Mathematical Background

1. Scope of these notes

Lecture 16 develops the elementary number theory needed later in the cryptography course. Its main topics are integer arithmetic, divisibility, prime factorization, greatest common divisors, the Euclidean and extended Euclidean algorithms, modular arithmetic, modular inverses, the group \(\mathbb{Z}_n^*\), and Euler’s totient function.

Lecture 17 continues from modular inverses. It studies exponentiation in finite modular groups, element orders, Euler’s theorem, Fermat’s little theorem, generators and cyclic groups, efficient modular exponentiation, the Chinese Remainder Theorem, and the discrete-logarithm, CDH, and DDH problems.

The Lecture 17 transcript contains several obvious speech-recognition errors and a brief in-class false start concerning \(2^{12345} \bmod 100\). The notes below follow the mathematical content of the transcript while using the slides and surrounding context to reconstruct the intended formulas. The mistaken use of Euler’s theorem for a non-invertible base is explicitly separated from the corrected CRT computation.

2. Lecture 16: Mathematical Background, Part I

2.1. Number systems

The lecture begins with the standard inclusions

\[ \mathbb{N} \subseteq \mathbb{Z} \subseteq \mathbb{Q}. \]

Here the convention used in the slides is

\[ \mathbb{N}=\{0,1,2,\ldots\}, \]

\[ \mathbb{Z}=\{\ldots,-2,-1,0,1,2,\ldots\}, \]

and

\[ \mathbb{Q} = \left\{ \frac{a}{b} \;\middle|\; a,b\in\mathbb{Z},\ b\neq 0 \right\}. \]

The set \(\mathbb{Z}\) is not merely a collection of values. It comes with addition and multiplication, and both operations map integers back to integers. The lecture later introduces the finite modular sets \(\mathbb{Z}_n\), where addition and multiplication are followed by reduction modulo \(n\).

A suggested reference for this mathematical background is Chapter 9 of Katz–Lindell.

2.2. Divisibility and prime numbers

For integers \(a\) and \(b\), one says that \(a\) divides \(b\), written

\[ a\mid b, \]

if there exists an integer \(m\) such that

\[ b=ma. \]

Equivalently, \(b\) is a multiple of \(a\).

A positive integer \(p\) is prime when its only positive divisors are \(1\) and \(p\). In particular, \(1\) is not prime.

The fundamental theorem of arithmetic states that every nonzero integer can be expressed as a product of prime powers, uniquely up to the ordering of the prime factors. In the notation used in the lecture,

\[ n = (\pm 1) p_1^{\alpha_1} p_2^{\alpha_2} \cdots p_k^{\alpha_k}, \]

where the \(p_i\) are distinct primes and the \(\alpha_i\) are positive integers.

For example,

\[ 10=2\cdot 5, \]

whereas

\[ 24=2^3\cdot 3. \]

Prime factorization is important throughout cryptography because many group orders, totient values, and hardness properties depend on the factorization of an integer.

2.3. Greatest common divisors and least common multiples

For integers \(n\) and \(m\), the greatest common divisor

\[ \gcd(n,m) \]

is the greatest positive integer dividing both \(n\) and \(m\). The least common multiple

\[ \operatorname{lcm}(n,m) \]

is the smallest positive integer divisible by both.

For example,

\[ 12=2^2\cdot 3 \qquad\text{and}\qquad 30=2\cdot 3\cdot 5. \]

Therefore,

\[ \gcd(12,30)=2\cdot 3=6. \]

The least common multiple satisfies

\[ \operatorname{lcm}(n,m) = \frac{|nm|}{\gcd(n,m)}. \]

Thus,

\begin{equation*} \operatorname{lcm}(12,30) = \frac{12\cdot 30}{6} = 60. \end{equation*}

Two integers \(a\) and \(b\) are called coprime when

\[ \gcd(a,b)=1. \]

Coprimality is especially important in modular arithmetic because an element has a multiplicative inverse modulo \(n\) exactly when it is coprime with \(n\).

2.4. Euclidean division

Let \(a,b\in\mathbb{Z}\) with \(b\neq 0\). Euclidean division states that there exist unique integers \(q\) and \(r\) such that

\[ a=qb+r \]

and

\[ 0\leq r<|b|. \]

The integer \(q\) is the quotient and \(r\) is the remainder. The remainder is also written

\[ r=a\bmod b. \]

For example,

\[ 113=12\cdot 9+5, \]

so

\[ 113\bmod 9=5. \]

2.5. Euclid’s theorem and the Euclidean algorithm

A central identity is

\[ \gcd(a,b) = \gcd(a\bmod b,b). \]

To see one direction, let \(d\) divide both \(a\) and \(b\). Since

\[ a\bmod b=a-qb \]

for an appropriate quotient \(q\), it follows that

\[ d\mid(a-qb), \]

so \(d\mid(a\bmod b)\). Conversely, if \(d\) divides both \(b\) and \(a\bmod b\), then

\[ a=qb+(a\bmod b) \]

implies \(d\mid a\). Thus the pairs \((a,b)\) and \((a\bmod b,b)\) have exactly the same common divisors.

