Chapter 18 of Trappe & Washington: flipping a coin over the telephone using the four square roots of a square modulo pq, where Alice's fairness is information-theoretic and Bob's honesty rests on factoring; and mental poker dealt with no dealer, built from commutative encryption by exponentiation, including the discard audit that works by adding a second lock. Covers both protocols' limitations — the quadratic residue leak and the abort problem that no two-party protocol can solve.
Subject: Cryptography · 61 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 18
Flipping a coin and playing poker over the telephone, between two people who expect each other to cheat
Objectives
Two protocols with a new flavour. Until now the adversary was outside the conversation; here the counterparty is the adversary, and the protocol must protect each party from the other.
Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.
Warm-up
The book's story: a friend leaves Alice and Bob a car. Bob offers to flip a coin, Alice calls tails, and Bob says it was heads. He is telling the truth — as soon as she called, he produced his two-headed penny so he would not have to lie.
Discussion prompt
State precisely what a fair coin flip over a distance requires.
Hint: There are two separate cheats to prevent, and they are prevented differently.
Answer:
The flipper must not be able to choose the outcome after hearing the call. Bob's two-headed penny is exactly this: he waited to see what Alice said.
And the caller must not be able to learn the outcome before calling. Otherwise Alice cheats instead of Bob.
So the requirement is simultaneity, over a channel that cannot deliver anything simultaneously. The two acts — committing to an outcome and committing to a call — must be locked in before either is revealed.
Which is bit commitment, from Section 10.3. Alice commits, Bob announces, Alice opens. The protocol in this chapter achieves the same thing by a different route, and both are answers to the same structural problem: manufacturing simultaneity out of sequence.
Section
Section 18.1 · pp. 349-351
Concept
The protocol rests entirely on one fact from Section 3.9, so it is worth restating before the protocol uses it.
Modulo a prime p, a square has two square roots, ±r, and no more — a polynomial of degree 2 over a field has at most two roots.
Modulo n = pq, the Chinese Remainder Theorem splits the problem in two. A square root mod n corresponds to a choice of square root mod p and a square root mod q, independently.
\[ 2 \text{ choices mod } p \;\times\; 2 \text{ choices mod } q \;=\; 4 \text{ square roots mod } n \]
The four group into two ± pairs, because negating both components at once gives the negative mod n. The two pairs differ by negating only one component, and that is what makes them useful: two roots from different pairs are congruent mod one prime and negatives mod the other, so their difference is divisible by exactly one prime.
Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.
Worked example
Small enough to check by hand, and it shows every feature the protocol uses.
n = 77 = 7 · 11, and both primes are ≡ 3 (mod 4)
Why: 7 = 4·1 + 3 and 11 = 4·2 + 3, exactly as the protocol requires.
Mod 7: 15 ≡ 1, whose square roots are ±1
Why: By the formula, 15^((7+1)/4) = 15² ≡ 1 (mod 7).
Mod 11: 15 ≡ 4, whose square roots are ±2
Why: And 15^((11+1)/4) = 15³ ≡ 9 ≡ −2 (mod 11), which is one of them.
Combine the four sign choices by CRT
Why: (1, 2) → 57, (1, −2) → 64, (−1, 2) → 13, (−1, −2) → 20.
| root | mod 7 | mod 11 | pair |
|---|---|---|---|
| 13 | −1 | 2 | ±13 = {13, 64} |
| 64 | 1 | −2 | ±13 |
| 20 | −1 | −2 | ±20 = {20, 57} |
| 57 | 1 | 2 | ±20 |
Verify: two roots from different pairs factor n
Why: gcd(13 − 20, 77) = gcd(7, 77) = 7. Two roots from the same pair give gcd(13 − 64, 77) = gcd(51, 77) = 1 and gcd(13 + 64, 77) = 77 — both useless, which is precisely why Bob learns nothing when he wins.
Figure (svg): The four square roots of 15 modulo 77, grouped into two plus-or-minus pairs, with a gcd across the pairs factoring 77.
Notation
The congruence condition looks arbitrary. It is a computational convenience with a one-line justification.
Annotate
On: \( r \equiv y^{(p+1)/4} \pmod p \)
A condition that costs nothing — such primes are half of all primes — and turns Alice's step into a single modular exponentiation.
Figure (svg): The closed-form square root formula available when a prime is congruent to 3 modulo 4.
Prediction
Predict first
How many square roots would a square have mod n?
Correct: Eight
Which is a useful sanity check on why n has exactly two prime factors. The fairness of the coin is 1/k where k is the number of ± pairs, so two primes is the only choice giving an even flip.
And it shows how to build a biased coin deliberately. If Alice and Bob wanted a 1-in-4 event rather than 1-in-2, three primes would give it, and Bob could still verify the count by being shown the factorisation afterwards.
Bob would need to check that n really has only two factors, which he cannot do directly. In practice the protocol is run with Alice revealing p and q at the end of the round, so a three-prime n would be caught the first time she was asked to open it.
Why: CRT splits the problem into three independent binary choices, so 2³ = 8 roots. The protocol would still work — Alice would pick one of four ± pairs and Bob would win three times in four — but the flip would no longer be fair, since it would be biased 3:1 toward Bob.
Socratic
The protocol says Alice finds the four square roots of y. Bob might send a number with none.
Discussion prompt
What happens, and why is this the easiest cheat to catch?
Hint: Alice knows p and q, and Euler's criterion is one exponentiation.
