#182 - RSA Encryption
The RSA encryption is based on the following procedure:
Generate two distinct primes \(p\) and \(q\).
Compute \(n = pq\) and \(\phi = (p - 1)(q - 1)\).
Find an integer \(e\), \(1 \lt e \lt \phi\), such that \(\gcd(e, \phi) = 1\).
A message in this system is a number in the interval \([0, n - 1]\).
A text to be encrypted is then somehow converted to messages (numbers in the interval \([0, n - 1]\)).
To encrypt the text, for each message, \(m\), \(c = m^e \bmod n\) is calculated.
To decrypt the text, the following procedure is needed: calculate \(d\) such that \(ed = 1 \bmod \phi\), then for each encrypted message, \(c\), calculate \(m = c^d \bmod n\).
There exist values of \(e\) and \(m\) such that \(m^e \bmod n = m\).
We call messages \(m\) for which \(m^e \bmod n = m\) unconcealed messages.
An issue when choosing \(e\) is that there should not be too many unconcealed messages.
For instance, let \(p = 19\) and \(q = 37\).
Then \(n = 19 \cdot 37 = 703\) and \(\phi = 18 \cdot 36 = 648\).
If we choose \(e = 181\), then, although \(\gcd(181,648) = 1\) it turns out that all possible messages \(m\) (\(0 \le m \le n - 1\)) are unconcealed when calculating \(m^e \bmod n\).
For any valid choice of \(e\) there exist some unconcealed messages.
It's important that the number of unconcealed messages is at a minimum.
Choose \(p = 1009\) and \(q = 3643\).
Find the sum of all values of \(e\), \(1 \lt e \lt \phi(1009,3643)\) and \(\gcd(e, \phi) = 1\), so that the number of unconcealed messages for this value of \(e\) is at a minimum.
Problem text © Project Euler, licensed under CC BY-NC-SA 4.0. Original: projecteuler.net/problem=182. Published Friday, 15th February 2008, 01:00 pm. Solved by 3,085 members at time of mirroring.
Why this is useful
Mathematical Foundation. Exact counting underlies discrete pricing lattices, scenario enumeration, and combinatorial probability (Phase 7).
We classify relevance honestly - not every Euler problem is a trading application.
Prerequisites
Lessons that prepare you:
1.3 Proof Techniques: Direct, Contrapositive, and Contradiction · 17.1 Python for Quants: NumPy, pandas, and Vectorization · 19.5 Combinatorics: Counting, Binomials, and Inclusion–Exclusion · 19.14 Computational Complexity, Feasibility Estimation, and Proving Algorithms Correct · 19.1 Divisibility, GCD, and the Euclidean Algorithm · 19.3 Modular Arithmetic, Inverses, and Fast Exponentiation · 19.11 Integer Partitions and Counting Structures · 19.10 Search: Backtracking, Branch-and-Bound, Binary Search, Meet-in-the-Middle · 19.2 Primes, Sieves, and Integer Factorization · 7.1 Probability Spaces, Random Variables, and Distributions
Recommended stepping-stone problems: #946 · #277 · #618
Concepts: combinatorics number-theory string-processing brute-force-reduction
Likely techniques: backtracking gcd-euclid hashing modular-inverse
Learning mode
Pick how much scaffolding you want. Your choice is remembered per problem.
Understand the problem
- What exactly is the input to problem 182? Is it a bound (1009), a supplied dataset, or a definition you must generate from?
- What is the required output - restate it precisely: a single sum.
- Which objects exactly are in scope, and which are excluded by the wording (strict vs non-strict inequality, 'distinct', 'proper', 'below' vs 'up to')?
- What constraint does the bound 1009 impose, and is it inclusive or exclusive?
- What are the edge cases: the smallest legal object, zero/one, ties, and the boundary at exactly 1009?
- Why is brute force hard HERE specifically? Estimate the number of candidates implied by 1009 and the cost of testing one.
- Which number-theory fact would, if true, collapse the search - and can you state it as a testable claim before you look for a proof?
Predict & plan (before you code)
- Predict the strategy: in one sentence, what will your solution do? (The classification says number-theory / modular-inverse - do you agree, and why?)
- Predict the complexity of your intended method in terms of N = 1009, and the wall-clock time you expect. Write both down now.
- Predict the key data structure: what is stored, keyed by what, and how large will it get at full scale?
- Predict the failure mode: what is most likely to break - an off-by-one on the bound, a definition misread, precision, or memory?
- Predict the output of the small case from rung 3 BEFORE running it (the statement says: "For instance, let p = 19 and q = 37.") - then run it. A surprise here is worth more than an hour of debugging later.
Scratchpad
Mathematical notes, formulas, pseudocode, hypotheses, complexity notes. Saved automatically with your progress.
Python workbench
Real Python (Pyodide) in a sandboxed Web Worker - no network, no filesystem, no DOM access. Ctrl/Cmd+Enter runs. Escape leaves the editor. Stop terminates the worker.
Check your answer
Answers are checked against a salted hash held in a separate file - not printed in this page. This prevents accidental spoilers; it is not cryptographic protection (see the build notes).
Progressive hints
Optimization
You have a correct answer. That is the start of the learning, not the end.
- Reduce the time complexity. What is the bottleneck, and what mathematical fact removes it?
- Reduce memory. Can you stream, or keep only the last k states?
- Replace brute force with a closed form, a sieve, a recurrence, or a symmetry argument.
- Prove the optimized version computes the same thing.
- Compare two implementations and time them.
Explain it
Which step of your solution were you least confident about, and what evidence would settle it?
What did you try first, and what specifically made you abandon it - a proof, a timing, or a wrong small-case answer?
Where did the number-theory structure do the real work? Name the single observation that collapsed the search space.
Could you have reached the modular-inverse idea faster? Which words in the statement were pointing at it, and did you notice them?
What was the bug that cost you the most time, and what CLASS of bug was it (off-by-one, definition misread, precision, state under-specified)?
How would your solution change if the bound 1009 were multiplied by 1000? Does it survive, or does it need a different idea?
What is the honest complexity of what you wrote (not what you intended), and where is the remaining slack?
Which problem you have already solved is this most similar to, and what is the shared skeleton - is it really 'modular-inverse' underneath?
State the transferable technique in one sentence, without mentioning this problem's story at all.
Self-assess (mastery is not a correct number)
You reach Mastered only when you have solved it, rated yourself at least Solid across the dimensions, and written a real explanation.
Confidence
Low confidence schedules this problem for spaced review, even if you solved it.
Mastery check
- Variation: change the bound (or a rule) in the statement. Does your method still work? What breaks first?
- Constraints: if the limit were 10× larger, which step fails, and what would you replace it with?
- Related problem: #946 · #277 · #618
- Transfer: where else does this technique appear? Name a lesson and a real computational setting.
- Spaced re-attempt: come back after the review interval and re-solve it with no hints.