0% found this document useful (0 votes)
5 views25 pages

Chapter 4

The document discusses number theory, focusing on integers, their properties, and representations such as binary and hexadecimal. It covers key concepts like divisibility, modular arithmetic, and congruences, along with their applications in computer science and cryptography. The document also details algorithms for integer operations and base conversions, emphasizing the importance of different numeral systems.

Uploaded by

yakiciy462
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views25 pages

Chapter 4

The document discusses number theory, focusing on integers, their properties, and representations such as binary and hexadecimal. It covers key concepts like divisibility, modular arithmetic, and congruences, along with their applications in computer science and cryptography. The document also details algorithms for integer operations and base conversions, emphasizing the importance of different numeral systems.

Uploaded by

yakiciy462
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter Motivation

 Number theory is the part of mathematics devoted to the study


of the integers and their properties.
 Key ideas in number theory include divisibility and the primality
of integers.
Chapter 4  Representations of integers, including binary and hexadecimal
representations, are part of number theory.
 Number theory has long been studied because of the beauty of
its ideas, its accessibility, and its wealth of open questions.
With Question/Answer Animations  We’ll use many ideas developed in Chapter 1 about proof
methods and proof strategy in our exploration of number theory.
 Mathematicians have long considered number theory to be pure
mathematics, but it has important applications to computer
science and cryptography studied in Sections 4.5 and 4.6.

Copyright © McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.

Chapter Summary
 Divisibility and Modular Arithmetic
 Integer Representations and Algorithms
 Primes and Greatest Common Divisors
 Solving Congruences Section 4.1
 Applications of Congruences
 Cryptography

1
Section Summary Division
 Division Definition: If a and b are integers with a ≠ 0, then
 Division Algorithm a divides b if there exists an integer c such that b = ac.
 Modular Arithmetic  When a divides b we say that a is a factor or divisor of b
and that b is a multiple of a.
 The notation a | b denotes that a divides b.
 If a | b, then b/a is an integer.
 If a does not divide b, we write a ∤ b.
Example: Determine whether 3 | 7 and whether
3 | 12.

Properties of Divisibility Division Algorithm


Theorem 1: Let a, b, and c be integers, where a ≠0.  When an integer is divided by a positive integer, there is a quotient and
a remainder. This is traditionally called the “Division Algorithm,” but is
i. If a | b and a | c, then a | (b + c); really a theorem.
[Link] a | b, then a | bc for all integers c; Division Algorithm: If a is an integer and d a positive integer, then
If a | b and b | c, then a | c.
iii. there are unique integers q and r, with 0 ≤ r < d, such that a = dq + r
Proof: (i) Suppose a | b and a | c, then it follows that there are (proved in Section 5.2). Definitions of Functions
d is called the divisor.
integers s and t with b = as and c = at. Hence, 
 a is called the dividend.
div and mod
b + c = as + at = a(s + t). Hence, a | (b + c)  q is called the quotient.
q = a div d
(Exercises 3 and 4 ask for proofs of parts (ii) and (iii).)  r is called the remainder.
r = a mod d
Corollary: If a, b, and c be integers, where a ≠0, such that Examples:
What are the quotient and remainder when 101 is divided by 11?
a | b and a | c, then a | mb + nc whenever m and n are 
Solution: The quotient when 101 is divided by 11 is 9 = 101 div 11, and the
integers. remainder is 2 = 101 mod 11.
Can you show how it follows easily from from (ii) and (i) of  What are the quotient and remainder when −11 is divided by 3?
Solution: The quotient when −11 is divided by 3 is −4 = −11 div 3, and the
Theorem 1? remainder is 1 = −11 mod 3.

2
Congruence Relation More on Congruences
Definition: If a and b are integers and m is a positive integer, then a is
congruent to b modulo m if m divides a – b. Theorem 4: Let m be a positive integer. The integers a
 The notation a ≡ b (mod m) says that a is congruent to b modulo m. and b are congruent modulo m if and only if there is
 We say that a ≡ b (mod m) is a congruence and that m is its modulus. an integer k such that a = b + km.
 Two integers are congruent mod m if and only if they have the same
remainder when divided by m. Proof:
 If a is not congruent to b modulo m, we write
a ≢ b (mod m)  If a ≡ b (mod m), then (by the definition of
Example: Determine whether 17 is congruent to 5 modulo 6 and congruence) m | a – b. Hence, there is an integer k such
whether 24 and 14 are congruent modulo 6. that a – b = km and equivalently a = b + km.
Solution:  Conversely, if there is an integer k such that a = b + km,
 17 ≡ 5 (mod 6) because 6 divides 17 − 5 = 12. then km = a – b. Hence, m | a – b and a ≡ b (mod m).
 24 ≢ 14 (mod 6) since 24 − 14 = 10 is not divisible by 6.

The Relationship between


(mod m) and mod m Notations Congruences of Sums and Products
 The use of “mod” in a ≡ b (mod m) and a mod m = b Theorem 5: Let m be a positive integer. If a ≡ b (mod m) and c
≡ d (mod m), then
are different. a + c ≡ b + d (mod m) and ac ≡ bd (mod m)
 a ≡ b (mod m) is a relation on the set of integers. Proof:
 Because a ≡ b (mod m) and c ≡ d (mod m), by Theorem 4 there
 In a mod m = b, the notation mod denotes a function. are integers s and t with b = a + sm and d = c + tm.
 The relationship between these notations is made  Therefore,
b + d = (a + sm) + (c + tm) = (a + c) + m(s + t) and
clear in this theorem.

 b d = (a + sm) (c + tm) = ac + m(at + cs + stm).
 Theorem 3: Let a and b be integers, and let m be a  Hence, a + c ≡ b + d (mod m) and ac ≡ bd (mod m).
Example: Because 7 ≡ 2 (mod 5) and 11 ≡ 1 (mod 5) , it
positive integer. Then a ≡ b (mod m) if and only if follows from Theorem 5 that
a mod m = b mod m. (Proof in the exercises) 18 = 7 + 11 ≡ 2 + 1 = 3 (mod 5)
77 = 7 ∙ 11 ≡ 2 ∙ 1 = 2 (mod 5)

3
Computing the mod m Function of
Algebraic Manipulation of Congruences Products and Sums
 Multiplying both sides of a valid congruence by an integer  We use the following corollary to Theorem 5 to
preserves validity.
If a ≡ b (mod m) holds then c∙a ≡ c∙b (mod m), where c is any
compute the remainder of the product or sum of two
integer, holds by Theorem 5 with d = c. integers when divided by m from the remainders when
 Adding an integer to both sides of a valid congruence preserves each is divided by m.
validity.
If a ≡ b (mod m) holds then c + a ≡ c + b (mod m), where c is any
Corollary: Let m be a positive integer and let a and b
integer, holds by Theorem 5 with d = c. be integers. Then
 Dividing a congruence by an integer does not always produce a (a + b) (mod m) = ((a mod m) + (b mod m)) mod m
valid congruence.
Example: The congruence 14≡ 8 (mod 6) holds. But dividing and
both sides by 2 does not produce a valid congruence since ab mod m = ((a mod m) (b mod m)) mod m.
14/2 = 7 and 8/2 = 4, but 7≢4 (mod 6).
See Section 4.3 for conditions when division is ok. (proof in text)

Arithmetic Modulo m
Definitions: Let Zm be the set of nonnegative integers less
than m: {0,1, …., m−1}
 The operation +m is defined as a +m b = (a + b) mod m.
This is addition modulo m.
 The operation ∙m is defined as a ∙m b = (a ∙ b) mod m. This Section 4.2
is multiplication modulo m.
 Using these operations is said to be doing arithmetic
modulo m.
Example: Find 7 +11 9 and 7 ∙11 9.
Solution: Using the definitions above:
 7 +11 9 = (7 + 9) mod 11 = 16 mod 11 = 5
 7 ∙11 9 = (7 ∙ 9) mod 11 = 63 mod 11 = 8

4
Section Summary Representations of Integers
 In the modern world, we use decimal, or base 10,
 Integer Representations notation to represent integers. For example when we
 Base b Expansions write 965, we mean 9∙102 + 6∙101 + 5∙100 .
 Binary Expansions  We can represent numbers using any base b, where b
 Octal Expansions
is a positive integer greater than 1.
 Hexadecimal Expansions  The bases b = 2 (binary), b = 8 (octal) , and b= 16
(hexadecimal) are important for computing and
 Base Conversion Algorithm
communications
 Algorithms for Integer Operations
 The ancient Mayans used base 20 and the ancient
Babylonians used base 60.