Answer:
Alice discovers it immediately. She computes the Legendre symbols of y mod p and mod q, and y is a square mod n exactly when both are +1. One exponentiation each.
Only a quarter of the residues are squares mod pq, so a randomly chosen y is a square with probability 1/4 — a cheating Bob would be caught three times in four even if he were guessing.
What would he gain? If y has no root, Alice cannot produce one, so the flip cannot complete. It is a way of stalling, not of winning — a variant of the abort problem dressed up as arithmetic.
And the book's protocol handles it explicitly: Alice accuses Bob of cheating. That is the right response, because Bob computed y as x² and has no honest reason to send a non-square.
The general shape is worth noting: every step where one party supplies a value that the other can validate should be validated. Chapter 9's small-exponent and common-modulus attacks are all failures to check something checkable, and this is the same discipline applied to a protocol rather than a cryptosystem.
Concept
Alice's cryptologist suggests a protocol built on Section 3.9's fact that a square modulo pq has four square roots, in two ± pairs.
If y turns out to have no square root, Alice's calculation reveals that fact and she accuses Bob of cheating.
Figure (svg): The coin flip protocol: Bob squares a secret x, Alice finds all four roots and returns one, and whether it matches decides the flip.
Worked example
The protocol has no coin and no random-number generator producing the outcome. The randomness is Alice's ignorance, and it is worth locating exactly.
Bob's x lies in one of the two ± pairs — either {+a, −a} or {+b, −b}
Why: He knows which, because x is his.
Alice computes all four roots from p and q, and they arrive with no labels
Why: Nothing about the arithmetic distinguishes the pair containing x from the other. Both pairs are equally consistent with everything she has seen.
So when she picks a pair, she is picking Bob's pair with probability exactly 1/2
Why: Not approximately, and not subject to any computation — the two pairs are symmetric from her position.
She sends one element of her chosen pair
Why: Whether it is +b or −b makes no difference: Bob checks against ±x, so the sign is irrelevant.
Verify: the outcome is a fair coin even though neither party flipped one
Why: Bob supplied the randomness (choosing x) and Alice supplied the unpredictability of the choice (not knowing which pair). Neither alone determines the result, which is exactly the simultaneity the warm-up asked for.
Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.
Concept
Bob declares the result, so he has an obvious opportunity to cheat: he could simply claim to have lost when he won. Alice's protection is that a false claim requires him to prove something he cannot.
Suppose Alice sends b and Bob's x was in the other pair, so b ≢ ±x. Then Bob knows both x and b — two square roots of y that are not negatives of each other.
\[ x^2 \equiv b^2 \pmod n, \quad x \not\equiv \pm b \;\Longrightarrow\; \gcd(x - b, \, n) \text{ is a factor of } n \]
So the winning case comes with a proof. Bob claims to have won by producing p and q, which Alice can verify instantly. And Section 3.9 established that producing them any other way requires factoring n, which is believed infeasible.
Conversely, if Alice sent ±x, Bob has learned nothing new — he already knew x — and cannot factor. So he can only produce the factorisation when he genuinely won, and the claim is self-certifying.
Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.
Socratic
The protocol turns 'knowing two unrelated square roots' into a verifiable claim.
Discussion prompt
Name two earlier places in the course where the same fact appeared, and say what it was doing in each.
Hint: Section 3.9, and a cryptosystem with a proof RSA lacks.
Answer:
Section 3.9, as an attack. Being able to take square roots mod n was shown equivalent to factoring n — which is why a decryption oracle for a Rabin-style system is a factoring oracle, and why Chapter 9 forbids one.
The Rabin cryptosystem, where the equivalence is the point: breaking Rabin provably requires factoring, which is a stronger security statement than RSA has ever had.
And Section 10.3's bit commitment, which uses the same difficulty — Bob cannot compute discrete logs, so he cannot open Alice's commitment early.
Here the same fact is a fairness mechanism. The ability to factor is used as evidence: Bob can produce it exactly when he genuinely won, so his claim is self-certifying.
Which is the general observation worth taking: a hard problem is not only a wall. It can be a currency — something you can only possess under particular circumstances, and can therefore spend as proof that those circumstances hold. Zero-knowledge proofs in Chapter 19 are built entirely on this idea.
Definition probe
Each step of the protocol defends one party against one specific cheat.
Sort into buckets
Sort each mechanism by whom it protects.
Anomaly
Alice sends her chosen root. Bob sees that he lost, and the line goes dead.
Predict first
Does the protocol prevent this?
Correct: No — a party who dislikes the result can always abort, and no two-party protocol can prevent it
It is not a flaw in this construction. A general result says that fairness in the presence of aborts is impossible for two parties without additional assumptions — you cannot make both parties learn the outcome simultaneously over a sequential channel.
The practical answers all come from outside the cryptography: a trusted third party to adjudicate, a penalty deposit forfeited on abort, or a design where aborting is worse for the aborter than losing.
And it generalises to every protocol in this chapter and the next. A prover who is failing can stop; a poker player holding a bad hand can disconnect. Cryptography secures what is exchanged, not whether the exchange completes.
Why: Alice cannot tell whether Bob lost or genuinely disconnected, and she has no way to complete the protocol alone — the result depends on x, which only Bob knows. This is the abort problem, and it is a fundamental limitation: in a two-party protocol the last party to learn the outcome can always refuse to continue.
Concept
Section 10.3's bit commitment solves the same simultaneity problem, and it is what real systems deploy.
