# Discrete Mathematics, Chapter 4: Number Theory and Cryptography

Save this PDF as:

Size: px
Start display at page:

Download "Discrete Mathematics, Chapter 4: Number Theory and Cryptography"

## Transcription

1 Discrete Mathematics, Chapter 4: Number Theory and Cryptography Richard Mayr University of Edinburgh, UK Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 1 / 35

2 Outline 1 Divisibility and Modular Arithmetic 2 Primes and Greatest Common Divisors 3 Solving Congruences 4 Cryptography Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 2 / 35

3 Division Definition If a and b are integers with a 0, then a divides b if there exists an integer c such that b = ac. When a divides b we write a b. We say that a is a factor or divisor of b and b is a multiple of a. If a b then b/a is an integer (namely the c above). If a does not divide b, we write a b. Theorem Let a, b, c be integers, where a 0. 1 If a b and a c, then a (b + c). 2 If a b, then a bc for all integers c. 3 If a b and b c, then a c. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 3 / 35

4 Division Algorithm When an integer is divided by a positive integer, there is a quotient and a remainder. This is traditionally called the Division Algorithm, but it is really a theorem. Theorem If a is an integer and d a positive integer, then there are unique integers q and r, with 0 r < d, such that a = dq + r a is called the dividend. d is called the divisor. q is called the quotient. q = a div d r is called the remainder. r = a mod d Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 4 / 35

5 Congruence Relation Definition If a and b are integers and m is a positive integer, then a is congruent to b modulo m iff m (a b). The notation a b( mod m) says that a is congruent to b modulo m. We say that a b( mod m) is a congruence and that m is its modulus. Two integers are congruent mod m if and only if they have the same remainder when divided by m. If a is not congruent to b modulo m, we write a b( mod m). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 5 / 35

6 Congruence: Examples Example: Determine Whether 17 is congruent to 5 modulo 6, and Whether 24 and 14 are congruent modulo 6. Clicker 1 No and No. 2 No and Yes. 3 Yes and No. 4 Yes and Yes. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 6 / 35

7 Congruence: Examples Example: Determine Whether 17 is congruent to 5 modulo 6, and Whether 24 and 14 are congruent modulo 6. Clicker 1 No and No. 2 No and Yes. 3 Yes and No. 4 Yes and Yes. Solution: 17 5( mod 6) because 6 divides 17 5 = 12. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 6 / 35

8 Congruence: Examples Example: Determine Clicker Whether 17 is congruent to 5 modulo 6, and Whether 24 and 14 are congruent modulo 6. 1 No and No. 2 No and Yes. 3 Yes and No. 4 Yes and Yes. Solution: 17 5( mod 6) because 6 divides 17 5 = ( mod 6) since = 10 is not divisible by 6. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 6 / 35

9 Terminology The uses of mod in the following expressions are different. a b( mod m), and a mod m = b a b( mod m) describes a binary relation on the set of integers. In a mod m = b, the notation mod denotes a function (from integers to integers). The relationship between these notations is made clear in this theorem. Theorem Let a and b be integers, and let m be a positive integer. Then a b( mod m) if and only if a mod m = b mod m Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 7 / 35

10 A Theorem on Congruences Theorem Let m be a positive integer. The integers a and b are congruent modulo m if and only if there is an integer k such that a = b + km. Proof. If a b( mod m), then (by the definition of congruence) m (a b). Hence, there is an integer k such that a b = km and equivalently a = b + km. Conversely, if there is an integer k such that a = b + km, then km = a b. Hence, m (a b) and a b( mod m). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 8 / 35

11 Congruences of Sums and Products Theorem Let m be a positive integer. If a b( mod m) and c d( mod m), then a + c b + d( mod m) and ac bd( mod m). Proof. Since a b( mod m) and c d( mod m), by the Theorem above there are integers s and t with b = a + sm and d = c + tm. Therefore, b + d = (a + sm) + (c + tm) = (a + c) + m(s + t), and bd = (a + sm)(c + tm) = ac + m(at + cs + stm). Hence, a + c b + d( mod m) and ac bd( mod m). Corollary Let m be a positive integer and let a and b be integers. Then (a + b) mod m = ((a mod m) + (b mod m)) mod m ab mod m = ((a mod m)(b mod m)) mod m. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 9 / 35

12 Arithmetic modulo m Let Z m = {0, 1,..., m 1}. The operation + m is defined as a + m b = (a + b) mod m. This is addition modulo m. The operation m is defined as a m b = (a b) mod m. This is multiplication modulo m. Using these operations is said to be doing arithmetic modulo m. Example: Find and Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 10 / 35

13 Arithmetic modulo m Let Z m = {0, 1,..., m 1}. The operation + m is defined as a + m b = (a + b) mod m. This is addition modulo m. The operation m is defined as a m b = (a b) mod m. This is multiplication modulo m. Using these operations is said to be doing arithmetic modulo m. Example: Find and Solution: Using the definitions above: = (7 + 9) mod 11 = 16 mod 11 = = (7 9) mod 11 = 63 mod 11 = 8 Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 10 / 35

14 Arithmetic modulo m The operations + m and m satisfy many of the same properties as ordinary addition and multiplication. Closure: If a, b Z m, then a + m b and a m b belong to Z m. Associativity: If a, b, c Z m, then (a + m b) + m c = a + m (b + m c) and (a m b) m c = a m (b m c). Commutativity: If a, b Z m, then a + m b = b + m a and a m b = b m a. Identity elements: The elements 0 and 1 are identity elements for addition and multiplication modulo m, respectively. If a Z m then a + m 0 = a and a m 1 = a. Additive inverses: If 0 a Z m, then m a is the additive inverse of a modulo m. Moreover, 0 is its own additive inverse. a + m (m a) = 0 and 0 + m 0 = 0. Distributivity: If a, b, c Z m, then a m (b + m c) = (a m b) + m (a m c) and (a + m b) m c = (a m c) + m (b m c). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 11 / 35