Base b Representations Binary Expansions


 We can use positive integer b greater than 1 as a base, because of Most computers represent integers and do arithmetic with
this theorem: binary (base 2) expansions of integers. In these
Theorem 1: Let b be a positive integer greater than 1. Then if n expansions, the only digits used are 0 and 1.
is a positive integer, it can be expressed uniquely in the form:
n = akbk + ak-1bk-1 + …. + a1b + a0 Example: What is the decimal expansion of the integer that
where k is a nonnegative integer, a0,a1,…. ak are nonnegative has (1 0101 1111)2 as its binary expansion?
integers less than b, and ak≠ 0. The aj, j = 0,…,k are called the Solution:
base-b digits of the representation.
(1 0101 1111)2 = 1∙28 + 0∙27 + 1∙26 + 0∙25 + 1∙24 + 1∙23
(We will prove this using mathematical induction in Section 5.1.)
+ 1∙22 + 1∙21 + 1∙20 =351.
 The representation of n given in Theorem 1 is called the base b
expansion of n and is denoted by (akak-1….a1a0)b. Example: What is the decimal expansion of the integer that
 We usually omit the subscript 10 for base 10 expansions. has (11011)2 as its binary expansion?
Solution: (11011)2 = 1 ∙24 + 1∙23 + 0∙22 + 1∙21 + 1∙20 =27.

5
Octal Expansions Hexadecimal Expansions
The octal expansion (base 8) uses the digits The hexadecimal expansion needs 16 digits, but our
decimal system provides only 10. So letters are used for the
{0,1,2,3,4,5,6,7}. additional symbols. The hexadecimal system uses the
Example: What is the decimal expansion of the digits {0,1,2,3,4,5,6,7,8,9,A,B,C,D,E,F}. The letters A
through F represent the decimal numbers 10 through 15.
number with octal expansion (7016)8 ?
Example: What is the decimal expansion of the number
Solution: 7∙83 + 0∙82 + 1∙81 + 6∙80 =3598 with hexadecimal expansion (2AE0B)16 ?
Example: What is the decimal expansion of the Solution:
number with octal expansion (111)8 ? 2∙164 + 10∙163 + 14∙162 + 0∙161 + 11∙160 =175627
Example: What is the decimal expansion of the number
Solution: 1∙82 + 1∙81 + 1∙80 = 64 + 8 + 1 = 73 with hexadecimal expansion (E5)16 ?
Solution: 14∙161 + 5∙160 = 224 + 5 = 229

Base Conversion Algorithm: Constructing Base b Expansions


procedure base b expansion(n, b: positive integers with b > 1)
To construct the base b expansion of an integer n: q := n
 Divide n by b to obtain a quotient and remainder. k := 0
n = bq0 + a0 0 ≤ a0 ≤ b while (q ≠ 0)
ak := q mod b
 The remainder, a0 , is the rightmost digit in the base b q := q div b
k := k + 1
expansion of n. Next, divide q0 by b. return(ak-1 ,…, a1,a0){(ak-1 … a1a0)b is base b expansion of n}
q0 = bq1 + a1 0 ≤ a1 ≤ b
 The remainder, a1, is the second digit from the right in
the base b expansion of n.  q represents the quotient obtained by successive divisions
by b, starting with q = n.
 Continue by successively dividing the quotients by b,
obtaining the additional base b digits as the remainder.  The digits in the base b expansion are the remainders of the
division given by q mod b.
The process terminates when the quotient is 0.
 The algorithm terminates when q = 0 is reached.
continued →

6
Comparison of Hexadecimal, Octal,
Base Conversion and Binary Representations
Example: Find the octal expansion of (12345)10
Solution: Successively dividing by 8 gives:
 12345 = 8 ∙ 1543 + 1
 1543 = 8 ∙ 192 + 7
 192 = 8 ∙ 24 + 0
 24 = 8 ∙ 3 + 0 Initial 0s are not shown
 3 =8∙0+3 Each octal digit corresponds to a block of 3 binary digits.
The remainders are the digits from right to left Each hexadecimal digit corresponds to a block of 4 binary digits.
So, conversion between binary, octal, and hexadecimal is easy.
yielding (30071)8.

Conversion Between Binary, Octal,


and Hexadecimal Expansions Binary Addition of Integers
Example: Find the octal and hexadecimal expansions  Algorithms for performing operations with integers using
of (11 1110 1011 1100)2. their binary expansions are important as computer chips
work with binary numbers. Each digit is called a bit.
Solution: procedure add(a, b: positive integers)
 To convert to octal, we group the digits into blocks of {the binary expansions of a and b are (an-1,an-2,…,a0)2 and (bn-1,bn-2,…,b0)2, respectively}
three (011 111 010 111 100)2, adding initial 0s as c := 0
needed. The blocks from left to right correspond to the for j := 0 to n − 1
digits 3,7,2,7, and 4. Hence, the solution is (37274)8. d := ⌊(aj + bj + c)/2⌋
sj := aj + bj + c − 2d
 To convert to hexadecimal, we group the digits into c := d
blocks of four (0011 1110 1011 1100)2, adding initial 0s sn := c
as needed. The blocks from left to right correspond to return(s0,s1,…, sn){the binary expansion of the sum is (sn,sn-1,…,s0)2}
the digits 3,E,B, and C. Hence, the solution is (3EBC)16.
 The number of additions of bits used by the algorithm to
add two n-bit integers is O(n).

7
Binary Multiplication of Integers Binary Modular Exponentiation
 Algorithm for computing the product of two n bit  In cryptography, it is important to be able to find bn mod m
efficiently, where b, n, and m are large integers.
integers.  Use the binary expansion of n, n = (ak-1,…,a1,ao)2 , to compute bn .
procedure multiply(a, b: positive integers)
{the binary expansions of a and b are (an-1,an-2,…,a0)2 and (bn-1,bn-2,…,b0)2, respectively} Note that:
for j := 0 to n − 1
if bj = 1 then cj = a shifted j places
else cj := 0  Therefore, to compute bn, we need only compute the values of
{co,c1,…, cn-1 are the partial products}
p := 0
b, b2, (b2)2 = b4, (b4)2 = b8 , …, and the multiply the terms
for j := 0 to n − 1
in this list, where aj = 1.
p := p + cj
return p {p is the value of ab}
Example: Compute 311 using this method.
 The number of additions of bits used by the algorithm Solution: Note that 11 = (1011)2 so that 311 = 38 32 31 =
to multiply two n-bit integers is O(n2). ((32)2 )2 32 31 = (92 )2 ∙ 9 ∙3 = (81)2 ∙ 9 ∙3 =6561 ∙ 9 ∙3 =117,147.
continued →

Binary Modular Exponentiation


Algorithm
 The algorithm successively finds b mod m, b2 mod m,
b4 mod m, …, mod m, and multiplies together the
terms where aj = 1.

procedure modular exponentiation(b: integer, n = (ak-1ak-2…a1a0)2 , m: positive Section 4.3


integers)
x := 1
power := b mod m
for i := 0 to k − 1
if ai= 1 then x := (x∙ power ) mod m
power := (power∙ power ) mod m
return x {x equals bn mod m }

 O((log m )2 log n) bit operations are used to find bn mod m.

