.

Answer:

Termination. The remainder a mod b is always strictly less than b and never negative, so the second component is a strictly decreasing sequence of non-negative integers. Such a sequence cannot go on forever, so a zero is reached.

Correctness. The key fact is that gcd(a, b) = gcd(b, a mod b). Any d dividing a and b also divides a − qb = a mod b, and conversely any d dividing b and a mod b divides qb + (a mod b) = a. So the two pairs have exactly the same set of common divisors, hence the same greatest one.

Therefore every step preserves the gcd, and the final pair is (g, 0), whose gcd is plainly g.

This is a good template for the arguments in this chapter: find a quantity that must decrease, and an invariant that must not change.

14. Find the error in this inverse calculation

Error analysis

A student computes the inverse of 5 mod 12 and gets it wrong in an instructive way.

Annotate

  • Every line up to 1 = 5·5 − 2·12 is correct, and this is the trap: the arithmetic is not where the error is.
  • The identity is 1 = 5·(5) + 12·(−2). Reducing mod 12 kills the 12 term, leaving 5·5 ≡ 1. So the inverse is the coefficient of 5, which is 5 — not the coefficient of 12.
  • 5 · 10 = 50 = 4·12 + 2 ≡ 2, not 1. One multiplication would have caught it. 5 · 5 = 25 = 2·12 + 1 ≡ 1 ✓.
  • Both coefficients are sitting there and only one is wanted. The rule: the inverse of a is the coefficient standing next to a, and the other coefficient is discarded.

Always multiply back. The check is one operation and it catches every version of this slip.

15. Congruences

Section

Section 3.3 · pp. 47-52

16. Congruences: arithmetic that wraps

Concept

Write a ≡ b (mod n) when n divides a − b. Equivalently, a and b leave the same remainder on division by n.

Addition, subtraction and multiplication all work exactly as usual: congruences may be added, subtracted and multiplied term by term. Division is the exception, and it is where every mistake happens.

\[ ax \equiv ay \pmod n \;\text{ and }\; \gcd(a, n) = 1 \;\Longrightarrow\; x \equiv y \pmod n \]

Without the coprimality condition the cancellation is invalid. For example 2 · 3 ≡ 2 · 6 (mod 6) since both sides are 0 mod 6 — but 3 is not congruent to 6 mod 6. The factor 2 shares a divisor with 6, and cancelling it is simply not permitted.

Figure (svg): A clock face for arithmetic modulo 12, showing 15 and 3 landing on the same mark.

Modular arithmetic is not a trick for keeping numbers small; it is arithmetic in a different set.

17. Solving 3x ≡ 4 (mod 7)

Worked example

A linear congruence. The method is always the same: find the inverse of the coefficient, then multiply through.

Check solvability: gcd(3, 7) = 1, so 3 is invertible mod 7 and the solution is unique mod 7

Why: If the gcd were d > 1, there would be either d solutions or none, depending on whether d divides 4.

Find 3⁻¹ mod 7 by inspection or extended Euclid: 3 · 5 = 15 ≡ 1 (mod 7), so 3⁻¹ ≡ 5

Why: For small moduli inspection is faster; for RSA-sized moduli it is the extended Euclidean algorithm every time.

Multiply both sides by 5: x ≡ 5 · 4 = 20 ≡ 6 (mod 7)

Why: Multiplying by the inverse is the modular version of dividing.

Verify: 3 · 6 = 18 = 2 · 7 + 4 ≡ 4 (mod 7)

Why: The congruence holds, so x ≡ 6 is the solution. Always substitute back — it costs one multiplication and catches every sign slip.

Figure (svg): Solving a linear congruence by multiplying through by the inverse of the coefficient.

There is no division mod n — only multiplication by an inverse, and only when the inverse exists.

18. Is this cancellation legal?

Discrimination

Cancelling a factor from both sides of a congruence is allowed only under a condition. Test each case.

Sort into buckets

Sort each cancellation.

Legal — the factor is coprime to the modulus
From 3x ≡ 3y (mod 7), conclude x ≡ y; From 5x ≡ 5y (mod 26), conclude x ≡ y; From 4x ≡ 4y (mod 9), conclude x ≡ y
Illegal — they share a factor
From 2x ≡ 2y (mod 6), conclude x ≡ y; From 13x ≡ 13y (mod 26), conclude x ≡ y
ok
gcd(3,7) = gcd(5,26) = gcd(4,9) = 1, so each factor has an inverse and multiplying by it is a legal operation. Note that neither 4 nor 9 is prime — coprimality is the condition, not primality.
bad
gcd(2,6) = 2 and gcd(13,26) = 13. Multiplying by such a factor is not injective, so the step throws information away: 2·0 ≡ 2·3 (mod 6) while 0 is not congruent to 3. The second case is the affine-cipher failure from Chapter 2 in its purest form.

19. The Chinese Remainder Theorem

Section

Section 3.4 · pp. 52-54

20. The Chinese Remainder Theorem: split, work, rejoin

Concept

Start with a single congruence and factor the modulus. If x ≡ 25 (mod 42), write 42 = 7 · 6 and x = 25 + 42k. Then x = 25 + 7(6k) gives x ≡ 4 (mod 7), and x = 25 + 6(7k) gives x ≡ 1 (mod 6).

The theorem is that this process reverses.

\[ \gcd(m, n) = 1 \;\Longrightarrow\; \begin{cases} x \equiv a \pmod m \\ x \equiv b \pmod n \end{cases} \text{ has exactly one solution mod } mn \]

The proof is the extended Euclidean algorithm again: write ms + nt = 1 and set x = bms + ant. Then x ≡ ant ≡ a (mod m) and x ≡ bms ≡ b (mod n). Uniqueness follows because a number divisible by both m and n is divisible by mn when they are coprime.

Figure (svg): One congruence mod 42 splitting into a pair of congruences mod 7 and mod 6, and recombining to a unique answer mod 42.

The Chinese Remainder Theorem is the licence to work modulo the factors instead of modulo the product.

21. Rejoining x ≡ 4 (mod 7) and x ≡ 1 (mod 6)

Worked example

Recover the single congruence mod 42 from the pair.

Check gcd(7, 6) = 1

Why: Required, and it is the only hypothesis the theorem has.

Find s, t with 7s + 6t = 1: take s = 1, t = −1

Why: Extended Euclid, or inspection for numbers this small.

