Security games · IND-CPA · IND-CCA2 · EUF-CMA
Flip the challenger's hidden bit, hand the adversary its oracle, and watch its advantage climb to one against textbook RSA and flatten against RSA-OAEP over real trials.
THE IDEA
A challenger hides one random bit inside a cryptographic task. An adversary sees only the public rules and tries to name that bit. Repeated wins reveal a usable pattern; repeated guesses reveal only that this particular strategy found none.
BOUNDARIES
Real browser cryptography inside faithfully sampled games. Not production crypto; session keys stay in memory and the interface deliberately exposes internals for teaching.
AES CBC/CTR/GCM and RSA OAEP/PSS use WebCrypto. AES-ECB, ristretto255 ElGamal, secp256k1 ECDSA, and Ed25519 use audited Noble packages. The challenger bit always comes from crypto.getRandomValues.
The PRP and PRF are mathematical ideal oracles, sampled lazily exactly as the switching game defines them. Trial counts are capped at 5,000; a sample is not a proof.
No proof assistant or symbolic analysis; see Protocol Checker. No CCA1, NM-CPA, visitor-authored code, TLS or Signal claims, or deployed-system verdicts.
KEM notions stay outside this game board; see KEM Trap for ML-KEM. No result label uses the word “secure”; it reports an attack or no advantage from named adversaries.
| Definition | Extra power | Why it is not an exhibit here |
|---|---|---|
| CCA1 | Decrypt before, not after, the challenge | CCA2 makes the sharper oracle boundary visible. |
| NM-CPA | Forbids useful ciphertext relations | The ElGamal CCA act shows malleability without claiming the full equivalence story. |
| KEM security | Challenges an encapsulated key | That interface belongs in the linked KEM lab. |
Goldwasser–Micali (1984) · Rackoff–Simon (1991) · Bellare–Desai–Pointcheval–Rogaway (1998) · Goldwasser–Micali–Rivest (1988) · Bellare–Rogaway (2006) · Shoup (2004) · FIPS 197 · RFC 6979 · RFC 8032.