8
Section Summary Primes
Definition: A positive integer p greater than 1 is
 Prime Numbers and their Properties called prime if the only positive factors of p are 1 and
 Conjectures and Open Problems About Primes p. A positive integer that is greater than 1 and is not
prime is called composite.
 Greatest Common Divisors and Least Common
Multiples
 The Euclidian Algorithm Example: The integer 7 is prime because its only
positive factors are 1 and 7, but 9 is composite
 gcds as Linear Combinations
because it is divisible by 3.

Erastothenes
The Fundamental Theorem of (276-194 B.C.)

Arithmetic The Sieve of Erastosthenes


Theorem: Every positive integer greater than 1 can be  The Sieve of Erastosthenes can be used to find all primes
written uniquely as a prime or as the product of two or not exceeding a specified positive integer. For example,
more primes where the prime factors are written in begin with the list of integers between 1 and 100.
order of nondecreasing size. a. Delete all the integers, other than 2, divisible by 2.
b. Delete all the integers, other than 3, divisible by 3.
Examples:
c. Next, delete all the integers, other than 5, divisible by 5.
 100 = 2 ∙ 2 ∙ 5 ∙ 5 = 22 ∙ 52
d. Next, delete all the integers, other than 7, divisible by 7.
 641 = 641
e. Since all the remaining integers are not divisible by any of
 999 = 3 ∙ 3 ∙ 3 ∙ 37 = 33 ∙ 37 the previous integers, other than 1, the primes are:
 1024 = 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 ∙ 2 = 210 {2,3,5,7,11,15,1719,23,29,31,37,41,43,47,53,
59,61,67,71,73,79,83,89, 97}
continued →

9
The Sieve of Erastosthenes Infinitude of Primes Euclid
(325 B.C.E. – 265 B.C.E.)
If an integer n is a
composite integer, then it Theorem: There are infinitely many primes. (Euclid)
has a prime divisor less than Proof: Assume finitely many primes: p1, p2, ….., pn
or equal to √n.  Let q = p1p2∙∙∙ pn + 1
 Either q is prime or by the fundamental theorem of arithmetic it is a
To see this, note that if n =
product of primes.
ab, then a ≤ √n or b ≤√n.
 But none of the primes pj divides q since if pj | q, then pj divides
q − p1p2∙∙∙ pn = 1 .
Trial division, a very  Hence, there is a prime not on the list p1, p2, ….., pn. It is either q, or if q is

inefficient method of composite, it is a prime factor of q. This contradicts the assumption that
determining if a number n p1, p2, ….., pn are all the primes.
is prime, is to try every  Consequently, there are infinitely many primes.
integer i ≤√n and see if n is This proof was given by Euclid The Elements. The proof is considered to be one of
divisible by i. the most beautiful in all mathematics. It is the first proof in The Book, inspired by
the famous mathematician Paul Erdős’ imagined collection of perfect proofs
Paul Erdős
maintained by God.
(1913-1996)

Marin Mersenne
(1588-1648)

Mersene Primes Distribution of Primes


Definition: Prime numbers of the form 2p − 1 , where p is  Mathematicians have been interested in the distribution of
prime, are called Mersene primes. prime numbers among the positive integers. In the
 22 − 1 = 3, 23 − 1 = 7, 25 − 1 = 37 , and 27 − 1 = 127 are nineteenth century, the prime number theorem was proved
Mersene primes. which gives an asymptotic estimate for the number of
 211 − 1 = 2047 is not a Mersene prime since 2047 = 23∙89. primes not exceeding x.
 There is an efficient test for determining if 2p − 1 is prime.
Prime Number Theorem: The ratio of the number of
 The largest known prime numbers are Mersene primes.
primes not exceeding x and x/ln x approaches 1 as x grows
 As of mid 2011, 47 Mersene primes were known, the largest
is 243,112,609 − 1, which has nearly 13 million decimal digits. without bound. (ln x is the natural logarithm of x)
 The Great Internet Mersene Prime Search (GIMPS) is a  The theorem tells us that the number of primes not exceeding
distributed computing project to search for new Mersene x, can be approximated by x/ln x.
Primes.  The odds that a randomly selected positive integer less than n
[Link] is prime are approximately (n/ln n)/n = 1/ln n.

10
Primes and Arithmetic Progressions
(optional) Generating Primes
 Euclid’s proof that there are infinitely many primes can be easily  The problem of generating large primes is of both theoretical and
adapted to show that there are infinitely many primes in the following practical interest.
4k + 3, k = 1,2,… (See Exercise 55)  We will see (in Section 4.6) that finding large primes with hundreds of
 In the 19th century G. Lejuenne Dirchlet showed that every arithmetic digits is important in cryptography.
progression ka + b, k = 1,2, …, where a and b have no common factor  So far, no useful closed formula that always produces primes has been
greater than 1 contains infinitely many primes. (The proof is beyond found. There is no simple function f(n) such that f(n) is prime for all
the scope of the text.) positive integers n.
 Are there long arithmetic progressions made up entirely of primes?  But f(n) = n2 − n + 41 is prime for all integers 1,2,…, 40. Because of
 5,11, 17, 23, 29 is an arithmetic progression of five primes. this, we might conjecture that f(n) is prime for all positive integers n.
 199, 409, 619, 829, 1039,1249,1459,1669,1879,2089 is an arithmetic But f(41) = 412 is not prime.
progression of ten primes.  More generally, there is no polynomial with integer coefficients such
 In the 1930s, Paul Erdős conjectured that for every positive integer n that f(n) is prime for all positive integers n. (See supplementary
greater than 1, there is an arithmetic progression of length n made up Exercise 23.)
entirely of primes. This was proven in 2006, by Ben Green and Terrence  Fortunately, we can generate large integers which are almost certainly
Tau. primes. See Chapter 7.
Terence Tao
(Born 1975)

Conjectures about Primes Greatest Common Divisor


 Even though primes have been studied extensively for centuries, many Definition: Let a and b be integers, not both zero. The
conjectures about them are unresolved, including: largest integer d such that d | a and also d | b is called the
 Goldbach’s Conjecture: Every even integer n, n > 2, is the sum of two greatest common divisor of a and b. The greatest common
primes. It has been verified by computer for all positive even integers divisor of a and b is denoted by gcd(a,b).
up to 1.6 ∙1018. The conjecture is believed to be true by most
mathematicians.
 There are infinitely many primes of the form n2 + 1, where n is a One can find greatest common divisors of small numbers
positive integer. But it has been shown that there are infinitely many by inspection.
primes of the form n2 + 1, where n is a positive integer or the product
of at most two primes. Example:What is the greatest common divisor of 24 and
 The Twin Prime Conjecture: The twin prime conjecture is that there are 36?
infinitely many pairs of twin primes. Twin primes are pairs of primes
that differ by 2. Examples are 3 and 5, 5 and 7, 11 and 13, etc. The
Solution: gcd(24, 36) = 12
current world’s record for twin primes (as of mid 2011) consists of Example:What is the greatest common divisor of 17 and
numbers 65,516,468,355∙2333,333 ±1, which have 100,355 decimal 22?
digits.
Solution: gcd(17,22) = 1

11
Greatest Common Divisor Greatest Common Divisor
Definition: The integers a and b are relatively prime if their Definition: The integers a and b are relatively prime if their
greatest common divisor is 1. greatest common divisor is 1.
Example: 17 and 22 Example: 17 and 22
Definition: The integers a1, a2, …, an are pairwise relatively prime Definition: The integers a1, a2, …, an are pairwise relatively prime
if gcd(ai, aj)= 1 whenever 1 ≤ i<j ≤n. if gcd(ai, aj)= 1 whenever 1 ≤ i<j ≤n.
Example: Determine whether the integers 10, 17 and 21 are Example: Determine whether the integers 10, 17 and 21 are
pairwise relatively prime. pairwise relatively prime.
Solution: Because gcd(10,17) = 1, gcd(10,21) = 1, and Solution: Because gcd(10,17) = 1, gcd(10,21) = 1, and
gcd(17,21) = 1, 10, 17, and 21 are pairwise relatively prime. gcd(17,21) = 1, 10, 17, and 21 are pairwise relatively prime.
Example: Determine whether the integers 10, 19, and 24 are Example: Determine whether the integers 10, 19, and 24 are
pairwise relatively prime. pairwise relatively prime.
Solution: Because gcd(10,24) = 2, 10, 19, and 24 are not Solution: Because gcd(10,24) = 2, 10, 19, and 24 are not
pairwise relatively prime. pairwise relatively prime.