Hiding comes from H being one-way and r being long: Bob cannot recover c from the hash, so he calls blind. Binding comes from collision resistance: Alice cannot find a second (c′, r′) with the same hash, so she cannot change her mind.
Both properties are computational, unlike the square-root protocol's unconditional half. But the scheme costs two hash computations rather than a modular square root, and it composes: a fair value can be built from both parties' contributions by XORing Alice's revealed bit with Bob's call.
And r must be long. Committing to a bare bit means Bob hashes both possibilities and knows the answer — Chapter 11's low-entropy trap, and the single most common way this scheme is implemented wrongly.
Figure (svg): The commit-reveal coin flip: Alice commits to a bit, Bob calls it, Alice opens the commitment.
Anomaly
In the square-root protocol Alice sends one of the four roots. Suppose she sends something else entirely.
Predict first
What does Bob do?
Correct: He squares it and checks against y — a one-multiplication test
So both of the obvious protocol-level cheats are cheap to detect — Bob's non-square by Alice, and Alice's non-root by Bob. Neither party needs to trust the other about anything checkable.
What is left uncheckable is what makes the protocol interesting: Alice cannot check that Bob really squared a random x rather than reusing an old one, and Bob cannot check that Alice chose her root uniformly. Those are handled by the structure, not by verification.
Why: Bob knows y, so he squares whatever Alice sends and compares. A value that is not a root of y is caught with one multiplication. This is the same discipline as the previous slide: every supplied value that can be validated should be.
Faded example
Five steps, four blanks.
Fill in the blanks
Alice sends n = pq with both primes ≡ 3 (mod 4). Bob picks a secret x and sends y = x² mod n. Alice computes all four square roots and returns one at random. If it is ±x, Alice wins; otherwise Bob wins and can prove it by factoring n.
Why: The 3 (mod 4) condition gives the closed-form square root; the four roots in two pairs give the fair coin; and the factorisation gives Bob's self-certifying claim. Every element of the protocol is doing one of those three jobs.
Definition probe
Suppose Bob wins — Alice sent a root from the pair Bob's x was not in.
Sort into buckets
Sort each item by who ends up knowing it.
Section
Section 18.2 · pp. 351-355
Concept
Alice and Bob tire of coin flipping and try poker. Bob shuffles and deals — and Alice will not let him read the cards to her, and suspects he may not be playing with a full deck.
They try each choosing their own cards, and after several hundred coins have been wagered they discover they each have a royal flush. Each accuses the other of cheating.
So the requirements are:
And there is no dealer. That is what makes it a cryptographic problem rather than a procedural one.
Figure (svg): The commutative locks metaphor: Bob locks 52 boxes, Alice adds her locks to five, and each removes their own in either order.
Concept
The book gives the solution in non-mathematical terms first, and the metaphor is the clearest part of the chapter.
Bob takes 52 identical boxes, puts a card in each, puts a lock on each, dumps them in a bag and sends them to Alice.
Alice chooses five boxes, puts her own locks on them, and sends them back. Bob takes his locks off and returns them. Alice takes her locks off and finds her five cards.
Then she chooses five more boxes and sends them to Bob; he removes his locks and gets his hand.
The essential property is that the locks come off in either order. Bob's lock can be removed while Alice's is still on. Mathematically that is commutative encryption: E_A(E_B(m)) = E_B(E_A(m)), so decryption layers need not be stripped in reverse order.
Figure (svg): Commutative encryption by exponentiation: two exponents applied in either order give the same result.
Worked example
The metaphor needs a mathematical realisation, and exponentiation modulo a prime supplies it exactly.
Fix a large prime p. Alice's key is an exponent a with gcd(a, p−1) = 1; Bob's is b
Why: Coprimality to p−1 is what makes the exponent invertible mod p−1, so each lock can be removed — the affine cipher's condition, one more time.
Encrypting a card m is m ↦ m^a mod p, and decrypting is raising to a⁻¹ mod p−1
Why: Because (m^a)^(a⁻¹) = m^(aa⁻¹) = m^(1 + k(p−1)) ≡ m by Fermat.
Two encryptions compose as (m^b)^a = m^(ab) = (m^a)^b
Why: Exponents multiply, and multiplication commutes.
\[ E_A\bigl(E_B(m)\bigr) = m^{ab} = E_B\bigl(E_A(m)\bigr) \]
Verify: so Bob can strip his layer from a doubly-encrypted card, leaving Alice's layer intact
Why: Applying b⁻¹ to m^(ab) gives m^a, which is exactly the card under Alice's lock alone. The locks genuinely come off in any order, and this is the same identity that makes Diffie-Hellman work in Section 10.4.
Figure (svg): Commutative encryption by exponentiation: two exponents applied in either order give the same result.
Worked example
Following the boxes through, with the mathematics attached.
Bob encrypts all 52 card values with his key b and shuffles the results
Why: The shuffle is what stops Alice knowing which encrypted value is which card; the encryption is what stops her reading them.
Alice picks five, encrypts each with her key a, and returns them
Why: They are now m^(ab). Bob cannot tell which five she took, because they are under her lock as well as his.
Bob applies b⁻¹, returning m^a, and sends them back
Why: He has removed his layer without ever seeing the cards, since Alice's layer is still on.
Alice applies a⁻¹ and reads her hand
Why: Five cards, dealt fairly, with Bob knowing nothing about them.
