Skip to content

Hidden Bit

Security games · IND-CPA · IND-CCA2 · EUF-CMA

Flip the challenger's hidden bit, hand the adversary its oracle, and watch its advantage climb to one against textbook RSA and flatten against RSA-OAEP over real trials.

THE IDEA

A definition you can run

A challenger hides one random bit inside a cryptographic task. An adversary sees only the public rules and tries to name that bit. Repeated wins reveal a usable pattern; repeated guesses reveal only that this particular strategy found none.

Checking the instruments Running 3 published vector cases before the lab opens.

BOUNDARIES

What this lab is, and is not

Real browser cryptography inside faithfully sampled games. Not production crypto; session keys stay in memory and the interface deliberately exposes internals for teaching.

What is real

AES CBC/CTR/GCM and RSA OAEP/PSS use WebCrypto. AES-ECB, ristretto255 ElGamal, secp256k1 ECDSA, and Ed25519 use audited Noble packages. The challenger bit always comes from crypto.getRandomValues.

What is idealized

The PRP and PRF are mathematical ideal oracles, sampled lazily exactly as the switching game defines them. Trial counts are capped at 5,000; a sample is not a proof.

What this is not

No proof assistant or symbolic analysis; see Protocol Checker. No CCA1, NM-CPA, visitor-authored code, TLS or Signal claims, or deployed-system verdicts.

Where KEMs fit

KEM notions stay outside this game board; see KEM Trap for ML-KEM. No result label uses the word “secure”; it reports an attack or no advantage from named adversaries.

Nearby definitions intentionally left out
DefinitionExtra powerWhy it is not an exhibit here
CCA1Decrypt before, not after, the challengeCCA2 makes the sharper oracle boundary visible.
NM-CPAForbids useful ciphertext relationsThe ElGamal CCA act shows malleability without claiming the full equivalence story.
KEM securityChallenges an encapsulated keyThat interface belongs in the linked KEM lab.
Definitions and primary sources

Goldwasser–Micali (1984) · Rackoff–Simon (1991) · Bellare–Desai–Pointcheval–Rogaway (1998) · Goldwasser–Micali–Rivest (1988) · Bellare–Rogaway (2006) · Shoup (2004) · FIPS 197 · RFC 6979 · RFC 8032.