15 Base b Representation of Integers Theorem Let b be a positive integer greater than 1. Every positive integer n can be expressed uniquely in the form: n = a k b k + a k 1 b k a 1 b + a 0 where k is a nonnegative integer, a 0, a 1,... a k {0,..., b 1} and a k 0. The a 0, a 1,... a k are called the base-b digits of the representation. This representation of n is called the base b expansion of n and it is denoted by (a k a k 1... a 1 a 0 ) b b = 2 is binary. b = 8 is octal. b = 10 is decimal. b = 16 is hexadecimal, etc. See Textbook Section 4.2 for algorithms on binary representations. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 12 / 35

16 Primes Definition A positive integer p > 1 is called prime iff the only positive factors of p are 1 and p. Otherwise it is called composite. Theorem (Fundamental Theorem of Arithmetic) Every positive integer greater than 1 can be written uniquely as a prime or as the product of its prime factors, written in order of nondecreasing size. Example: 765 = = Theorem (Euclid ( BCE)) There are infinitely many primes. Proof by contradiction. If there were only finitely many primes then multiply them all and add 1. This would be a new prime. Contradiction. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 13 / 35

17 The Sieve of Eratosthenes ( BCE) How to find all primes between 2 and n? 1 Write the numbers 2,..., n into a list. Let i := 2. 2 Remove all strict multiples of i from the list. 3 Let k be the smallest number present in the list s.t. k > i. Then let i := k. 4 If i > n then stop else goto step 2. Trial division: A very inefficient method of determining if a number n is prime, is to try every integer i n and see if n is divisible by i. Testing if a number is prime can be done efficiently in polynomial time [Agrawal-Kayal-Saxena 2002], i.e., polynomial in the number of bits used to describe the input number. Efficient randomized tests had been available previously. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 14 / 35

18 Distribution of Primes What part of the numbers are primes? Do primes get scarce among the large numbers? The prime number theorem gives an asymptotic estimate for the number of primes not exceeding x. Theorem (Prime Number Theorem) The ratio of the number of primes not exceeding x and x/ ln(x) approaches 1 as x grows without bound. (ln(x) is the natural logarithm of x.) The theorem tells us that the number of primes not exceeding x, can be approximated by x/ ln(x). The odds that a randomly selected positive integer less than x is prime are approximately (x/ ln(x))/x = 1/ ln(x). The k-th prime is approximately of size k ln(k). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 15 / 35

19 Greatest Common Divisor Definition Let a, b Z {0}. The largest integer d such that d a and also d b is called the greatest common divisor of a and b. It is denoted by gcd(a, b). Example: gcd(24, 36) = 12. Definition The integers a and b are relatively prime (coprime) iff gcd(a, b) = 1. Example: 17 and 22. (Note that 22 is not a prime.) Definition The integers a 1, a 2,..., a n are pairwise relatively prime iff gcd(a i, a j ) = 1 whenever 1 i < j n. Example: 10, 17 and 21 are pairwise relatively prime, since gcd(10, 17) = gcd(10, 21) = gcd(17, 21) = 1. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 16 / 35

20 Least Common Multiple Definition The least common multiple of the positive integers a and b is the smallest positive integer that is divisible by both a and b. It is denoted by lcm(a, b). Example: lcm(45, 21) = 7 45 = = 315. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 17 / 35

21 Gcd and Lcm by Prime Factorizations Suppose that the prime factorizations of a and b are: a = p a 1 1 pa pan n, b = p b 1 1 pb pbn n where each exponent is a nonnegative integer (possibly zero). Then gcd(a, b) = p min(a 1,b 1 ) 1 p min(a 2,b 2 ) 2... p min(an,bn) n This number clearly divides a and b. No larger number can divide both a and b. Proof by contradiction and the prime factorization of a postulated larger divisor. lcm(a, b) = p max(a 1,b 1 ) 1 p max(a 2,b 2 ) 2... p max(an,bn) n This number is clearly a multiple of a and b. No smaller number can be a multiple of both a and b. Proof by contradiction and the prime factorization of a postulated smaller multiple. Factorization is a very inefficient method to compute gcd and lcm. The Euclidian algorithm is much better. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 18 / 35

22 Euclidian Algorithm Lemma Let a = bq + r, where a, b, q, and r are integers. Then gcd(a, b) = gcd(b, r). Proof. Suppose that d divides both a and b. Then d also divides a bq = r. Hence, any common divisor of a and b must also be a common divisor of b and r. For the opposite direction suppose that d divides both b and r. Then d also divides bq + r = a. Hence, any common divisor of b and r must also be a common divisor of a and b. Therefore, gcd(a, b) = gcd(b, r). This means that if a > b then gcd(a, b) = gcd(b, a mod b), which directly yields the algorithm. (Note that both arguments have gotten smaller.) One can show that its complexity is O(log b). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 19 / 35

23 Gcd as a Linear Combination Theorem (Bézout s Theorem) If a and b are positive integers, then there exist integers s and t such that gcd(a, b) = sa + tb (Proof in exercises of Section 5.2). The numbers s and t are called Bézout coefficients of a and b. Example: 2 = gcd(6, 14) = ( 2) The Bézout coefficients can be computed as follows. First use the Euclidian algorithm to find the gcd and then work backwards (by division and substitution) to express the gcd as a linear combination of the original two integers. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 20 / 35

24 Linear Congruences Definition A congruence of the form ax b( mod m) where m is a positive integer, a, b are integers and x is an integer variable is called a linear congruence. The solution of the congruence are all the integers x that satisfy it. Definition An integer a such that aa 1( mod m) is called a multiplicative inverse of a modulo m. Multiplicative inverses can be used to solve congruences. If ax b( mod m) then aax (ab)( mod m) and thus x (ab)( mod m). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 21 / 35