Apply x = b·ms + a·nt with a = 4, m = 7, b = 1, n = 6: x = 1·7·1 + 4·6·(−1) = 7 − 24 = −17

Why: Substituting straight into the formula from the proof.

Reduce: −17 ≡ 25 (mod 42)

Why: And 25 is where we started, which is the check we wanted.

Verify: 25 mod 7 = 4 ✓ and 25 mod 6 = 1 ✓

Why: Both original congruences are satisfied, and the theorem promises this is the only solution mod 42.

Figure (svg): One congruence mod 42 splitting into a pair of congruences mod 7 and mod 6, and recombining to a unique answer mod 42.

The Chinese Remainder Theorem is the licence to work modulo the factors instead of modulo the product.

22. Why anyone would want to split a congruence

Real world

The theorem looks like bookkeeping. Its uses in this book are anything but.

Discussion prompt

Name two places where working modulo the factors instead of modulo the product is a decisive advantage.

Hint: One is about speed. One is about an attack.

Answer:

Speed: RSA decryption. Instead of computing c^d mod n, compute it mod p and mod q separately and glue the results. Each exponentiation is on numbers half as long, and modular exponentiation costs roughly cubically in the length — so the split gives about a fourfold speed-up. Every RSA implementation does this.

Attack: square roots mod n. Section 3.9 solves x² ≡ b (mod pq) by solving mod p and mod q and recombining — which gives four roots rather than two. Knowing two roots that are not negatives of each other factors n immediately.

And a caution that follows from the first. The CRT speed-up is also a vulnerability: if a hardware fault corrupts one of the two half-computations, comparing the faulty and correct signatures factors n on the spot. That is the Bellcore fault attack, and it is the reason RSA implementations verify a signature after producing it.

So the same theorem is a speed-up, an attack, and the reason for a defensive check — which is fairly typical of this chapter.

23. Modular Exponentiation

Section

Section 3.5 · pp. 54-55

24. Modular Exponentiation: square and multiply

Concept

Numbers of the form xᵃ (mod n) appear on nearly every page from Chapter 9 onwards, with a of a few hundred digits. Computing xᵃ first and reducing afterwards is impossible — the intermediate number has more digits than the universe has particles.

Two rules make it easy. Reduce after every multiplication, so no number ever exceeds n². And use repeated squaring, so the exponent is consumed a bit at a time rather than one unit at a time.

\[ a^b \bmod n \text{ costs at most } 2\log_2(b) \text{ multiplications mod } n \]

The consequence is worth stating explicitly, because a whole subject rests on it: exponentiation is fast, and its inverse — the discrete logarithm — is not known to be. That is the one-way function Chapter 10 is built on.

Figure (svg): Repeated squaring computing 2 to the 1234 mod 789: ten squarings, then five multiplications selected by the binary expansion.

Square, reduce, repeat — and multiply in only the powers the binary expansion asks for.

25. Computing 2¹²³⁴ (mod 789)

Worked example

The book's own example. Naively this needs 1233 modular multiplications; here it takes fifteen.

Square repeatedly from 2² ≡ 4, reducing mod 789 every time

Why: 2⁴ ≡ 16, 2⁸ ≡ 256, 2¹⁶ ≡ 49, 2³² ≡ 34, 2⁶⁴ ≡ 367, 2¹²⁸ ≡ 559, 2²⁵⁶ ≡ 37, 2⁵¹² ≡ 580, 2¹⁰²⁴ ≡ 286. Ten squarings.

Write the exponent in binary: 1234 = 10011010010₂ = 1024 + 128 + 64 + 16 + 2

Why: The set bits name exactly which of the squared values are needed.

Multiply those five values together, reducing as you go

Why: 286 · 559 · 367 · 49 · 4, all mod 789.

\[ 2^{1234} \equiv 286 \cdot 559 \cdot 367 \cdot 49 \cdot 4 \equiv 481 \pmod{789} \]

Verify: no intermediate value ever exceeded 788² = 621 444

Why: That bound is the practical point: the whole computation fits in machine arithmetic for small n, and in a fixed number of limbs for RSA-sized n. Ten squarings plus four multiplications replaced 1233 multiplications.

Figure (svg): Repeated squaring computing 2 to the 1234 mod 789: ten squarings, then five multiplications selected by the binary expansion.

Square, reduce, repeat — and multiply in only the powers the binary expansion asks for.

26. Watch the exponent get consumed

Invariant

Square-and-multiply is easiest to trust once you have watched the invariant hold. Read the exponent's binary digits from the top.

Step through it

Why does a 0 bit cost one operation and a 1 bit cost two?

  1. The invariant: after processing k bits, the result is 2 raised to the number those k bits spell.
  2. First bit 1: result is 2¹.
  3. Next bit 0: square only. The exponent doubles, 1 → 2.
  4. Another 0: square again. Exponent 2 → 4.
  5. Bit 1: square, then multiply by the base. Exponent 4 → 9, and 2⁹ = 512. The invariant held at every step.

A 0 doubles the exponent — one squaring. A 1 doubles it and adds one — a squaring and a multiply. That is why the cost is between log₂(b) and 2log₂(b).

27. Read the cost of a public key operation

Cost model

Chapter 1 claimed public key methods are orders of magnitude slower. This formula is why.

Annotate

On: \( \text{cost} \approx 1.5 \log_2(b) \text{ modular multiplications on } \log_2(n) \text{-bit numbers} \)

  • The exponent's bit length. For RSA with a 2048-bit modulus and a full-length private exponent, that is about 2048 squarings.
  • Every bit costs a squaring; about half the bits also cost a multiply. So the expected count is 1.5 per bit, not 2.
  • Each one is a multiplication of two 2048-bit numbers plus a reduction — hundreds of machine-word operations, not one.
  • About 3000 big-number multiplications for one RSA operation, against a handful of table lookups and XORs per block for AES. That is the several orders of magnitude, and it is why Chapter 1's hybrid pattern exists.
  • RSA encryption usually uses e = 65537 = 2¹⁶ + 1, which is 17 bits with only two set. Encryption is therefore cheap and decryption is not — an asymmetry real protocols are designed around.

The formula also explains the CRT speed-up: halving the modulus length cuts each multiplication's cost by about four.