Repeatedly applying this identity gives the Euclidean algorithm.

For example,

\begin{equation*} \begin{aligned} \gcd(113,9) &=\gcd(5,9)\\ &=\gcd(9,5)\\ &=\gcd(4,5)\\ &=\gcd(5,4)\\ &=\gcd(1,4)\\ &=\gcd(4,1)\\ &=\gcd(0,1)\\ &=1. \end{aligned} \end{equation*}

The corresponding divisions are

\[ 113=12\cdot 9+5, \]

\[ 9=1\cdot 5+4, \]

\[ 5=1\cdot 4+1, \]

and

\[ 4=4\cdot 1+0. \]

The final nonzero remainder is the gcd. Since it is \(1\), the numbers \(113\) and \(9\) are coprime.

2.6. Bézout’s identity

Bézout’s theorem states that for any integers \(a\) and \(b\), there exist integers \(x\) and \(y\) satisfying

\[ xa+yb=\gcd(a,b). \]

The coefficients \(x\) and \(y\) are called Bézout coefficients. They need not be positive, and they are generally not unique.

When \(\gcd(a,b)=1\), Bézout’s identity becomes

\[ xa+yb=1. \]

This equation is the key to computing modular inverses.

2.7. The extended Euclidean algorithm

The ordinary Euclidean algorithm computes the gcd. The extended Euclidean algorithm additionally computes Bézout coefficients.

Maintain triples

\[ (r_i,\lambda_i,\mu_i) \]

such that

\[ r_i=\lambda_i a+\mu_i b. \]

Initialize

\[ r_0=a, \qquad \lambda_0=1, \qquad \mu_0=0, \]

and

\[ r_1=b, \qquad \lambda_1=0, \qquad \mu_1=1. \]

At each step, perform Euclidean division

\[ r_{i-1}=q_i r_i+r_{i+1}, \qquad 0\leq r_{i+1}<|r_i|. \]

The new coefficients are

\[ \lambda_{i+1} = \lambda_{i-1}-q_i\lambda_i \]

and

\[ \mu_{i+1} = \mu_{i-1}-q_i\mu_i. \]

These recurrences preserve the invariant

\[ r_{i+1} = \lambda_{i+1}a+\mu_{i+1}b. \]

The algorithm stops when some \(r_k=0\). It then returns

\[ \gcd(a,b)=r_{k-1}, \]

together with

\[ x=\lambda_{k-1}, \qquad y=\mu_{k-1}, \]

for which

\[ xa+yb=\gcd(a,b). \]

2.7.1. Example: \(a=101\) and \(b=17\)

Start with

\[ r_0=101, \qquad r_1=17. \]

The first division is

\[ 101=5\cdot 17+16. \]

Hence

\[ r_2=16, \qquad \lambda_2=1, \qquad \mu_2=-5. \]

The second division is

\[ 17=1\cdot 16+1. \]

Hence

\[ r_3=1, \qquad \lambda_3=-1, \qquad \mu_3=6. \]

Finally,

\[ 16=16\cdot 1+0. \]

Therefore,

\[ \gcd(101,17)=1, \]

and the extended algorithm gives

\[ 101(-1)+17(6)=1. \]

2.8. Modular arithmetic and residue classes

Fix a positive integer \(m\). Euclidean division implies that every integer has exactly one remainder in

\[ \{0,1,\ldots,m-1\} \]

when divided by \(m\). The lecture uses

\[ \mathbb{Z}_m=\{0,1,\ldots,m-1\} \]

as the canonical representation.

More formally, each element of \(\mathbb{Z}_m\) represents an equivalence class. Two integers \(a\) and \(b\) represent the same class when

\[ a\equiv b\pmod m, \]

which means

\[ m\mid(a-b). \]

For instance, modulo \(3\), all numbers of the form \(3k\) belong to the class represented by \(0\), all numbers \(3k+1\) belong to the class represented by \(1\), and all numbers \(3k+2\) belong to the class represented by \(2\).

Addition and multiplication in \(\mathbb{Z}_m\) are defined by reducing the ordinary integer result modulo \(m\):

\[ a+_m b := (a+b)\bmod m, \]

and

\[ a\cdot_m b := (ab)\bmod m. \]

Usually the subscript is omitted when the modulus is clear.

