I'm intrigued by how the law would handle one time pad cryptography in such a case. You could produce two numbers of similar length, each on its own bearing no relationship to the 'illegal' number, but which can be combined to give that number. Then post them separately. Could either of them legally be taken down?
I believe they would both be infringing. The issue here is intent, and the intent of those two numbers are both to be used to recreate the original number. It's not any different than if one website had the first half and another had the second half.
The alternative here would be if you could somehow find preexisting content whose intent was not to recreate this number. In that case it's trivial that the only infringing content would be something that told you how to recreate it based on those (eg if you just have a website for each digit that is trivially noninfringing, but a website that links to each of those websites in the correct order is infringing).
It's easy to act like this is absurd because of the natural existing of numbers, but the law is generally pragrmatic and not concerned with extreme hypotheticals. You could similarly argue (and plenty have on internet forums) that every mp3 in existence could be found encoded somewhere in pi, which is technically true but absolutely irrelevant in copyright law; if you encode someones content in a novel encoding it's still infringing the other ephemeral protected content.
The only way to produce such a pair of numbers is by using the restricted material as a source -- therefore the numbers would be a derivative work. This is already covered under copyright law.
Now there is a twist to this concept -- plausible deny-ability. Let's say Bob posts a non-infringing work encrypted with a one time pad (randomly generated), and also posts the one time pad too. Both files would appear to be random text until put together. Further, someone else, Bill, produces a "random" number by XORing the Bob's one-time pad with an infringing work, and uses the result as a one-time pad to encrypt another non-infringing work, and posts both of those files. The two one-time pads can recreate the infringing work by XORing them together. But you can't prove who's "random" file was actually randomly created, and which one was produced as a derivative work. Who do you send the take-down notice to?
The initial example presents the same which-part-is-infringing conundrum as the more convoluted example you presented.
- restricted material is X
- generate Y randomly (using a typical cryptographically secure RNG or PRNG, zero-bias, with an entropy source unlikely to be observed by anyone else)
- Z = X xor Y
There is no way to prove that it wasn't Z generated randomly, with Y = X xor Z.
It's clear that the only way to generate both Y and Z is to have the restricted material, but you don't know which piece is tainted and which isn't. You have to know which piece was generated first to know which one is infringing (the non-infringing one had to be used as input for the infringing one).
That just encourages the powers that be to take a "shoot 'em both and let God sort it out" approach. Also, the metadata that says Z = X xor Y will be seen as infringing.
I think my case is essentially identical to yours. One of my two numbers (the 'key' of the one time pad) is randomly generated, so it can't be a derivative work. But there's no way of telling which that is.
The main difference is that the case I presented, although it may seem to be a stretch, there is a plausible reason for the two random-looking files to be present on one site (or the other). Whereas if each site only had one random-looking file, in neither case was there a plausible reason for that file to be there.