Chapter 18: Games

Chapter 18 of Trappe & Washington: flipping a coin over the telephone using the four square roots of a square modulo pq, where Alice's fairness is information-theoretic and Bob's honesty rests on factoring; and mental poker dealt with no dealer, built from commutative encryption by exponentiation, including the discard audit that works by adding a second lock. Covers both protocols' limitations — the quadratic residue leak and the abort problem that no two-party protocol can solve.

Subject: Cryptography · 61 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Games

Title

Cryptography · Chapter 18

Flipping a coin and playing poker over the telephone, between two people who expect each other to cheat

2. What you will be able to do

Objectives

Two protocols with a new flavour. Until now the adversary was outside the conversation; here the counterparty is the adversary, and the protocol must protect each party from the other.

Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.

Two different mechanisms for two different cheats — indistinguishability on one side, a hard problem on the other.

3. Why is flipping a coin over the phone hard?

Warm-up

The book's story: a friend leaves Alice and Bob a car. Bob offers to flip a coin, Alice calls tails, and Bob says it was heads. He is telling the truth — as soon as she called, he produced his two-headed penny so he would not have to lie.

Discussion prompt

State precisely what a fair coin flip over a distance requires.

Hint: There are two separate cheats to prevent, and they are prevented differently.

Answer:

The flipper must not be able to choose the outcome after hearing the call. Bob's two-headed penny is exactly this: he waited to see what Alice said.

And the caller must not be able to learn the outcome before calling. Otherwise Alice cheats instead of Bob.

So the requirement is simultaneity, over a channel that cannot deliver anything simultaneously. The two acts — committing to an outcome and committing to a call — must be locked in before either is revealed.

Which is bit commitment, from Section 10.3. Alice commits, Bob announces, Alice opens. The protocol in this chapter achieves the same thing by a different route, and both are answers to the same structural problem: manufacturing simultaneity out of sequence.

4. Flipping Coins over the Telephone

Section

Section 18.1 · pp. 349-351

5. Square Roots Mod n: four roots, two pairs

Concept

The protocol rests entirely on one fact from Section 3.9, so it is worth restating before the protocol uses it.

Modulo a prime p, a square has two square roots, ±r, and no more — a polynomial of degree 2 over a field has at most two roots.

Modulo n = pq, the Chinese Remainder Theorem splits the problem in two. A square root mod n corresponds to a choice of square root mod p and a square root mod q, independently.

\[ 2 \text{ choices mod } p \;\times\; 2 \text{ choices mod } q \;=\; 4 \text{ square roots mod } n \]

The four group into two ± pairs, because negating both components at once gives the negative mod n. The two pairs differ by negating only one component, and that is what makes them useful: two roots from different pairs are congruent mod one prime and negatives mod the other, so their difference is divisible by exactly one prime.

Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.

The randomness of the flip is exactly Alice's ignorance of which pair Bob's x came from — and that ignorance is provable.

6. Finding the four roots of 15 modulo 77

Worked example

Small enough to check by hand, and it shows every feature the protocol uses.

n = 77 = 7 · 11, and both primes are ≡ 3 (mod 4)

Why: 7 = 4·1 + 3 and 11 = 4·2 + 3, exactly as the protocol requires.

Mod 7: 15 ≡ 1, whose square roots are ±1

Why: By the formula, 15^((7+1)/4) = 15² ≡ 1 (mod 7).

Mod 11: 15 ≡ 4, whose square roots are ±2

Why: And 15^((11+1)/4) = 15³ ≡ 9 ≡ −2 (mod 11), which is one of them.

Combine the four sign choices by CRT

Why: (1, 2) → 57, (1, −2) → 64, (−1, 2) → 13, (−1, −2) → 20.

rootmod 7mod 11pair
13−12±13 = {13, 64}
641−2±13
20−1−2±20 = {20, 57}
5712±20

Verify: two roots from different pairs factor n

Why: gcd(13 − 20, 77) = gcd(7, 77) = 7. Two roots from the same pair give gcd(13 − 64, 77) = gcd(51, 77) = 1 and gcd(13 + 64, 77) = 77 — both useless, which is precisely why Bob learns nothing when he wins.

Figure (svg): The four square roots of 15 modulo 77, grouped into two plus-or-minus pairs, with a gcd across the pairs factoring 77.

The whole coin flip in one picture: two pairs, a random choice between them, and a factorisation waiting across the gap.

7. Why p and q are chosen ≡ 3 (mod 4)

Notation

The congruence condition looks arbitrary. It is a computational convenience with a one-line justification.

Annotate

On: \( r \equiv y^{(p+1)/4} \pmod p \)

  • r² = y^((p+1)/2) = y · y^((p−1)/2), and Euler's criterion says y^((p−1)/2) = 1 when y is a quadratic residue. So r² ≡ y.
  • Exactly when p ≡ 3 (mod 4), so p + 1 is divisible by 4. This is the whole reason for the condition.
  • No closed form. Square roots need the Tonelli-Shanks algorithm, which is still polynomial time but is a loop rather than one exponentiation.
  • Only someone who knows p. Alice does; Bob has only n, and taking square roots mod n without the factorisation is as hard as factoring.
  • Rabin encryption and Blum integers use it for the same reason, and Blum-Blum-Shub's generator in Chapter 5 needs p ≡ q ≡ 3 (mod 4) as well.

A condition that costs nothing — such primes are half of all primes — and turns Alice's step into a single modular exponentiation.

Figure (svg): The closed-form square root formula available when a prime is congruent to 3 modulo 4.

The congruence condition on p and q is not decoration — it is what makes Alice's step a single exponentiation.

8. How many roots modulo a product of three primes?

Prediction

Predict first

How many square roots would a square have mod n?

  • Two
  • Four
  • Six
  • Eight

Correct: Eight

Which is a useful sanity check on why n has exactly two prime factors. The fairness of the coin is 1/k where k is the number of ± pairs, so two primes is the only choice giving an even flip.

And it shows how to build a biased coin deliberately. If Alice and Bob wanted a 1-in-4 event rather than 1-in-2, three primes would give it, and Bob could still verify the count by being shown the factorisation afterwards.

Bob would need to check that n really has only two factors, which he cannot do directly. In practice the protocol is run with Alice revealing p and q at the end of the round, so a three-prime n would be caught the first time she was asked to open it.

Why: CRT splits the problem into three independent binary choices, so 2³ = 8 roots. The protocol would still work — Alice would pick one of four ± pairs and Bob would win three times in four — but the flip would no longer be fair, since it would be biased 3:1 toward Bob.

9. What if Bob sends a y that is not a square?

Socratic

The protocol says Alice finds the four square roots of y. Bob might send a number with none.

Discussion prompt

What happens, and why is this the easiest cheat to catch?

Hint: Alice knows p and q, and Euler's criterion is one exponentiation.

Answer:

Alice discovers it immediately. She computes the Legendre symbols of y mod p and mod q, and y is a square mod n exactly when both are +1. One exponentiation each.

Only a quarter of the residues are squares mod pq, so a randomly chosen y is a square with probability 1/4 — a cheating Bob would be caught three times in four even if he were guessing.