The slides illustrate these operations with the complete addition and multiplication tables of \(\mathbb{Z}_5\). In the multiplication table, the nonzero elements permute one another under multiplication, which foreshadows the multiplicative group \(\mathbb{Z}_5^*\).

2.9. Modular inverses

Let \(a\in\mathbb{Z}_n\). An inverse of \(a\) modulo \(n\), if it exists, is an element \(b\in\mathbb{Z}_n\) satisfying

\[ ab\equiv 1\pmod n. \]

It is written

\[ b=a^{-1}\pmod n. \]

For example, in \(\mathbb{Z}_3\),

\[ 1^{-1}=1 \]

because

\[ 1\cdot 1\equiv 1\pmod 3. \]

Also,

\[ 2^{-1}=2 \]

because

\[ 2\cdot 2=4\equiv 1\pmod 3. \]

The element \(0\) has no inverse because multiplying by \(0\) can never produce \(1\).

In \(\mathbb{Z}_5\), the inverse of \(2\) is \(3\), since

\[ 2\cdot 3=6\equiv 1\pmod 5. \]

For a small modulus, inverses can be found by brute force. For large moduli, the extended Euclidean algorithm gives a systematic and efficient method.

2.10. The invertible residues \(\mathbb{Z}_n^*\)

The set of invertible elements modulo \(n\) is

\[ \mathbb{Z}_n^* = \left\{ a\in\mathbb{Z}_n \;\middle|\; a\text{ is invertible modulo }n \right\}. \]

An element is invertible exactly when it is coprime with the modulus:

\[ \mathbb{Z}_n^* = \left\{ a\in\mathbb{Z}_n \;\middle|\; \gcd(a,n)=1 \right\}. \]

For \(n=6\),

\[ \mathbb{Z}_6=\{0,1,2,3,4,5\}. \]

The elements \(1\) and \(5\) are invertible:

\[ 1^{-1}=1 \]

and

\[ 5^{-1}=5, \]

because

\[ 5\cdot 5=25\equiv 1\pmod 6. \]

The elements \(0,2,3,4\) are not invertible. Correspondingly,

\[ \gcd(1,6)=\gcd(5,6)=1, \]

whereas each of \(0,2,3,4\) has a nontrivial common divisor with \(6\).

To prove the characterization, first suppose that \(a\) has an inverse \(b\). Then

\[ ab\equiv 1\pmod n, \]

so for some integer \(k\),

\[ ab+kn=1. \]

Any common divisor of \(a\) and \(n\) must divide the left-hand side and hence must divide \(1\). Therefore,

\[ \gcd(a,n)=1. \]

Conversely, if

\[ \gcd(a,n)=1, \]

then Bézout’s identity gives integers \(x,y\) such that

\[ ax+ny=1. \]

Reducing this equation modulo \(n\) yields

\[ ax\equiv 1\pmod n, \]

so \(x\) is an inverse of \(a\).

2.11. Euler’s totient function

Euler’s totient function counts the invertible residues:

\begin{equation*} \varphi(n) = |\mathbb{Z}_n^*|. \end{equation*}

If

\[ n = p_1^{\alpha_1} p_2^{\alpha_2} \cdots p_k^{\alpha_k} \]

is the prime factorization of \(n\), then

\[ \varphi(n) = p_1^{\alpha_1-1}(p_1-1) \cdots p_k^{\alpha_k-1}(p_k-1). \]

Equivalently,

\[ \varphi(n) = n \prod_{p\mid n} \left(1-\frac{1}{p}\right). \]

For a prime \(p\),

\[ \varphi(p)=p-1, \]

because every nonzero residue modulo \(p\) is coprime with \(p\).

2.12. Computing inverses with the extended Euclidean algorithm

Suppose

\[ a\in\mathbb{Z}_n^*. \]

Then

\[ \gcd(a,n)=1. \]

The extended Euclidean algorithm produces integers \(x,y\) satisfying

\[ ax+ny=1. \]

Modulo \(n\), the term \(ny\) vanishes, so

\[ ax\equiv 1\pmod n. \]

Therefore,

\[ a^{-1}\equiv x\pmod n. \]

The coefficient may be negative or outside the canonical interval \(\{0,\ldots,n-1\}\). In that case it is simply reduced modulo \(n\).

3. Lecture 17: Mathematical Background, Part II

3.1. Recap: computing an inverse modulo \(101\)

The lecture begins by recalling that the extended Euclidean algorithm computes modular inverses.