28. Fermat's and Euler's Theorems

Section

Section 3.6 · pp. 55-59

29. Fermat's Theorem

Concept

The book calls this one of the two most basic results in number theory, and it is used repeatedly from here on.

\[ p \text{ prime}, \;; p \nmid a \;\Longrightarrow\; a^{p-1} \equiv 1 \pmod p \]

The proof is a counting argument and worth knowing, because the same move appears again in Euler's theorem and in Chapter 10. Consider multiplying every element of {1, 2, …, p−1} by a, mod p. Because gcd(a, p) = 1 that map is injective and never produces 0, so it is a permutation of the set.

Therefore the product of all the images equals the product of all the originals. Cancelling the common factors — legal, since each is coprime to p — leaves a^(p−1) ≡ 1.

Figure (svg): Multiplying every non-zero residue mod 7 by 2 permutes the set, which is the proof of Fermat's theorem in one picture.

Because the map is a permutation, the two products are equal — and cancelling them leaves a^(p−1) ≡ 1.

30. Using Fermat to compute 2⁵³ (mod 11)

Worked example

The book's example. Fermat's theorem turns a large exponent into a small one.

p = 11 is prime and 11 does not divide 2, so Fermat applies: 2¹⁰ ≡ 1 (mod 11)

Why: Check directly: 2¹⁰ = 1024 = 93 · 11 + 1. ✓

Reduce the exponent modulo p − 1 = 10: 53 = 5 · 10 + 3

Why: Exponents live mod p−1, not mod p. This is the single most common slip in the whole chapter.

So 2⁵³ = (2¹⁰)⁵ · 2³ ≡ 1⁵ · 8 = 8 (mod 11)

Why: The five factors of 2¹⁰ each collapse to 1.

\[ 2^{53} \equiv 8 \pmod{11} \]

Verify: 2⁵³ has sixteen digits, and we never wrote any of them down

Why: That is the whole value of the theorem: it bounds the exponent by p−1 before any computation starts, and combined with square-and-multiply it makes public key cryptography possible.

Figure (svg): Multiplying every non-zero residue mod 7 by 2 permutes the set, which is the proof of Fermat's theorem in one picture.

Because the map is a permutation, the two products are equal — and cancelling them leaves a^(p−1) ≡ 1.

31. Euler's Theorem and the function φ

Concept

Fermat needs a prime modulus. Euler's theorem removes that restriction, and the price is a new quantity.

φ(n) — Euler's totient: the count of integers in 1, …, n that are coprime to n. For a prime p, φ(p) = p − 1. For a product of distinct primes, φ(pq) = (p−1)(q−1).

\[ \gcd(a, n) = 1 \;\Longrightarrow\; a^{\varphi(n)} \equiv 1 \pmod n \]

Fermat is the special case n = p, where φ(p) = p − 1. And φ(pq) = (p−1)(q−1) is the single fact that makes RSA work: it is computable by whoever knows p and q, and believed infeasible for anyone else — because computing φ(n) from n is as hard as factoring n.

Figure (svg): Euler's totient counted for 26, showing the twelve residues coprime to it and the two families that are excluded.

φ counts the invertible elements — which is why it counts the legal keys of an affine cipher and the exponents of RSA alike.

32. Computing φ(n) three ways

Worked example

φ is multiplicative over coprime factors, which makes it easy once n is factored — and hopeless when it is not.

φ(p) = p − 1 for prime p: φ(13) = 12

Why: Every non-zero residue is coprime to a prime.

φ(pq) = (p−1)(q−1) for distinct primes: φ(26) = φ(2)φ(13) = 1 · 12 = 12

Why: Matching the count in the figure above.

φ(pᵏ) = pᵏ − p^(k−1): φ(27) = 27 − 9 = 18

Why: Exclude the multiples of p, of which there are p^(k−1).

\[ \varphi(n) = n \prod_{p \mid n} \left(1 - \frac{1}{p}\right) \]

Verify: apply the formula to 26: 26(1 − 1/2)(1 − 1/13) = 26 · (1/2) · (12/13) = 12

Why: Agrees with the direct count. But note what the formula needs: the prime factorization of n. For a 2048-bit RSA modulus nobody can supply that, which is exactly why the private key is private.

Figure (svg): Two paths to phi of n: easy with the factorization, believed as hard as factoring without it.

The same quantity is trivial for the key holder and infeasible for everybody else. That is a trapdoor.

33. Fermat and Euler, stated correctly

Two truths and a lie

Two of these misstate the hypotheses in ways that matter. One is right.

Eliminate the wrong options

Which statement is correct?

  • a. If gcd(a, n) = 1 then a^φ(n) ≡ 1 (mod n), for any modulus n
  • b. For any prime p and any integer a, a^(p−1) ≡ 1 (mod p)
  • c. For any n and any a, a^n ≡ a (mod n)

Survives elimination: a

Why: Euler's theorem needs only gcd(a, n) = 1, and it holds for every modulus. Fermat is its special case at n = p, where φ(p) = p − 1 and the coprimality condition becomes p ∤ a. Getting the hypotheses right matters practically: RSA's correctness proof is exactly an application of Euler's theorem, and it breaks in precisely the cases where gcd(a, n) ≠ 1.

34. How much does the CRT actually save?

Estimation

RSA decryption computes c^d mod n. With the factors known, it can instead compute mod p and mod q and recombine. Modular exponentiation cost grows roughly as the cube of the modulus length.

Predict first

Roughly how much faster is the CRT route for a 2048-bit modulus?

  • No faster — two exponentiations instead of one
  • About twice as fast
  • About four times as fast
  • About eight times as fast

Correct: About four times as fast

The same reasoning explains why RSA encryption with e = 65537 is so much cheaper than decryption: 17 bits of exponent against 2048.

And it is why the Bellcore fault attack matters — the speed-up is universal, so the vulnerability it introduces is universal too.

Why: Each half-computation uses a 1024-bit modulus, so each costs about (1/2)³ = 1/8 of the full one. Two of them cost 2/8 = 1/4, giving roughly a fourfold speed-up before the small cost of recombining. This is not a micro-optimisation — it is the difference between a server handling four times as many TLS handshakes on the same hardware, and every RSA library does it.