What would he gain? If y has no root, Alice cannot produce one, so the flip cannot complete. It is a way of stalling, not of winning — a variant of the abort problem dressed up as arithmetic.

And the book's protocol handles it explicitly: Alice accuses Bob of cheating. That is the right response, because Bob computed y as x² and has no honest reason to send a non-square.

The general shape is worth noting: every step where one party supplies a value that the other can validate should be validated. Chapter 9's small-exponent and common-modulus attacks are all failures to check something checkable, and this is the same discipline applied to a protocol rather than a cryptosystem.

10. Coin Flipping from square roots

Concept

Alice's cryptologist suggests a protocol built on Section 3.9's fact that a square modulo pq has four square roots, in two ± pairs.

  1. Alice chooses two large primes p and q, both ≡ 3 (mod 4), keeps them secret, and sends n = pq to Bob
  2. Bob chooses a random x and computes y ≡ x² (mod n). He keeps x secret and sends y
  3. Alice, knowing p and q, finds all four square roots ±a, ±b of y. One of them is x, and she does not know which
  4. She chooses one at random — say b — and sends it. This is the flip
  5. If b ≡ ±x (mod n), Bob tells Alice she wins. Otherwise Bob wins

If y turns out to have no square root, Alice's calculation reveals that fact and she accuses Bob of cheating.

Figure (svg): The coin flip protocol: Bob squares a secret x, Alice finds all four roots and returns one, and whether it matches decides the flip.

Section 3.9's four square roots, used as a fair coin: Alice picks one of two ± pairs and cannot tell which Bob started from.

11. Where the randomness comes from

Worked example

The protocol has no coin and no random-number generator producing the outcome. The randomness is Alice's ignorance, and it is worth locating exactly.

Bob's x lies in one of the two ± pairs — either {+a, −a} or {+b, −b}

Why: He knows which, because x is his.

Alice computes all four roots from p and q, and they arrive with no labels

Why: Nothing about the arithmetic distinguishes the pair containing x from the other. Both pairs are equally consistent with everything she has seen.

So when she picks a pair, she is picking Bob's pair with probability exactly 1/2

Why: Not approximately, and not subject to any computation — the two pairs are symmetric from her position.

She sends one element of her chosen pair

Why: Whether it is +b or −b makes no difference: Bob checks against ±x, so the sign is irrelevant.

Verify: the outcome is a fair coin even though neither party flipped one

Why: Bob supplied the randomness (choosing x) and Alice supplied the unpredictability of the choice (not knowing which pair). Neither alone determines the result, which is exactly the simultaneity the warm-up asked for.

Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.

The randomness of the flip is exactly Alice's ignorance of which pair Bob's x came from — and that ignorance is provable.

12. Why Bob cannot lie

Concept

Bob declares the result, so he has an obvious opportunity to cheat: he could simply claim to have lost when he won. Alice's protection is that a false claim requires him to prove something he cannot.

Suppose Alice sends b and Bob's x was in the other pair, so b ≢ ±x. Then Bob knows both x and b — two square roots of y that are not negatives of each other.

\[ x^2 \equiv b^2 \pmod n, \quad x \not\equiv \pm b \;\Longrightarrow\; \gcd(x - b, \, n) \text{ is a factor of } n \]

So the winning case comes with a proof. Bob claims to have won by producing p and q, which Alice can verify instantly. And Section 3.9 established that producing them any other way requires factoring n, which is believed infeasible.

Conversely, if Alice sent ±x, Bob has learned nothing new — he already knew x — and cannot factor. So he can only produce the factorisation when he genuinely won, and the claim is self-certifying.

Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.

Two different mechanisms for two different cheats — indistinguishability on one side, a hard problem on the other.

13. Where else have you seen this construction?

Socratic

The protocol turns 'knowing two unrelated square roots' into a verifiable claim.

Discussion prompt

Name two earlier places in the course where the same fact appeared, and say what it was doing in each.

Hint: Section 3.9, and a cryptosystem with a proof RSA lacks.

Answer:

Section 3.9, as an attack. Being able to take square roots mod n was shown equivalent to factoring n — which is why a decryption oracle for a Rabin-style system is a factoring oracle, and why Chapter 9 forbids one.

The Rabin cryptosystem, where the equivalence is the point: breaking Rabin provably requires factoring, which is a stronger security statement than RSA has ever had.

And Section 10.3's bit commitment, which uses the same difficulty — Bob cannot compute discrete logs, so he cannot open Alice's commitment early.

Here the same fact is a fairness mechanism. The ability to factor is used as evidence: Bob can produce it exactly when he genuinely won, so his claim is self-certifying.

Which is the general observation worth taking: a hard problem is not only a wall. It can be a currency — something you can only possess under particular circumstances, and can therefore spend as proof that those circumstances hold. Zero-knowledge proofs in Chapter 19 are built entirely on this idea.

14. Who is protected against what?

Definition probe

Each step of the protocol defends one party against one specific cheat.

Sort into buckets

Sort each mechanism by whom it protects.

Protects Alice from Bob
Bob must produce p and q to claim a win; Alice checks that y actually has a square root
Protects Bob from Alice
Alice chooses one of four roots at random; Bob keeps x secret until the flip is announced
alice
Bob is the one who declares the outcome and the one who supplies y, so Alice needs protection against a false declaration and against a y with no roots at all. The factorisation requirement and the root check are her two defences.
bob
Alice knows p and q, so she could otherwise compute anything she liked. Her ignorance of which root Bob used is what stops her biasing the flip, and Bob keeping x secret is what preserves that ignorance.

15. What if Bob simply hangs up?

Anomaly

Alice sends her chosen root. Bob sees that he lost, and the line goes dead.

Predict first

Does the protocol prevent this?

  • Yes — Alice can prove the outcome from what she has
  • No — a party who dislikes the result can always abort, and no two-party protocol can prevent it
  • Yes, because Bob has already committed to x
  • No, but Alice can compute Bob's x and prove it

Correct: No — a party who dislikes the result can always abort, and no two-party protocol can prevent it

It is not a flaw in this construction. A general result says that fairness in the presence of aborts is impossible for two parties without additional assumptions — you cannot make both parties learn the outcome simultaneously over a sequential channel.

The practical answers all come from outside the cryptography: a trusted third party to adjudicate, a penalty deposit forfeited on abort, or a design where aborting is worse for the aborter than losing.

And it generalises to every protocol in this chapter and the next. A prover who is failing can stop; a poker player holding a bad hand can disconnect. Cryptography secures what is exchanged, not whether the exchange completes.

Why: Alice cannot tell whether Bob lost or genuinely disconnected, and she has no way to complete the protocol alone — the result depends on x, which only Bob knows. This is the abort problem, and it is a fundamental limitation: in a two-party protocol the last party to learn the outcome can always refuse to continue.

16. Bit commitment: the other way to flip a coin

Concept

Section 10.3's bit commitment solves the same simultaneity problem, and it is what real systems deploy.

  1. Alice picks her bit c and a long random r, and sends H(c ‖ r)
  2. Bob calls heads or tails
  3. Alice reveals c and r; Bob checks the hash

Hiding comes from H being one-way and r being long: Bob cannot recover c from the hash, so he calls blind. Binding comes from collision resistance: Alice cannot find a second (c′, r′) with the same hash, so she cannot change her mind.