To compute the inverse of \(7\) modulo \(101\), run the algorithm on \(101\) and \(7\):

\[ 101=14\cdot 7+3, \]

\[ 7=2\cdot 3+1, \]

and

\[ 3=3\cdot 1+0. \]

Tracking the Bézout coefficients gives

\[ 101(-2)+7(29)=1. \]

Reducing modulo \(101\),

\[ 7\cdot 29\equiv 1\pmod{101}. \]

Hence,

\[ 7^{-1}\equiv 29\pmod{101}. \]

The integer coefficient produced by the algorithm is not required to lie in \(\{0,\ldots,100\}\). For example, \(-72\) and \(29\) represent the same residue class modulo \(101\). More generally, if \(x\) is an inverse, then every integer

\[ x+k n, \qquad k\in\mathbb{Z}, \]

represents the same modular inverse. The inverse is unique as an element of \(\mathbb{Z}_n\), but it has infinitely many integer representatives.

This discussion also explains why negative outputs from the extended Euclidean algorithm are not a problem: one reduces the result modulo \(n\) to obtain the canonical representative.

3.2. Powers modulo \(n\)

The next topic is repeated exponentiation modulo \(n\). Since \(\mathbb{Z}_n\) is finite, the sequence

\[ 1,a,a^2,a^3,\ldots \]

must eventually repeat. The behavior differs depending on whether \(a\) is invertible.

Consider powers modulo \(10\).

For \(a=2\),

\begin{equation*} \begin{aligned} 2^0&\equiv 1,\\ 2^1&\equiv 2,\\ 2^2&\equiv 4,\\ 2^3&\equiv 8,\\ 2^4&\equiv 6,\\ 2^5&\equiv 2 \pmod{10}. \end{aligned} \end{equation*}

The sequence enters the cycle

\[ 2\longrightarrow 4\longrightarrow 8\longrightarrow 6 \longrightarrow 2. \]

It does not return to \(1\), because \(2\notin\mathbb{Z}_{10}^*\).

For \(a=3\),

\begin{equation*} \begin{aligned} 3^0&\equiv 1,\\ 3^1&\equiv 3,\\ 3^2&\equiv 9,\\ 3^3&\equiv 7,\\ 3^4&\equiv 1 \pmod{10}. \end{aligned} \end{equation*}

This sequence returns to the identity:

\[ 1\longrightarrow 3\longrightarrow 9\longrightarrow 7 \longrightarrow 1. \]

This happens because \(3\in\mathbb{Z}_{10}^*\).

For \(a=4\),

\[ 4^0\equiv 1, \qquad 4^1\equiv 4, \qquad 4^2\equiv 6, \qquad 4^3\equiv 4 \pmod{10}. \]

Thus \(4\) enters the cycle \(4\leftrightarrow 6\), again without returning to \(1\).

The diagrams in the slides also show fixed-point behavior for non-invertible elements. For example,

\[ 5^k\equiv 5\pmod{10} \]

for every \(k\geq 1\), and similarly

\[ 6^k\equiv 6\pmod{10} \]

for every \(k\geq 1\).

The conceptual distinction is that multiplication by an invertible element is a permutation of \(\mathbb{Z}_n^*\). Therefore its powers cannot collapse into a non-identity cycle. In a finite group, they must eventually return to \(1\).

3.3. The subgroup generated by an element and its order

Let

\[ a\in\mathbb{Z}_n^*. \]

The set of all powers of \(a\) is denoted

\[ \langle a\rangle = \{a^i\mid i\in\mathbb{Z}\}. \]

Because \(a\) is invertible, negative powers are meaningful as powers of \(a^{-1}\). In a finite group, it is enough to list the nonnegative powers until the sequence first returns to \(1\).

The order of \(a\) modulo \(n\), written

\[ \operatorname{ord}_n(a), \]

is the size of this generated subgroup:

\begin{equation*} \operatorname{ord}_n(a) = |\langle a\rangle|. \end{equation*}

Equivalently, it is the least positive integer \(r\) satisfying

\[ a^r\equiv 1\pmod n. \]

For example,

\[ \mathbb{Z}_{10}^*=\{1,3,7,9\}, \]

and

\[ \langle 3\rangle=\{1,3,9,7\}. \]

Therefore,

\[ \operatorname{ord}_{10}(3)=4 \]

and

\[ \langle 3\rangle=\mathbb{Z}_{10}^*. \]

A standard finite-group fact is that the order of an element divides the order of the group. Thus,

\[ \operatorname{ord}_n(a)\mid |\mathbb{Z}_n^*| \]

and hence

\[ \operatorname{ord}_n(a)\mid\varphi(n). \]

In particular,

\[ \operatorname{ord}_n(a)\leq\varphi(n). \]

3.4. Euler’s theorem

Euler’s theorem states that for every invertible residue

\[ a\in\mathbb{Z}_n^*, \]

one has

\[ a^{\varphi(n)}\equiv 1\pmod n. \]

This follows from the fact that

\[ \operatorname{ord}_n(a)\mid\varphi(n). \]

Euler’s theorem provides a general upper bound on the length of the power cycle and allows large exponents to be reduced modulo \(\varphi(n)\), provided that the base is invertible.

