The unicity distance is the ciphertext length at which the key is uniquely determined, or equivalently at which key equivocation vanishes:For Shannon's idealized calculation, assume a uniformly chosen key independent of an iid plaintext source, deterministic invertible encryption for each key, and uniformly distributed ciphertext over an alphabet . Since is determined by ,Setting this to zero givesEquivalently, each ciphertext symbol supplies the source redundancy bits toward identifying the key.
For the stated cipher, the original formula uses , so , while . Split first according to whether . This event and its complement each have probability , and conditional on the probabilities are . HenceIf , thenso, using ,Therefore
Binary entropy is symmetric about probability and increases up to that point. Since equality holds at , it also holds at . Thusand all requested values are
Finally let , so the source is uniform on . Use one uniform key bit and encrypt each symbol byThus the second key swaps and . Every ciphertext has two possible plaintexts, a binary string and its complement, with equal source probability. No amount of ciphertext distinguishes the keys: for every . This cipher has infinite unicity distance.
Solved by gpt-5.6-sol high.
Codex Wiki