Schedule — Fall 2026

Schedule is subject to arbitrary changes.

Lectures meet Mondays and Wednesdays, 3:00–4:15 pm in Krieger 170. No class on Labor Day (Sep 7) or Thanksgiving break (Nov 23–27). Readings marked book are excerpts from the instructor’s draft book, posted here as each becomes ready (please don’t redistribute them); B&S is Boneh–Shoup (supplementary). Lecture slides and recordings are posted in the Materials column after each class.

In-class quizzes (10–12 minutes, start of class, every other Monday) are marked in the right column; each covers the lectures and readings since the previous quiz. Your best 4 of 6 count toward your grade — the two drops are the makeup policy. Code-review labs are 15-minute individual sessions scheduled outside class time during the weeks indicated.

# Date Topic Reading Milestones Materials
1 Mon Aug 31 Introduction: practical cryptography, threat models, and course logistics optional: METR, Investigation of the OpenAI / Hugging Face hacking incident   Lecture slides · Lecture recording
2 Wed Sep 2 Classical ciphers and cryptanalysis MTU Vigenère cryptanalysis tutorial (esp. frequency analysis, Kasiski, and index-of-coincidence pages); optional: Friedman, The Index of Coincidence and Its Applications in Cryptanalysis (1922); background: book ch. 2 Background (PDF) — classical ciphers, the one-time pad, and the Enigma A1 out Lecture slides · Lecture recording
— Mon Sep 7 No class — Labor Day      
3 Wed Sep 9 Symmetric encryption I: block ciphers, stream ciphers, and modes of operation book §5.1–5.3.1 (PDF): recommendations, ciphers (block & stream), modes of operation through CBC/CFB; B&S ch. 2–3 A1 Part 0 (key registration) due Fri Sep 11 Lecture slides · no recording (room equipment failure)
4 Mon Sep 14 Symmetric encryption II: padding, chaining pitfalls, padding-oracle attacks, and authenticated encryption book ch. 5 reading 2 (PDF): padding-oracle attacks, authenticated modes (GCM, Poly1305), nonce misuse-resistance, key-committing encryption; B&S ch. 5, 9 In-class quiz #1 · key roster published Lecture slides · Lecture recording
5 Wed Sep 16 Hash functions and message authentication book §6.1–6.3 (PDF): hash functions (building, security levels), commitments, and message authentication codes (updated Sep 21 with §6.3); supplementary: Boneh–Shoup ch. 6–7 A1 due Fri Sep 18 Lecture slides · Lecture recording
6 Mon Sep 21 Randomness, entropy, and key derivation book ch. 14 §14.1–14.2 (PDF): true and pseudo-random generation, deployed designs, testing Review Lab 1 this week Lecture slides · Lecture recording
7 Wed Sep 23 Public-key cryptography I: groups, finite-field groups, and Diffie–Hellman book §4.4.3 cyclic groups (PDF); book §7.1 public-key intro and key exchange (PDF); B&S §10.3–10.4   Lecture recording
8 Mon Sep 28 Public-key cryptography II: public-key encryption, Elgamal, and KEMs (with a note on RSA) book PK ch. (fragments, as available) In-class quiz #2 · A2 out Tue Sep 29  
9 Wed Sep 30 Digital signatures and elliptic curves supplemental: FIPS 204    
10 Mon Oct 5 Midterm exam (in class). Covers all material through Sep 30. No books, no electronics. You may bring a single 8.5×11 sheet of paper, handwritten, both sides.   Midterm  
11 Wed Oct 7 Post-quantum key exchange: lattices and ML-KEM Valsorda, The Math of ML-KEM; supplemental: FIPS 203    
12 Mon Oct 12 Protocols I: TLS design and PKI B&S ch. 15 In-class quiz #3  
13 Wed Oct 14 Protocols II: PQC TLS and a history of TLS attacks SSL/TLS attack papers; optional: Cloudflare, The state of the post-quantum Internet    
14 Mon Oct 19 Secure messaging: OTR, Signal, ratcheting, and PQXDH Signal protocol specifications    
15 Wed Oct 21 Side-channel attacks: timing timing-attack papers    
16 Mon Oct 26 Oracle and downgrade attacks in protocols: Bleichenbacher, compression oracles, FREAK/Logjam/DROWN attack papers In-class quiz #4 · A3 out  
17 Wed Oct 28 Implementation failures: nonce reuse, RNG failures, real-world postmortems book §14.3.2 RNG failures: X9.31, Debian, factorable keys (PDF); incident postmortems A2 due Fri Oct 30  
18 Mon Nov 2 Secret sharing B&S §22.1 Review Lab 2 this week  
19 Wed Nov 4 Threshold cryptography (and a glimpse of MPC) TBA    
20 Mon Nov 9 Zero-knowledge proofs I TBA In-class quiz #5  
21 Wed Nov 11 Zero-knowledge proofs II: applications TBA    
22 Mon Nov 16 Anonymous communication: Tor Tor design paper    
23 Wed Nov 18 Anonymity II: mixnets and iCloud Private Relay Private Relay analysis    
— Nov 23–27 No class — Thanksgiving break      
24 Mon Nov 30 Cryptographic backdoors: Dual EC and the Juniper incident book §14.3.1 Dual EC DRBG (PDF); Juniper/Dual EC paper    
25 Wed Dec 2 Passwords and authentication: hashing, PAKEs, passkeys, and secure value recovery book ch. 11 (passwords), excerpt to come    
26 Mon Dec 7 Special topic: cryptography and AI selected papers In-class quiz #6 · A3 due Fri Dec 4 · Review Lab 3 this week  
27 Wed Dec 9 Wrap-up and final exam review      
— TBA Final exam (December exam period, scheduled by registrar). No books, no electronics. You may bring a single 8.5×11 sheet of paper, handwritten, both sides.   Final  

Assignment overview

  • Assignment 1 — Classical cryptanalysis (handout PDF · repository). Implement the Vigenère cipher, then break it: index-of-coincidence key-length recovery and ciphertext-only frequency analysis. Security-critical regions and review-lab focus announced in the handout.
  • Assignment 2 — Encrypted messaging: build it and break it. Implement a complete client for the JMessage end-to-end encrypted messaging system against a reference server, then implement an automated adaptive chosen-ciphertext attack that decrypts another user’s intercepted message.
  • Assignment 3 — TBA. Released in late October.

Each assignment is followed by a code-review lab round (see Syllabus); you must pass the autograder to sign up for it.