More precisely, if

\[ e=q\varphi(n)+r, \]

then

\[ a^e = \left(a^{\varphi(n)}\right)^q a^r \equiv a^r\pmod n. \]

The condition

\[ \gcd(a,n)=1 \]

is essential.

3.5. Fermat’s little theorem

When the modulus is a prime \(p\),

\[ \varphi(p)=p-1. \]

Euler’s theorem therefore gives Fermat’s little theorem:

\[ x^{p-1}\equiv 1\pmod p \]

for every

\[ x\in\mathbb{Z}_p^*. \]

Equivalently, the theorem applies to every integer \(x\) not divisible by \(p\).

3.6. Generators and cyclic groups

An element

\[ a\in\mathbb{Z}_n^* \]

is called a generator when

\[ \langle a\rangle=\mathbb{Z}_n^*. \]

If such an element exists, the group is called cyclic.

The example above shows that \(3\) is a generator of \(\mathbb{Z}_{10}^*\).

A nontrivial theorem states that for every prime \(p\),

\[ \mathbb{Z}_p^* \]

is cyclic. Therefore, there exists an element \(g\) of order \(p-1\), and

\[ \mathbb{Z}_p^*=\langle g\rangle. \]

The slides give the example \(p=13\). The powers of \(2\) are

\begin{equation*} \begin{aligned} 2^0&\equiv 1, & 2^1&\equiv 2, & 2^2&\equiv 4, & 2^3&\equiv 8,\\ 2^4&\equiv 3, & 2^5&\equiv 6, & 2^6&\equiv 12, & 2^7&\equiv 11,\\ 2^8&\equiv 9, & 2^9&\equiv 5, & 2^{10}&\equiv 10, & 2^{11}&\equiv 7,\\ 2^{12}&\equiv 1 \pmod{13}. \end{aligned} \end{equation*}

All twelve nonzero residues occur, so

\[ \operatorname{ord}_{13}(2)=12 \]

and

\[ \langle 2\rangle=\mathbb{Z}_{13}^*. \]

Not every group \(\mathbb{Z}_n^*\) for composite \(n\) is cyclic. The lecture also remarks that even when a generator is guaranteed to exist, finding one can require knowledge about the factorization of the group order. Generator selection is therefore not always a trivial computational task.

3.7. Efficient modular exponentiation

A direct computation of

\[ a^e\bmod n \]

by multiplying \(a\) by itself \(e-1\) times requires a number of multiplications linear in \(e\). This is infeasible when \(e\) is very large.

There are two separate ways to reduce the work:

  1. When \(a\in\mathbb{Z}_n^*\), Euler’s theorem may reduce the exponent modulo \(\varphi(n)\).
  2. Square-and-multiply computes the remaining power using only \(O(\log e)\) squarings and multiplications.

These two ideas are complementary. Square-and-multiply works for every base, whereas reducing the exponent with Euler’s theorem requires the base to be invertible.

3.7.1. Example: \(3^{12345}\bmod 100\)

First factor the modulus:

\[ 100=2^2\cdot 5^2. \]

The totient is

\begin{equation*} \varphi(100) = 2^{2-1}(2-1)\cdot 5^{2-1}(5-1) = 2\cdot 1\cdot 5\cdot 4 = 40. \end{equation*}

Since

\[ \gcd(3,100)=1, \]

Euler’s theorem applies:

\[ 3^{40}\equiv 1\pmod{100}. \]

Now divide the exponent:

\[ 12345=308\cdot 40+25. \]

Therefore,

\[ 3^{12345} = \left(3^{40}\right)^{308}3^{25} \equiv 3^{25} \pmod{100}. \]

It remains to compute \(3^{25}\bmod 100\).