Alice then chooses five more encrypted cards and sends them to Bob, who removes his own locks and reads his hand
Why: Symmetric, and Alice learns nothing about Bob's cards because she never applied her lock to them.
Verify: no card can be dealt twice, because each encrypted value is used once
Why: And neither player chose their own cards: Bob shuffled, so Alice's choice of position is uninformative, and Alice chose Bob's cards by position without being able to read them.
Figure (svg): The mental poker deal: Bob encrypts and shuffles the deck, Alice double-encrypts her chosen cards, and each strips their own layer.
Concept
Replacing cards works the same way. Alice puts three cards in a discard box, locks it, and sends it to Bob. She then chooses three of the remaining 42 encrypted cards, adds her locks, and Bob strips his — giving her three replacements.
If Bob wants two replacements he puts his two discards in a box under his own lock and takes two more from the deck.
The audit is the elegant part. After the hand, Bob wants to check that Alice really discarded three cards, rather than playing with eight. He puts his lock on her discard box and sends it back; Alice removes hers. His lock is still on, so she cannot alter the contents, and he can now open it and count.
So the protocol is verifiable after the fact even though nothing was visible during play — which is the same shape as Chapter 16's double-spending detection: anonymity while the rules are followed, and evidence the moment they are not.
Figure (svg): The commutative locks metaphor: Bob locks 52 boxes, Alice adds her locks to five, and each removes their own in either order.
Socratic
The protocol prevents reading the other's hand, dealing twice, and choosing your own cards.
Discussion prompt
Name two weaknesses that remain, and say what they come from.
Hint: One is about the encryption, one is about the game.
Answer:
The encryption leaks quadratic residuosity. Under exponentiation mod p, whether m^a is a quadratic residue is determined by whether m is — because a is odd, being coprime to p−1. So a player can tell which encrypted values are residues, which partitions the deck into two known halves and leaks real information about the cards.
The fix is to encode the cards so that all 52 values are residues, or to use a group where the leak does not exist. This was a genuine flaw in the original Shamir-Rivest-Adleman mental poker scheme, found soon after publication.
And the abort problem remains. A player holding a losing hand can disconnect before the reveal, exactly as in the coin flip. No two-party protocol prevents it.
Plus collusion in the multi-player case: the two-party protocol generalises, but three players of whom two collude can share what they see, and nothing in the cryptography detects it.
The general lesson, and it is Chapter 14's: a protocol that provably prevents the attacks it was designed against may still leak through a property of the primitive that nobody was thinking about. Here it was a Legendre symbol.
Anomaly
Cards are encrypted as m^a mod p, with a coprime to p−1.
Predict first
What can a player determine about an encrypted card without decrypting it?
Correct: Whether the underlying card value is a quadratic residue mod p
How much this leaks depends on the encoding. If the 52 card values split evenly, each encrypted card is narrowed to 26 possibilities before any other information — which is a serious advantage in poker.
The fix is to choose the 52 representatives to all lie in the same class, so the symbol carries no information. It is a small change and it was not in the original scheme.
This is a good example of a leak nobody designed in. The commutativity was the property being used; the residue behaviour came along with the choice of group, and it took separate analysis to notice.
Why: a is coprime to p−1 and therefore odd, so m^a is a quadratic residue exactly when m is. The Legendre symbol of the ciphertext equals that of the plaintext, and Section 3.10's Euler criterion computes it in one exponentiation. So the deck splits into two publicly identifiable halves, and a player learns which half each card is in.
Worked example
One card through the whole protocol, with numbers small enough to check.
Fix p = 47, so exponents live mod 46. Bob's key is b = 7 and Alice's is a = 5
Why: gcd(7, 46) = gcd(5, 46) = 1, so both are invertible: 7⁻¹ = 33 and 5⁻¹ = 37 modulo 46.
The card is encoded as m = 10. Bob encrypts: 10⁷ ≡ 45 (mod 47)
Why: He does this to all 52 cards and shuffles the results before sending them.
Alice picks it and adds her layer: 45⁵ ≡ 15 (mod 47)
Why: 15 is now m^(ab) = 10³⁵.
Bob strips his layer: 15³³ ≡ 31 (mod 47)
Why: And 31 = 10⁵ = m^a — the card under Alice's lock alone. Bob has removed his own encryption without seeing the card.
Alice strips hers: 31³⁷ ≡ 10 (mod 47)
Why: Her card. Bob never learned it, and Alice never saw the other 51.
Verify: the order genuinely did not matter
Why: Encrypting the other way round, 10⁵ ≡ 31 and 31⁷ ≡ 15 — the same doubly-encrypted value. That equality is the entire protocol.
Figure (svg): A single card travelling through both encryption layers and back out, with the actual numbers modulo 47.
Concept
The protocol encrypts card values, so the cards need a numeric encoding, and the choice matters more than it looks.
The naive encoding is 1 through 52, or a short string like AH, 2H, ... padded to a fixed length and read as an integer. Either works arithmetically.
But the encoding determines what leaks. Under exponentiation mod p, the Legendre symbol of a card survives encryption, so if the 52 values split between residues and non-residues, that split is visible on the encrypted deck.
So the encoding must be chosen deliberately: pick 52 values that are all quadratic residues mod p. They are easy to find — square anything — and the symbol then carries no information at all.
The card values must also be public and agreed in advance, so that when a hand is revealed both parties can check that each claimed card really is one of the 52. Otherwise a player could claim to hold a value that was never in the deck.
