Crypto Lab

Course module

Security & symmetric encryption

Fits the modes-of-operation and misuse week of an upper-division applied-cryptography or computer-security course. About 87 minutes of core lab time: two 50-minute meetings with little slack, or two 75-minute meetings comfortably. An introductory security unit that stops after AES Modes is a different, shorter assignment — not this module with the last two exhibits skipped mid-sequence.

Audience
Upper-division undergraduate computer science and security students, and motivated newcomers already comfortable with XOR, hexadecimal, and AES as a keyed function on 16-byte blocks. An introductory security course can take Hidden Bit, OTP Vault, and AES Modes as a one-meeting cut; Padding Oracle and Nonce Collision assume that cut has already happened.
Class time
About 87 minutes of class time for the core sequence. Predict is pre-class reading and Explain is a spoken debrief.
Last checked
2026-09-22

Ready to teach

Class time
About 87 minutes for the core sequence. Predict is pre-class reading and Explain is a spoken debrief.
Checked in
Chromium 153, Firefox 155 and WebKit 26.6, at desktop width and phone width.
Known issues
None recorded in the checks below.

Prerequisites

Learning outcomes

  1. Students will be able to explain, using the hidden-bit IND-CPA game, why deterministic AES-ECB and CBC with a predictable chained IV let a named adversary tell which of two messages was encrypted.
  2. Students will be able to demonstrate that reusing a one-time-pad key or a stream-cipher keystream reduces two ciphertexts to the XOR of their plaintexts, and recover plaintext from that XOR by crib-dragging.
  3. Students will be able to compare ECB, CBC, CTR, GCM and CCM by whether each provides confidentiality alone or authenticated encryption, and predict how each responds when a ciphertext bit is flipped.
  4. Students will be able to trace how a padding-validity oracle lets an attacker recover AES-CBC plaintext byte by byte without the key, and explain why verifying a MAC before decryption stops the same attack.
  5. Students will be able to distinguish the consequences of nonce reuse for AES-CTR, AES-GCM, ChaCha20-Poly1305 and AES-CBC, including which key material the attacker recovers and which it does not.

Which meeting finishes which outcome

Taken from each worksheet's own outcome tags, grouped by the meeting its exhibit sits in. An outcome is listed where a student finishes it, not where it is first met.

Sequence

Nonce Collision: This is where keystream reuse is shown on a real stream cipher. OTP Vault meets the same outcome on an admitted stand-in keystream, so a course that stops after the first meeting has the outcome as written and not that instance of it.

Each exhibit opens in its own site. Roles: Intro builds the idea, Break it has students cause the failure, Fix shows the construction that holds, and Extension is optional depth.

ExhibitRoleTimeWorksheet
Hidden BitIntro15 minWorksheet for Hidden Bit
In Exhibit 01, pick an AES scheme (GCM, CTR, chained-IV CBC or ECB) and an adversary (random guess, re-encrypt and compare, or the BEAST-style IV predictor), run or step real trials, and read the measured advantage, Wilson interval and verdict.
Cite this exhibit: Clark, P. A. (2026). Hidden Bit [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-hidden-bit/
OTP VaultBreak it19 minWorksheet for OTP Vault
Encrypt a message under a fresh random pad, type any same-length plaintext to derive a key that maps the fixed ciphertext to it, then switch on key reuse and crib-drag C1 ⊕ C2 to peel both messages apart, including a built-in challenge.
Cite this exhibit: Clark, P. A. OTP Vault [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-otp-vault/
AES ModesFix14 minWorksheet for AES Modes
Encrypt your own plaintext under ECB, CBC, CTR, GCM and CCM, inspect the key, IV or nonce, ciphertext and tag, and run the ECB pattern-leak, CBC bit-flip and GCM tamper-detection demos to see which modes accept a modified ciphertext.
Cite this exhibit: Clark, P. A. (2026). AES Modes [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-aes-modes/
Padding OracleBreak it24 minWorksheet for Padding Oracle
Predict whether a crafted final padding byte passes the real oracle, run the byte-by-byte attack on a block you type, then run the identical attack against leaky, silent and Encrypt-then-MAC servers and tamper with an AES-GCM ciphertext.
Cite this exhibit: Clark, P. A. Padding Oracle [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-padding-oracle/
Nonce CollisionBreak it15 minWorksheet for Nonce Collision
Encrypt two messages under one AES-CTR key and nonce and crib-drag the second out of C1 ⊕ C2, then switch each construction to a reused nonce (or press "Run all four — one reused nonce") and read each card's cryptographic result beside its security verdict.
Cite this exhibit: Clark, P. A. (2026). Nonce Collision [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-nonce-collision/