35. Primitive Roots

Section

Section 3.7 · pp. 59-61

36. A Primitive Root generates everything

Concept

Look at the powers of 3 mod 7: 3, 2, 6, 4, 5, 1. Every non-zero class appears. So 3 is a primitive root mod 7 — the book notes that multiplicative generator would be a better name but is less common.

Contrast the powers of 3 mod 13: 3, 9, 1, 3, 9, 1, … Only three values ever appear, so 3 is not a primitive root mod 13. The primitive roots mod 13 are 2, 6, 7 and 11.

\[ \alpha^{n} \equiv 1 \pmod p \;\Longleftrightarrow\; n \equiv 0 \pmod{p-1} \]

For prime p there are exactly φ(p − 1) primitive roots, so at least one always exists. Finding one is easy in practice when the factorization of p − 1 is known.

Figure (svg): The powers of 3 mod 7 walking through every non-zero residue, next to the powers of 3 mod 13 closing after three steps.

A primitive root's powers reach every non-zero class. A non-primitive root walks a short cycle and stops.

37. Testing whether 2 is a primitive root mod 13

Worked example

The naive test computes all twelve powers. The efficient test uses the structure of p − 1.

p − 1 = 12 = 2² · 3, so the prime divisors are 2 and 3

Why: The order of any element divides 12, so the possible orders are 1, 2, 3, 4, 6, 12.

2 fails to be a primitive root only if its order is a proper divisor of 12 — equivalently if 2^(12/2) ≡ 1 or 2^(12/3) ≡ 1

Why: Checking the maximal proper divisors is enough, because any smaller order divides one of them.

2⁶ = 64 = 4 · 13 + 12 ≡ 12 ≡ −1, which is not 1

Why: So the order does not divide 6.

2⁴ = 16 ≡ 3, which is not 1

Why: So the order does not divide 4 either.

Verify: the order divides 12 but neither 6 nor 4, so it is 12

Why: 2 is a primitive root mod 13, confirmed with two exponentiations instead of twelve. This is exactly how Diffie-Hellman parameters are generated in practice, and it is why p − 1 is chosen with a known factorization.

Figure (svg): The powers of 3 mod 7 walking through every non-zero residue, next to the powers of 3 mod 13 closing after three steps.

A primitive root's powers reach every non-zero class. A non-primitive root walks a short cycle and stops.

38. How many primitive roots are there mod 13?

Prediction

The proposition says a prime p has exactly φ(p − 1) primitive roots.

Predict first

So how many does 13 have?

  • 2
  • 4
  • 6
  • 12

Correct: 4

The same counting explains why Diffie-Hellman implementations often use a subgroup generator rather than a full primitive root: the security depends on the order of the element being large and having a large prime factor, not on it being maximal.

Why: p − 1 = 12 = 2² · 3, so φ(12) = 12(1 − 1/2)(1 − 1/3) = 4. The four primitive roots mod 13 are 2, 6, 7 and 11, exactly as the book lists. Note how small the fraction is: only a third of the non-zero classes generate. That is typical, and it is why finding a generator is a search rather than a formula — though a short one, since a third of all candidates work.

39. Order the moduli by how many primitive roots they have

Ranking

The count is φ(p − 1), so it depends on the factorization of p − 1 rather than on p itself.

Put in order

  1. p = 7 (p − 1 = 6 = 2 · 3)
  2. p = 11 (p − 1 = 10 = 2 · 5)
  3. p = 13 (p − 1 = 12 = 2² · 3)
  4. p = 23 (p − 1 = 22 = 2 · 11)

Why: φ(6) = 2, φ(10) = 4, φ(12) = 4, φ(22) = 10. So 7 has 2 primitive roots, 11 and 13 have 4 each, and 23 has 10. The pattern worth seeing is that p − 1 = 2q with q prime gives φ(2q) = q − 1, which is close to half of p — the largest possible density. Primes of that shape are called safe primes, and Chapter 10 prefers them for exactly this reason.

40. Inverting Matrices Mod n

Section

Section 3.8 · pp. 61-62

41. Matrices mod n: one determinant condition

Concept

Everything from linear algebra carries over, with one change: dividing by the determinant requires the determinant to be invertible mod n, not merely non-zero.

\[ M^{-1} = (\det M)^{-1} \, \operatorname{adj}(M) \pmod n, \qquad \gcd(\det M, n) = 1 \]

For a 2 × 2 matrix the adjugate is the familiar swap-and-negate, so the whole computation is one modular inverse plus four multiplications.

This is the same condition as the affine cipher's, one dimension up — and it is exactly what a Hill cipher key must satisfy. Chapter 6 uses it directly.

Figure (svg): The two by two inverse formula mod n, with the determinant condition highlighted.

One extra condition on top of ordinary linear algebra, and it is the same condition as everywhere else in the chapter.

42. Inverting a matrix mod 26

Worked example

Take M with rows (1, 2) and (3, 5), working mod 26 — the setting of a Hill cipher on digrams.

det M = 1 · 5 − 2 · 3 = −1 ≡ 25 (mod 26)

Why: Reduce the determinant into the range 0…25 before doing anything else.

Check gcd(25, 26) = 1, so the inverse exists

Why: If this failed, the matrix would be an illegal Hill key — the two-dimensional version of Chapter 2's α = 13.

Find 25⁻¹ mod 26: since 25 ≡ −1, its inverse is −1 ≡ 25

Why: A pleasant special case; in general use extended Euclid.

Adjugate: swap the diagonal and negate the off-diagonal, giving rows (5, −2) and (−3, 1) ≡ (5, 24) and (23, 1)

Why: Then multiply by 25 mod 26, which is multiplication by −1.

\[ M^{-1} \equiv \begin{pmatrix} 21 & 2 \\ 3 & 25 \end{pmatrix} \pmod{26} \]

Verify: multiply out: 1·21 + 2·3 = 27 ≡ 1, and 1·2 + 2·25 = 52 ≡ 0

Why: The top row of the product is (1, 0) as required; the bottom row checks the same way. Always multiply back — a sign error in the adjugate is silent otherwise.

Figure (svg): The product of the matrix and its computed inverse reducing to the identity mod 26.

The identity comes out mod 26, which is the only sense in which this is an inverse.

43. Square Roots Mod n

Section

Section 3.9 · pp. 62-64

44. Square Roots Mod n, and why four is the interesting number

Concept

Modulo a prime p ≡ 3 (mod 4) there is a formula, and it is a single exponentiation.

\[ x \equiv y^{(p+1)/4} \pmod p \]

If y is a square mod p, its roots are ±x. If not, then −y is a square and its roots are ±x — exactly one of the two is a square, and the same computation settles which.

