Schedule

The following is a tentative list of topics that may be covered. Some adjustments to the topics may occur over the course of the semester. Click on each topic for links to lecture notes and suggested readings.

  • Introduction to cryptography
  • The one-time pad and perfect secrecy
  • Pseudorandom generators (PRGs)
  • Cryptographic definitions and security reductions
  • Semantic security
  • Examples of attacks and security reductions
  • Security of a stream cipher
  • Introduction to hybrid arguments
  • The Blum-Micali PRG
  • Hybrid arguments
  • Stream cipher constructions
Mon, Sep 7 Labor Day (No Class)
  • Chosen-plaintext security (CPA-security)
  • Pseudorandom functions (PRFs) and permutations (PRPs)
  • PRF switching lemma
  • Counter mode encryption (CTR)
  • Cipher block chaining mode encryption (CBC)
  • Introduction to message integrity
  • Message authentication codes (MACs)
  • MACs from PRFs
  • Collision-resistant hash functions (CRHFs)
  • Birthday bound
  • Merkle-Damgård construction
  • Davies-Meyer compression function
  • Hash-based MACs (HMAC)
  • Domain extension for PRFs
  • rawCBC, ECBC, CMAC, and PMAC
  • Authenticated encryption
  • CCA-security
  • Authenticated encryption from encrypt-then-MAC
  • One-time MAC and the Carter-Wegman MAC
  • Galois counter mode (GCM)
  • Authenticated encryption with associated data
  • Even-Mansour cipher
  • Advanced Encryption Standard (AES)
  • One-way functions
  • Merkle puzzles and key-agreement protocols
  • Prime-order groups: definitions and properties
  • Discrete log, CDH, and DDH
  • Concrete instantiations of discrete log groups
  • Diffie-Hellman key exchange
  • Public-key encryption
  • ElGamal encryption
  • CCA-secure public-key encryption
  • Hybrid encryption
  • Elliptic-curve groups
  • Digital signatures
  • One-way functions
  • Lamport signatures
  • Merkle signatures
  • Identification schemes
  • Signatures from identification schemes
  • Schnorr's identification scheme
  • Digital signature algorithm (DSA)
  • Authenticated key exchange (AKE)
  • Transport Layer Security (TLS)
Mon, Oct 26 Exam 1 (In Class)
  • Interactive proofs
  • Defining zero knowledge and the simulation paradigm
  • Zero-knowledge proof for 3-coloring
  • Implications of quantum computing on cryptography
  • Introduction to lattices
  • Short integer solutions (SIS) problem
  • Short integer solutions (SIS) problem
  • Collision-resistant hash functions from SIS
  • The leftover hash lemma (LHL)
  • Commitments from SIS
  • Inhomogeneous SIS and gadget trapdoors
  • Lattice-based signatures in the random oracle model
  • Preimage-sampleable trapdoor functions
  • Lattice-based signatures in the random oracle model
  • The learning with errors (LWE) assumption
  • Symmetric encryption from LWE
  • Public-key encryption from LWE
  • Somewhat homomorphic encryption (SWHE)
  • The Gentry-Sahai-Waters (GSW) FHE scheme
  • Bootstrapping SWHE to FHE
  • Key agreement from LWE
Mon, Nov 23 Thanksgiving Break (No Class)
Wed, Nov 25 Thanksgiving Break (No Class)
  • Private information retrieval (PIR)
Wed, Dec 2 Course Wrap-up / Catch-Up Lecture
Mon, Dec 7 Exam 2 (In Class)