25 Multiplicative Inverses Example: Let m = 15. Find a multiplicative inverse of 8 modulo 15. Clicker Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 22 / 35

26 Multiplicative Inverses Example: Let m = 15. Find a multiplicative inverse of 8 modulo 15. Clicker = 16 1( mod 15). Thus 2 is a multiplicative inverse of 8 modulo 15. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 22 / 35

27 Multiplicative Inverses Find a multiplicative inverse of 7 modulo 15. Clicker between 4 and 8 3 between 9 and 11 4 between 12 and 14 Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 23 / 35

28 Multiplicative Inverses What is the multiplicative inverse of 5 modulo 15? Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 24 / 35

29 Multiplicative Inverses What is the multiplicative inverse of 5 modulo 15? 1 5 5( mod 15) ( mod 15) 3 5 0( mod 15) 4 5 5( mod 15) ( mod 15) 6 5 0( mod 15) 7 5 5( mod 15)... Where is the inverse??? 5 does not have any inverse modulo 15. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 24 / 35

30 The multiplicative group Z m Theorem If a and m are relatively prime integers and m > 1, then a multiplicative inverse of a modulo m exists. Furthermore, this inverse is unique modulo m. Proof. Since gcd(a, m) = 1, by Bézout s Theorem there are integers s and t such that sa + tm = 1. Hence, sa + tm 1( mod m). Since tm 0( mod m), it follows that sa 1( mod m). Consequently, s is a multiplicative inverse of a modulo m. Uniqueness: Exercise. Definition Let Z m = {x 1 x < m and gcd(x, m) = 1}. Together with multiplication modulo m, this is called the multiplicative group modulo m. It is closed, associative, has a neutral element (namely 1) and every element has an inverse. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 25 / 35

31 The Chinese Remainder Theorem Let x 2( mod 3) x 3( mod 5) x 2( mod 7) What is x? (Or rather, what is the smallest x that satisfies these?) Theorem (Chinese Remainder Theorem) Let m 1, m 2,..., m n be pairwise relatively prime positive integers greater than one and a 1, a 2,..., a n arbitrary integers. Then the system x a 1 ( mod m 1 ) x a 2 ( mod m 2 )... x a n ( mod m n ) has a unique solution modulo m = m 1 m 2... m n. (I.e., there is a solution x with 0 x < m and all other solutions are congruent modulo m to this solution.) Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 26 / 35

32 The Chinese Remainder Theorem: Proof We will construct a solution x. First, let M k = m/m k for k = 1, 2,..., n and m = m 1 m 2... m n. Since gcd(m k, M k ) = 1, the number M k has a multiplicative inverse y k modulo m k. I.e., M k y k 1( mod m k ) Now we let x = a 1 M 1 y 1 + a 2 M 2 y a n M n y n Why does this x satisfy all the congruences? If j k then M j 0( mod m k ), since M j contains m k as a factor. Thus x mod m k = 0 + a k M k y k mod m k = (a k mod m k )(M k y k mod m k ) = (a k mod m k ) 1 = a k mod m k Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 27 / 35

33 Fermat s Little Theorem (Pierre de Fermat ( )) Theorem If p is prime and p a, then a p 1 1( mod p). Furthermore, for every integer a we have a p a( mod p). Proof sketch: a x mod p = (a mod p) x mod p. Also p a. So without restriction we consider only 0 < a < p. Consider the powers of a 1, a 2, a 3,... modulo p. These form a subgroup of Z p which has some size k and we have a k 1 mod p. By Lagrange s theorem, k divides the size of Z p which is p 1, so p 1 = km for some positive integer m. Thus a p 1 a km (a k ) m 1 m 1 mod p This directly implies a p a( mod p). In the other case where p a we trivially have a p a 0( mod p). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 28 / 35

34 Fermat s Little Theorem Fermat s little theorem is useful in computing the remainders modulo p of large powers of integers. Example: Find mod 11. By Fermat s little theorem, we know that mod 11, and so (7 10 ) k 1( mod 11) for every positive integer k. Therefore, = = (7 10 ) ( mod 11). Hence, mod 11 = 5. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 29 / 35

35 Number Theory in Cryptography Terminology: Two parties Alice and Bob want to communicate securely s.t. a third party Eve who intercepts messages cannot learn the content of the messages. Symmetric Cryptosystems: Alice and Bob share a secret. Only they know a secret key K that is used to encrypt and decrypt messages. Given a message M, Alice encodes it (possibly with padding) into m, and then sends the ciphertext encrypt(m, K ) to Bob. Then Bob uses K to decrypt it and obtains decrypt(encrypt(m, K ), K ) = m. Example: AES. Public Key Cryptosystems: Alice and Bob do a-priori not share a secret. How can they establish a shared secret when others are listening to their messages? Idea: Have a two-part key, i.e., a key pair. A public key that is used to encrypt messages, and a secret key to decrypt them. Alice uses Bob s public key to encrypt a message (everyone can do that). Only Bob can decrypt the message with his secret key. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 30 / 35

36 RSA: an example of a Public Key Cryptosystem Named after Rivest, Shamir, Adelman (1976 at MIT). Discovered earlier by Clifford Cocks, working secretly for the UK government. Still widely used, e.g., in PGP and ssh. Described here because it is easy to explain with elementary number theory. Cryptography: Caveats There do not exist any cryptosystems that are proven to be secure for complexity theoretic reasons (i.e., easy to encrypt, hard to decrypt). The only systems proven secure are so for information theoretic reasons. Random one-time pad: secret key longer than message and used only once (Vernam scheme). Message: m n... m 0 bits. Secret key: k n... k 0 bits. Ciphertext: c i = m i xor k i. Decryption: m i = c i xor k i. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 31 / 35