Modulo n = pq the picture changes and the change is the whole point. Solve mod p (two roots) and mod q (two roots), then recombine by the Chinese Remainder Theorem: four square roots, not two.

And that fourth root is a factoring oracle. If you know two roots x and z with x ≢ ±z (mod n), then gcd(x − z, n) is a non-trivial factor of n. Being able to take square roots mod n is therefore equivalent to being able to factor n — a fact Chapters 9 and 10 both build on.

Figure (svg): Four square roots of 71 modulo 77, arising from two choices mod 7 and two mod 11 recombined by the CRT.

A square root mod a prime has two solutions; mod a product of two primes it has four — and that fourth root is what factors n.

45. Finding the square roots of 71 mod 77

Worked example

The book's opening question. n = 77 = 7 · 11, and both primes are 3 mod 4, so the formula applies twice.

Mod 7: 71 ≡ 1, and (7+1)/4 = 2, so x ≡ 1² = 1. The roots mod 7 are ±1

Why: Check: 1² = 1 ≡ 71 (mod 7). ✓

Mod 11: 71 ≡ 5, and (11+1)/4 = 3, so x ≡ 5³ = 125 ≡ 4. The roots mod 11 are ±4

Why: Check: 4² = 16 ≡ 5 (mod 11). ✓ This is the book's own worked example of the formula.

Combine the four sign choices by the CRT: (+1, +4), (+1, −4), (−1, +4), (−1, −4)

Why: Each pair gives one residue mod 77.

\[ x \equiv 15, \; 29, \; 48, \; 62 \pmod{77} \]

Verify: 15² = 225 = 2·77 + 71 ✓ and 29² = 841 = 10·77 + 71 ✓

Why: All four square to 71. Note 48 = 77 − 29 and 62 = 77 − 15, so the four roots are two ± pairs — and mixing across the pairs is what factors n.

Figure (svg): Four square roots of 71 modulo 77, arising from two choices mod 7 and two mod 11 recombined by the CRT.

A square root mod a prime has two solutions; mod a product of two primes it has four — and that fourth root is what factors n.

46. The fourth root gives away the factorization

Anomaly

You know that 15² ≡ 71 and 29² ≡ 71 (mod 77), and 29 is neither 15 nor −15 (which is 62).

Predict first

What can you compute from this?

  • Nothing more — two square roots are just two square roots
  • The factorization of 77, from gcd(29 − 15, 77)
  • A square root of 71 mod 7 only
  • The value of φ(77)

Correct: The factorization of 77, from gcd(29 − 15, 77)

It also explains a design rule in Chapter 9: never let an RSA implementation act as a square-root oracle, because that is the same as letting it factor its own modulus.

And it is why the Rabin system, unlike RSA, has a proof that breaking it is as hard as factoring — a stronger guarantee than RSA has ever had.

Why: Since 15² ≡ 29² (mod 77), we have 77 | (29 − 15)(29 + 15) = 14 · 44. Neither factor is divisible by 77, so the primes must split between them: gcd(14, 77) = 7 and gcd(44, 77) = 11. Two 'unrelated' square roots factor the modulus in one gcd. This equivalence — taking square roots mod n is as hard as factoring n — is the foundation of the Rabin cryptosystem and of the bit-commitment scheme in Section 10.3.

Figure (svg): Four square roots of 71 modulo 77, arising from two choices mod 7 and two mod 11 recombined by the CRT.

A square root mod a prime has two solutions; mod a product of two primes it has four — and that fourth root is what factors n.

47. Explain why square roots mod n are dangerous

Explain it

A colleague is building a system that, given b, returns a square root of b mod n for a public modulus n = pq.

Discussion prompt

Explain in three sentences why this service hands out the factorization of n, and what it would take to make it safe.

Hint: Ask what the caller can do if they already knew one root before they asked.

Answer:

The attack. Pick a random x, compute b = x² mod n, and ask the service for a square root of b. It returns one of the four roots, and with probability 1/2 the one it returns is neither x nor −x. Then gcd(x − answer, n) is a prime factor of n.

Why it works. Four roots exist because the CRT combines two sign choices independently. Two roots from different ± pairs differ by something divisible by exactly one of the two primes, so the gcd separates them.

Cost to the attacker: one query, on average two. Not a weakness to be mitigated — a total break, delivered on request.

Making it safe means not offering the service at all. There is no parameter choice that fixes it, because the equivalence between square roots and factoring is a theorem, not an implementation detail. This is why Chapter 9's design rules forbid a decryption oracle of any kind.

48. Legendre and Jacobi Symbols

Section

Section 3.10 · pp. 64-69

49. The Legendre symbol: is this a square mod p?

Concept

For an odd prime p and a not divisible by p, the Legendre symbol records one bit of information.

\[ \left(\frac{a}{p}\right) = \begin{cases} +1 & a \text{ is a square mod } p \\ -1 & a \text{ is not} \end{cases} \]

Euler's criterion computes it with one exponentiation, so the question 'is a a square mod p' is answered as cheaply as any modular power.

\[ \left(\frac{a}{p}\right) \equiv a^{(p-1)/2} \pmod p \]

Exactly half the non-zero residues mod p are squares, so the symbol is a fair coin over random inputs — a fact Chapter 10's bit commitment and Chapter 19's zero-knowledge protocols both exploit.

Figure (svg): The squares mod 11 marked out among all ten non-zero residues, showing exactly five of them.

Each square has exactly two roots, so the ten classes pair up into five squares.

50. The Jacobi symbol: the same notation without the factorization

Concept

The Jacobi symbol extends the Legendre symbol to any odd n, by multiplying the Legendre symbols of n's prime factors.

\[ \left(\frac{a}{n}\right) = \prod_i \left(\frac{a}{p_i}\right)^{e_i}, \qquad n = \prod_i p_i^{e_i} \]

The definition needs the factorization; computing it does not. Quadratic reciprocity gives a Euclidean-style algorithm that reduces the symbol step by step, so the Jacobi symbol of a mod n is computable in logarithmic time for an n nobody can factor.