Both properties are computational, unlike the square-root protocol's unconditional half. But the scheme costs two hash computations rather than a modular square root, and it composes: a fair value can be built from both parties' contributions by XORing Alice's revealed bit with Bob's call.

And r must be long. Committing to a bare bit means Bob hashes both possibilities and knows the answer — Chapter 11's low-entropy trap, and the single most common way this scheme is implemented wrongly.

Figure (svg): The commit-reveal coin flip: Alice commits to a bit, Bob calls it, Alice opens the commitment.

The same simultaneity problem, solved with a hash instead of a modulus — cheaper, and what is actually deployed.

17. Alice sends a number that is not a root

Anomaly

In the square-root protocol Alice sends one of the four roots. Suppose she sends something else entirely.

Predict first

What does Bob do?

  • He cannot detect it, since he does not know the roots
  • He squares it and checks against y — a one-multiplication test
  • He factors n to check
  • Nothing; the protocol assumes honesty here

Correct: He squares it and checks against y — a one-multiplication test

So both of the obvious protocol-level cheats are cheap to detect — Bob's non-square by Alice, and Alice's non-root by Bob. Neither party needs to trust the other about anything checkable.

What is left uncheckable is what makes the protocol interesting: Alice cannot check that Bob really squared a random x rather than reusing an old one, and Bob cannot check that Alice chose her root uniformly. Those are handled by the structure, not by verification.

Why: Bob knows y, so he squares whatever Alice sends and compares. A value that is not a root of y is caught with one multiplication. This is the same discipline as the previous slide: every supplied value that can be validated should be.

18. Complete the coin flip

Faded example

Five steps, four blanks.

Fill in the blanks

Alice sends n = pq with both primes ≡ 3 (mod 4). Bob picks a secret x and sends y = x² mod n. Alice computes all four square roots and returns one at random. If it is ±x, Alice wins; otherwise Bob wins and can prove it by factoring n.

Why: The 3 (mod 4) condition gives the closed-form square root; the four roots in two pairs give the fair coin; and the factorisation gives Bob's self-certifying claim. Every element of the protocol is doing one of those three jobs.

19. Sort what each party knows after the flip

Definition probe

Suppose Bob wins — Alice sent a root from the pair Bob's x was not in.

Sort into buckets

Sort each item by who ends up knowing it.

Both parties
The factorisation n = pq; Which root Alice chose
Only one party
The value of x; All four square roots of y
both
Alice knew the factorisation from the start; Bob computes it from the gcd once he holds two roots from different pairs — which is exactly the winning case. And the chosen root was sent in the clear, so both see it.
one
x is Bob's alone, and Alice never learns it — she cannot tell which of her four roots he squared. All four roots are Alice's alone unless Bob does the gcd and factors, at which point he could compute them too.

20. Poker over the Telephone

Section

Section 18.2 · pp. 351-355

21. The problem with dealing

Concept

Alice and Bob tire of coin flipping and try poker. Bob shuffles and deals — and Alice will not let him read the cards to her, and suspects he may not be playing with a full deck.

They try each choosing their own cards, and after several hundred coins have been wagered they discover they each have a royal flush. Each accuses the other of cheating.

So the requirements are:

  1. Each player's hand is dealt from a genuine 52-card deck, with no card dealt twice
  2. Neither player learns the other's hand
  3. Neither player can choose their own cards
  4. Everything can be verified afterwards, so cheating is detectable once the hand is over

And there is no dealer. That is what makes it a cryptographic problem rather than a procedural one.

Figure (svg): The commutative locks metaphor: Bob locks 52 boxes, Alice adds her locks to five, and each removes their own in either order.

The whole protocol is two locks that can be removed in either order — and exponentiation mod p has exactly that property.

22. Commutative Encryption and the locked boxes

Concept

The book gives the solution in non-mathematical terms first, and the metaphor is the clearest part of the chapter.

Bob takes 52 identical boxes, puts a card in each, puts a lock on each, dumps them in a bag and sends them to Alice.

Alice chooses five boxes, puts her own locks on them, and sends them back. Bob takes his locks off and returns them. Alice takes her locks off and finds her five cards.

Then she chooses five more boxes and sends them to Bob; he removes his locks and gets his hand.

The essential property is that the locks come off in either order. Bob's lock can be removed while Alice's is still on. Mathematically that is commutative encryption: E_A(E_B(m)) = E_B(E_A(m)), so decryption layers need not be stripped in reverse order.

Figure (svg): Commutative encryption by exponentiation: two exponents applied in either order give the same result.

Commutativity is the property; exponentiation modulo a prime is the cheapest thing that has it.

23. Why exponentiation is the right lock

Worked example

The metaphor needs a mathematical realisation, and exponentiation modulo a prime supplies it exactly.

Fix a large prime p. Alice's key is an exponent a with gcd(a, p−1) = 1; Bob's is b

Why: Coprimality to p−1 is what makes the exponent invertible mod p−1, so each lock can be removed — the affine cipher's condition, one more time.

Encrypting a card m is m ↦ m^a mod p, and decrypting is raising to a⁻¹ mod p−1

Why: Because (m^a)^(a⁻¹) = m^(aa⁻¹) = m^(1 + k(p−1)) ≡ m by Fermat.

Two encryptions compose as (m^b)^a = m^(ab) = (m^a)^b

Why: Exponents multiply, and multiplication commutes.

\[ E_A\bigl(E_B(m)\bigr) = m^{ab} = E_B\bigl(E_A(m)\bigr) \]

Verify: so Bob can strip his layer from a doubly-encrypted card, leaving Alice's layer intact

Why: Applying b⁻¹ to m^(ab) gives m^a, which is exactly the card under Alice's lock alone. The locks genuinely come off in any order, and this is the same identity that makes Diffie-Hellman work in Section 10.4.

Figure (svg): Commutative encryption by exponentiation: two exponents applied in either order give the same result.

Commutativity is the property; exponentiation modulo a prime is the cheapest thing that has it.

24. Dealing a hand of Mental Poker

Worked example

Following the boxes through, with the mathematics attached.

Bob encrypts all 52 card values with his key b and shuffles the results

Why: The shuffle is what stops Alice knowing which encrypted value is which card; the encryption is what stops her reading them.

Alice picks five, encrypts each with her key a, and returns them

Why: They are now m^(ab). Bob cannot tell which five she took, because they are under her lock as well as his.

Bob applies b⁻¹, returning m^a, and sends them back

Why: He has removed his layer without ever seeing the cards, since Alice's layer is still on.

Alice applies a⁻¹ and reads her hand

Why: Five cards, dealt fairly, with Bob knowing nothing about them.

Alice then chooses five more encrypted cards and sends them to Bob, who removes his own locks and reads his hand

Why: Symmetric, and Alice learns nothing about Bob's cards because she never applied her lock to them.

Verify: no card can be dealt twice, because each encrypted value is used once

Why: And neither player chose their own cards: Bob shuffled, so Alice's choice of position is uninformative, and Alice chose Bob's cards by position without being able to read them.

Figure (svg): The mental poker deal: Bob encrypts and shuffles the deck, Alice double-encrypts her chosen cards, and each strips their own layer.