37 Cryptography: More Caveats RSA could be broken with an efficient algorithm to factorize numbers, but possibly also by other means. It is an open question if an efficient method to break RSA would imply an efficient factorization method. A 768 bit RSA key has been broken, and experts believe 1024 bit could be broken with sufficient resources. Many experts increasingly doubt the security of RSA in general, and recommend to use Elliptic curve cryptography systems instead. (Also based on number theory, but harder to explain.) Key generation relies on strong random number generation. Vulnerabilities have been deliberately inserted by the NSA into some systems (e.g., Dual_EC_DRBG). Closed source implementations of cryptographic software are likely to contain more such backdoors, and can not be considered secure. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 32 / 35

38 Description of RSA: Key generation Choose two distinct prime numbers p and q. Numbers p and q should be chosen at random, and be of similar bit-length. Prime integers can be efficiently found using a primality test. Let n = pq and k = (p 1)(q 1). (In particular, k = Z n ). Choose an integer e such that 1 < e < k and gcd(e, k) = 1; i.e., e and k are coprime. e (for encryption) is released as the public key exponent. (e must not be very small.) Let d be the multiplicative inverse of e modulo k, i.e., de 1( mod k). (Computed using the extended Euclidean algorithm.) d (for decryption) is the private key and kept secret. The public key is (n, e) and the private key is (n, d). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 33 / 35

39 RSA: Encryption and Decryption Alice transmits her public key (n, e) to Bob and keeps the private key secret. Encryption: Bob then wishes to send message M to Alice. He first turns M into an integer m, such that 0 m < n by using an agreed-upon reversible protocol known as a padding scheme. He then computes the ciphertext c corresponding to c m e mod n This can be done quickly using the method of exponentiation by squaring. Bob then transmits c to Alice. Decryption: Alice can recover m from c by using her private key exponent d via computing m c d mod n Given m, she can recover the original message M by reversing the padding scheme. Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 34 / 35

40 RSA: Correctness of decryption Given that c m e mod n, why is c d m mod n? c d (m e ) d m ed ( mod n). By construction, d and e are each others multiplicative inverses modulo k, i.e., ed 1( mod k). Also k = (p 1)(q 1). Thus ed 1 = h(p 1)(q 1) for some integer h. We consider m ed modulo p. If p m then m ed = m h(p 1)(q 1) m = (m p 1 ) h(q 1) m 1 h(q 1) m m( mod p) by Fermat s little theorem. Otherwise m ed 0 m( mod p). Symmetrically, m ed m( mod q). Since p, q are distinct primes, we have m ed m( mod pq). Since n = pq, we have c d m ed m( mod n). Richard Mayr (University of Edinburgh, UK) Discrete Mathematics. Chapter 4 35 / 35

### 3. Applications of Number Theory

3. APPLICATIONS OF NUMBER THEORY 163 3. Applications of Number Theory 3.1. Representation of Integers. Theorem 3.1.1. Given an integer b > 1, every positive integer n can be expresses uniquely as n = a

### CHAPTER 5. Number Theory. 1. Integers and Division. Discussion

CHAPTER 5 Number Theory 1. Integers and Division 1.1. Divisibility. Definition 1.1.1. Given two integers a and b we say a divides b if there is an integer c such that b = ac. If a divides b, we write a

### Elementary Number Theory We begin with a bit of elementary number theory, which is concerned

CONSTRUCTION OF THE FINITE FIELDS Z p S. R. DOTY Elementary Number Theory We begin with a bit of elementary number theory, which is concerned solely with questions about the set of integers Z = {0, ±1,

### Today s Topics. Primes & Greatest Common Divisors

Today s Topics Primes & Greatest Common Divisors Prime representations Important theorems about primality Greatest Common Divisors Least Common Multiples Euclid s algorithm Once and for all, what are prime

### RSA and Primality Testing

and Primality Testing Joan Boyar, IMADA, University of Southern Denmark Studieretningsprojekter 2010 1 / 81 Correctness of cryptography cryptography Introduction to number theory Correctness of with 2

### The application of prime numbers to RSA encryption

The application of prime numbers to RSA encryption Prime number definition: Let us begin with the definition of a prime number p The number p, which is a member of the set of natural numbers N, is considered

### Number Theory. Proof. Suppose otherwise. Then there would be a finite number n of primes, which we may

Number Theory Divisibility and Primes Definition. If a and b are integers and there is some integer c such that a = b c, then we say that b divides a or is a factor or divisor of a and write b a. Definition

### Homework 5 Solutions

Homework 5 Solutions 4.2: 2: a. 321 = 256 + 64 + 1 = (01000001) 2 b. 1023 = 512 + 256 + 128 + 64 + 32 + 16 + 8 + 4 + 2 + 1 = (1111111111) 2. Note that this is 1 less than the next power of 2, 1024, which

### MA2C03 Mathematics School of Mathematics, Trinity College Hilary Term 2016 Lecture 59 (April 1, 2016) David R. Wilkins

MA2C03 Mathematics School of Mathematics, Trinity College Hilary Term 2016 Lecture 59 (April 1, 2016) David R. Wilkins The RSA encryption scheme works as follows. In order to establish the necessary public

### Integers and division

CS 441 Discrete Mathematics for CS Lecture 12 Integers and division Milos Hauskrecht milos@cs.pitt.edu 5329 Sennott Square Symmetric matrix Definition: A square matrix A is called symmetric if A = A T.

