IA idea · Cryptography & number theory
Agreeing a secret in public: the Diffie–Hellman key exchange
Research question
How can two people agree a secret number over a public channel using powers modulo a prime, why must the base be chosen carefully, and how does the work an eavesdropper must do grow with the size of the prime?
Adapt it: change the place, the data or the comparison until the question is yours.
Free: the A–E checklist an examiner uses, by email ↓
Why it makes a good exploration
It is a short, complete piece of number theory with a real purpose. Small primes let you do every step by hand and see exactly where the security comes from.
The mathematics you'll need
- Modular arithmetic and powers mod p (new: explain)
- Primitive roots: the order of an element
- Proof that both parties get the same key
- Fast exponentiation by repeated squaring
- Growth of brute-force search with the size of p
Course labels show where a technique sits; using maths from outside your course is fine if you explain it clearly and say it is new to you.
Where the data comes from
No data needed; use small primes by hand and a spreadsheet or calculator for larger ones; check sequences on OEIS.
- OEIS (On-Line Encyclopedia of Integer Sequences) — Check a sequence you have found and read its known formulas and references.
- Desmos graphing calculator — Free graphing and regression (y₁ ~ ax₁ + b) — fit models to your data and show residuals.
Cite every source in a footnote where you use it and in your bibliography. Check the licence of any dataset you download.
A possible outline
- Explain modular arithmetic with clock examples.
- Run the exchange with a small prime by hand.
- Prove the shared keys are equal.
- Investigate primitive roots and why a bad base leaks information.
- Measure how search time grows with p and reflect on real key sizes.
Pitfalls that cost marks
- Quoting results about primitive roots without testing them.
- Mixing up the public and private numbers.
- Overclaiming: real systems use extra protections you are not modelling.
Showing personal engagement
- Run the exchange with a classmate.
- Find primes whose structure makes the attack easier.
- Time your own brute-force search.
See Criterion C: personal engagement for what examiners look for.
Which course is it for?
| Course | Fit | Maths to lean on |
|---|---|---|
| AA SL | Not a natural fit | The core technique sits in the AI course or at HL; an AA SL student could use it only as clearly explained new mathematics. |
| AA HL | Good fit | Modular arithmetic and powers mod p (new: explain); Primitive roots: the order of an element |
| AI SL | Not a natural fit | The mathematics is mainly AA or HL (calculus or proof beyond AI SL); an AI SL version would need a data-driven, technology-based approach. |
| AI HL | Not a natural fit | The mathematics is mainly from the AA course; an AI HL version would need modelling with technology, statistics or networks at HL level. |
Level: Ambitious. Suits confident students; expect to learn some mathematics on your own. See how the IA differs between AA and AI, SL and HL.
How this idea reaches the top bands
Personal engagement (C)
Build and break your own small cipher or code, invent examples to test each result, and record the conjectures you made and the ones that turned out to be false.
Reflection (D)
Reflect on what each result guarantees and what it doesn't: which errors a check digit misses, which attacks a cipher survives, and how the answer depends on the size of the numbers. For this idea, start with: quoting results about primitive roots without testing them — say how it affects your answer.
Use of mathematics (E)
SL: Counting principles, probability or frequency statistics used correctly; any number theory (modular arithmetic, primes) introduced with your own small worked examples and explained, not quoted.
HL: Rigorous proofs (by contradiction or induction) of the number-theory facts you rely on, counting arguments made general, or a statistical attack tested formally.
Criteria A and B (presentation and communication) work the same way for every idea: see the guides to Criterion A and Criterion B.
Taking it further
Investigate the number of primitive roots of a prime, or Fermat's little theorem and its proof.
Extending it for HL
Prove the key result in general (why the check digit catches every single-digit error, why the decryption undoes the encryption) rather than checking examples.
See a complete IA, marked
Our annotated exemplar How far can a stack of books lean over the edge of a table? (AA HL) asks a different question, but shows how a complete cryptography exploration is structured and marked, with an examiner's comment on every criterion. Free excerpts and the full marking table are on its page.
Before you start: the checklist an examiner uses
Every check for Criteria A–E in a 4-page PDF, the mistakes that cost the most marks and a self-assessment grid. We'll email it with a short IA tip every few days, timed to your deadline if you give it. Free — no account, no payment.
While you wait for the email: read the free excerpt of a complete, annotated IA (Book-stack overhang (AA HL)) →
Turn this idea into your IA
Similar ideas
- The Collatz conjecture: what can we say about stopping times?AA SLAA HLAI SLAI HLSolid
- How many primes are there below n? Testing the prime number theoremAA SLAA HLAI SLSolid
- Which typing errors does a check digit catch? ISBN-10 versus ISBN-13AA HLAA SLSolid
- Patterns in the last digits of powersAA SLAA HLSolid