Finding the Greatest Common Divisor


Using Prime Factorizations Least Common Multiple
 Suppose the prime factorizations of a and b are: Definition: The least common multiple of the positive integers a and b
is the smallest positive integer that is divisible by both a and b. It is
denoted by lcm(a,b).
where each exponent is a nonnegative integer, and where all primes  The least common multiple can also be computed from the prime
occurring in either prime factorization are included in both. Then: factorizations.

 This formula is valid since the integer on the right (of the equals sign) This number is divided by both a and b and no smaller number is
divides both a and b. No larger integer can divide both a and b. divided by a and b.
Example: 120 = 23 ∙3 ∙5 500 = 22 ∙53 Example: lcm(233572, 2433) = 2max(3,4) 3max(5,3) 7max(2,0) = 24 35 72
gcd(120,500) = 2min(3,2) ∙3min(1,0) ∙5min(1,3) = 22 ∙30 ∙51 = 20  The greatest common divisor and the least common multiple of two
integers are related by:
 Finding the gcd of two positive integers using their prime factorizations
is not efficient because there is no efficient algorithm for finding the Theorem 5: Let a and b be positive integers. Then
prime factorization of a positive integer. ab = gcd(a,b) ∙lcm(a,b)
(proof is Exercise 31)

12
Euclidean Algorithm Euclid
(325 B.C.E. – 265 B.C.E.)
Euclidean Algorithm
 The Euclidian algorithm is an efficient method for  The Euclidean algorithm expressed in pseudocode is:
computing the greatest common divisor of two integers. It procedure gcd(a, b: positive integers)
is based on the idea that gcd(a,b) is equal to gcd(a,c) when x := a
a > b and c is the remainder when a is divided by b. y := b
while y ≠ 0
Example: Find gcd(91, 287): r := x mod y
 287 = 91 ∙ 3 + 14 x := y
Divide 287 by 91 y := r
 91 = 14 ∙ 6 + 7 Divide 91 by 14 return x {gcd(a,b) is x}
 14 = 7 ∙ 2 + 0 Divide 14 by 7
Stopping
condition
 In Section 5.3, we’ll see that the time complexity of the
gcd(287, 91) = gcd(91, 14) = gcd(14, 7) = 7 algorithm is O(log b), where a > b.
continued →

Correctness of Euclidean Algorithm Correctness of Euclidean Algorithm


 Suppose that a and b are positive
Lemma 1: Let a = bq + r, where a, b, q, and r are integers with a ≥ b.
r0 = r1q1 + r2 0 ≤ r2 < r1,
r1 = r2q2 + r3 0 ≤ r3 < r2,
integers. Then gcd(a,b) = gcd(b,r). Let r0 = a and r1 = b. ∙
Successive applications of the division
Proof: algorithm yields:


 Suppose that d divides both a and b. Then d also divides rn-2 = rn-1qn-1 + r2 0 ≤ rn < rn-1,
a − bq = r (by Theorem 1 of Section 4.1). Hence, any rn-1 = rnqn .
common divisor of a and b must also be any common
divisor of b and r.  Eventually, a remainder of zero occurs in the sequence of terms: a = r0 > r1 > r2 > ∙ ∙ ∙ ≥ 0.
The sequence can’t contain more than a terms.
 Suppose that d divides both b and r. Then d also divides  By Lemma 1
bq + r = a. Hence, any common divisor of a and b must gcd(a,b) = gcd(r0,r1) = ∙ ∙ ∙ = gcd(rn-1,rn) = gcd(rn , 0) = rn.
also be a common divisor of b and r.  Hence the greatest common divisor is the last nonzero remainder in the sequence of
divisions.
 Therefore, gcd(a,b) = gcd(b,r).

13
Étienne Bézout
(1730-1783)

gcds as Linear Combinations Finding gcds as Linear Combinations


Bézout’s Theorem: If a and b are positive integers, then Example: Express gcd(252,198) = 18 as a linear combination of 252 and 198.
there exist integers s and t such that gcd(a,b) = sa + tb. Solution: First use the Euclidean algorithm to show gcd(252,198) = 18
i. 252 = 1∙198 + 54
(proof in exercises of Section 5.2) ii. 198 = 3 ∙54 + 36
Definition: If a and b are positive integers, then integers s iii. 54 = 1 ∙36 + 18
36 = 2 ∙18
and t such that gcd(a,b) = sa + tb are called Bézout
iv.
 Now working backwards, from iii and i above
coefficients of a and b. The equation gcd(a,b) = sa + tb is  18 = 54 − 1 ∙36

called Bézout’s identity.  36 = 198 − 3 ∙54


 Substituting the 2nd equation into the 1st yields:
 By Bézout’s Theorem, the gcd of integers a and b can be  18 = 54 − 1 ∙(198 − 3 ∙54 )= 4 ∙54 − 1 ∙198
expressed in the form sa + tb where s and t are integers.  Substituting 54 = 252 − 1 ∙198 (from i)) yields:
This is a linear combination with integer coefficients of a  18 = 4 ∙(252 − 1 ∙198) − 1 ∙198 = 4 ∙252 − 5 ∙198
and b.  This method illustrated above is a two pass method. It first uses the Euclidian
algorithm to find the gcd and then works backwards to express the gcd as a
 gcd(6,14) = (−2)∙6 + 1∙14 linear combination of the original two integers. A one pass method, called the
extended Euclidean algorithm, is developed in the exercises.

Consequences of Bézout’s Theorem Uniqueness of Prime Factorization


Lemma 2: If a, b, and c are positive integers such that gcd(a, b) = 1 and a | bc,  We will prove that a prime factorization of a positive integer where the primes
then a | c. are in nondecreasing order is unique. (This part of the fundamental theorem of
Proof: Assume gcd(a, b) = 1 and a | bc arithmetic. The other part, which asserts that every positive integer has a prime
 Since gcd(a, b) = 1, by Bézout’s Theorem there are integers s and t such that
factorization into primes, will be proved in Section 5.2.)
sa + tb = 1. Proof: (by contradiction) Suppose that the positive integer n can be written as a
product of primes in two distinct ways:
 Multiplying both sides of the equation by c, yields sac + tbc = c.
 From Theorem 1 of Section 4.1:
n = p1p2 ∙∙∙ ps and n = q1q2 ∙∙∙ pt.
a | tbc (part ii) and a divides sac + tbc since a | sac and a|tbc (part i)  Remove all common primes from the factorizations to get
 We conclude a | c, since sac + tbc = c.

Lemma 3: If p is prime and p | a1a2∙∙∙an, then p | ai for some i.  By Lemma 3, it follows that divides , for some k, contradicting the
assumption that and are distinct primes.
(proof uses mathematical induction; see Exercise 64 of Section 5.1)

 Lemma 3 is crucial in the proof of the uniqueness of prime factorizations.  Hence, there can be at most one factorization of n into primes in nondecreasing
order.

