How to run a mode 01 Pick a mode from the tab row and fill its fields; integer-only inputs are validated before any arithmetic runs. 02 Prime: enter an integer, press Compute, and read the verdict plus the neighbouring primes. 03 Factor: the result is n = product of prime powers, followed by every divisor sorted ascending. 04 Modular: a and n give a mod n, a⁻¹ mod n when gcd(a, n) = 1, φ(n) and a^φ(n) mod n when n ≤ 10¹². 05 CRT: one "remainder, modulus" pair per line; the answer is the smallest non-negative x and the combined modulus. 06 RSA / Crypto: p and q must pass primality checks; the message must be smaller than n; the round trip and Bézout identity are printed for verification.
Worked readouts
Mode · input
Readout
Prime · 561
561 is NOT Prime ✗ ; Prev prime 557 ; Next prime 563
Factor · 360
360 = 2^3 × 3^2 × 5 ; Divisors (24 ): 1, 2, 3, 4, 5, 6, 8, 9, 10, 12, … 360
Modular · a 17, n 5
17 mod 5 = 2 ; Mod inverse 3 ; φ(5) = 4 ; 17^φ(5) mod 5 = 1
Modular · a 14, n 21
Mod inverse none (gcd(14, 21) = 7 ≠ 1)
Base · 255, 10 → 16
Dec 255 ; Bin 11111111 ; Oct 377 ; Hex FF
φ(n) · 100
φ(100) = 40 ; Prime No ; Factors 2 × 2 × 5 × 5
RSA · p 61, q 53, msg 42
n 3233 , φ 3120 , e 7 , d 1783 ; Encrypt 42^7 mod 3233 = 240 ; Decrypt 240^1783 mod 3233 = 42 ; round trip matches ✓
BigInt Crypto · a 123456789012345678901234567890, b 65537, m 998244353
gcd 1 ; Bézout a·(−30199) + b·(56888041432836827397323385503) = 1 ; a^b mod m = 825377327
CRT · 2,3 / 3,5 / 2,7
General solution x = 23 + 105·k
The modular row is Fermat's little theorem in one line: φ(5) = 4 and 17⁴ mod 5 = 1 . The CRT row checks out three ways — 23 mod 3 = 2 , 23 mod 5 = 3 , 23 mod 7 = 2 — and the RSA round trip returns the original message 42 , which is the point of printing both directions.
Why 561 is the interesting test 561 = 3 × 11 × 17 is a Carmichael number: it satisfies a^560 ≡ 1 (mod 561) for every a coprime to it, so a naive Fermat test calls it prime. The panel uses Miller–Rabin with a fixed base set, which detects the composite and prints NOT Prime , while the neighbouring primes come back as 557 and 563 . The same check guards RSA: p and q are rejected before any key is built if either fails, and e is chosen coprime with φ(n) by gcd, not by a modulo test.
Limits
Trial division has a ceiling. Factoring and φ(n) by trial division refuse n above 2⁵³ − 1 and φ(n) above 10¹² rather than mis-factoring; the BigInt Crypto tab still handles primality and modular powers for larger inputs.
RSA is a teaching demo. p and q are limited to 50 digits, the message must be smaller than n, and the panel never claims security — it is for checking the arithmetic, not generating keys. What it doesn't do. It does not factor semiprimes of cryptographic size, run elliptic-curve or Pollard methods, or compute discrete logarithms; for exact fractions, gcd and lcm use the arithmetic tab of step-by-step , for root scans and linear systems use equations , and for statistical sampling over integers use statistics .
The coprime trap A modular inverse exists only when gcd(a, n) = 1. Enter a = 14, n = 21 and the panel answers none (gcd(14, 21) = 7 ≠ 1) instead of a number that would not multiply back to 1. The same guard explains the RSA field: e = 65537 is replaced when it is not coprime with φ(n) — for p 61, q 53 the panel settles on e = 7 and d = 1783 , and 7 × 1783 = 12481 ≡ 1 (mod 3120).
Where it is useful Homework checks without a calculator stack Prime, factor and divisor lists answer most elementary number-theory exercises in one pass; the previous/next prime rows make prime-gap questions quick, and base conversion covers the 2–36 range.
Learning why cryptography needs more than a demo The RSA tab shows every step — n, φ, e, d, both modular powers — and the round-trip line is the correctness proof. The BigInt tab then shows that the same primitives scale to 30-digit inputs: the Bézout identity still returns 1 and a^b mod m is exact, while factoring the modulus is exactly the problem the panel refuses to pretend to solve.
Privacy All integer arithmetic runs in your browser; nothing you enter is sent anywhere.
References
Wikipedia, Miller–Rabin primality test , en.wikipedia.org (访问日期:2026-10-07)— deterministic base sets and probable primes.
Wikipedia, Carmichael number , en.wikipedia.org (访问日期:2026-10-07)— composites that fool Fermat tests.
Wikipedia, Modular multiplicative inverse , en.wikipedia.org (访问日期:2026-10-07)— existence iff gcd = 1.
Wikipedia, Chinese remainder theorem , en.wikipedia.org (访问日期:2026-10-07)— systems with coprime and non-coprime moduli.
Wikipedia, RSA (cryptosystem) , en.wikipedia.org (访问日期:2026-10-07)— key generation and the e·d ≡ 1 relation.
Calculators in this hub
Hand-picked tools, one click away. The mini versions compute live and carry your values into the full calculator.
Sources & review
Reviewed by CalcX Editorial Team
Updated 2026-10-07