Crypto Lab

Course module

Public-key & signatures

Fits the public-key unit of an undergraduate computer security, network security, or applied cryptography course. The nonce-lattice extension suits a cryptanalysis elective or an advanced assignment for students comfortable with vectors and bases.

Audience
Upper-division undergraduate CS and security students, and motivated newcomers, meeting public-key encryption and digital signatures with the math worked on small numbers before real key sizes appear.
Class time
About 107 minutes of class time for the core sequence, plus about 30 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief. These figures are class time only. Each worksheet's own accounting counted its Predict questions inside the total, and Predict is answered before the exhibit is opened, so every figure here is five minutes lower than the draft's.
Last checked
2026-09-22

Ready to teach

Class time
About 107 minutes for the core sequence, plus about 30 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Checked in
Chromium 153, Firefox 155 and WebKit 26.6, at desktop width and phone width.
Known issues
ECDSA Forge (Chromium 153, Firefox 155 and WebKit 26.6). What the checks found. Last re-derived against the live page 2026-09-22.

Prerequisites

Learning outcomes

  1. Students will be able to compute an RSA keypair (n, φ(n), e, d) from two small primes and explain why d is taken as the inverse of e modulo φ(n).
  2. Students will be able to demonstrate that textbook RSA is deterministic and malleable, and contrast it with randomized RSA-OAEP encryption of the same plaintext.
  3. Students will be able to trace how Håstad's broadcast attack and Bleichenbacher's padding-oracle attack recover plaintext without the private key, and identify the exponent or padding choice each attack exploits.
  4. Students will be able to perform elliptic-curve point addition and scalar multiplication over the reals and over a finite field, and compare double-and-add with repeated addition to explain why reversing k·P (the ECDLP) is hard.
  5. Students will be able to derive an ECDSA private key from two signatures that reuse a nonce, and justify how RFC 6979 deterministic nonces block that recovery.

Sequence

Educational RSA: Runs about 29 minutes against the 25 planned. The earlier figure came from a cut-savings claim rather than a recount, and some of those savings were Fix / Extend items, which are homework and cost no class time; counted step by step, the cut freed about four minutes, not ten.

Each exhibit opens in its own site. Roles: Intro builds the idea, Break it has students cause the failure, Fix shows the construction that holds, and Extension is optional depth.

ExhibitRoleTimeWorksheet
Educational RSAIntro29 minWorksheet for Educational RSA
Build an RSA key from two small primes (or random ones) and follow n, φ(n), e and d, encrypt and decrypt a short message with the square-and-multiply trace, sign and verify with the tamper toggle, factor the weak key, and compare textbook ciphertext with WebCrypto RSA-OAEP and the live Enc(a)·Enc(b) malleability forgery.
Cite this exhibit: Clark, P. A. Educational RSA [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-rsa-educational/
RSA ForgeBreak it32 minWorksheet for RSA Forge
On the Small Exponent Attack and Bleichenbacher Oracle tabs, pick a config and run the Håstad broadcast attack (CRT plus cube root on three e = 3 ciphertexts), then set up the 128-bit key, query the padding oracle, show Enc(a)·Enc(b) = Enc(a·b), and run the Bleichenbacher attack both automatically and in You Are the Oracle mode.
Cite this exhibit: Clark, P. A. (2026). RSA Forge [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-rsa-forge/
Point ArithmeticIntro17 minWorksheet for Point Arithmetic
Drag P and Q along a real curve (or use the menus and arrow keys) to watch the chord or tangent, reflection and λ, x₃, y₃ update, flip Over ℝ / Over 𝔽ₚ to run the same addition on a point lattice, step k·P by repeated addition and by double-and-add, and walk a small subgroup until it lands on the target point.
Cite this exhibit: Clark, P. A. (2026). Point Arithmetic [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-ec-point-arithmetic/
ECDSA ForgeBreak it29 minWorksheet for ECDSA Forge
Generate a secp256k1 or P-256 key, sign and verify, move the toy-curve sliders to watch two same-nonce signatures give up d, run the nonce-reuse compromise on real 256-bit keys with its recovered-equals-victim proof, then compare random and RFC 6979 signatures and try the attack against RFC 6979.
Cite this exhibit: Clark, P. A. (2026). ECDSA Forge [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-ecdsa-forge/
Nonce LatticeExtension30 minWorksheet for Nonce Lattice
Choose a scenario preset or set curve, leak mode, leak size and signature count, read the feasibility gauge, run the HNP/LLL attack and step through Sign, Build HNP, Reduce and Extract to the byte-for-byte key grid, then press Measure this column to test where recovery starts failing.
Cite this exhibit: Clark, P. A. (2026). Nonce Lattice [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-nonce-lattice/