14
Dividing Congruences by an Integer
 Dividing both sides of a valid congruence by an integer
does not always produce a valid congruence (see
Section 4.1).
 But dividing by an integer relatively prime to the
Section 4.4
modulus does produce a valid congruence:
Theorem 7: Let m be a positive integer and let a, b,
and c be integers. If ac ≡ bc (mod m) and gcd(c,m) = 1,
then a ≡ b (mod m).
Proof: Since ac ≡ bc (mod m), m | ac − bc = c(a − b)
by Lemma 2 and the fact that gcd(c,m) = 1, it follows
that m | a − b. Hence, a ≡ b (mod m).

Section Summary Linear Congruences


Definition: A congruence of the form
ax ≡ b( mod m),
 Linear Congruences where m is a positive integer, a and b are integers, and x is a variable, is
called a linear congruence.
 The Chinese Remainder Theorem
 Computer Arithmetic with Large Integers (not  The solutions to a linear congruence ax≡ b( mod m) are all integers x
that satisfy the congruence.
currently included in slides, see text)
 Fermat’s Little Theorem Definition: An integer ā such that āa ≡ 1( mod m) is said to be an
inverse of a modulo m.
 Pseudoprimes Example: 5 is an inverse of 3 modulo 7 since 5∙3 = 15 ≡ 1(mod 7)

 Primitive Roots and Discrete Logarithms  One method of solving linear congruences makes use of an inverse ā,
if it exists. Although we can not divide both sides of the congruence by
a, we can multiply by ā to solve for x.

15
Inverse of a modulo m Finding Inverses
 The following theorem guarantees that an inverse of a modulo m exists  The Euclidean algorithm and Bézout coefficients gives us a
whenever a and m are relatively prime. Two integers a and b are
relatively prime when gcd(a,b) = 1. systematic approaches to finding inverses.
Theorem 1: If a and m are relatively prime integers and m > 1, then an Example: Find an inverse of 3 modulo 7.
inverse of a modulo m exists. Furthermore, this inverse is unique
modulo m. (This means that there is a unique positive integer ā less Solution: Because gcd(3,7) = 1, by Theorem 1, an inverse
than m that is an inverse of a modulo m and every other inverse of a
modulo m is congruent to ā modulo m.) of 3 modulo 7 exists.
Proof: Since gcd(a,m) = 1, by Theorem 6 of Section 4.3, there are  Using the Euclidian algorithm: 7 = 2∙3 + 1.
integers s and t such that sa + tm = 1.
 Hence, sa + tm ≡ 1 ( mod m).  From this equation, we get −2∙3 + 1∙7 = 1, and see that −2
 Since tm ≡ 0 ( mod m), it follows that sa ≡ 1 ( mod m) and 1 are Bézout coefficients of 3 and 7.
 Consequently, s is an inverse of a modulo m.  Hence, −2 is an inverse of 3 modulo 7.
 The uniqueness of the inverse is Exercise 7.
 Also every integer congruent to −2 modulo 7 is an inverse of
3 modulo 7, i.e., 5, −9, 12, etc.

Finding Inverses Using Inverses to Solve Congruences


 We can solve the congruence ax≡ b( mod m) by multiplying both
Example: Find an inverse of 101 modulo 4620. sides by ā.
Solution: First use the Euclidian algorithm to show that Example: What are the solutions of the congruence 3x≡ 4( mod 7).
gcd(101,4620) = 1. Working Backwards: Solution: We found that −2 is an inverse of 3 modulo 7 (two slides
back). We multiply both sides of the congruence by −2 giving
42620 = 45∙101 + 75 1 = 3 − 1∙2
1 = 3 − 1∙(23 − 7∙3) = − 1 ∙23 + 8∙3 −2 ∙ 3x ≡ −2 ∙ 4(mod 7).
101 = 1∙75 + 26
1 = −1∙23 + 8∙(26 − 1∙23) = 8∙26 − 9 ∙23 Because −6 ≡ 1 (mod 7) and −8 ≡ 6 (mod 7), it follows that if x is a
75 = 2∙26 + 23
1 = 8∙26 − 9 ∙(75 − 2∙26 )= 26∙26 − 9 ∙75 solution, then x ≡ −8 ≡ 6 (mod 7)
26 = 1∙23 + 3
1 = 26∙(101 − 1∙75) − 9 ∙75 We need to determine if every x with x ≡ 6 (mod 7) is a solution.
23 = 7∙3 + 2
= 26∙101 − 35 ∙75 Assume that x ≡ 6 (mod 7). By Theorem 5 of Section 4.1, it follows
3 = 1∙2 + 1 that 3x ≡ 3 ∙ 6 = 18 ≡ 4( mod 7) which shows that all such x satisfy the
2 = 2∙1 1 = 26∙101 − 35 ∙(42620 − 45∙101)
congruence.
Since the last nonzero = − 35 ∙42620 + 1601∙101
The solutions are the integers x such that x ≡ 6 (mod 7), namely,
remainder is 1, Bézout coefficients : − 35 and 1601 1601 is an inverse of
101 modulo 42620 6,13,20 … and −1, − 8, − 15,…
gcd(101,4260) = 1

16
The Chinese Remainder Theorem The Chinese Remainder Theorem
 In the first century, the Chinese mathematician Sun-Tsu asked: Theorem 2: (The Chinese Remainder Theorem) Let m1,m2,…,mn be pairwise
relatively prime positive integers greater than one and a1,a2,…,an arbitrary
There are certain things whose number is unknown. When divided integers. Then the system
by 3, the remainder is 2; when divided by 5, the remainder is 3; x ≡ a1 ( mod m1)
when divided by 7, the remainder is 2. What will be the number of x ≡ a2 ( mod m2)
things? ∙
 This puzzle can be translated into the solution of the system of ∙

congruences: x ≡ an ( mod mn)
x ≡ 2 ( mod 3), has a unique solution modulo m = m1m2 ∙ ∙ ∙ mn.
x ≡ 3 ( mod 5), (That is, there is a solution x with 0 ≤ x <m and all other solutions are
congruent modulo m to this solution.)
x ≡ 2 ( mod 7)?
 We’ll see how the theorem that is known as the Chinese  Proof: We’ll show that a solution exists by describing a way to construct the
Remainder Theorem can be used to solve Sun-Tsu’s problem. solution. Showing that the solution is unique modulo m is Exercise 30.

continued →

The Chinese Remainder Theorem The Chinese Remainder Theorem


To construct a solution first let Mk=m/mk for k = 1,2,…,n and m = m1m2 ∙ ∙ ∙ mn. Example: Consider the 3 congruences from Sun-Tsu’s problem:
Since gcd(mk ,Mk ) = 1, by Theorem 1, there is an integer yk , an inverse of Mk modulo x ≡ 2 ( mod 3), x ≡ 3 ( mod 5), x ≡ 2 ( mod 7).
mk, such that  Let m = 3∙ 5 ∙ 7 = 105, M1 = m/3 = 35, M3 = m/5 = 21,
Mk yk ≡ 1 ( mod mk ). M3 = m/7 = 15.
Form the sum
 We see that
x = a 1 M 1 y1 + a 2 M 2 y2 + ∙ ∙ ∙ + a n M n yn .
 2 is an inverse of M1 = 35 modulo 3 since 35 ∙ 2 ≡ 2 ∙ 2 ≡ 1 (mod 3)
Note that because Mj ≡ 0 ( mod mk) whenever j ≠k , all terms except the kth term in this sum  1 is an inverse of M2 = 21 modulo 5 since 21 ≡ 1 (mod 5)
are congruent to 0 modulo mk .  1 is an inverse of M3 = 15 modulo 7 since 15 ≡ 1 (mod 7)
Because Mk yk ≡ 1 ( mod mk ), we see that x ≡ ak Mk yk ≡ ak( mod mk), for k = 1,2,…,n.
Hence, x is a simultaneous solution to the n congruences.  Hence,
x ≡ a1 ( mod m1) x = a1M1y1 + a2M2y2 + a3M3y3
x ≡ a2 ( mod m2) = 2 ∙ 35 ∙ 2 + 3 ∙ 21 ∙ 1 + 2 ∙ 15 ∙ 1 = 233 ≡ 23 (mod 105)


∙  We have shown that 23 is the smallest positive integer that is a
x ≡ an ( mod mn) simultaneous solution. Check it!