Six messages and a fair deal with no dealer, from the single fact that the two encryptions commute.

25. Discards and the audit

Concept

Replacing cards works the same way. Alice puts three cards in a discard box, locks it, and sends it to Bob. She then chooses three of the remaining 42 encrypted cards, adds her locks, and Bob strips his — giving her three replacements.

If Bob wants two replacements he puts his two discards in a box under his own lock and takes two more from the deck.

The audit is the elegant part. After the hand, Bob wants to check that Alice really discarded three cards, rather than playing with eight. He puts his lock on her discard box and sends it back; Alice removes hers. His lock is still on, so she cannot alter the contents, and he can now open it and count.

So the protocol is verifiable after the fact even though nothing was visible during play — which is the same shape as Chapter 16's double-spending detection: anonymity while the rules are followed, and evidence the moment they are not.

Figure (svg): The commutative locks metaphor: Bob locks 52 boxes, Alice adds her locks to five, and each removes their own in either order.

The whole protocol is two locks that can be removed in either order — and exponentiation mod p has exactly that property.

26. What can still go wrong?

Socratic

The protocol prevents reading the other's hand, dealing twice, and choosing your own cards.

Discussion prompt

Name two weaknesses that remain, and say what they come from.

Hint: One is about the encryption, one is about the game.

Answer:

The encryption leaks quadratic residuosity. Under exponentiation mod p, whether m^a is a quadratic residue is determined by whether m is — because a is odd, being coprime to p−1. So a player can tell which encrypted values are residues, which partitions the deck into two known halves and leaks real information about the cards.

The fix is to encode the cards so that all 52 values are residues, or to use a group where the leak does not exist. This was a genuine flaw in the original Shamir-Rivest-Adleman mental poker scheme, found soon after publication.

And the abort problem remains. A player holding a losing hand can disconnect before the reveal, exactly as in the coin flip. No two-party protocol prevents it.

Plus collusion in the multi-player case: the two-party protocol generalises, but three players of whom two collude can share what they see, and nothing in the cryptography detects it.

The general lesson, and it is Chapter 14's: a protocol that provably prevents the attacks it was designed against may still leak through a property of the primitive that nobody was thinking about. Here it was a Legendre symbol.

27. The residue leak

Anomaly

Cards are encrypted as m^a mod p, with a coprime to p−1.

Predict first

What can a player determine about an encrypted card without decrypting it?

  • Nothing whatever
  • Whether the underlying card value is a quadratic residue mod p
  • The card's suit
  • The card's exact value

Correct: Whether the underlying card value is a quadratic residue mod p

How much this leaks depends on the encoding. If the 52 card values split evenly, each encrypted card is narrowed to 26 possibilities before any other information — which is a serious advantage in poker.

The fix is to choose the 52 representatives to all lie in the same class, so the symbol carries no information. It is a small change and it was not in the original scheme.

This is a good example of a leak nobody designed in. The commutativity was the property being used; the residue behaviour came along with the choice of group, and it took separate analysis to notice.

Why: a is coprime to p−1 and therefore odd, so m^a is a quadratic residue exactly when m is. The Legendre symbol of the ciphertext equals that of the plaintext, and Section 3.10's Euler criterion computes it in one exponentiation. So the deck splits into two publicly identifiable halves, and a player learns which half each card is in.

28. A hand dealt with p = 47

Worked example

One card through the whole protocol, with numbers small enough to check.

Fix p = 47, so exponents live mod 46. Bob's key is b = 7 and Alice's is a = 5

Why: gcd(7, 46) = gcd(5, 46) = 1, so both are invertible: 7⁻¹ = 33 and 5⁻¹ = 37 modulo 46.

The card is encoded as m = 10. Bob encrypts: 10⁷ ≡ 45 (mod 47)

Why: He does this to all 52 cards and shuffles the results before sending them.

Alice picks it and adds her layer: 45⁵ ≡ 15 (mod 47)

Why: 15 is now m^(ab) = 10³⁵.

Bob strips his layer: 15³³ ≡ 31 (mod 47)

Why: And 31 = 10⁵ = m^a — the card under Alice's lock alone. Bob has removed his own encryption without seeing the card.

Alice strips hers: 31³⁷ ≡ 10 (mod 47)

Why: Her card. Bob never learned it, and Alice never saw the other 51.

Verify: the order genuinely did not matter

Why: Encrypting the other way round, 10⁵ ≡ 31 and 31⁷ ≡ 15 — the same doubly-encrypted value. That equality is the entire protocol.

Figure (svg): A single card travelling through both encryption layers and back out, with the actual numbers modulo 47.

The middle step is the one the metaphor was built for: a lock removed from underneath another lock.

29. Encoding 52 cards as numbers

Concept

The protocol encrypts card values, so the cards need a numeric encoding, and the choice matters more than it looks.

The naive encoding is 1 through 52, or a short string like AH, 2H, ... padded to a fixed length and read as an integer. Either works arithmetically.

But the encoding determines what leaks. Under exponentiation mod p, the Legendre symbol of a card survives encryption, so if the 52 values split between residues and non-residues, that split is visible on the encrypted deck.

So the encoding must be chosen deliberately: pick 52 values that are all quadratic residues mod p. They are easy to find — square anything — and the symbol then carries no information at all.

The card values must also be public and agreed in advance, so that when a hand is revealed both parties can check that each claimed card really is one of the 52. Otherwise a player could claim to hold a value that was never in the deck.

Figure (svg): The deck splitting into quadratic residues and non-residues, a division that survives encryption and is publicly computable.

A leak nobody designed in: it came with the choice of group, and it took separate analysis to notice.

30. The residue leak, in numbers

Worked example

Worth doing explicitly, because the argument is three lines and the consequence is severe.

gcd(a, p−1) = 1 and p−1 is even, so a is odd

Why: Every valid key exponent is odd. There is no way to choose an even one.

The Legendre symbol is multiplicative, so (mᵃ | p) = (m | p)ᵃ

Why: And since a is odd, (m | p)ᵃ = (m | p) — the symbol is ±1 and an odd power leaves it unchanged.

Concretely, mod 47: 10 is a non-residue, since 10²³ ≡ 46 ≡ −1

Why: And 10⁵ = 31, with 31²³ ≡ −1 as well. Encryption did not move it across the divide.

This was a real flaw in the original Shamir-Rivest-Adleman scheme, found shortly after publication — and it is the clearest illustration in the book of Chapter 14's lesson that a primitive leaks through properties nobody was designing with.

Verify: so anyone can partition the encrypted deck into two halves in one exponentiation per card

Why: Euler's criterion from Section 3.10, applied 52 times. If the encoding splits the deck evenly, every card is narrowed from 52 possibilities to 26 before a single bet is placed.

Figure (svg): The deck splitting into quadratic residues and non-residues, a division that survives encryption and is publicly computable.

A leak nobody designed in: it came with the choice of group, and it took separate analysis to notice.

31. Why must Bob shuffle before sending?

Explain it to yourself

Bob encrypts all 52 cards and shuffles them. Suppose he skipped the shuffle and sent them in order.

Discussion prompt

Explain what Alice could then do, and which requirement it violates.