### U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009. Notes on Algebra

U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, 2009 Notes on Algebra These notes contain as little theory as possible, and most results are stated without proof. Any introductory

### Module 5: Basic Number Theory

Module 5: Basic Number Theory Theme 1: Division Given two integers, say a and b, the quotient b=a may or may not be an integer (e.g., 16=4 =4but 12=5 = 2:4). Number theory concerns the former case, and

### Integers, Division, and Divisibility

Number Theory Notes (v. 4.23 October 31, 2002) 1 Number Theory is the branch of mathematics that deals with integers and their properties, especially properties relating to arithmetic operations like addition,

### Further linear algebra. Chapter I. Integers.

Further linear algebra. Chapter I. Integers. Andrei Yafaev Number theory is the theory of Z = {0, ±1, ±2,...}. 1 Euclid s algorithm, Bézout s identity and the greatest common divisor. We say that a Z divides

### Elements of Applied Cryptography Public key encryption

Network Security Elements of Applied Cryptography Public key encryption Public key cryptosystem RSA and the factorization problem RSA in practice Other asymmetric ciphers Asymmetric Encryption Scheme Let

### Chapter 6. Number Theory. 6.1 The Division Algorithm

Chapter 6 Number Theory The material in this chapter offers a small glimpse of why a lot of facts that you ve probably nown and used for a long time are true. It also offers some exposure to generalization,

### 4. Number Theory (Part 2)

4. Number Theory (Part 2) Terence Sim Mathematics is the queen of the sciences and number theory is the queen of mathematics. Reading Sections 4.8, 5.2 5.4 of Epp. Carl Friedrich Gauss, 1777 1855 4.3.

### Public Key Cryptography: RSA and Lots of Number Theory

Public Key Cryptography: RSA and Lots of Number Theory Public vs. Private-Key Cryptography We have just discussed traditional symmetric cryptography: Uses a single key shared between sender and receiver

### Lecture 13 - Basic Number Theory.

Lecture 13 - Basic Number Theory. Boaz Barak March 22, 2010 Divisibility and primes Unless mentioned otherwise throughout this lecture all numbers are non-negative integers. We say that A divides B, denoted

### Course notes on Number Theory

Course notes on Number Theory In Number Theory, we make the decision to work entirely with whole numbers. There are many reasons for this besides just mathematical interest, not the least of which is that

### Public-Key Cryptography. Oregon State University

Public-Key Cryptography Çetin Kaya Koç Oregon State University 1 Sender M Receiver Adversary Objective: Secure communication over an insecure channel 2 Solution: Secret-key cryptography Exchange the key

### Mathematics of Cryptography Modular Arithmetic, Congruence, and Matrices. A Biswas, IT, BESU SHIBPUR

Mathematics of Cryptography Modular Arithmetic, Congruence, and Matrices A Biswas, IT, BESU SHIBPUR McGraw-Hill The McGraw-Hill Companies, Inc., 2000 Set of Integers The set of integers, denoted by Z,

### Principles of Public Key Cryptography. Applications of Public Key Cryptography. Security in Public Key Algorithms

Principles of Public Key Cryptography Chapter : Security Techniques Background Secret Key Cryptography Public Key Cryptography Hash Functions Authentication Chapter : Security on Network and Transport

### Lecture 1: Elementary Number Theory

Lecture 1: Elementary Number Theory The integers are the simplest and most fundamental objects in discrete mathematics. All calculations by computers are based on the arithmetical operations with integers

### MODULAR ARITHMETIC. a smallest member. It is equivalent to the Principle of Mathematical Induction.

MODULAR ARITHMETIC 1 Working With Integers The usual arithmetic operations of addition, subtraction and multiplication can be performed on integers, and the result is always another integer Division, on

### Cryptography: RSA and the discrete logarithm problem

Cryptography: and the discrete logarithm problem R. Hayden Advanced Maths Lectures Department of Computing Imperial College London February 2010 Public key cryptography Assymmetric cryptography two keys:

### 9 Modular Exponentiation and Cryptography

9 Modular Exponentiation and Cryptography 9.1 Modular Exponentiation Modular arithmetic is used in cryptography. In particular, modular exponentiation is the cornerstone of what is called the RSA system.

### Algebra for Digital Communication

EPFL - Section de Mathématiques Algebra for Digital Communication Fall semester 2008 Solutions for exercise sheet 1 Exercise 1. i) We will do a proof by contradiction. Suppose 2 a 2 but 2 a. We will obtain

### Announcements. CS243: Discrete Structures. More on Cryptography and Mathematical Induction. Agenda for Today. Cryptography

Announcements CS43: Discrete Structures More on Cryptography and Mathematical Induction Işıl Dillig Class canceled next Thursday I am out of town Homework 4 due Oct instead of next Thursday (Oct 18) Işıl

### The Mathematics of the RSA Public-Key Cryptosystem

The Mathematics of the RSA Public-Key Cryptosystem Burt Kaliski RSA Laboratories ABOUT THE AUTHOR: Dr Burt Kaliski is a computer scientist whose involvement with the security industry has been through

### 8 Primes and Modular Arithmetic

8 Primes and Modular Arithmetic 8.1 Primes and Factors Over two millennia ago already, people all over the world were considering the properties of numbers. One of the simplest concepts is prime numbers.

### Mathematics of Cryptography

CHAPTER 2 Mathematics of Cryptography Part I: Modular Arithmetic, Congruence, and Matrices Objectives This chapter is intended to prepare the reader for the next few chapters in cryptography. The chapter

### Prime Numbers. Chapter Primes and Composites

Chapter 2 Prime Numbers The term factoring or factorization refers to the process of expressing an integer as the product of two or more integers in a nontrivial way, e.g., 42 = 6 7. Prime numbers are

### Lecture 13: Factoring Integers

CS 880: Quantum Information Processing 0/4/0 Lecture 3: Factoring Integers Instructor: Dieter van Melkebeek Scribe: Mark Wellons In this lecture, we review order finding and use this to develop a method

### Discrete Mathematics Lecture 3 Elementary Number Theory and Methods of Proof. Harper Langston New York University

Discrete Mathematics Lecture 3 Elementary Number Theory and Methods of Proof Harper Langston New York University Proof and Counterexample Discovery and proof Even and odd numbers number n from Z is called

### Theorem (The division theorem) Suppose that a and b are integers with b > 0. There exist unique integers q and r so that. a = bq + r and 0 r < b.