17
Back Substitution Fermat’s Little Theorem Pierre de Fermat
(1601-1665)
 We can also solve systems of linear congruences with pairwise relatively prime moduli by Theorem 3: (Fermat’s Little Theorem) If p is prime and a is an integer not
rewriting a congruences as an equality using Theorem 4 in Section 4.1, substituting the divisible by p, then ap-1 ≡ 1 (mod p)
value for the variable into another congruence, and continuing the process until we have
worked through all the congruences. This method is known as back substitution. Furthermore, for every integer a we have ap ≡ a (mod p)
Example: Use the method of back substitution to find all integers x such that x ≡ 1 (proof outlined in Exercise 19)
(mod 5), x ≡ 2 (mod 6), and x ≡ 3 (mod 7).
Solution: By Theorem 4 in Section 4.1, the first congruence can be rewritten as x = 5t +1, Fermat’s little theorem is useful in computing the remainders modulo p of
where t is an integer. large powers of integers.
 Substituting into the second congruence yields 5t +1 ≡ 2 (mod 6).
 Solving this tells us that t ≡ 5 (mod 6). Example: Find 7222 mod 11.
 Using Theorem 4 again gives t = 6u + 5 where u is an integer. By Fermat’s little theorem, we know that 710 ≡ 1 (mod 11), and so (710 )k ≡ 1
 Substituting this back into x = 5t +1, gives x = 5(6u + 5) +1 = 30u + 26. (mod 11), for every positive integer k. Therefore,
 Inserting this into the third equation gives 30u + 26 ≡ 3 (mod 7).
 Solving this congruence tells us that u ≡ 6 (mod 7). 7222 = 722∙10 + 2 = (710)2272 ≡ (1)22 ∙49 ≡ 5 (mod 11).
 By Theorem 4, u = 7v + 6, where v is an integer.
 Substituting this expression for u into x = 30u + 26, tells us that x = 30(7v + 6) + 26 =
210u + 206. Hence, 7222 mod 11 = 5.
Translating this back into a congruence we find the solution x ≡ 206 (mod 210).

Pseudoprimes Pseudoprimes
 By Fermat’s little theorem n > 2 is prime, where  Given a positive integer n, such that 2n-1 ≡ 1 (mod n):
2n-1 ≡ 1 (mod n).  If n does not satisfy the congruence, it is composite.
 But if this congruence holds, n may not be prime.  If n does satisfy the congruence, it is either prime or a
Composite integers n such that 2n-1 ≡ 1 (mod n) are called pseudoprime to the base 2.
pseudoprimes to the base 2.  Doing similar tests with additional bases b, provides more
Example: The integer 341 is a pseudoprime to the base 2. evidence as to whether n is prime.
341 = 11 ∙ 31
 Among the positive integers not exceeding a positive real
2340 ≡ 1 (mod 341) (see in Exercise 37)
number x, compared to primes, there are relatively few
 We can replace 2 by any integer b ≥ 2. pseudoprimes to the base b.
Definition: Let b be a positive integer. If n is a composite
 For example, among the positive integers less than 1010 there
integer, and bn-1 ≡ 1 (mod n), then n is called a
pseudoprime to the base b. are 455,052,512 primes, but only 14,884 pseudoprimes to the
base 2.

18
Carmichael Numbers
(optional) Robert Carmichael
(1879-1967)
Primitive Roots
 There are composite integers n that pass all tests with bases b such that gcd(b,n) = 1.
Definition: A composite integer n that satisfies the congruence bn-1 ≡ 1 (mod n) for all
Definition: A primitive root modulo a prime p is an
positive integers b with gcd(b,n) = 1 is called a Carmichael number. integer r in Zp such that every nonzero element of Zp is a
Example: The integer 561 is a Carmichael number. To see this: power of r.
 561 is composite, since 561 = 3 ∙ 11 ∙ 13.
 If gcd(b, 561) = 1, then gcd(b, 3) = 1, then gcd(b, 11) = gcd(b, 17) =1. Example: Since every element of Z11 is a power of 2, 2 is a
 Using Fermat’s Little Theorem: b2 ≡ 1 (mod 3), b10 ≡ 1 (mod 11), b16 ≡ 1 (mod 17).
 Then
primitive root of 11.
b560 = (b2) 280 ≡ 1 (mod 3), Powers of 2 modulo 11: 21 = 2, 22 = 4, 23 = 8, 24 = 5, 25 = 10, 26 = 9, 27 = 7,
b560 = (b10) 56 ≡ 1 (mod 11), 28 = 3, 210 = 2.
b560 = (b16) 35 ≡ 1 (mod 17).
 It follows (see Exercise 29) that b560 ≡ 1 (mod 561) for all positive integers b with Example: Since not all elements of Z11 are powers of 3, 3
gcd(b,561) = 1. Hence, 561 is a Carmichael number.
 Even though there are infinitely many Carmichael numbers, there are other tests is not a primitive root of 11.
(described in the exercises) that form the basis for efficient probabilistic primality Powers of 3 modulo 11: 31 = 3, 32 = 9, 33 = 5, 34 = 4, 35 = 1, and the pattern
testing. (see Chapter 7)
repeats for higher powers.
Important Fact: There is a primitive root modulo p for
every prime number p.

Discrete Logarithms
Suppose p is prime and r is a primitive root modulo p. If a is an integer
between 1 and p −1, that is an element of Zp, there is a unique
exponent e such that re = a in Zp, that is, re mod p = a.
Definition: Suppose that p is prime, r is a primitive root modulo p, and
a is an integer between 1 and p −1, inclusive. If re mod p = a and
1 ≤ e ≤ p − 1, we say that e is the discrete logarithm of a modulo p to
the base r and we write logr a = e (where the prime p is understood). Section 4.5
Example 1: We write log2 3 = 8 since the discrete logarithm of 3 modulo
11 to the base 2 is 8 as 28 = 3 modulo 11.
Example 2: We write log2 5 = 4 since the discrete logarithm of 5 modulo
11 to the base 2 is 4 as 24 = 5 modulo 11.
There is no known polynomial time algorithm for computing the
discrete logarithm of a modulo p to the base r (when given the
prime p, a root r modulo p, and a positive integer a ∊Zp). The
problem plays a role in cryptography as will be discussed in Section 4.6.

19
Section Summary Hashing Functions
Definition: A hashing function h assigns memory location h(k) to the record that has k
as its key.
 A common hashing function is h(k) = k mod m, where m is the number of memory
 Hashing Functions locations.
 Because this hashing function is onto, all memory locations are possible.
 Pseudorandom Numbers Example: Let h(k) = k mod 111. This hashing function assigns the records of customers
with social security numbers as keys to memory locations in the following manner:
 Check Digits h(064212848) = 064212848 mod 111 = 14
h(037149212) = 037149212 mod 111 = 65
h(107405723) = 107405723 mod 111 = 14, but since location 14 is already occupied, the record is
assigned to the next available position, which is 15.
 The hashing function is not one-to-one as there are many more possible keys than
memory locations. When more than one record is assigned to the same location, we say
a collision occurs. Here a collision has been resolved by assigning the record to the first
free location.
 For collision resolution, we can use a linear probing function:
h(k,i) = (h(k) + i) mod m, where i runs from 0 to m − 1.
 There are many other methods of handling with collisions. You may cover these in a
later CS course.