Hint: The encryption hides the values. The positions are a separate channel.

Answer:

Alice would know the position of every card, because the encryption is deterministic and the order is the standard deck order. Position 1 is the ace of hearts whether or not she can read it.

So she would choose her own hand, violating the third requirement. She could take the four aces without ever decrypting anything.

The encryption and the shuffle are doing different jobs. Encryption hides the values; the shuffle destroys the correspondence between position and value. Neither substitutes for the other.

Note also that the encryption must be deterministic here — the same card must always give the same ciphertext, or Bob could not strip layers consistently. Determinism is usually a weakness, and it is exactly what forces the shuffle to carry the whole burden of hiding the ordering.

The same pairing appears in mix networks and in Chapter 16's blind signatures: hiding content is one problem and hiding correspondence is another, and a protocol that solves only one of them is usually broken by the other.

Figure (svg): The mental poker deal: Bob encrypts and shuffles the deck, Alice double-encrypts her chosen cards, and each strips their own layer.

Six messages and a fair deal with no dealer, from the single fact that the two encryptions commute.

32. Who can strip a layer?

Prediction

Predict first

Who can turn it into m^a?

  • Either party
  • Only Bob, by raising it to b⁻¹ mod p−1
  • Only Alice
  • Neither, without both keys

Correct: Only Bob, by raising it to b⁻¹ mod p−1

And it is why the two layers must be applied by different parties. If Alice held both exponents there would be no protocol; the security comes from each party controlling exactly one lock.

Note what Bob does see: he sees m^(ab) going in and m^a coming out, and both are meaningless to him. He learns that Alice selected this encrypted card, but since he shuffled, that tells him nothing about which card it is.

Why: Stripping the b layer needs b⁻¹, which only Bob has. He applies it to get m^(ab·b⁻¹) = m^a, and the card remains under Alice's lock throughout — he never sees m. That asymmetry is what lets him participate in the deal without learning the hand.

33. Reading the commutativity requirement

Notation

One equation is the whole of mental poker, and it is worth reading carefully.

Annotate

On: \( E_A\bigl(E_B(m)\bigr) = E_B\bigl(E_A(m)\bigr) \)

  • Not merely that both are decryptable, but that they are the same value. That is what lets Bob remove his layer from underneath Alice's.
  • (m^b)^a = m^(ab) = (m^a)^b, because exponents multiply and multiplication is commutative. It is the same identity as Diffie-Hellman's.
  • Block ciphers are deliberately non-commutative — encrypting with two keys in different orders gives unrelated results. Chapter 6's meet-in-the-middle discussion depends on exactly that.
  • Exponents mod one n do commute — but sharing a modulus between two parties means each can compute the other's private exponent, which Chapter 9 flags as a fatal misuse.
  • Structure, and structure is exploitable. The residue leak on the previous slide is the price of choosing a group with a usable algebraic identity.

A recurring shape in this course: the property that makes a construction possible is the property an attacker works with. RSA's multiplicativity gave blind signatures and a forgery; here commutativity gives poker and a leak.

34. Why must Alice not know which root Bob used?

Explain it to yourself

Alice knows p and q, so she can compute anything she wants about y.

Discussion prompt

Explain precisely what she cannot compute, and why that specific ignorance makes the flip fair.

Hint: She has complete information about y and incomplete information about Bob.

Answer:

She can compute all four roots of y, and she does — the protocol requires it. What she cannot compute is which one Bob started from.

Because y determines the four roots and nothing more. Bob's x is one of them, and every root produces the same y, so y carries no information about which was squared.

This is information-theoretic, not computational. It is not that finding x is hard; it is that x is genuinely not determined by what she has. Even with unlimited computing power she would be guessing between two pairs.

Which is why the flip is exactly fair rather than approximately so. Her probability of picking Bob's pair is 1/2 on the nose, and no strategy improves it.

Compare Chapter 17's shares and Chapter 4's pad: the same shape of argument, and the same strength of conclusion. Whenever a protocol's fairness rests on an ignorance that is provably absolute rather than merely expensive, the guarantee is of the strongest available kind.

Figure (svg): The four square roots of y modulo pq, forming two plus-or-minus pairs, with Alice choosing one pair at random.

The randomness of the flip is exactly Alice's ignorance of which pair Bob's x came from — and that ignorance is provable.

35. What the coin flip protocol guarantees

Two truths and a lie

Two of these claim more than it delivers.

Eliminate the wrong options

Which statement is correct?

  • a. Neither party can bias the outcome, and a false claim of winning requires factoring n
  • b. The protocol guarantees both parties learn the outcome
  • c. The protocol is unconditionally secure

Survives elimination: a

Why: The protocol has two guarantees resting on two different foundations, which is unusual and worth noticing. Alice's fairness is unconditional; Bob's honesty is computational. And neither addresses availability — a party who dislikes the result can always leave, which is a limitation of the setting rather than of the construction.

36. Match each protocol element to what it prevents

Matching

Every step of the two protocols is there to stop something specific.

Match the pairs

  • l1. Bob shuffles the encrypted deck
  • l2. Alice adds her lock before Bob removes his
  • l3. Bob puts his lock on Alice's discard box
  • l4. Bob must produce p and q to claim the flip
  • r1. Alice choosing which cards she gets
  • r2. Bob learning which cards Alice took
  • r3. Alice altering her discards before the audit
  • r4. Bob lying about the outcome

Why: Four steps, four specific cheats, and each defence is minimal — nothing in either protocol is decoration. The third is the subtlest: putting a second lock on a box before returning it is what makes the contents unalterable while still being returnable, and the same trick appears in fair-exchange protocols generally.

37. Where these protocols actually matter

Real world

Coin flipping and poker sound like toys. The primitives are deployed.

Discussion prompt

Name three real settings where mutually distrusting parties must generate a fair random value or deal without a dealer.

Hint: Gambling, blockchains, and cryptographic protocol setup.

Answer:

Online gambling and card games. A player cannot verify a server's shuffle, so provably fair schemes have the server commit to a seed, the player contribute randomness, and the combination determine the deal — commit-reveal, which is Section 10.3's bit commitment doing coin flipping.

Blockchain randomness. Lotteries, NFT distribution and validator selection all need a random value nobody can bias, on a public ledger where every input is visible. Commit-reveal is the standard construction, and its abort problem is handled by forfeiting a deposit.

Distributed key generation. When several parties must jointly create a key that none of them knows, they run essentially a multiparty coin flip — this is what makes threshold cryptography possible without a trusted dealer, and it is the answer to Chapter 17's 'who generates the polynomial' problem.

And trusted setup ceremonies, where participants contribute randomness that must be destroyed, and the setup is secure if any one participant was honest. Chapter 16's discarded exponents, done as a protocol.

The common requirement: a value that is random, verifiable, and produced by parties who each want to influence it. That is precisely what this chapter's two protocols are for.

38. Find the problems in this coin-flip implementation

Error analysis

From an online game's fairness documentation.