The binary expansion is

\[ 25=(11001)_2. \]

A left-to-right square-and-multiply algorithm is as follows. If

\[ e=(b_\ell b_{\ell-1}\cdots b_0)_2 \]

with \(b_\ell=1\), initialize

\[ y=a. \]

Then, for

\[ i=\ell-1,\ell-2,\ldots,0, \]

perform

\[ y\leftarrow y^2\bmod n, \]

and, when \(b_i=1\), additionally perform

\[ y\leftarrow ya\bmod n. \]

For \(a=3\), \(n=100\), and \(25=(11001)_2\), the steps are

\[ y=3, \]

then, for the next bit \(1\),

\[ y\equiv 3^2\cdot 3=27\pmod{100}, \]

for the next bit \(0\),

\[ y\equiv 27^2=729\equiv 29\pmod{100}, \]

for the next bit \(0\),

\[ y\equiv 29^2=841\equiv 41\pmod{100}, \]

and for the final bit \(1\),

\[ y\equiv 41^2\cdot 3 =5043 \equiv 43 \pmod{100}. \]

Hence,

\[ 3^{12345}\equiv 43\pmod{100}. \]

3.7.2. The in-class correction concerning the base \(2\)

During the lecture, a student correctly pointed out that Euler’s theorem cannot be applied directly to

\[ 2^{12345}\bmod 100, \]

because

\[ \gcd(2,100)\neq 1. \]

Thus the reduction

\[ 2^{12345}\stackrel{\text{invalid}}{\equiv}2^{25}\pmod{100} \]

does not follow from Euler’s theorem.

The lecturer briefly mentioned that generalizations exist for non-invertible elements, but did not develop them. The course instead returns to this example after introducing the Chinese Remainder Theorem and computes it correctly by splitting the modulus into \(4\) and \(25\).

The square-and-multiply algorithm itself remains valid for a non-invertible base. What fails is only the Euler-theorem exponent reduction.

3.8. The Chinese Remainder Theorem

Let \(n\) and \(m\) be coprime positive integers, and let \(a,b\in\mathbb{Z}\). The system

\begin{equation*} \begin{cases} x\equiv a\pmod n,\\ x\equiv b\pmod m \end{cases} \end{equation*}

has exactly one solution modulo \(nm\).

Define

\[ M=m^{-1}\pmod n \]

and

\[ N=n^{-1}\pmod m. \]

Then one solution is

\[ c = a+(b-a)Nn. \]

Indeed, modulo \(n\), the second term vanishes, so

\[ c\equiv a\pmod n. \]

Modulo \(m\), because \(Nn\equiv 1\pmod m\),

\[ c \equiv a+(b-a) \equiv b \pmod m. \]

An equivalent formula is

\[ c = b+(a-b)Mm. \]

Every integer solution is congruent to \(c\) modulo \(nm\).

3.8.1. Example: reconstructing a secret number

Suppose

\[ x\in[0,100] \]

and one knows

\[ x\equiv 2\pmod 7 \]

and

\[ x\equiv 3\pmod{11}. \]

The first congruence implies

\[ x=2+7k \]

for some integer \(k\). Substitute this into the second congruence:

\[ 2+7k\equiv 3\pmod{11}. \]

Therefore,

\[ 7k\equiv 1\pmod{11}. \]

Since

\[ 7^{-1}\equiv 8\pmod{11}, \]

one gets

\[ k\equiv 8\pmod{11}. \]

Thus,

\[ k=8+11h \]

for some \(h\in\mathbb{Z}\). Substitution gives

\begin{equation*} \begin{aligned} x &=2+7(8+11h)\\ &=58+77h. \end{aligned} \end{equation*}

Hence,

\[ x\equiv 58\pmod{77}. \]

The range restriction \(x\in[0,100]\) selects the unique value

\[ x=58. \]

This illustrates a general use of CRT: if an unknown integer is known modulo several pairwise coprime small moduli, the residues determine it modulo the product of those moduli. If that product is larger than the known range of the integer, the integer itself is uniquely determined.

3.8.2. CRT as a computational tool in RSA

Suppose an RSA modulus has the form

\[ N=pq \]

for distinct large primes \(p\) and \(q\). A modular exponentiation modulo \(N\), such as an RSA decryption

\[ m=c^d\bmod N, \]

can be performed by separately computing

\[ m_p=c^d\bmod p \]

and

\[ m_q=c^d\bmod q. \]

The two residues are then recombined with CRT to recover \(m\bmod N\).

Working modulo \(p\) and modulo \(q\) uses smaller operands than working directly modulo \(N\), so the CRT form substantially accelerates RSA private operations. Exponents may also be reduced modulo \(p-1\) and \(q-1\) when the relevant coprimality conditions hold.