Pseudorandom Numbers Pseudorandom Numbers


 Randomly chosen numbers are needed for many purposes, including  Example: Find the sequence of pseudorandom numbers generated by the linear
computer simulations. congruential method with modulus m = 9, multiplier a = 7, increment c = 4, and
seed x0 = 3.
 Pseudorandom numbers are not truly random since they are generated  Solution: Compute the terms of the sequence by successively using the congruence
by systematic methods. xn+1 = (7xn + 4) mod 9, with x0 = 3.
x1 = 7x0 + 4 mod 9 = 7∙3 + 4 mod 9 = 25 mod 9 = 7,
 The linear congruential method is one commonly used procedure for x2 = 7x1 + 4 mod 9 = 7∙7 + 4 mod 9 = 53 mod 9 = 8,
generating pseudorandom numbers. x3 = 7x2 + 4 mod 9 = 7∙8 + 4 mod 9 = 60 mod 9 = 6,
 Four integers are needed: the modulus m, the multiplier a, the x4 = 7x3 + 4 mod 9 = 7∙6 + 4 mod 9 = 46 mod 9 = 1,
x5 = 7x4 + 4 mod 9 = 7∙1 + 4 mod 9 = 11 mod 9 = 2,
increment c, and seed x0, with 2 ≤ a < m, 0 ≤ c < m, 0 ≤ x0 < m. x6 = 7x5 + 4 mod 9 = 7∙2 + 4 mod 9 = 18 mod 9 = 0,
 We generate a sequence of pseudorandom numbers {xn}, with x7 = 7x6 + 4 mod 9 = 7∙0 + 4 mod 9 = 4 mod 9 = 4,
0 ≤ xn < m for all n, by successively using the recursively defined x8 = 7x7 + 4 mod 9 = 7∙4 + 4 mod 9 = 32 mod 9 = 5,
x9 = 7x8 + 4 mod 9 = 7∙5 + 4 mod 9 = 39 mod 9 = 3.
function
xn+1 = (axn + c) mod m. The sequence generated is 3,7,8,6,1,2,0,4,5,3,7,8,6,1,2,0,4,5,3,…
It repeats after generating 9 terms.
(an example of a recursive definition, discussed in Section 5.3)  Commonly, computers use a linear congruential generator with increment c = 0. This is
called a pure multiplicative generator. Such a generator with modulus 231 − 1 and
 If psudorandom numbers between 0 and 1 are needed, then the multiplier 75 = 16,807 generates 231 − 2 numbers before repeating.
generated numbers are divided by the modulus, xn /m.

20
Check Digits: UPCs Check Digits:ISBNs
 A common method of detecting errors in strings of digits is to add an extra Books are identified by an International Standard Book Number (ISBN-10), a 10 digit code. The first
digit at the end, which is evaluated using a function. If the final digit is not 9 digits identify the language, the publisher, and the book. The tenth digit is a check digit, which is
determined by the following congruence
correct, then the string is assumed not to be correct.
Example: Retail products are identified by their Universal Product Codes
(UPCs). Usually these have 12 decimal digits, the last one being the check
digit. The check digit is determined by the congruence: The validity of an ISBN-10 number can be evaluated with the equivalent
3x1 + x2 + 3x3 + x4 + 3x5 + x6 + 3x7 + x8 + 3x9 + x10 + 3x11 + x12 ≡ 0 (mod 10).
a. Suppose that the first 11 digits of the UPC are 79357343104. What is the check digit? a. Suppose that the first 9 digits of the ISBN-10 are 007288008. What is the check digit?
b. Is 041331021641 a valid UPC? b. Is 084930149X a valid ISBN10?
Solution: Solution: X is used
a. 3∙7 + 9 + 3∙3 + 5 + 3∙7 + 3 + 3∙4 + 3 + 3∙1 + 0 + 3∙4 + x12 ≡ 0 (mod 10) a. X10 ≡ 1∙0 + 2∙0 + 3∙7 + 4∙2 + 5∙8 + 6∙8 + 7∙ 0 + 8∙0 + 9∙8 (mod 11). for the
21 + 9 + 9 + 5 + 21 + 3 + 12+ 3 + 3 + 0 + 12 + x12 ≡ 0 (mod 10) X10 ≡ 0 + 0 + 21 + 8 + 40 + 48 + 0 + 0 + 72 (mod 11). digit 10.
X10 ≡ 189 ≡ 2 (mod 11). Hence, X10 = 2.
98 + x12 ≡ 0 (mod 10) b. 1∙0 + 2∙8 + 3∙4 + 4∙9 + 5∙3 + 6∙0 + 7∙ 1 + 8∙4 + 9∙9 + 10∙10 =
x12 ≡ 2 (mod 10) So, the check digit is 2. 0 + 16 + 12 + 36 + 15 + 0 + 7 + 32 + 81 + 100 = 299 ≡ 2 ≢ 0 (mod 11)
b. 3∙0 + 4 + 3∙1 + 3 + 3∙3 + 1 + 3∙0 + 2 + 3∙1 + 6 + 3∙4 + 1 ≡ 0 (mod 10) Hence, 084930149X is not a valid ISBN-10.
0 + 4 + 3 + 3 + 9 + 1 + 0+ 2 + 3 + 6 + 12 + 1 = 44 ≡ 4 ≢ 0 (mod 10)  A single error is an error in one digit of an identification number and a transposition error is the
Hence, 041331021641 is not a valid UPC. accidental interchanging of two digits. Both of these kinds of errors can be detected by the check
digit for ISBN-10. (see text for more details)

Section Summary
 Classical Cryptography
 Cryptosystems
Section 4.6  Public Key Cryptography
 RSA Cryptosystem
 Crytographic Protocols
 Primitive Roots and Discrete Logarithms

21
Caesar Cipher Caesar Cipher
Julius Caesar created secret messages by shifting each letter three letters  To recover the original message, use f−1(p) = (p−3) mod 26.
forward in the alphabet (sending the last three letters to the first three letters.)
For example, the letter B is replaced by E and the letter X is replaced by A. This So, each letter in the coded message is shifted back three
process of making a message secret is an example of encryption. letters in the alphabet, with the first three letters sent to
Here is how the encryption process works:
 Replace each letter by an integer from Z26, that is an integer from 0 to 25
the last three letters. This process of recovering the original
representing one less than its position in the alphabet. message from the encrypted message is called decryption.
 The encryption function is f(p) = (p + 3) mod 26. It replaces each integer p in
the set {0,1,2,…,25} by f(p) in the set {0,1,2,…,25} .  The Caesar cipher is one of a family of ciphers called shift
 Replace each integer p by the letter with the position p + 1 in the alphabet. ciphers. Letters can be shifted by an integer k, with 3 being
Example: Encrypt the message “MEET YOU IN THE PARK” using the Caesar
cipher.
just one possibility. The encryption function is
Solution: 12 4 4 19 24 14 20 8 13 19 7 4 15 0 17 10. f(p) = (p + k) mod 26
Now replace each of these numbers p by f(p) = (p + 3) mod 26. and the decryption function is
15 7 7 22 1 17 23 11 16 22 10 7 18 3 20 13.
Translating the numbers back to letters produces the encrypted message
f−1(p) = (p−k) mod 26
“PHHW BRX LQ WKH SDUN.” The integer k is called a key.

Shift Cipher Shift Cipher


Example 1: Encrypt the message “STOP GLOBAL Example 2: Decrypt the message “LEWLYPLUJL PZ H
WARMING” using the shift cipher with k = 11. NYLHA ALHJOLY” that was encrypted using the shift
Solution: Replace each letter with the corresponding cipher with k = 7.
element of Z26. Solution: Replace each letter with the corresponding
element of Z26.
18 19 14 15 6 11 14 1 0 11 22 0 17 12 8 13 6.
11 4 22 11 24 15 11 20 9 11 15 25 7 13 24 11 7 0 0 11 7 9 14 11 24.
Apply the shift f(p) = (p + 11) mod 26, yielding Shift each of the numbers by −k = −7 modulo 26, yielding
3 4 25 0 17 22 25 12 11 22 7 11 2 23 19 24 17. 4 23 15 4 17 8 4 13 2 4 8 18 0 6 17 4 0 19 19 4 0 2 7 4 17.
Translating the numbers back to letters produces the Translating the numbers back to letters produces the
ciphertext decrypted message
“DEZA RWZMLW HLCXTYR.” “EXPERIENCE IS A GREAT TEACHER.”