Annotate

  • The commitment is a hash of one of 65 536 values, so the player computes all of them and knows the outcome before choosing. Hashing a low-entropy input is Chapter 11's trap, and here it removes the commitment entirely.
  • Even with a large seed, the server picks the value. A fair flip needs both parties to contribute — the standard fix is to combine the server's seed with a value the player supplies after the commitment.
  • A retry is a selective abort: the server aborts when it dislikes the result and calls it a network error. This is the abort problem being exploited rather than merely tolerated.
  • Better than most of the rest, but it means the server can search for a seed whose hash it likes if the commitment is ever computed after the seed is chosen — the ordering of the steps has to be enforced, not assumed.

Four problems, and the first alone makes the scheme worthless. The fix is a long seed, a player contribution combined into the result, and no retries.

39. Two ways to flip a coin

Trade off

The book's square-root protocol and Section 10.3's commitment approach solve the same problem. Fill the blanks.

Comparison matrix

Square roots mod nCommit-reveal
Randomness comes fromAlice's ignorance of which root Bob usedboth parties' contributions combined
Fairness for the chooserinformation-theoreticcomputational — rests on the commitment hiding
Honesty of the announcercomputational — a false claim needs a factorisationcomputational — opening needs the committed value
Costmodular square roots and a gcdtwo hash computations
Abort problempresentpresent — it is inherent to two parties

The commit-reveal version is cheaper and is what is deployed. The square-root version is more interesting, because half its guarantee is unconditional and because it makes the winner's claim self-certifying.

40. Which protocols need commutativity?

Discrimination

Commutative encryption is a strong requirement and only some constructions need it.

Sort into buckets

Sort each protocol.

Relies on operations commuting
Mental poker; Diffie-Hellman key exchange; A mix network shuffling encrypted ballots
Does not
The coin-flip protocol of Section 18.1; CBC-mode encryption
needs
All three rest on (m^a)^b = (m^b)^a. Poker needs layers removable in any order; Diffie-Hellman needs both parties to reach the same value from opposite directions; a mix network needs each server to remove its own layer regardless of position in the chain.
not
The coin flip uses square roots and a gcd, with no layered encryption at all. CBC is deliberately order-dependent — its whole purpose is chaining, and commutativity would destroy it.

41. How many players can play?

Edge cases

The protocol as described is for two people. Poker usually has more.

Discussion prompt

Does it generalise, and what breaks as the number of players grows?

Hint: Consider the layers, the message count, and collusion.

Answer:

It generalises directly. Each of k players encrypts the whole deck with their own key and shuffles, so the deck ends up under k commuting layers. To deal a card, every player except the recipient strips their layer.

The cost grows. Each deal needs a message to and from every other player, so a hand costs O(k²) messages — fine for a table of five and unattractive at scale.

Collusion is the real problem. Two players who share what they see between them learn far more than either alone, and nothing in the protocol detects it. With k players, any k−1 colluding know every card.

And the abort problem gets worse, because any one of k players can stall the deal, and identifying which one is deliberately stalling is itself a protocol problem.

Which is why the general form of this problem has its own name: secure multiparty computation. It asks how k parties can compute a function of their private inputs revealing nothing but the output, and mental poker is one of its founding examples. The collusion threshold — how many can conspire — is a parameter of every such protocol, exactly as t is in Chapter 17.

42. Complete the poker deal

Faded example

Six steps, four blanks.

Fill in the blanks

Bob encrypts all 52 cards with his key and shuffles them. Alice picks five and adds her own encryption. Bob strips his layer and returns them. Alice strips hers and reads her hand. The whole thing works because the two encryptions commute.

Why: The shuffle is what stops Alice choosing her own cards — without it she would know which encrypted value was which. And the commutativity is what lets Bob remove his layer from underneath hers, which is the step that has no analogue with an ordinary block cipher.

43. How many messages does a hand cost?

Estimation

Two players, five cards each, and three discards for Alice.

Predict first

Roughly how many protocol messages does one hand take?

  • About 4
  • About 10
  • About 50
  • About 500

Correct: About 10

The computational cost is more notable: each card is a modular exponentiation, and the deck is encrypted 52 times per player per hand. For a large prime that is a few thousand exponentiations, which was significant in 1979 and is negligible now.

Note also that the protocol is interactive — no step can be precomputed, because each depends on the other party's response. That interactivity is what makes it robust and what makes it vulnerable to aborts.

Why: The deck goes across once, Alice's five go over and back, Bob's five go across, and each discard round costs another two or three exchanges — a total in the region of ten messages. That is entirely practical, which is why the protocol is a real construction rather than a thought experiment. The cost grows quadratically only when the number of players does.

44. Explain the coin flip to someone who does not trust either party

Explain it

An observer wants to know why the protocol is fair, without following the number theory.

Discussion prompt

Explain both halves of the fairness in terms they can check.

Hint: Use the metaphor of a locked box with four keys.

Answer:

Bob's side first: Bob picks a secret and gives Alice a scrambled version. Because of how the scrambling works, that version could have come from any of four secrets, in two matched pairs — and Alice can work out all four but not which pair Bob's came from.

So Alice's guess is a genuine coin. She picks a pair, and she is right half the time, no matter how clever she is. That half is not an estimate; it is exact.

Alice's side: if Bob loses, he could simply lie about it. But losing means Alice sent him a secret from the other pair — and holding two secrets from different pairs lets him work out something he otherwise could not: the two large primes hidden in Alice's number.

So Bob must show those primes to claim a win, and Alice checks them in a second. He can only produce them when he genuinely won.

The one thing to warn the observer about: neither of these stops Bob simply hanging up when he sees he lost. No protocol between two people can, which is why real systems add a stake that is forfeited by whoever walks away.

45. Which cheat would you worry about?

Commit first

An online poker site implements mental poker correctly between all players, with no server holding the deck.

Predict first

What is the realistic attack?

  • Breaking the commutative encryption
  • Collusion between players sharing their hands over a side channel
  • Factoring the modulus
  • A flaw in the shuffle

Correct: Collusion between players sharing their hands over a side channel

The countermeasures are all statistical and behavioural: detecting improbable fold patterns, correlating IP addresses and play times, and limiting table selection. None of it is cryptography.

Which is this chapter's version of the recurring lesson. The protocol secures the information channel it defines, and an adversary who has another channel is outside its model entirely. Chapter 1's threat-model question — what can the adversary do — is what decides whether a protocol is relevant, and here the answer includes 'talk on the phone'.

Why: The cryptography prevents a player from reading another's cards through the protocol. It does nothing about two players in the same room, or on a voice call, telling each other what they hold — and collusion is the dominant form of cheating in online poker precisely because no protocol addresses it.

46. Reading the fairness guarantee

Cost model

The coin flip's two halves rest on different foundations, and the difference is worth stating precisely.

Annotate

On: \( \Pr[\text{Alice picks Bob's pair}] = \tfrac{1}{2} \quad \text{(unconditional)}, \qquad \Pr[\text{Bob forges a win}] \approx \Pr[\text{factoring } n] \quad \text{(computational)} \)

  • Exactly 1/2, against any adversary with any resources. y determines the four roots and carries no information about which was squared, so there is nothing to compute.
  • Bounded by the difficulty of factoring n, which is Chapter 9's assumption. It could in principle fail if factoring became easy.
  • The overall protocol is only as strong as its weakest half, so it is computationally secure. But knowing which half is which tells you what a future advance would break — a quantum computer would let Bob lie and would not let Alice bias the flip.
  • Set by the factoring requirement, so 2048 bits or more, exactly as in Chapter 9. Nothing about the coin flip itself constrains it.
  • Aborts. Both probabilities are conditional on the protocol completing.