But the meaning changes, and the change is a trap worth stating loudly. A Jacobi symbol of −1 does prove a is a non-square mod n. A Jacobi symbol of +1 proves nothing: it can arise from two genuine squares or from two non-squares. Solovay-Strassen primality testing and several protocols in Chapter 19 turn on exactly this gap.

Figure (svg): A comparison of what the Legendre and Jacobi symbols tell you, and what each costs to compute.

The Jacobi symbol trades certainty for computability, and protocols are built in the gap.

51. Legendre against Jacobi

Comparison

Fill the blanks. The last row is the one that gets misused.

Comparison matrix

Legendre (a/p)Jacobi (a/n)
Modulusan odd primeany odd integer
Needs the factorization to compute?no — p is already primeno — quadratic reciprocity
Value −1 meansnot a square mod pnot a square mod n
Value +1 meansis a square mod pnothing conclusive
Used forquadratic residues, Euler's criterionSolovay-Strassen primality testing, zero-knowledge protocols

The asymmetry in the +1 row is not a defect to be worked around — it is the resource that several protocols in this book are built on.

52. Finite Fields

Section

Section 3.11 · pp. 69-76

53. Finite Fields: where you can always divide

Concept

Working mod p, you can add, subtract, multiply, and — crucially — divide by anything non-zero. Working mod 6 you cannot: 3x ≡ 1 (mod 6) has no solution. A set with all four operations, obeying the usual laws, is a field.

The integers mod a prime form a field, written GF(p). But fields also exist with pⁿ elements for any prime power, and there is exactly one of each size up to isomorphism.

\[ |GF(p^n)| = p^n, \qquad \text{e.g. } GF(2^8) \text{ has } 256 \text{ elements} \]

The book flags where these appear: GF(2⁸) is what AES computes in (Chapter 8), finite fields explain the LFSR behaviour of Section 5.2, and they underpin Section 21.4, Chapter 22 and the error-correcting codes of Chapter 24. This section exists to serve those five places.

Figure (svg): The addition and multiplication tables of the four-element field GF(4).

Four elements, and division works. GF(2⁸) is the same idea with 256 elements, and it is what AES computes in.

54. Building GF(4) by hand

Worked example

The smallest field that is not the integers mod a prime. Its four elements are 0, 1, ω and ω².

The rules: x + x = 0 for every x, and ω + 1 = ω²

Why: The first says the characteristic is 2 — adding anything to itself gives zero, so addition is XOR.

Check ω³ = 1: ω³ = ω · ω² = ω(1 + ω) = ω + ω²

Why: Using ω² = 1 + ω, which is rule two rearranged.

Continue: ω + ω² = ω + (1 + ω) = 1 + (ω + ω) = 1 + 0 = 1

Why: The two ω terms cancel because x + x = 0.

So ω³ = 1, which makes ω² the multiplicative inverse of ω

Why: And 1 is its own inverse, so every non-zero element is invertible.

Verify: all three non-zero elements have inverses, so GF(4) is a field with four elements

Why: Note that GF(4) is NOT the integers mod 4 — mod 4, the element 2 has no inverse. Fields of size pⁿ for n > 1 are genuinely different objects, built from polynomials rather than from integers.

Figure (svg): The addition and multiplication tables of the four-element field GF(4).

Four elements, and division works. GF(2⁸) is the same idea with 256 elements, and it is what AES computes in.

55. Where each field shows up

Analogy

The book lists four places finite fields are used. Match each to what it is used for.

Match the pairs

  • f1. GF(2⁸)
  • f2. GF(2ⁿ) generally
  • f3. GF(p), p a large prime
  • f4. GF(2ᵐ) in coding theory
  • g1. AES: one byte is one field element (Chapter 8)
  • g2. LFSR sequences and their periods (Section 5.2)
  • g3. Diffie-Hellman and elliptic curves mod p (Chapters 10, 21)
  • g4. Reed-Solomon and BCH codes (Chapter 24)

Why: The unifying reason is always the same: a field is where division works, so linear algebra, polynomial factorization and interpolation all behave. AES uses GF(2⁸) because a byte has 256 values and the field operations are cheap in hardware; Reed-Solomon uses GF(2ᵐ) because a polynomial of degree k is determined by any k+1 of its values, which is exactly what makes erasures recoverable. Secret sharing in Chapter 17 is the same interpolation fact used for a different purpose.

56. Why AES computes in GF(2⁸) rather than mod 256

Real world

A byte holds 256 values, and the integers mod 256 are the obvious arithmetic to put on it.

Discussion prompt

Why does AES use the field GF(2⁸) instead, and what would go wrong with arithmetic mod 256?

Hint: Ask which elements have multiplicative inverses in each.

Answer:

Mod 256 is not a field. 256 = 2⁸, so every even number shares a factor with the modulus and has no inverse. Only the 128 odd residues are invertible — half the byte values cannot be divided by.

AES's S-box is built from the operation take the multiplicative inverse in the field. That construction needs every non-zero element to have one, which mod 256 simply does not provide.

GF(2⁸) has 256 elements and all 255 non-zero ones are invertible. It is built as polynomials over GF(2) modulo an irreducible polynomial, so addition is plain XOR — free in hardware — and multiplication is a shift-and-XOR.

So the choice is not aesthetic. The field structure is what makes the S-box's algebraic properties provable, and Section 8.4's design rationale is largely an argument about those properties.

It is a good example of the chapter's general lesson: the algebraic structure you choose determines which constructions are available to you.

57. What do you still need to know?

Missing information

You are handed a modulus n = 3233 and told it is an RSA modulus with public exponent e = 17.

Discussion prompt

To compute the private exponent d you need φ(n). List what you would have to determine first, and say which step is the hard one in general.

Hint: Write down the chain from n to d and mark which link has no known shortcut.

Answer:

The chain: factor n into p and q → compute φ(n) = (p−1)(q−1) → compute d ≡ e⁻¹ (mod φ(n)) by extended Euclid.

For n = 3233 this is easy: 3233 = 61 · 53, so φ(n) = 60 · 52 = 3120, and d = 17⁻¹ mod 3120 = 2753. Check: 17 · 2753 = 46 801 = 15 · 3120 + 1 ✓.

The hard link is the first one, and only the first one. Given the factors, everything after is logarithmic-time arithmetic from this chapter. Without them, computing φ(n) is as hard as factoring — that equivalence is what makes the trapdoor a trapdoor.