Theorem (The division theorem) Suppose that a and b are integers with b > 0. There exist unique integers q and r so that a = bq + r and 0 r < b. We re dividing a by b: q is the quotient and r is the remainder,

### Integer Factorization using the Quadratic Sieve

Integer Factorization using the Quadratic Sieve Chad Seibert* Division of Science and Mathematics University of Minnesota, Morris Morris, MN 56567 seib0060@morris.umn.edu March 16, 2011 Abstract We give

### 12 Greatest Common Divisors. The Euclidean Algorithm

Arkansas Tech University MATH 4033: Elementary Modern Algebra Dr. Marcel B. Finan 12 Greatest Common Divisors. The Euclidean Algorithm As mentioned at the end of the previous section, we would like to

### 1 Die hard, once and for all

ENGG 2440A: Discrete Mathematics for Engineers Lecture 4 The Chinese University of Hong Kong, Fall 2014 6 and 7 October 2014 Number theory is the branch of mathematics that studies properties of the integers.

### Computer and Network Security

MIT 6.857 Computer and Networ Security Class Notes 1 File: http://theory.lcs.mit.edu/ rivest/notes/notes.pdf Revision: December 2, 2002 Computer and Networ Security MIT 6.857 Class Notes by Ronald L. Rivest

### CHAPTER 5: MODULAR ARITHMETIC

CHAPTER 5: MODULAR ARITHMETIC LECTURE NOTES FOR MATH 378 (CSUSM, SPRING 2009). WAYNE AITKEN 1. Introduction In this chapter we will consider congruence modulo m, and explore the associated arithmetic called

### Math 319 Problem Set #3 Solution 21 February 2002

Math 319 Problem Set #3 Solution 21 February 2002 1. ( 2.1, problem 15) Find integers a 1, a 2, a 3, a 4, a 5 such that every integer x satisfies at least one of the congruences x a 1 (mod 2), x a 2 (mod

### GREATEST COMMON DIVISOR

DEFINITION: GREATEST COMMON DIVISOR The greatest common divisor (gcd) of a and b, denoted by (a, b), is the largest common divisor of integers a and b. THEOREM: If a and b are nonzero integers, then their

### Algebraic Systems, Fall 2013, September 1, 2013 Edition. Todd Cochrane

Algebraic Systems, Fall 2013, September 1, 2013 Edition Todd Cochrane Contents Notation 5 Chapter 0. Axioms for the set of Integers Z. 7 Chapter 1. Algebraic Properties of the Integers 9 1.1. Background

### Section 4.2: The Division Algorithm and Greatest Common Divisors

Section 4.2: The Division Algorithm and Greatest Common Divisors The Division Algorithm The Division Algorithm is merely long division restated as an equation. For example, the division 29 r. 20 32 948

### Homework until Test #2

MATH31: Number Theory Homework until Test # Philipp BRAUN Section 3.1 page 43, 1. It has been conjectured that there are infinitely many primes of the form n. Exhibit five such primes. Solution. Five such

### Basic Algorithms In Computer Algebra

Basic Algorithms In Computer Algebra Kaiserslautern SS 2011 Prof. Dr. Wolfram Decker 2. Mai 2011 References Cohen, H.: A Course in Computational Algebraic Number Theory. Springer, 1993. Cox, D.; Little,

### CS 103X: Discrete Structures Homework Assignment 3 Solutions

CS 103X: Discrete Structures Homework Assignment 3 s Exercise 1 (20 points). On well-ordering and induction: (a) Prove the induction principle from the well-ordering principle. (b) Prove the well-ordering

### 1) A very simple example of RSA encryption

Solved Examples 1) A very simple example of RSA encryption This is an extremely simple example using numbers you can work out on a pocket calculator (those of you over the age of 35 45 can probably even

### Practice Problems for First Test

Mathematicians have tried in vain to this day to discover some order in the sequence of prime numbers, and we have reason to believe that it is a mystery into which the human mind will never penetrate.-

### SUM OF TWO SQUARES JAHNAVI BHASKAR

SUM OF TWO SQUARES JAHNAVI BHASKAR Abstract. I will investigate which numbers can be written as the sum of two squares and in how many ways, providing enough basic number theory so even the unacquainted

### Discrete Mathematics and Probability Theory Fall 2009 Satish Rao, David Tse Note 5

CS 70 Discrete Mathematics and Probability Theory Fall 2009 Satish Rao, David Tse Note 5 Modular Arithmetic One way to think of modular arithmetic is that it limits numbers to a predefined range {0,1,...,N

### Integers: applications, base conversions.

CS 441 Discrete Mathematics for CS Lecture 14 Integers: applications, base conversions. Milos Hauskrecht milos@cs.pitt.edu 5329 Sennott Square Modular arithmetic in CS Modular arithmetic and congruencies

### Kevin James. MTHSC 412 Section 2.4 Prime Factors and Greatest Comm

MTHSC 412 Section 2.4 Prime Factors and Greatest Common Divisor Greatest Common Divisor Definition Suppose that a, b Z. Then we say that d Z is a greatest common divisor (gcd) of a and b if the following

### Public Key Cryptography and RSA. Review: Number Theory Basics

Public Key Cryptography and RSA Murat Kantarcioglu Based on Prof. Ninghui Li s Slides Review: Number Theory Basics Definition An integer n > 1 is called a prime number if its positive divisors are 1 and

### CIS 5371 Cryptography. 8. Encryption --

CIS 5371 Cryptography p y 8. Encryption -- Asymmetric Techniques Textbook encryption algorithms In this chapter, security (confidentiality) is considered in the following sense: All-or-nothing secrecy.