Being able to say which half of a guarantee is unconditional is worth the effort: it is what lets you predict how a system ages.

47. What does “provably fair” not tell you?

Missing information

Online gambling sites advertise provably fair shuffling.

Discussion prompt

List what the phrase leaves undetermined.

Hint: The proof covers one step of a longer process.

Answer:

Whose randomness is combined? If only the operator contributes, the operator chooses the outcome whatever is published afterwards. A player contribution, supplied after the commitment, is essential.

How large is the committed value? A commitment to a small seed is enumerable, so the commitment hides nothing — Chapter 11's trap.

Can the operator abort selectively? Retrying on an unfavourable result, under any pretext, converts a fair scheme into a chosen one.

Is the ordering enforced? The commitment must precede the player's input, and the player's input must precede the reveal. If any step can be reordered, the guarantee evaporates.

What is actually being proved? Usually only that the published outcome matches the published seed — which says nothing about how the seed was chosen or whether the operator ran the protocol many times and reported one.

And collusion is entirely outside it. The strongest possible shuffle protocol does nothing about two players sharing hands.

48. Order these by how completely they break a mental poker game

Ranking

Five things that can go wrong.

Put in order

  1. The residue leak partitions the deck into two halves
  2. A player aborts when dealt a bad hand
  3. Two players collude over a voice call
  4. A player's exponent is not coprime to p−1
  5. The prime p is 64 bits

Why: The residue leak halves the uncertainty about each card — real, and short of total. Aborting is disruptive and detectable, and denies the aborter any winnings. Collusion between two players in a heads-up game means one party sees everything, which is complete. A non-coprime exponent means the encryption is not invertible and the hand cannot be dealt at all — a correctness failure that stops play. And a 64-bit prime means discrete logs are computable, so every card is readable by anyone. The ordering runs from partial information to total exposure.

49. Design a fair lottery on a public ledger

Constraint

A hundred participants, a public blockchain where every message is visible, and no trusted party. One winner must be chosen at random.

Discussion prompt

Design it, and address the abort problem explicitly.

Hint: Commit-reveal, plus something that makes aborting costly.

Answer:

Commit phase: each participant publishes a hash of a large random value together with a deposit. The commitment must be to at least 128 bits, or others enumerate it.

Reveal phase: after all commitments are in, each participant publishes their value. Anyone can check it against the published hash.

Combine: the winner is determined by the XOR or the hash of all revealed values. Every participant contributes, so no one party controls the result — and a participant who wants a particular outcome would have to control everyone else's contribution.

The abort problem, addressed directly: a participant who sees the emerging result and dislikes it can refuse to reveal, changing the outcome. So the deposit is forfeited on non-reveal, and the protocol proceeds without that participant. Aborting now costs money and gains only a re-roll.

And the ordering must be enforced by the ledger, which it is: no reveal is accepted until every commitment is recorded, and the block structure makes the ordering verifiable by everyone.

Note what the ledger provided — a broadcast channel with agreed ordering and the ability to hold a deposit. Those three things are what turn a two-party protocol with an unavoidable abort problem into a many-party protocol where aborting is merely expensive.

50. Secure multiparty computation: the general problem

Concept

Both protocols in this chapter are instances of one question, and naming it is worth doing before Chapter 19.

k parties each hold a private input x₁, ..., x_k. They want to learn f(x₁, ..., x_k) and nothing else. No trusted party, and any coalition below some threshold may be trying to cheat.

  1. Coin flipping is this with f = a random bit and k = 2
  2. Mental poker is this with f = a fair deal, and it is one of the founding examples
  3. Chapter 17's secret sharing supplies the standard machinery for the k-party case
  4. Threshold signatures and distributed key generation are the deployed forms

A general result says any computable f can be done this way, with security against a coalition of fewer than half the parties. The construction is far more expensive than a special-purpose protocol, which is why chapters like this one exist: a bespoke protocol for a specific f is usually orders of magnitude cheaper.

And two limitations survive the generalisation, both met already: aborts cannot be prevented without an external mechanism, and a coalition above the threshold sees everything.

Figure (svg): Secure multiparty computation: several private inputs entering a protocol that emits only the agreed output.

The general problem these two protocols are special cases of — and the frame for most of modern protocol design.

51. Where does the trust actually sit?

Socratic

Both protocols are advertised as needing no trusted party.

Discussion prompt

What must each party still trust, and what is genuinely eliminated?

Hint: Distinguish trusting a person from trusting an assumption.

Answer:

What is eliminated: trusting the counterparty's honesty. Bob cannot lie about the flip and Alice cannot choose her cards, whatever they intend. That is the real achievement, and it is what 'no trusted party' means.

What remains: trust in the mathematics. Bob's honesty rests on factoring being hard, and mental poker's secrecy rests on discrete logs being hard. Neither is proved, and both would fail on a large quantum computer — Chapter 25's subject.

Trust in the implementation. A biased random number generator on either side undermines everything, exactly as in Chapter 5. Alice's primes and Bob's x must be genuinely unpredictable.

Trust that the model matches reality. Nothing prevents two poker players from talking on the phone, and nothing prevents an abort. Both are outside what the protocol models.

So the accurate claim is narrow and still valuable: within the channel the protocol defines, and under standard hardness assumptions, neither party can gain by deviating. That is a great deal more than the two-headed penny offered, and a great deal less than 'the game is fair'.

52. Sort by which foundation the guarantee rests on

Definition probe

This chapter's guarantees do not all rest on the same thing, and the difference predicts how each ages.

Sort into buckets

Sort each claim.

Information-theoretic
Alice cannot bias the coin flip; Chapter 17's t−1 shares reveal nothing
Computational
Bob cannot falsely claim a win; Bob cannot read Alice's poker hand
info
In both cases the adversary is missing information rather than computing power. y is produced identically by all four roots, and t−1 shares are consistent with every possible secret. Unlimited computation changes nothing.
comp
Bob's honesty is bounded by the difficulty of factoring n, and the secrecy of a poker hand by the difficulty of discrete logarithms. Both would fall to a sufficiently large quantum computer.

53. What Chapter 19 takes from this one

Concept

The next chapter is about proving you know something without revealing it, and two ideas from here go straight into it.

Square roots mod n reappear as the Feige-Fiat-Shamir scheme. Peggy proves she knows a square root of a public value, by a protocol that is recognisably the coin flip run backwards: Victor issues a random challenge, and Peggy can answer both possible challenges only if she really holds the root.

And the idea of a hard problem as evidence carries over intact. In this chapter Bob's ability to factor n proved he had won. In the next, Peggy's ability to answer proves she holds a secret — the possession of a solution to a hard problem, used as a claim that can be checked.

What changes is the goal. Here the protocols produce a result — a coin, a hand. There they produce a conviction: Victor becomes certain, and learns nothing he could not have made up himself. That last clause is the whole content of the word 'zero-knowledge'.