Notice what this means for key sizes: 3233 is four digits and factors instantly. RSA uses 600-digit moduli precisely because the difficulty of that single step is the entire security of the system.

58. Which tool solves this?

Sorting

Retrieval practice across the whole chapter. Each problem is solved by one of the tools you have just met.

Sort into buckets

Sort each problem by the tool that solves it.

Extended Euclid
Find x with 17x ≡ 1 (mod 3120)
Fermat / Euler
Compute 7^1000000 mod 13
Chinese Remainder Theorem
Solve x ≡ 2 (mod 5) and x ≡ 3 (mod 7) simultaneously
Legendre symbol
Decide whether 5 is a square mod 11 without listing squares
Square and multiply
Compute 3^500 mod 1001 with a modest number of multiplications
Continued fractions
Find the best fraction approximating 0.318309 with a small denominator
ee
A modular inverse is Bézout's identity read mod n. This exact computation is how RSA turns a public exponent into a private one.
fe
A huge exponent over a prime modulus collapses: 13 is prime, so reduce the exponent mod 12 first and the problem becomes trivial.
crt
Two congruences with coprime moduli glue into one congruence mod 35, uniquely.
leg
Euler's criterion answers it with one exponentiation: 5^5 mod 11. No enumeration needed.
sm
The exponent is large but the modulus is not prime-friendly here, so reduce the exponent by repeated squaring rather than by a theorem.
cf
The convergents of a real number are exactly the best rational approximations for their denominator size — and 0.318309 is 1/π.

59. Continued Fractions

Section

Section 3.12 · pp. 76-78

60. Continued Fractions: the best approximation for the denominator

Concept

To approximate a real number, take the integer part, invert what is left, and repeat. For π: the integer part is 3, and 1/0.14159… = 7.0625…, whose integer part is 7 — giving 22/7.

\[ \pi = 3 + \cfrac{1}{7 + \cfrac{1}{15 + \cfrac{1}{1 + \cdots}}} \]

Truncating gives 3, then 22/7, then 333/106, then 355/113. The last is accurate to about 3 × 10⁻⁷.

The reason this matters here is a theorem: the convergents are the best rational approximations for their size of denominator. Compare 157/50 — a larger denominator than 22/7 and a worse approximation. That optimality is what turns continued fractions into an attack.

Figure (svg): Successive continued-fraction approximations to pi, each with a small denominator and rapidly improving accuracy.

Continued fractions find the best rational approximation for the size of denominator — which is exactly what Wiener's attack on RSA needs.

61. Four steps of the algorithm on π

Worked example

Each step is: take the integer part, subtract it, invert the remainder.

π = 3.14159265…, so a₀ = 3 and the remainder is 0.14159265…

Why: The first convergent is just 3.

1/0.14159265 = 7.06251…, so a₁ = 7

Why: Convergent 3 + 1/7 = 22/7 ≈ 3.142857, already correct to two decimals.

1/0.06251 = 15.9966…, so a₂ = 15 — take 15, not 16

Why: The book notes 16 is closer, and that the algorithm corrects for this at the next step. Rounding here would break the optimality theorem.

Next term is 1, giving 355/113

Why: The unusually large partial quotient that follows is why 355/113 is such a famously good approximation.

\[ 3, \quad \frac{22}{7}, \quad \frac{333}{106}, \quad \frac{355}{113} \]

Verify: 355/113 = 3.14159292…, against π = 3.14159265…

Why: Correct to six decimal places with a three-digit denominator — and 157/50, with a comparable denominator, manages only two. The convergents are optimal in a way that decimal truncation is not.

Figure (svg): Successive continued-fraction approximations to pi, each with a small denominator and rapidly improving accuracy.

Continued fractions find the best rational approximation for the size of denominator — which is exactly what Wiener's attack on RSA needs.

62. Where does this become an attack?

Edge cases

Continued fractions look like a numerical-methods topic. Chapter 9 uses them to break RSA outright.

Discussion prompt

If an attacker knows the public pair (n, e) and suspects the private exponent d is small, how could 'best rational approximation' help?

Hint: The RSA relation ed ≡ 1 (mod φ(n)) can be rearranged into an equation saying e/n is nearly equal to something over d.

Answer:

The relation ed − kφ(n) = 1 rearranges to e/φ(n) − k/d = 1/(dφ(n)). And since φ(n) = n − p − q + 1 is close to n, e/n is very nearly k/d.

If d is small, that approximation is close enough that k/d must be one of the convergents of e/n — because the convergents are exactly the best approximations for their denominator size, and nothing else can be that close.

So the attacker computes the continued fraction of e/n, tries each convergent as a candidate k/d, and tests it. There are only about log n convergents, so the whole attack runs in seconds.

This is Wiener's attack, and it works whenever d is less than roughly n^(1/4). The practical consequence is a rule you will meet in Chapter 9: never choose a small private exponent to speed up decryption. Use the CRT instead.

It is also a clean illustration of this chapter's theme — a tool from pure approximation theory becomes an attack because it is optimal, and optimality is exactly what an attacker needs.

63. What every section of this chapter had in common

Pattern

Twelve sections, and one structure repeated. Every tool here is an instance of the same three-part shape.

  1. A condition for the operation to be legal. gcd(a, n) = 1 for inverses, gcd(m, n) = 1 for the CRT, gcd(det, n) = 1 for matrices, p ∤ a for Fermat. It is the same condition every time, and it is always about not sharing a factor with the modulus.
  2. An algorithm that is logarithmic, not linear. Euclid, square-and-multiply, the Jacobi symbol by reciprocity, continued fractions. Every one of them consumes its input a digit or a bit at a time.
  3. A gap between a fast direction and a slow one. Multiply versus factor. Exponentiate versus take a discrete log. Compute φ(n) with the factors versus without. Every public key system in this book lives inside one of these gaps.

The third point is the one to keep. This chapter is not a toolbox of unrelated tricks; it is a catalogue of operations that are easy forwards and believed hard backwards, which is precisely what cryptography needs and precisely what nothing else in mathematics supplies so readily.

Figure (svg): A map from each tool in this chapter to the chapter that consumes it.

Nothing in this chapter is here for its own sake — every section is consumed by a later one.