### Asymmetric Cryptography. Mahalingam Ramkumar Department of CSE Mississippi State University

Asymmetric Cryptography Mahalingam Ramkumar Department of CSE Mississippi State University Mathematical Preliminaries CRT Chinese Remainder Theorem Euler Phi Function Fermat's Theorem Euler Fermat's Theorem

### NUMBER THEORY AMIN WITNO

NUMBER THEORY AMIN WITNO ii Number Theory Amin Witno Department of Basic Sciences Philadelphia University JORDAN 19392 Originally written for Math 313 students at Philadelphia University in Jordan, this

### Section Summary. Integer Representations. Base Conversion Algorithm Algorithms for Integer Operations

Section 4.2 Section Summary Integer Representations Base b Expansions Binary Expansions Octal Expansions Hexadecimal Expansions Base Conversion Algorithm Algorithms for Integer Operations Representations

### Breaking The Code. Ryan Lowe. Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and

Breaking The Code Ryan Lowe Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and a minor in Applied Physics. As a sophomore, he took an independent study

### Handout NUMBER THEORY

Handout of NUMBER THEORY by Kus Prihantoso Krisnawan MATHEMATICS DEPARTMENT FACULTY OF MATHEMATICS AND NATURAL SCIENCES YOGYAKARTA STATE UNIVERSITY 2012 Contents Contents i 1 Some Preliminary Considerations

### Mathematics of Cryptography

Number Theory Modular Arithmetic: Two numbers equivalent mod n if their difference is multiple of n example: 7 and 10 are equivalent mod 3 but not mod 4 7 mod 3 10 mod 3 = 1; 7 mod 4 = 3, 10 mod 4 = 2.

### Mathematics is the queen of sciences and number theory is the queen of mathematics.

Number Theory Mathematics is the queen of sciences and number theory is the queen of mathematics. But why is it computer science? It turns out to be critical for cryptography! Carl Friedrich Gauss Division

### MODULAR ARITHMETIC KEITH CONRAD

MODULAR ARITHMETIC KEITH CONRAD. Introduction We will define the notion of congruent integers (with respect to a modulus) and develop some basic ideas of modular arithmetic. Applications of modular arithmetic

### Elementary Number Theory

Elementary Number Theory A revision by Jim Hefferon, St Michael s College, 2003-Dec of notes by W. Edwin Clark, University of South Florida, 2002-Dec L A TEX source compiled on January 5, 2004 by Jim Hefferon,

### PUBLIC KEY ENCRYPTION

PUBLIC KEY ENCRYPTION http://www.tutorialspoint.com/cryptography/public_key_encryption.htm Copyright tutorialspoint.com Public Key Cryptography Unlike symmetric key cryptography, we do not find historical

### 8 Divisibility and prime numbers

8 Divisibility and prime numbers 8.1 Divisibility In this short section we extend the concept of a multiple from the natural numbers to the integers. We also summarize several other terms that express

### This section demonstrates some different techniques of proving some general statements.

Section 4. Number Theory 4.. Introduction This section demonstrates some different techniques of proving some general statements. Examples: Prove that the sum of any two odd numbers is even. Firstly you

### Primality - Factorization

Primality - Factorization Christophe Ritzenthaler November 9, 2009 1 Prime and factorization Definition 1.1. An integer p > 1 is called a prime number (nombre premier) if it has only 1 and p as divisors.

### Factoring Algorithms

Factoring Algorithms The p 1 Method and Quadratic Sieve November 17, 2008 () Factoring Algorithms November 17, 2008 1 / 12 Fermat s factoring method Fermat made the observation that if n has two factors

### Topics in Number Theory

Chapter 1 Topics in Number Theory We assume familiarity with the number systems. The notion of a number line, which extends from to +, represents the ordering of the real numbers. Among these, the counting

### Factoring & Primality

Factoring & Primality Lecturer: Dimitris Papadopoulos In this lecture we will discuss the problem of integer factorization and primality testing, two problems that have been the focus of a great amount

### Factoring integers, Producing primes and the RSA cryptosystem Harish-Chandra Research Institute

RSA cryptosystem HRI, Allahabad, February, 2005 0 Factoring integers, Producing primes and the RSA cryptosystem Harish-Chandra Research Institute Allahabad (UP), INDIA February, 2005 RSA cryptosystem HRI,

### MA257: INTRODUCTION TO NUMBER THEORY LECTURE NOTES

MA257: INTRODUCTION TO NUMBER THEORY LECTURE NOTES 2016 47 4. Diophantine Equations A Diophantine Equation is simply an equation in one or more variables for which integer (or sometimes rational) solutions

### Cryptography. Helmer Aslaksen Department of Mathematics National University of Singapore

Cryptography Helmer Aslaksen Department of Mathematics National University of Singapore aslaksen@math.nus.edu.sg www.math.nus.edu.sg/aslaksen/sfm/ 1 Basic Concepts There are many situations in life where

### Elementary Number Theory and Methods of Proof. CSE 215, Foundations of Computer Science Stony Brook University http://www.cs.stonybrook.

Elementary Number Theory and Methods of Proof CSE 215, Foundations of Computer Science Stony Brook University http://www.cs.stonybrook.edu/~cse215 1 Number theory Properties: 2 Properties of integers (whole

### CS Computer and Network Security: Applied Cryptography

CS 5410 - Computer and Network Security: Applied Cryptography Professor Patrick Traynor Spring 2016 Reminders Project Ideas are due on Tuesday. Where are we with these? Assignment #2 is posted. Let s get

### ALGEBRAIC APPROACH TO COMPOSITE INTEGER FACTORIZATION

ALGEBRAIC APPROACH TO COMPOSITE INTEGER FACTORIZATION Aldrin W. Wanambisi 1* School of Pure and Applied Science, Mount Kenya University, P.O box 553-50100, Kakamega, Kenya. Shem Aywa 2 Department of Mathematics,

### Number Theory and Cryptography using PARI/GP

Number Theory and Cryptography using Minh Van Nguyen nguyenminh2@gmail.com 25 November 2008 This article uses to study elementary number theory and the RSA public key cryptosystem. Various commands will