Figure (svg): The deck splitting into quadratic residues and non-residues, a division that survives encryption and is publicly computable.
Worked example
Worth doing explicitly, because the argument is three lines and the consequence is severe.
gcd(a, p−1) = 1 and p−1 is even, so a is odd
Why: Every valid key exponent is odd. There is no way to choose an even one.
The Legendre symbol is multiplicative, so (mᵃ | p) = (m | p)ᵃ
Why: And since a is odd, (m | p)ᵃ = (m | p) — the symbol is ±1 and an odd power leaves it unchanged.
Concretely, mod 47: 10 is a non-residue, since 10²³ ≡ 46 ≡ −1
Why: And 10⁵ = 31, with 31²³ ≡ −1 as well. Encryption did not move it across the divide.
This was a real flaw in the original Shamir-Rivest-Adleman scheme, found shortly after publication — and it is the clearest illustration in the book of Chapter 14's lesson that a primitive leaks through properties nobody was designing with.
Verify: so anyone can partition the encrypted deck into two halves in one exponentiation per card
Why: Euler's criterion from Section 3.10, applied 52 times. If the encoding splits the deck evenly, every card is narrowed from 52 possibilities to 26 before a single bet is placed.
Figure (svg): The deck splitting into quadratic residues and non-residues, a division that survives encryption and is publicly computable.
Explain it to yourself
Bob encrypts all 52 cards and shuffles them. Suppose he skipped the shuffle and sent them in order.
Discussion prompt
Explain what Alice could then do, and which requirement it violates.
Hint: The encryption hides the values. The positions are a separate channel.
Answer:
Alice would know the position of every card, because the encryption is deterministic and the order is the standard deck order. Position 1 is the ace of hearts whether or not she can read it.
So she would choose her own hand, violating the third requirement. She could take the four aces without ever decrypting anything.
The encryption and the shuffle are doing different jobs. Encryption hides the values; the shuffle destroys the correspondence between position and value. Neither substitutes for the other.
Note also that the encryption must be deterministic here — the same card must always give the same ciphertext, or Bob could not strip layers consistently. Determinism is usually a weakness, and it is exactly what forces the shuffle to carry the whole burden of hiding the ordering.
The same pairing appears in mix networks and in Chapter 16's blind signatures: hiding content is one problem and hiding correspondence is another, and a protocol that solves only one of them is usually broken by the other.
Figure (svg): The mental poker deal: Bob encrypts and shuffles the deck, Alice double-encrypts her chosen cards, and each strips their own layer.
Prediction
Predict first
Who can turn it into m^a?
Correct: Only Bob, by raising it to b⁻¹ mod p−1
And it is why the two layers must be applied by different parties. If Alice held both exponents there would be no protocol; the security comes from each party controlling exactly one lock.
Note what Bob does see: he sees m^(ab) going in and m^a coming out, and both are meaningless to him. He learns that Alice selected this encrypted card, but since he shuffled, that tells him nothing about which card it is.
Why: Stripping the b layer needs b⁻¹, which only Bob has. He applies it to get m^(ab·b⁻¹) = m^a, and the card remains under Alice's lock throughout — he never sees m. That asymmetry is what lets him participate in the deal without learning the hand.
Notation
One equation is the whole of mental poker, and it is worth reading carefully.
Annotate
On: \( E_A\bigl(E_B(m)\bigr) = E_B\bigl(E_A(m)\bigr) \)
A recurring shape in this course: the property that makes a construction possible is the property an attacker works with. RSA's multiplicativity gave blind signatures and a forgery; here commutativity gives poker and a leak.
Explain it to yourself
Alice knows p and q, so she can compute anything she wants about y.
Discussion prompt
Explain precisely what she cannot compute, and why that specific ignorance makes the flip fair.
Hint: She has complete information about y and incomplete information about Bob.
Answer:
She can compute all four roots of y, and she does — the protocol requires it. What she cannot compute is which one Bob started from.
Because y determines the four roots and nothing more. Bob's x is one of them, and every root produces the same y, so y carries no information about which was squared.
This is information-theoretic, not computational. It is not that finding x is hard; it is that x is genuinely not determined by what she has. Even with unlimited computing power she would be guessing between two pairs.
Which is why the flip is exactly fair rather than approximately so. Her probability of picking Bob's pair is 1/2 on the nose, and no strategy improves it.
Compare Chapter 17's shares and Chapter 4's pad: the same shape of argument, and the same strength of conclusion. Whenever a protocol's fairness rests on an ignorance that is provably absolute rather than merely expensive, the guarantee is of the strongest available kind.
Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.
Two truths and a lie
Two of these claim more than it delivers.
Eliminate the wrong options
Which statement is correct?
Survives elimination: a
Why: The protocol has two guarantees resting on two different foundations, which is unusual and worth noticing. Alice's fairness is unconditional; Bob's honesty is computational. And neither addresses availability — a party who dislikes the result can always leave, which is a limitation of the setting rather than of the construction.
Matching
Every step of the two protocols is there to stop something specific.
Match the pairs
Why: Four steps, four specific cheats, and each defence is minimal — nothing in either protocol is decoration. The third is the subtlest: putting a second lock on a box before returning it is what makes the contents unalterable while still being returnable, and the same trick appears in fair-exchange protocols generally.
Real world
Coin flipping and poker sound like toys. The primitives are deployed.
