IA idea · Cryptography & number theory
How long would it take to guess your password? Counting and logarithms
Research question
How many guesses does it take, on average and in the worst case, to find passwords built by common rules (length, character sets, words plus digits), and which rule change adds the most security?
Adapt it: change the place, the data or the comparison until the question is yours.
Free: the A–E checklist an examiner uses, by email ↓
Why it makes a good exploration
Counting principles and logarithms answer a question everyone cares about. Comparing realistic password patterns with purely random ones shows why human choices matter more than length rules.
The mathematics you'll need
- Multiplication principle and permutations
- Expected number of guesses for a uniform search
- Logarithms: bits of entropy as log₂ of the number of possibilities
- Comparing growth: exponential in length, linear in alphabet
- Probability of guessing within k tries
Course labels show where a technique sits; using maths from outside your course is fine if you explain it clearly and say it is new to you.
Where the data comes from
No personal data. Use rules from real sign-up pages and, for word-based passwords, the size of a dictionary word list you can count.
- Desmos graphing calculator — Free graphing and regression (y₁ ~ ax₁ + b) — fit models to your data and show residuals.
Cite every source in a footnote where you use it and in your bibliography. Check the licence of any dataset you download.
A possible outline
- Count possibilities for several password rules.
- Convert to bits and to expected guessing time at a stated guess rate.
- Compare adding length with adding symbols.
- Model passphrases of random words.
- Reflect on human patterns that make the real number much smaller.
Pitfalls that cost marks
- Never collect or use anyone's real passwords.
- Treating human-chosen passwords as uniformly random.
- Using a guess rate with no source; state it as an assumption and vary it.
Showing personal engagement
- Compare the rules of sites you use.
- Design a rule that is secure and memorable.
- Survey (anonymously) which patterns people say they use, not their passwords.
See Criterion C: personal engagement for what examiners look for.
Which course is it for?
| Course | Fit | Maths to lean on |
|---|---|---|
| AA SL | Good fit | Multiplication principle and permutations; Expected number of guesses for a uniform search |
| AA HL | Fits, but add an HL technique | Multiplication principle and permutations; Expected number of guesses for a uniform search |
| AI SL | Good fit | Multiplication principle and permutations; Expected number of guesses for a uniform search |
| AI HL | Fits, but add an HL technique | Multiplication principle and permutations; Expected number of guesses for a uniform search |
Level: Accessible. A good first extended piece of maths, with room to go deeper. See how the IA differs between AA and AI, SL and HL.
How this idea reaches the top bands
Personal engagement (C)
Build and break your own small cipher or code, invent examples to test each result, and record the conjectures you made and the ones that turned out to be false.
Reflection (D)
Reflect on what each result guarantees and what it doesn't: which errors a check digit misses, which attacks a cipher survives, and how the answer depends on the size of the numbers. For this idea, start with: never collect or use anyone's real passwords — say how it affects your answer.
Use of mathematics (E)
SL: Counting principles, probability or frequency statistics used correctly; any number theory (modular arithmetic, primes) introduced with your own small worked examples and explained, not quoted.
HL: Rigorous proofs (by contradiction or induction) of the number-theory facts you rely on, counting arguments made general, or a statistical attack tested formally.
Criteria A and B (presentation and communication) work the same way for every idea: see the guides to Criterion A and Criterion B.
Taking it further
Model a dictionary attack with a probability distribution over words, or study how many guesses are needed to find one password in a large set.
Extending it for HL
Prove the key result in general (why the check digit catches every single-digit error, why the decryption undoes the encryption) rather than checking examples.
See a complete IA, marked
Our annotated exemplar How long does a game of Snakes and Ladders last on my grandmother's board? (AI HL) asks a different question, but shows how a complete cryptography exploration is structured and marked, with an examiner's comment on every criterion. Free excerpts and the full marking table are on its page.
Before you start: the checklist an examiner uses
Every check for Criteria A–E in a 4-page PDF, the mistakes that cost the most marks and a self-assessment grid. We'll email it with a short IA tip every few days, timed to your deadline if you give it. Free — no account, no payment.
While you wait for the email: read the free excerpt of a complete, annotated IA (Snakes and Ladders (AI HL)) →
Turn this idea into your IA
Similar ideas
- Finding the key length of a Vigenère cipher with the index of coincidenceAA HLAI HLAmbitious
- Breaking a cipher with letter frequencies and chi-squaredAI SLAA SLAI HLAA HLAccessible
- The Collatz conjecture: what can we say about stopping times?AA SLAA HLAI SLAI HLSolid
- Encrypting with matrices: when can a Hill cipher be undone?AI HLAA HLAmbitious
All cryptography ideas · AA SL ideas · AI SL ideas · AA HL ideas · AI HL ideas · All 239 IA ideas