Figure (svg): Secure multiparty computation: several private inputs entering a protocol that emits only the agreed output.

The general problem these two protocols are special cases of — and the frame for most of modern protocol design.

54. Protocols where the counterparty is the adversary

Pattern

Every earlier chapter put the adversary outside the conversation. These two put her inside it, and that changes the design questions.

  1. Each step defends one party against one specific cheat. There is no general 'security'; there is Alice's protection from Bob and Bob's from Alice, and both columns must be filled.
  2. Fairness usually comes from provable ignorance. Alice cannot bias the flip because she genuinely does not know which pair Bob used — an information-theoretic argument, like Chapter 17's shares.
  3. Verifiability replaces prevention. Bob's discard audit and Bob's factorisation proof both catch a cheat after the fact rather than preventing it, which is Chapter 16's pattern again.
  4. And aborts cannot be prevented by two parties alone. Fairness in the face of a walkout needs a third party, a deposit, or a ledger — something outside the protocol.

The general form of this problem is secure multiparty computation, and mental poker is one of its founding examples: k parties compute a function of their private inputs and learn nothing but the output. The collusion threshold is a parameter, exactly as t is in Chapter 17.

Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.

Two different mechanisms for two different cheats — indistinguishability on one side, a hard problem on the other.

55. A protocol that prevents cheating makes the game fair

Trap

The trap

The trap. Mental poker provably prevents reading another player's hand, dealing a card twice, or choosing your own cards. Every cheat available in a face-to-face game is eliminated. So an online game running this protocol is at least as fair as a physical one.

The premise is accurate — every one of those cheats really is prevented — and the conclusion does not follow.

The fix

Collusion is untouched. Two players sharing their hands over a phone call see everything the protocol was designed to hide, and no cryptographic step detects it. In online poker this is the dominant form of cheating, and it is entirely outside the model.

Aborts are untouched. A player dealt a bad hand disconnects, and no two-party protocol can prevent it — a result that holds regardless of how good the cryptography is.

And the primitive leaked anyway. The residue property of exponentiation partitions the deck into two publicly identifiable halves, which nobody designed in and which took separate analysis to find. Chapter 14's lesson, in a chapter about games.

The accurate claim is narrow: the protocol prevents the specific cheats it models, assuming both parties complete it and neither has a channel outside it. Both provisos are doing real work.

The habit: after establishing what a protocol prevents, ask what channels the adversary has that the model does not mention. In this chapter the answer is a telephone, and it defeats everything.

56. Check: where the randomness lives

Check

Work it out before you click.

Check your understanding

In the coin-flip protocol, what makes the outcome unpredictable to Alice?

  • A. Bob's choice of x is random
  • B. She cannot tell which of the two ± pairs contains Bob's x (correct)
  • C. She cannot compute square roots mod n
  • D. The primes p and q are secret from her

Answer: B

Why: Alice computes all four roots, so she is not short of computation — she is short of information. y is produced identically by all four roots, so it carries nothing about which was squared. Her ignorance is information-theoretic, which is why the flip is exactly fair rather than approximately so.

Why A tempts people
Bob's randomness matters, but if Alice could tell which pair was his she would win every time regardless of how randomly he chose.
Why C tempts people
She can compute them, and the protocol requires her to — she knows p and q.
Why D tempts people
She chose p and q; they are secret from Bob, not from her.

57. Check: the commutativity requirement

Check

Consider what mental poker needs from its encryption.

Check your understanding

Why can AES not be used for the locked-box protocol?

  • A. AES is too slow
  • B. AES encryptions do not commute, so Bob cannot remove his layer from under Alice's (correct)
  • C. AES keys are too short
  • D. AES is symmetric

Answer: B

Why: The protocol requires E_A(E_B(m)) = E_B(E_A(m)), so that a layer can be stripped regardless of the order it was applied in. Block ciphers are deliberately designed so that composing two keys gives something unrelated to either — Chapter 6's discussion of double encryption depends on exactly that non-commutativity.

Why A tempts people
AES is far faster than modular exponentiation; speed is the one thing it has in abundance here.
Why C tempts people
Key length is irrelevant to whether operations commute.
Why D tempts people
The exponentiation scheme used here is also symmetric — each party holds a private exponent. Symmetry is not the obstacle; the algebraic structure is.

58. Check: the abort problem

Check

Consider what happens when a party stops responding.

Check your understanding

Bob sees that he has lost the coin flip and stops replying. What can Alice do?

  • A. Prove the outcome from what she holds
  • B. Nothing within the protocol — this is the abort problem, and no two-party protocol prevents it (correct)
  • C. Factor n and determine the result
  • D. Repeat the protocol with the same n

Answer: B

Why: The outcome depends on x, which only Bob knows, so Alice cannot determine or prove it alone — and she cannot distinguish a sulking Bob from a dropped connection. Fairness against aborts is impossible for two parties without an external mechanism: an adjudicator, a forfeited deposit, or a ledger that records the state.

Why A tempts people
She holds the four roots and does not know which was Bob's, so she cannot establish the outcome even to herself.
Why C tempts people
She chose p and q — she already knows the factorisation, and it tells her nothing about x.
Why D tempts people
Repeating gives a fresh flip and does not settle the abandoned one, and Bob can abort the repeat too.

59. Write the two protocols out

Connect it up

Both are short, and writing them down is the fastest way to see what each step is for.

Draw it

Write the coin flip in five steps, marking beside each which party it protects and against what. Then write the poker deal in six, marking where the shuffle prevents Alice choosing her cards and where commutativity is required. Beside both, note which guarantees are unconditional and which are computational. Finish with the abort problem stated in one sentence and the three external mechanisms that address it.

The unconditional-versus-computational annotation is the one worth keeping: it is unusual for a single protocol to contain both, and knowing which is which tells you how it ages.

60. Exit ticket

Exit ticket

One question, about what makes these protocols different from the previous seventeen chapters.

Predict first

What is structurally new about the protocols in this chapter?

  • They use stronger cryptography
  • The counterparty is the adversary, so each step must protect one party from the other rather than both from an outsider
  • They are unconditionally secure
  • They do not need keys

Correct: The counterparty is the adversary, so each step must protect one party from the other rather than both from an outsider

Why: Every earlier chapter placed Eve outside the conversation, with Alice and Bob cooperating. Here Alice and Bob each want to cheat the other, so there is no shared interest to appeal to and every step must be justified from both sides. That is why the protocols look so asymmetric — Alice's protections and Bob's are entirely different mechanisms — and it is the setting that generalises into secure multiparty computation.

61. What to carry into Chapter 19

Recap

Two short protocols with a new adversary model.

Chapter 19 next. Zero-knowledge techniques, where Peggy proves to Victor that she knows a secret while revealing nothing about it — and the Feige-Fiat-Shamir scheme, which uses the same square roots mod n that decided the coin flip.

Figure (svg): Why neither party can cheat: Alice cannot tell which root Bob used, and Bob cannot lie without producing a factorisation.

Two different mechanisms for two different cheats — indistinguishability on one side, a hard problem on the other.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 18 — Games (sections 18.1-18.2) — Trappe & Washington, 3rd edition, pp. 349-356

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108