22
Affine Ciphers Cryptanalysis of Affine Ciphers
 Shift ciphers are a special case of affine ciphers which use functions of the form  The process of recovering plaintext from ciphertext without knowledge both of the
f(p) = (ap + b) mod 26, encryption method and the key is known as cryptanalysis or breaking codes.
 An important tool for cryptanalyzing ciphertext produced with a affine ciphers is the
where a and b are integers, chosen so that f is a bijection. relative frequencies of letters. The nine most common letters in the English texts are E
The function is a bijection if and only if gcd(a,26) = 1. 13%, T 9%, A 8%, O 8%, I 7%, N 7%, S 7%, H 6%, and R 6%.
 Example: What letter replaces the letter K when the function f(p) = (7p + 3)  To analyze ciphertext:
mod 26 is used for encryption.  Find the frequency of the letters in the ciphertext.
Solution: Since 10 represents K, f(10) = (7∙10 + 3) mod 26 =21, which is then  Hypothesize that the most frequent letter is produced by encrypting E.
replaced by V.  If the value of the shift from E to the most frequent letter is k, shift the ciphertext by −k
and see if it makes sense.
 To decrypt a message encrypted by a shift cipher, the congruence c ≡ ap + b  If not, try T as a hypothesis and continue.
(mod 26) needs to be solved for p.  Example: We intercepted the message “ZNK KGXRE HOXJ MKZY ZNK CUXS” that we
 Subtract b from both sides to obtain c− b ≡ ap (mod 26). know was produced by a shift cipher. Let’s try to cryptanalyze.
 Multiply both sides by the inverse of a modulo 26, which exists since gcd(a,26)  Solution: The most common letter in the ciphertext is K. So perhaps the letters were
= 1. shifted by 6 since this would then map E to K. Shifting the entire message by −6 gives us
 ā(c− b) ≡ āap (mod 26), which simplifies to ā(c− b) ≡ p (mod 26). “THE EARLY BIRD GETS THE WORM.”
 p ≡ ā(c− b) (mod 26) is used to determine p in Z26.

Block Ciphers Block Ciphers


 Ciphers that replace each letter of the alphabet by another letter Example: Using the transposition cipher based on the
are called character or monoalphabetic ciphers. permutation σ of the set {1,2,3,4} with σ(1) = 3, σ(2) = 1,
 They are vulnerable to cryptanalysis based on letter frequency. σ(3) = 4, σ(4) = 2,
Block ciphers avoid this problem, by replacing blocks of letters a. Encrypt the plaintext PIRATE ATTACK
with other blocks of letters. b. Decrypt the ciphertext message SWUE TRAEOEHS, which
 A simple type of block cipher is called the transposition cipher. was encryted using the same cipher.
The key is a permutation σ of the set {1,2,…,m}, where m is an Solution:
integer, that is a one-to-one function from {1,2,…,m} to itself. a. Split into four blocks PIRA TEAT TACK.
 To encrypt a message, split the letters into blocks of size m, Apply the permutation σ giving IAPR ETTA AKTC.
adding additional letters to fill out the final block. We encrypt b. σ−1 : σ −1(1) = 2, σ −1(2) = 4, σ −1(3) = 1, σ −1(4) = 3.
p1,p2,…,pm as c1,c2,…,cm = pσ(1),pσ(2),…,pσ(m). Apply the permutation σ−1 giving USEW ATER HOSE.
 To decrypt the c1,c2,…,cm transpose the letters using the inverse Split into words to obtain USE WATER HOSE.
permutation σ−1.

23
Cryptosystems Cryptosystems
Definition: A cryptosystem is a five-tuple (P,C,K,E,D), Example: Describe the family of shift ciphers as a
where cryptosystem.
 P is the set of plainntext strings,
 C is the set of ciphertext strings,
Solution: Assume the messages are strings consisting
 K is the keyspace (set of all possible keys), of elements in Z26.
 E is the set of encription functions, and  P is the set of strings of elements in Z26,
 D is the set of decryption functions.  C is the set of strings of elements in Z26,
 The encryption function in E corresponding to the key k is  K = Z26,
denoted by Ek and the decription function in D that
 E consists of functions of the form
decrypts cipher text enrypted using Ek is denoted by Dk.
Therefore: Ek (p) = (p + k) mod 26 , and
Dk(Ek(p)) = p, for all plaintext strings p.  D is the same as E where Dk (p) = (p − k) mod 26 .

Clifford Cocks
(Born 1950)
Public Key Cryptography The RSA Cryptosystem
 All classical ciphers, including shift and affine ciphers, are  A public key cryptosystem, now known as the RSA system was
introduced in 1976 by three researchers at MIT.
private key cryptosystems. Knowing the encryption key
allows one to quickly determine the decryption key.
Leonard
 All parties who wish to communicate using a private key Ronald Rivest Adi Shamir Adelman
(Born 1948) (Born 1952) (Born 1945)
cryptosystem must share the key and keep it a secret.
 In public key cryptosystems, first invented in the 1970s,  It is now known that the method was discovered earlier by
Clifford Cocks, working secretly for the UK government.
knowing how to encrypt a message does not help one to  The public encryption key is (n,e), where n = pq (the modulus)
decrypt the message. Therefore, everyone can have a is the product of two large (200 digits) primes p and q, and an
publicly known encryption key. The only key that needs to exponent e that is relatively prime to (p−1)(q −1). The two large
primes can be quickly found using probabilistic primality tests,
be kept secret is the decryption key. discussed earlier. But n = pq, with approximately 400 digits,
cannot be factored in a reasonable length of time.

24
RSA Encryption RSA Decryption
 To encrypt a message using RSA using a key (n,e) :  To decrypt a RSA ciphertext message, the decryption key d, an inverse of e
i. Translate the plaintext message M into sequences of two digit integers representing the modulo (p−1)(q −1) is needed. The inverse exists since gcd(e,(p−1)(q −1)) =
letters. Use 00 for A, 01 for B, etc. gcd(13, 42∙ 58) = 1.
ii. Concatenate the two digit integers into strings of digits.  With the decryption key d, we can decrypt each block with the computation
iii. Divide this string into equally sized blocks of 2N digits where 2N is the largest even M = Cd mod p∙q. (see text for full derivation)
number 2525…25 with 2N digits that does not exceed n.
iv. The plaintext message M is now a sequence of integers m1,m2,…,mk.  RSA works as a public key system since the only known method of finding d is
v. Each block (an integer) is encrypted using the function C = Me mod n. based on a factorization of n into primes. There is currently no known feasible
method for factoring large numbers into primes.
Example: Encrypt the message STOP using the RSA cryptosystem with key(2537,13). Example: The message 0981 0461 is received. What is the decrypted message
 2537 = 43∙ 59, if it was encrypted using the RSA cipher from the previous example.
 p = 43 and q = 59 are primes and gcd(e,(p−1)(q −1)) = gcd(13, 42∙ 58) = 1. Solution: The message was encrypted with n = 43∙ 59 and exponent 13. An
Solution: Translate the letters in STOP to their numerical equivalents 18 19 14 15. inverse of 13 modulo 42∙ 58 = 2436 (exercise 2 in Section 4.4) is d = 937.
 Divide into blocks of four digits (because 2525 < 2537 < 252525) to obtain 1819 1415.  To decrypt a block C, M = C937 mod 2537.
 Encrypt each block using the mapping C = M13 mod 2537.  Since 0981937 mod 2537 = 0704 and 0461937 mod 2537 = 1115, the decrypted
 Since 181913 mod 2537 = 2081 and 141513 mod 2537 = 2182, the encrypted message is message is 0704 1115. Translating back to English letters, the message is HELP.
2081 2182.

25

You might also like