Hand-out: every worksheet in this module, in sequence order

What students hand in

Mode failure brief. One page that takes each exhibit in the sequence in turn, names the property the mode or key was supposed to provide, points at the line or value from the student's own run where it stopped holding, and names the one change that would have closed it. Every claim and every proposed change has to cite something the student recorded rather than a general statement about the mode.

It is drawn from what the worksheets already produce, so it adds no new task. Values differ from run to run, so there is no key to mark against: what a marker is reading is whether each claim is tied to something the student recorded, and whether the reasoning from it holds.

Discussion questions

  1. In Hidden Bit, random guessing and re-encryption both flatten against chained-IV CBC, yet the BEAST-style predictor breaks it. What does a flat measurement tell you about a scheme, and what does it not tell you?
  2. Why does XORing two ciphertexts made with the same one-time pad, or the same CTR nonce, remove the key entirely, and why does that undo what OTP Vault's Panel 2 shows about a single ciphertext?
  3. AES-CBC with a random IV hides repeated messages, yet Padding Oracle recovers its plaintext without the key. What is CBC missing, and why does the lab call the silent server's protection fragile while Encrypt-then-MAC stops the attack before decryption?
  4. One reused nonce produces different outcomes across Nonce Collision's cards. Why does AES-GCM lose integrity while AES-CBC leaks a shared prefix, and why is recovering the GHASH subkey H not the same as recovering the AES key?
  5. Where do repeated nonces come from in real systems, and which remedy the lab names (a persistent counter with a single encryptor, limiting how many random-nonce messages one key encrypts, or a misuse-resistant AEAD such as AES-GCM-SIV) addresses which cause?

Instructor notes

These notes are public, and they are conceptual on purpose: they describe what students should notice and why, never the specific values a run produces.

Expected observations

Common misconceptions

Conceptual answers

Checks

Browser support. Every exhibit in this module, and every step of its worksheet, was run in Chromium, Firefox and WebKit at a desktop width and at a phone width (1280 by 720 and 390 by 720), checked 2026-09-22. No exhibit had a problem at either width.

Privacy. Opening these exhibits sends nothing to anyone but the site they are served from: no exhibit sets a cookie, and none stores anything beyond the setting that pins its dark theme.

Detailed check results — engine versions, every step run, transfer sizes, and the source line behind each run-specific verdict. The worksheet drift check reads this module’s anchors manifest.

For your syllabus

Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data. https://crypto-lab.systemslibrarian.dev/teach/symmetric/

How to cite this module’s exhibits

Each exhibit's citation is in the Sequence table above, in that exhibit's own row. Exhibits change as they are improved, so the retrieval date is what says which version you used; it is filled in from your device's clock when the page loads.

BibTeX
@misc{clark_hidden_bit,
  author       = {Clark, Paul A.},
  title        = {Hidden Bit},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-hidden-bit/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_otp_vault,
  author       = {Clark, Paul A.},
  title        = {OTP Vault},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-otp-vault/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_aes_modes,
  author       = {Clark, Paul A.},
  title        = {AES Modes},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-aes-modes/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_padding_oracle,
  author       = {Clark, Paul A.},
  title        = {Padding Oracle},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-padding-oracle/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_nonce_collision,
  author       = {Clark, Paul A.},
  title        = {Nonce Collision},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-nonce-collision/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

To cite the whole collection, see How to cite.