Hand-out: every worksheet in this module, in sequence order

What students hand in

Accept-or-reject sheet. A verdict of accept or reject on each scheme the sequence exercises, each verdict tied to a value from the student's own Record tables rather than to a claim printed on the page. Each reject has to name the failure it rests on and what an observer learns from published values alone; each accept has to name what the page says that acceptance still depends on.

It is drawn from what the worksheets already produce, so it adds no new task. Values differ from run to run, so there is no key to mark against: what a marker is reading is whether each claim is tied to something the student recorded, and whether the reasoning from it holds.

Discussion questions

  1. Textbook RSA and RSA-OAEP both compute m^e mod n. What does OAEP's randomized padding change about what an eavesdropper or attacker learns, and which of the attacks you ran in Educational RSA and RSA Forge would it stop?
  2. The weak RSA key, the factoring wall and the subgroup walk each fall quickly on toy parameters. Why does an attack that works on small numbers not show that RSA or elliptic-curve cryptography is broken, and what decides how long the same attack takes at real sizes?
  3. Bleichenbacher's oracle answers only 'conformant' or 'not conformant'. Why is one bit per query enough to recover the plaintext, and what does that imply for how a server should handle decryption errors?
  4. ECDSA nonce reuse and (in the extension) the nonce-lattice attack both recover d from public signatures. What does each attacker need, which failure does RFC 6979 remove from the trust path, and what does it leave to the implementation?
  5. Given the trade-offs the labs present (key and signature size, padding pitfalls, nonce fragility, deterministic signing), when would you choose RSA-PSS, ECDSA with RFC 6979, or Ed25519 for a new signing system?

Instructor notes

These notes are public, and they are conceptual on purpose: they describe what students should notice and why, never the specific values a run produces.

Expected observations

Common misconceptions

Conceptual answers

Checks

Browser support. Every exhibit in this module, and every step of its worksheet, was run in Chromium, Firefox and WebKit at a desktop width and at a phone width (1280 by 720 and 390 by 720), checked 2026-09-22. One exhibit needs a word of warning:

Privacy. Opening these exhibits sends nothing to anyone but the site they are served from: no exhibit sets a cookie, and none stores anything beyond the setting that pins its dark theme. The exception:

Detailed check results — engine versions, every step run, transfer sizes, and the source line behind each run-specific verdict. The worksheet drift check reads this module’s anchors manifest.

For your syllabus

Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data. https://crypto-lab.systemslibrarian.dev/teach/public-key/

How to cite this module’s exhibits

Each exhibit's citation is in the Sequence table above, in that exhibit's own row. Exhibits change as they are improved, so the retrieval date is what says which version you used; it is filled in from your device's clock when the page loads.

BibTeX
@misc{clark_rsa_educational,
  author       = {Clark, Paul A.},
  title        = {Educational RSA},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-rsa-educational/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_rsa_forge,
  author       = {Clark, Paul A.},
  title        = {RSA Forge},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-rsa-forge/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_ec_point_arithmetic,
  author       = {Clark, Paul A.},
  title        = {Point Arithmetic},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-ec-point-arithmetic/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_ecdsa_forge,
  author       = {Clark, Paul A.},
  title        = {ECDSA Forge},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-ecdsa-forge/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_nonce_lattice,
  author       = {Clark, Paul A.},
  title        = {Nonce Lattice},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-nonce-lattice/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

To cite the whole collection, see How to cite.