3.8.3. Correct computation of \(2^{12345}\bmod 100\)

Factor the modulus as

\[ 100=4\cdot 25, \]

where

\[ \gcd(4,25)=1. \]

Let

\[ x=2^{12345}\bmod 100. \]

CRT reduces the computation to

\begin{equation*} \begin{cases} x\equiv 2^{12345}\pmod 4,\\ x\equiv 2^{12345}\pmod{25}. \end{cases} \end{equation*}

Since the exponent is at least \(2\),

\[ 2^{12345}\equiv 0\pmod 4. \]

Modulo \(25\), the base \(2\) is invertible and

\[ \varphi(25)=5(5-1)=20. \]

Because

\[ 12345=617\cdot 20+5, \]

Euler’s theorem gives

\[ 2^{12345} \equiv 2^5 = 32 \equiv 7 \pmod{25}. \]

Therefore,

\begin{equation*} \begin{cases} x\equiv 0\pmod 4,\\ x\equiv 7\pmod{25}. \end{cases} \end{equation*}

The unique solution modulo \(100\) is

\[ x\equiv 32\pmod{100}. \]

Consequently,

\[ 2^{12345}\equiv 32\pmod{100}. \]

This is the corrected solution to the earlier non-invertible-base example.

3.9. The discrete logarithm problem

Let \(p\) be prime. Since \(\mathbb{Z}_p^*\) is cyclic, choose a generator \(g\) such that

\[ \mathbb{Z}_p^*=\langle g\rangle. \]

The discrete logarithm problem asks: given

\[ h\in\mathbb{Z}_p^*, \]

find an exponent \(a\) such that

\[ g^a=h\pmod p. \]

The exponent is determined modulo the order of \(g\). When \(g\) generates the full group, it is determined modulo \(p-1\).

Exponentiation

\[ a\longmapsto g^a \]

is efficient by square-and-multiply, but no efficient classical algorithm is known in appropriately chosen groups for reversing this map. This computational asymmetry is the basis of Diffie–Hellman-type cryptography.

3.10. Why the factorization of the group order matters

The order of the full multiplicative group is

\begin{equation*} |\mathbb{Z}_p^*|=p-1. \end{equation*}

The hardness of discrete logarithms depends strongly on the factorization of \(p-1\). If

\[ p-1 \]

factors entirely into small prime powers, then the discrete logarithm can be reduced to discrete logarithms in much smaller subgroups.

More generally, suppose the relevant group order is

\[ N = \prod_{i=1}^k \ell_i^{e_i}. \]

The Pohlig–Hellman method reduces one discrete logarithm modulo \(N\) to discrete logarithms in subgroups of orders \(\ell_i^{e_i}\). It then uses CRT to reconstruct the exponent modulo \(N\).

Consequently, a group whose order is smooth, meaning that all of its prime factors are small, is unsuitable for discrete-logarithm cryptography. The group order must contain at least one large prime factor.

This is another application of the Chinese Remainder Theorem: CRT recombines the exponent information obtained modulo the relatively prime factors of the group order.

3.11. Safe primes and prime-order subgroups

A common way to obtain a large prime factor is to choose a safe prime

\[ p=2q+1, \]

where \(q\) is also prime.

Then

\begin{equation*} |\mathbb{Z}_p^*|=p-1=2q. \end{equation*}

The full group has one small factor \(2\) and one large prime factor \(q\). Rather than using the whole group, it is often preferable to use a subgroup

\[ H=\langle g\rangle \]

whose order is exactly

\[ \operatorname{ord}(g)=q. \]

Within this subgroup, exponents are taken modulo \(q\), and Pohlig–Hellman cannot decompose the problem into smaller nontrivial prime-order components.

The lecture emphasizes that merely choosing a large prime modulus is not enough. One must also choose the group and generator so that the relevant group order has the desired large prime factor.

3.12. The Computational Diffie–Hellman problem

Let

\[ H=\langle g\rangle \]

be a cyclic group of large prime order \(q\). Choose secret exponents

\[ a,b\leftarrow\mathbb{Z}_q. \]

The Computational Diffie–Hellman problem, abbreviated CDH, is:

Given

\[ g,\quad g^a,\quad g^b, \]

compute

\[ g^{ab}. \]

A formal experiment samples random \(a,b\), gives \((g,g^a,g^b)\) to an adversary \(\mathcal{A}\), and accepts when

\[ \mathcal{A}(g,g^a,g^b)=g^{ab}. \]

The CDH assumption states that for every probabilistic polynomial-time adversary, the success probability is negligible in the security parameter.

If discrete logarithms can be computed efficiently, then CDH can also be solved efficiently: recover \(a\) from \(g^a\), recover \(b\) from \(g^b\), and compute \(g^{ab}\). Thus a discrete-logarithm solver immediately yields a CDH solver.

3.13. The Decisional Diffie–Hellman problem

The Decisional Diffie–Hellman problem, abbreviated DDH, asks whether a fourth group element is the genuine Diffie–Hellman value.