Discussion prompt
Name three real settings where mutually distrusting parties must generate a fair random value or deal without a dealer.
Hint: Gambling, blockchains, and cryptographic protocol setup.
Answer:
Online gambling and card games. A player cannot verify a server's shuffle, so provably fair schemes have the server commit to a seed, the player contribute randomness, and the combination determine the deal — commit-reveal, which is Section 10.3's bit commitment doing coin flipping.
Blockchain randomness. Lotteries, NFT distribution and validator selection all need a random value nobody can bias, on a public ledger where every input is visible. Commit-reveal is the standard construction, and its abort problem is handled by forfeiting a deposit.
Distributed key generation. When several parties must jointly create a key that none of them knows, they run essentially a multiparty coin flip — this is what makes threshold cryptography possible without a trusted dealer, and it is the answer to Chapter 17's 'who generates the polynomial' problem.
And trusted setup ceremonies, where participants contribute randomness that must be destroyed, and the setup is secure if any one participant was honest. Chapter 16's discarded exponents, done as a protocol.
The common requirement: a value that is random, verifiable, and produced by parties who each want to influence it. That is precisely what this chapter's two protocols are for.
Error analysis
From an online game's fairness documentation.
Annotate
Four problems, and the first alone makes the scheme worthless. The fix is a long seed, a player contribution combined into the result, and no retries.
Trade off
The book's square-root protocol and Section 10.3's commitment approach solve the same problem. Fill the blanks.
Comparison matrix
| Square roots mod n | Commit-reveal | |
|---|---|---|
| Randomness comes from | Alice's ignorance of which root Bob used | both parties' contributions combined |
| Fairness for the chooser | information-theoretic | computational — rests on the commitment hiding |
| Honesty of the announcer | computational — a false claim needs a factorisation | computational — opening needs the committed value |
| Cost | modular square roots and a gcd | two hash computations |
| Abort problem | present | present — it is inherent to two parties |
The commit-reveal version is cheaper and is what is deployed. The square-root version is more interesting, because half its guarantee is unconditional and because it makes the winner's claim self-certifying.
Discrimination
Commutative encryption is a strong requirement and only some constructions need it.
Sort into buckets
Sort each protocol.
Edge cases
The protocol as described is for two people. Poker usually has more.
Discussion prompt
Does it generalise, and what breaks as the number of players grows?
Hint: Consider the layers, the message count, and collusion.
Answer:
It generalises directly. Each of k players encrypts the whole deck with their own key and shuffles, so the deck ends up under k commuting layers. To deal a card, every player except the recipient strips their layer.
The cost grows. Each deal needs a message to and from every other player, so a hand costs O(k²) messages — fine for a table of five and unattractive at scale.
Collusion is the real problem. Two players who share what they see between them learn far more than either alone, and nothing in the protocol detects it. With k players, any k−1 colluding know every card.
And the abort problem gets worse, because any one of k players can stall the deal, and identifying which one is deliberately stalling is itself a protocol problem.
Which is why the general form of this problem has its own name: secure multiparty computation. It asks how k parties can compute a function of their private inputs revealing nothing but the output, and mental poker is one of its founding examples. The collusion threshold — how many can conspire — is a parameter of every such protocol, exactly as t is in Chapter 17.
Faded example
Six steps, four blanks.
Fill in the blanks
Bob encrypts all 52 cards with his key and shuffles them. Alice picks five and adds her own encryption. Bob strips his layer and returns them. Alice strips hers and reads her hand. The whole thing works because the two encryptions commute.
Why: The shuffle is what stops Alice choosing her own cards — without it she would know which encrypted value was which. And the commutativity is what lets Bob remove his layer from underneath hers, which is the step that has no analogue with an ordinary block cipher.
Estimation
Two players, five cards each, and three discards for Alice.
Predict first
Roughly how many protocol messages does one hand take?
Correct: About 10
The computational cost is more notable: each card is a modular exponentiation, and the deck is encrypted 52 times per player per hand. For a large prime that is a few thousand exponentiations, which was significant in 1979 and is negligible now.
Note also that the protocol is interactive — no step can be precomputed, because each depends on the other party's response. That interactivity is what makes it robust and what makes it vulnerable to aborts.
Why: The deck goes across once, Alice's five go over and back, Bob's five go across, and each discard round costs another two or three exchanges — a total in the region of ten messages. That is entirely practical, which is why the protocol is a real construction rather than a thought experiment. The cost grows quadratically only when the number of players does.
Explain it
An observer wants to know why the protocol is fair, without following the number theory.
Discussion prompt
Explain both halves of the fairness in terms they can check.
Hint: Use the metaphor of a locked box with four keys.
Answer:
Bob's side first: Bob picks a secret and gives Alice a scrambled version. Because of how the scrambling works, that version could have come from any of four secrets, in two matched pairs — and Alice can work out all four but not which pair Bob's came from.
So Alice's guess is a genuine coin. She picks a pair, and she is right half the time, no matter how clever she is. That half is not an estimate; it is exact.
Alice's side: if Bob loses, he could simply lie about it. But losing means Alice sent him a secret from the other pair — and holding two secrets from different pairs lets him work out something he otherwise could not: the two large primes hidden in Alice's number.
So Bob must show those primes to claim a win, and Alice checks them in a second. He can only produce them when he genuinely won.
The one thing to warn the observer about: neither of these stops Bob simply hanging up when he sees he lost. No protocol between two people can, which is why real systems add a stake that is forfeited by whoever walks away.