64. Exponents reduce mod n, like everything else

Trap

The trap

The trap. Working mod 11, a student wants 2⁵³. They know everything reduces mod 11, so they reduce the exponent: 53 ≡ 9 (mod 11), and compute 2⁹ = 512 ≡ 6 (mod 11).

The answer is 6. It feels consistent — the whole chapter has been about reducing things mod 11.

The fix

Why it fails. The correct answer is 8. Exponents do not live in the same world as bases: the base is reduced mod n, but the exponent is reduced mod φ(n) — here mod p − 1 = 10.

53 ≡ 3 (mod 10), so 2⁵³ ≡ 2³ = 8 (mod 11), which matches the direct calculation.

The reason is Fermat's theorem itself: a^(p−1) ≡ 1, so the powers of a cycle with period dividing p − 1, not p. The exponent is an index into a cycle of length p − 1, and reducing it modulo the wrong number lands on the wrong element of that cycle.

This is the single most common error in the chapter, and it is invisible — both calculations produce a plausible residue. The rule to memorise: bases mod n, exponents mod φ(n). In RSA this is exactly why d is computed as e⁻¹ mod φ(n) and not mod n.

65. Check: when does an inverse exist?

Check

Work it out before you click.

Check your understanding

For which of these does a⁻¹ mod n exist?

  • A. a = 6, n = 9
  • B. a = 8, n = 15 (correct)
  • C. a = 14, n = 21
  • D. a = 10, n = 25

Answer: B

Why: An inverse exists exactly when gcd(a, n) = 1. gcd(8, 15) = 1, so 8 is invertible mod 15 — indeed 8 · 2 = 16 ≡ 1. Neither number needs to be prime; coprimality is the whole condition, and it is the same condition behind legal affine keys, invertible Hill matrices and the Chinese Remainder Theorem.

Why A tempts people
gcd(6, 9) = 3. Both are composite and they share the factor 3, so no inverse exists.
Why C tempts people
gcd(14, 21) = 7. A tempting case because 14 and 21 look unrelated, but both are multiples of 7.
Why D tempts people
gcd(10, 25) = 5. Sharing a single prime factor is enough to destroy invertibility — the gcd does not have to be large.

66. Check: reducing an exponent

Check

This is the trap slide, in question form.

Check your understanding

Compute 3¹⁰⁰ (mod 7).

  • A. 1
  • B. 2
  • C. 4 (correct)
  • D. 6

Answer: C

Why: 7 is prime and does not divide 3, so Fermat gives 3⁶ ≡ 1 (mod 7). Reduce the exponent mod 6, not mod 7: 100 = 16 · 6 + 4, so 3¹⁰⁰ ≡ 3⁴ = 81 = 11 · 7 + 4 ≡ 4 (mod 7).

Why A tempts people
This is what you get by assuming 3¹⁰⁰ ≡ 1 because the exponent is a multiple of something — but 100 is not a multiple of 6, so Fermat does not collapse it to 1.
Why B tempts people
This comes from reducing the exponent mod 7 instead of mod 6: 100 ≡ 2 (mod 7) gives 3² = 9 ≡ 2. It is the exact error the trap slide warns about.
Why D tempts people
3³ = 27 ≡ 6 (mod 7), so this is the answer for exponent 3 — a slip in reducing 100 mod 6.

67. Check: how many square roots?

Check

Count carefully; the answer is the reason this section exists.

Check your understanding

Let n = pq with p and q distinct odd primes. If b has a square root mod n, how many square roots does it have?

  • A. 1
  • B. 2
  • C. 4 (correct)
  • D. It depends on b

Answer: C

Why: Mod each prime there are two roots, ±x. The Chinese Remainder Theorem combines every choice of sign independently, giving 2 × 2 = 4 roots mod n. This is the fact that makes square roots mod n equivalent to factoring: any two roots that are not negatives of each other yield a factor via gcd(x − z, n).

Why A tempts people
One root would make squaring injective, which it is not — x and −x always both work, for any modulus.
Why B tempts people
Two is correct modulo a prime. The jump from two to four when the modulus is composite is precisely the point of the section.
Why D tempts people
The count is 4 for every b that has a root at all, independent of which b. What varies is whether a root exists, not how many there are.

68. One page of number theory

Connect it up

Twelve sections is a lot to hold. Compress it once, in your own hand, and it becomes usable.

Draw it

On one page write: (1) the condition gcd(·, n) = 1 and the four places in this chapter it appears; (2) the extended Euclidean table for a small pair, ending in Bézout's identity, and the one line that turns it into a modular inverse; (3) Fermat's and Euler's theorems with their hypotheses, and the rule 'bases mod n, exponents mod φ(n)'; (4) the square-and-multiply recipe; (5) why x² ≡ b (mod pq) has four roots and what that gives an attacker. Then, beside each, write the later chapter that consumes it.

The last column is the point. Nothing in this chapter is here for itself, and knowing what consumes each tool is what makes it stick.

69. Exit ticket

Exit ticket

One question, and it is the one that separates this chapter from a general number theory course.

Predict first

What property must an operation have to be useful as the basis of a public key cryptosystem?

  • It must be impossible to compute in either direction
  • It must be easy in one direction and believed infeasible in the other, with a trapdoor making the reverse easy for the key holder
  • It must involve prime numbers
  • It must be provably secure

Correct: It must be easy in one direction and believed infeasible in the other, with a trapdoor making the reverse easy for the key holder

Why: The pattern behind every system in this book: multiplication is easy and factoring is not; exponentiation is easy and discrete logarithms are not; computing φ(n) is easy with the factors and infeasible without them. The trapdoor is what makes it a cryptosystem rather than merely a hard problem — the key holder has extra information that collapses the hard direction. Note the word 'believed': none of these has been proved hard, which is the honest state of the subject.

70. What to carry into Chapter 4

Recap

Twelve tools, each of which is used without further comment from here on.

Chapter 4 next. A complete change of register: the one-time pad needs almost none of this machinery, and is the only cipher in the book that is provably secure. It is worth seeing precisely because it shows what 'secure' can mean when computation is taken out of the picture entirely.

Figure (svg): A map from each tool in this chapter to the chapter that consumes it.

Nothing in this chapter is here for its own sake — every section is consumed by a later one.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 3 — Basic Number Theory (sections 3.1-3.12) — Trappe & Washington, 3rd edition, pp. 40-87

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108