### UNIVERSITY OF MASSACHUSETTS Dept. of Electrical & Computer Engineering. Introduction to Cryptography ECE 597XX/697XX

UNIVERSITY OF MASSACHUSETTS Dept. of Electrical & Computer Engineering Introduction to Cryptography ECE 597XX/697XX Part 6 Introduction to Public-Key Cryptography Israel Koren ECE597/697 Koren Part.6.1

### Applications of Fermat s Little Theorem and Congruences

Applications of Fermat s Little Theorem and Congruences Definition: Let m be a positive integer. Then integers a and b are congruent modulo m, denoted by a b mod m, if m (a b). Example: 3 1 mod 2, 6 4

### EULER S THEOREM. 1. Introduction Fermat s little theorem is an important property of integers to a prime modulus. a p 1 1 mod p.

EULER S THEOREM KEITH CONRAD. Introduction Fermat s little theorem is an important property of integers to a prime modulus. Theorem. (Fermat). For prime p and any a Z such that a 0 mod p, a p mod p. If

### 3. QUADRATIC CONGRUENCES

3. QUADRATIC CONGRUENCES 3.1. Quadratics Over a Finite Field We re all familiar with the quadratic equation in the context of real or complex numbers. The formula for the solutions to ax + bx + c = 0 (where

### APPLICATIONS OF THE ORDER FUNCTION

APPLICATIONS OF THE ORDER FUNCTION LECTURE NOTES: MATH 432, CSUSM, SPRING 2009. PROF. WAYNE AITKEN In this lecture we will explore several applications of order functions including formulas for GCDs and

### Modular arithmetic. x ymodn if x = y +mn for some integer m. p. 1/??

p. 1/?? Modular arithmetic Much of modern number theory, and many practical problems (including problems in cryptography and computer science), are concerned with modular arithmetic. While this is probably

### Secure Network Communication Part II II Public Key Cryptography. Public Key Cryptography

Kommunikationssysteme (KSy) - Block 8 Secure Network Communication Part II II Public Key Cryptography Dr. Andreas Steffen 2000-2001 A. Steffen, 28.03.2001, KSy_RSA.ppt 1 Secure Key Distribution Problem

### 10 k + pm pm. 10 n p q = 2n 5 n p 2 a 5 b q = p

Week 7 Summary Lecture 13 Suppose that p and q are integers with gcd(p, q) = 1 (so that the fraction p/q is in its lowest terms) and 0 < p < q (so that 0 < p/q < 1), and suppose that q is not divisible

### I. GROUPS: BASIC DEFINITIONS AND EXAMPLES

I GROUPS: BASIC DEFINITIONS AND EXAMPLES Definition 1: An operation on a set G is a function : G G G Definition 2: A group is a set G which is equipped with an operation and a special element e G, called

### Advanced Maths Lecture 3

Advanced Maths Lecture 3 Next generation cryptography and the discrete logarithm problem for elliptic curves Richard A. Hayden rh@doc.ic.ac.uk EC crypto p. 1 Public key cryptography Asymmetric cryptography

### ΕΠΛ 674: Εργαστήριο 3

ΕΠΛ 674: Εργαστήριο 3 Ο αλγόριθμος ασύμμετρης κρυπτογράφησης RSA Παύλος Αντωνίου Department of Computer Science Private-Key Cryptography traditional private/secret/single key cryptography uses one key

### 2 The Euclidean algorithm

2 The Euclidean algorithm Do you understand the number 5? 6? 7? At some point our level of comfort with individual numbers goes down as the numbers get large For some it may be at 43, for others, 4 In

### The RSA Algorithm: A Mathematical History of the Ubiquitous Cryptological Algorithm

The RSA Algorithm: A Mathematical History of the Ubiquitous Cryptological Algorithm Maria D. Kelly December 7, 2009 Abstract The RSA algorithm, developed in 1977 by Rivest, Shamir, and Adlemen, is an algorithm

### (x + a) n = x n + a Z n [x]. Proof. If n is prime then the map

22. A quick primality test Prime numbers are one of the most basic objects in mathematics and one of the most basic questions is to decide which numbers are prime (a clearly related problem is to find

### Continued Fractions and the Euclidean Algorithm

Continued Fractions and the Euclidean Algorithm Lecture notes prepared for MATH 326, Spring 997 Department of Mathematics and Statistics University at Albany William F Hammond Table of Contents Introduction

### CRYPTOGRAPHIC ALGORITHMS (AES, RSA)

CALIFORNIA STATE POLYTECHNIC UNIVERSITY, POMONA CRYPTOGRAPHIC ALGORITHMS (AES, RSA) A PAPER SUBMITTED TO PROFESSOR GILBERT S. YOUNG IN PARTIAL FULFILLMENT OF THE REQUIREMENT FOR THE COURSE CS530 : ADVANCED

### Outline. Computer Science 418. Digital Signatures: Observations. Digital Signatures: Definition. Definition 1 (Digital signature) Digital Signatures

Outline Computer Science 418 Digital Signatures Mike Jacobson Department of Computer Science University of Calgary Week 12 1 Digital Signatures 2 Signatures via Public Key Cryptosystems 3 Provable 4 Mike

### RSA Encryption. Tom Davis tomrdavis@earthlink.net http://www.geometer.org/mathcircles October 10, 2003

RSA Encryption Tom Davis tomrdavis@earthlink.net http://www.geometer.org/mathcircles October 10, 2003 1 Public Key Cryptography One of the biggest problems in cryptography is the distribution of keys.

### The Laws of Cryptography Cryptographers Favorite Algorithms

2 The Laws of Cryptography Cryptographers Favorite Algorithms 2.1 The Extended Euclidean Algorithm. The previous section introduced the field known as the integers mod p, denoted or. Most of the field