Commit first
An online poker site implements mental poker correctly between all players, with no server holding the deck.
Predict first
What is the realistic attack?
Correct: Collusion between players sharing their hands over a side channel
The countermeasures are all statistical and behavioural: detecting improbable fold patterns, correlating IP addresses and play times, and limiting table selection. None of it is cryptography.
Which is this chapter's version of the recurring lesson. The protocol secures the information channel it defines, and an adversary who has another channel is outside its model entirely. Chapter 1's threat-model question — what can the adversary do — is what decides whether a protocol is relevant, and here the answer includes 'talk on the phone'.
Why: The cryptography prevents a player from reading another's cards through the protocol. It does nothing about two players in the same room, or on a voice call, telling each other what they hold — and collusion is the dominant form of cheating in online poker precisely because no protocol addresses it.
Cost model
The coin flip's two halves rest on different foundations, and the difference is worth stating precisely.
Annotate
On: \( \Pr[\text{Alice picks Bob's pair}] = \tfrac{1}{2} \quad \text{(unconditional)}, \qquad \Pr[\text{Bob forges a win}] \approx \Pr[\text{factoring } n] \quad \text{(computational)} \)
Being able to say which half of a guarantee is unconditional is worth the effort: it is what lets you predict how a system ages.
Missing information
Online gambling sites advertise provably fair shuffling.
Discussion prompt
List what the phrase leaves undetermined.
Hint: The proof covers one step of a longer process.
Answer:
Whose randomness is combined? If only the operator contributes, the operator chooses the outcome whatever is published afterwards. A player contribution, supplied after the commitment, is essential.
How large is the committed value? A commitment to a small seed is enumerable, so the commitment hides nothing — Chapter 11's trap.
Can the operator abort selectively? Retrying on an unfavourable result, under any pretext, converts a fair scheme into a chosen one.
Is the ordering enforced? The commitment must precede the player's input, and the player's input must precede the reveal. If any step can be reordered, the guarantee evaporates.
What is actually being proved? Usually only that the published outcome matches the published seed — which says nothing about how the seed was chosen or whether the operator ran the protocol many times and reported one.
And collusion is entirely outside it. The strongest possible shuffle protocol does nothing about two players sharing hands.
Ranking
Five things that can go wrong.
Put in order
Why: The residue leak halves the uncertainty about each card — real, and short of total. Aborting is disruptive and detectable, and denies the aborter any winnings. Collusion between two players in a heads-up game means one party sees everything, which is complete. A non-coprime exponent means the encryption is not invertible and the hand cannot be dealt at all — a correctness failure that stops play. And a 64-bit prime means discrete logs are computable, so every card is readable by anyone. The ordering runs from partial information to total exposure.
Constraint
A hundred participants, a public blockchain where every message is visible, and no trusted party. One winner must be chosen at random.
Discussion prompt
Design it, and address the abort problem explicitly.
Hint: Commit-reveal, plus something that makes aborting costly.
Answer:
Commit phase: each participant publishes a hash of a large random value together with a deposit. The commitment must be to at least 128 bits, or others enumerate it.
Reveal phase: after all commitments are in, each participant publishes their value. Anyone can check it against the published hash.
Combine: the winner is determined by the XOR or the hash of all revealed values. Every participant contributes, so no one party controls the result — and a participant who wants a particular outcome would have to control everyone else's contribution.
The abort problem, addressed directly: a participant who sees the emerging result and dislikes it can refuse to reveal, changing the outcome. So the deposit is forfeited on non-reveal, and the protocol proceeds without that participant. Aborting now costs money and gains only a re-roll.
And the ordering must be enforced by the ledger, which it is: no reveal is accepted until every commitment is recorded, and the block structure makes the ordering verifiable by everyone.
Note what the ledger provided — a broadcast channel with agreed ordering and the ability to hold a deposit. Those three things are what turn a two-party protocol with an unavoidable abort problem into a many-party protocol where aborting is merely expensive.
Concept
Both protocols in this chapter are instances of one question, and naming it is worth doing before Chapter 19.
k parties each hold a private input x₁, ..., x_k. They want to learn f(x₁, ..., x_k) and nothing else. No trusted party, and any coalition below some threshold may be trying to cheat.
A general result says any computable f can be done this way, with security against a coalition of fewer than half the parties. The construction is far more expensive than a special-purpose protocol, which is why chapters like this one exist: a bespoke protocol for a specific f is usually orders of magnitude cheaper.
And two limitations survive the generalisation, both met already: aborts cannot be prevented without an external mechanism, and a coalition above the threshold sees everything.
Figure (svg): Secure multiparty computation: several private inputs entering a protocol that emits only the agreed output.
Socratic
Both protocols are advertised as needing no trusted party.
Discussion prompt
What must each party still trust, and what is genuinely eliminated?
Hint: Distinguish trusting a person from trusting an assumption.
Answer:
What is eliminated: trusting the counterparty's honesty. Bob cannot lie about the flip and Alice cannot choose her cards, whatever they intend. That is the real achievement, and it is what 'no trusted party' means.
What remains: trust in the mathematics. Bob's honesty rests on factoring being hard, and mental poker's secrecy rests on discrete logs being hard. Neither is proved, and both would fail on a large quantum computer — Chapter 25's subject.
Trust in the implementation. A biased random number generator on either side undermines everything, exactly as in Chapter 5. Alice's primes and Bob's x must be genuinely unpredictable.
