Schedule
Schedule — Fall 2026
Schedule is subject to arbitrary changes.
Lectures meet Mondays and Wednesdays, 3:00–4:15 pm in Krieger 170. No class on Labor Day (Sep 7) or Thanksgiving break (Nov 23–27). Readings marked book are excerpts from the instructor’s draft book, posted here as each becomes ready (please don’t redistribute them); B&S is Boneh–Shoup (supplementary). Lecture slides and recordings are posted in the Materials column after each class.
In-class quizzes (10–12 minutes, start of class, every other Monday) are marked in the right column; each covers the lectures and readings since the previous quiz. Your best 4 of 6 count toward your grade — the two drops are the makeup policy. Code-review labs are 15-minute individual sessions scheduled outside class time during the weeks indicated.
| # | Date | Topic | Reading | Milestones | Materials |
|---|---|---|---|---|---|
| 1 | Mon Aug 31 | Introduction: practical cryptography, threat models, and course logistics | optional: METR, Investigation of the OpenAI / Hugging Face hacking incident | Lecture slides · Lecture recording | |
| 2 | Wed Sep 2 | Classical ciphers and cryptanalysis | MTU Vigenère cryptanalysis tutorial (esp. frequency analysis, Kasiski, and index-of-coincidence pages); optional: Friedman, The Index of Coincidence and Its Applications in Cryptanalysis (1922); background: book ch. 2 Background (PDF) — classical ciphers, the one-time pad, and the Enigma | A1 out | Lecture slides · Lecture recording |
| — | Mon Sep 7 | No class — Labor Day | |||
| 3 | Wed Sep 9 | Symmetric encryption I: block ciphers, stream ciphers, and modes of operation | book §5.1–5.3.1 (PDF): recommendations, ciphers (block & stream), modes of operation through CBC/CFB; B&S ch. 2–3 | A1 Part 0 (key registration) due Fri Sep 11 | Lecture slides · no recording (room equipment failure) |
| 4 | Mon Sep 14 | Symmetric encryption II: padding, chaining pitfalls, padding-oracle attacks, and authenticated encryption | book ch. 5 reading 2 (PDF): padding-oracle attacks, authenticated modes (GCM, Poly1305), nonce misuse-resistance, key-committing encryption; B&S ch. 5, 9 | In-class quiz #1 · key roster published | Lecture slides · Lecture recording |
| 5 | Wed Sep 16 | Hash functions and message authentication | book §6.1–6.3 (PDF): hash functions (building, security levels), commitments, and message authentication codes (updated Sep 21 with §6.3); supplementary: Boneh–Shoup ch. 6–7 | A1 due Fri Sep 18 | Lecture slides · Lecture recording |
| 6 | Mon Sep 21 | Randomness, entropy, and key derivation | book ch. 14 §14.1–14.2 (PDF): true and pseudo-random generation, deployed designs, testing | Review Lab 1 this week | Lecture slides · Lecture recording |
| 7 | Wed Sep 23 | Public-key cryptography I: groups, finite-field groups, and Diffie–Hellman | book §4.4.3 cyclic groups (PDF); book §7.1 public-key intro and key exchange (PDF); B&S §10.3–10.4 | Lecture recording | |
| 8 | Mon Sep 28 | Public-key cryptography II: public-key encryption, Elgamal, and KEMs (with a note on RSA) | book PK ch. (fragments, as available) | In-class quiz #2 · A2 out Tue Sep 29 | |
| 9 | Wed Sep 30 | Digital signatures and elliptic curves | supplemental: FIPS 204 | ||
| 10 | Mon Oct 5 | Midterm exam (in class). Covers all material through Sep 30. No books, no electronics. You may bring a single 8.5×11 sheet of paper, handwritten, both sides. | Midterm | ||
| 11 | Wed Oct 7 | Post-quantum key exchange: lattices and ML-KEM | Valsorda, The Math of ML-KEM; supplemental: FIPS 203 | ||
| 12 | Mon Oct 12 | Protocols I: TLS design and PKI | B&S ch. 15 | In-class quiz #3 | |
| 13 | Wed Oct 14 | Protocols II: PQC TLS and a history of TLS attacks | SSL/TLS attack papers; optional: Cloudflare, The state of the post-quantum Internet | ||
| 14 | Mon Oct 19 | Secure messaging: OTR, Signal, ratcheting, and PQXDH | Signal protocol specifications | ||
| 15 | Wed Oct 21 | Side-channel attacks: timing | timing-attack papers | ||
| 16 | Mon Oct 26 | Oracle and downgrade attacks in protocols: Bleichenbacher, compression oracles, FREAK/Logjam/DROWN | attack papers | In-class quiz #4 · A3 out | |
| 17 | Wed Oct 28 | Implementation failures: nonce reuse, RNG failures, real-world postmortems | book §14.3.2 RNG failures: X9.31, Debian, factorable keys (PDF); incident postmortems | A2 due Fri Oct 30 | |
| 18 | Mon Nov 2 | Secret sharing | B&S §22.1 | Review Lab 2 this week | |
| 19 | Wed Nov 4 | Threshold cryptography (and a glimpse of MPC) | TBA | ||
| 20 | Mon Nov 9 | Zero-knowledge proofs I | TBA | In-class quiz #5 | |
| 21 | Wed Nov 11 | Zero-knowledge proofs II: applications | TBA | ||
| 22 | Mon Nov 16 | Anonymous communication: Tor | Tor design paper | ||
| 23 | Wed Nov 18 | Anonymity II: mixnets and iCloud Private Relay | Private Relay analysis | ||
| — | Nov 23–27 | No class — Thanksgiving break | |||
| 24 | Mon Nov 30 | Cryptographic backdoors: Dual EC and the Juniper incident | book §14.3.1 Dual EC DRBG (PDF); Juniper/Dual EC paper | ||
| 25 | Wed Dec 2 | Passwords and authentication: hashing, PAKEs, passkeys, and secure value recovery | book ch. 11 (passwords), excerpt to come | ||
| 26 | Mon Dec 7 | Special topic: cryptography and AI | selected papers | In-class quiz #6 · A3 due Fri Dec 4 · Review Lab 3 this week | |
| 27 | Wed Dec 9 | Wrap-up and final exam review | |||
| — | TBA | Final exam (December exam period, scheduled by registrar). No books, no electronics. You may bring a single 8.5×11 sheet of paper, handwritten, both sides. | Final |
Assignment overview
- Assignment 1 — Classical cryptanalysis (handout PDF · repository). Implement the Vigenère cipher, then break it: index-of-coincidence key-length recovery and ciphertext-only frequency analysis. Security-critical regions and review-lab focus announced in the handout.
- Assignment 2 — Encrypted messaging: build it and break it. Implement a complete client for the JMessage end-to-end encrypted messaging system against a reference server, then implement an automated adaptive chosen-ciphertext attack that decrypts another user’s intercepted message.
- Assignment 3 — TBA. Released in late October.
Each assignment is followed by a code-review lab round (see Syllabus); you must pass the autograder to sign up for it.