Given

\[ g,\quad g^a,\quad g^b,\quad h, \]

decide whether

\[ h=g^{ab} \]

or whether \(h\) is an independently sampled random element of \(H\).

A standard distinguishing experiment samples

\[ a,b\leftarrow\mathbb{Z}_q \]

and a hidden bit

\[ \beta\leftarrow\{0,1\}. \]

When \(\beta=0\), the challenger sets

\[ h=g^{ab}. \]

When \(\beta=1\), it samples

\[ h\leftarrow H \]

uniformly and independently. It then gives

\[ (g,g^a,g^b,h) \]

to an adversary, which outputs a guess \(\beta'\).

One equivalent definition of the DDH advantage is

\begin{equation*} \operatorname{Adv}^{\mathsf{DDH}}_{\mathcal{A}} = \left| \Pr[\mathcal{A}(g,g^a,g^b,g^{ab})=1] - \Pr[\mathcal{A}(g,g^a,g^b,h)=1] \right|, \end{equation*}

where the second \(h\) is uniform in \(H\).

The DDH assumption states that this advantage is negligible for every probabilistic polynomial-time adversary.

The two distributions are therefore computationally indistinguishable:

\[ (g,g^a,g^b,g^{ab}) \]

and

\[ (g,g^a,g^b,h), \qquad h\leftarrow H. \]

3.14. Relations among DLOG, CDH, and DDH

The three problems are related by straightforward reductions.

A discrete-logarithm solver yields a CDH solver:

\[ \mathsf{CDH}\leq\mathsf{DLOG}. \]

A CDH solver yields a DDH solver: compute \(g^{ab}\) from \((g,g^a,g^b)\) and compare it with \(h\). Therefore,

\[ \mathsf{DDH}\leq\mathsf{CDH}. \]

Together,

\[ \mathsf{DDH} \leq \mathsf{CDH} \leq \mathsf{DLOG}. \]

This notation describes problem reductions: an algorithm for the problem on the right solves the problem on the left.

The corresponding hardness assumptions run in the opposite implication direction:

\[ \text{DDH hard} \Longrightarrow \text{CDH hard} \Longrightarrow \text{DLOG hard}. \]

Therefore, assuming DDH hardness is stronger than merely assuming CDH hardness, and assuming CDH hardness is stronger than merely assuming discrete-logarithm hardness. The converses are not known in general. There are groups in which discrete logarithms appear hard but DDH is easy.

3.15. Exercise left by the lecture

The lecture ends by asking students to investigate DDH in two related settings inside a multiplicative group modulo a prime:

  1. \(g\) generates the entire group \(\mathbb{Z}_p^*\).
  2. \(g\) generates only a proper subgroup, typically a subgroup of large prime order \(q\).

The task is to examine whether the DDH assumption is plausible in each setting and how the order of \(\langle g\rangle\) affects the information visible in a purported Diffie–Hellman tuple.

The transcript leaves this as an exercise rather than presenting the full solution.

4. Consolidated conceptual picture

The two lectures build a continuous chain of ideas.

The Euclidean algorithm computes gcds. Its extended form computes Bézout coefficients. Bézout coefficients compute modular inverses. Modular inverses identify the multiplicative group

\[ \mathbb{Z}_n^*. \]

Inside this finite group, powers form cycles. The cycle length is the order of an element, and the order divides

\begin{equation*} |\mathbb{Z}_n^*|=\varphi(n). \end{equation*}

This yields Euler’s theorem and, for prime moduli, Fermat’s little theorem.

Cyclic groups have generators, so every element can be written as a power of a generator. Computing that power is easy, while recovering the exponent is the discrete logarithm problem.

The Chinese Remainder Theorem connects arithmetic modulo coprime factors with arithmetic modulo their product. It reconstructs integers from residues, accelerates RSA computations, correctly handles modular exponentiation when a base is not invertible modulo the full composite modulus, and appears inside the Pohlig–Hellman reduction.

Finally, the discrete logarithm, CDH, and DDH assumptions formalize three different levels of computational difficulty:

\begin{equation*} \begin{aligned} \mathsf{DLOG}:&\quad g^a\longmapsto a,\\ \mathsf{CDH}:&\quad (g^a,g^b)\longmapsto g^{ab},\\ \mathsf{DDH}:&\quad (g^a,g^b,h)\longmapsto \text{whether }h=g^{ab}. \end{aligned} \end{equation*}

Choosing the modulus alone is insufficient. Secure constructions require a carefully selected cyclic group, usually a large prime-order subgroup, in which the relevant hardness assumption is believed to hold.

Author: Lowtroo

Created on: 2026-08-02 Sun 11:48

Powered by Emacs 29.3 (Org mode 9.6.15)