Trust that the model matches reality. Nothing prevents two poker players from talking on the phone, and nothing prevents an abort. Both are outside what the protocol models.
So the accurate claim is narrow and still valuable: within the channel the protocol defines, and under standard hardness assumptions, neither party can gain by deviating. That is a great deal more than the two-headed penny offered, and a great deal less than 'the game is fair'.
Definition probe
This chapter's guarantees do not all rest on the same thing, and the difference predicts how each ages.
Sort into buckets
Sort each claim.
Concept
The next chapter is about proving you know something without revealing it, and two ideas from here go straight into it.
Square roots mod n reappear as the Feige-Fiat-Shamir scheme. Peggy proves she knows a square root of a public value, by a protocol that is recognisably the coin flip run backwards: Victor issues a random challenge, and Peggy can answer both possible challenges only if she really holds the root.
And the idea of a hard problem as evidence carries over intact. In this chapter Bob's ability to factor n proved he had won. In the next, Peggy's ability to answer proves she holds a secret — the possession of a solution to a hard problem, used as a claim that can be checked.
What changes is the goal. Here the protocols produce a result — a coin, a hand. There they produce a conviction: Victor becomes certain, and learns nothing he could not have made up himself. That last clause is the whole content of the word 'zero-knowledge'.
Figure (svg): Secure multiparty computation: several private inputs entering a protocol that emits only the agreed output.
Pattern
Every earlier chapter put the adversary outside the conversation. These two put her inside it, and that changes the design questions.
The general form of this problem is secure multiparty computation, and mental poker is one of its founding examples: k parties compute a function of their private inputs and learn nothing but the output. The collusion threshold is a parameter, exactly as t is in Chapter 17.
Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.
Trap
The trap. Mental poker provably prevents reading another player's hand, dealing a card twice, or choosing your own cards. Every cheat available in a face-to-face game is eliminated. So an online game running this protocol is at least as fair as a physical one.
The premise is accurate — every one of those cheats really is prevented — and the conclusion does not follow.
Collusion is untouched. Two players sharing their hands over a phone call see everything the protocol was designed to hide, and no cryptographic step detects it. In online poker this is the dominant form of cheating, and it is entirely outside the model.
Aborts are untouched. A player dealt a bad hand disconnects, and no two-party protocol can prevent it — a result that holds regardless of how good the cryptography is.
And the primitive leaked anyway. The residue property of exponentiation partitions the deck into two publicly identifiable halves, which nobody designed in and which took separate analysis to find. Chapter 14's lesson, in a chapter about games.
The accurate claim is narrow: the protocol prevents the specific cheats it models, assuming both parties complete it and neither has a channel outside it. Both provisos are doing real work.
The habit: after establishing what a protocol prevents, ask what channels the adversary has that the model does not mention. In this chapter the answer is a telephone, and it defeats everything.
Check
Work it out before you click.
Check your understanding
In the coin-flip protocol, what makes the outcome unpredictable to Alice?
Answer: B
Why: Alice computes all four roots, so she is not short of computation — she is short of information. y is produced identically by all four roots, so it carries nothing about which was squared. Her ignorance is information-theoretic, which is why the flip is exactly fair rather than approximately so.
Check
Consider what mental poker needs from its encryption.
Check your understanding
Why can AES not be used for the locked-box protocol?
Answer: B
Why: The protocol requires E_A(E_B(m)) = E_B(E_A(m)), so that a layer can be stripped regardless of the order it was applied in. Block ciphers are deliberately designed so that composing two keys gives something unrelated to either — Chapter 6's discussion of double encryption depends on exactly that non-commutativity.
Check
Consider what happens when a party stops responding.
Check your understanding
Bob sees that he has lost the coin flip and stops replying. What can Alice do?
Answer: B
Why: The outcome depends on x, which only Bob knows, so Alice cannot determine or prove it alone — and she cannot distinguish a sulking Bob from a dropped connection. Fairness against aborts is impossible for two parties without an external mechanism: an adjudicator, a forfeited deposit, or a ledger that records the state.
Connect it up
Both are short, and writing them down is the fastest way to see what each step is for.
Draw it
Write the coin flip in five steps, marking beside each which party it protects and against what. Then write the poker deal in six, marking where the shuffle prevents Alice choosing her cards and where commutativity is required. Beside both, note which guarantees are unconditional and which are computational. Finish with the abort problem stated in one sentence and the three external mechanisms that address it.
The unconditional-versus-computational annotation is the one worth keeping: it is unusual for a single protocol to contain both, and knowing which is which tells you how it ages.
Exit ticket
One question, about what makes these protocols different from the previous seventeen chapters.
Predict first
What is structurally new about the protocols in this chapter?
Correct: The counterparty is the adversary, so each step must protect one party from the other rather than both from an outsider
Why: Every earlier chapter placed Eve outside the conversation, with Alice and Bob cooperating. Here Alice and Bob each want to cheat the other, so there is no shared interest to appeal to and every step must be justified from both sides. That is why the protocols look so asymmetric — Alice's protections and Bob's are entirely different mechanisms — and it is the setting that generalises into secure multiparty computation.
Recap
Two short protocols with a new adversary model.
Chapter 19 next. Zero-knowledge techniques, where Peggy proves to Victor that she knows a secret while revealing nothing about it — and the Feige-Fiat-Shamir scheme, which uses the same square roots mod n that decided the coin flip.
Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.