Instructors
Vinod Vaikuntanathan
vinodv at csail dot mit dot edu
Office hours: Wed · 2:30–3:30 PM · 32-G696
Massachusetts Institute of Technology
Fall 2026 · Graduate course
MIT 6.5620 / 6.875 / 18.425
Cryptography gives us a precise technical language to define important notions such as security, privacy and integrity; a mathematical toolkit to construct mechanisms for encryption, digital signatures, zero-knowledge proofs, homomorphic encryption and secure multiparty computation; and a complexity-theoretic framework to prove security using reductions. Together, they help us enforce the rules of the road in digital interactions.
This fast-paced graduate course travels from the classical
foundations to recent developments. The emphasis is not only on
constructing mechanisms, but on learning how to state what security
means—and how to prove that a construction achieves it.
Prerequisites: Fluency in algorithms (6.1220), complexity theory (6.1400), and
discrete probability (6.1200). Mathematical maturity and comfort
writing proofs are assumed right from the first lecture.
Instructors
vinodv at csail dot mit dot edu
Office hours: Wed · 2:30–3:30 PM · 32-G696
Teaching assistants
Noga Amit
nogamit at mit dot edu
Office hours: Time TBD · Location TBD
Review Material
Grading is based on five problem sets (10%), a midterm exam (30%), a final exam (40%), an oral problem-set review (10%), and class participation (10%).
Oral problem-set review
Each student will meet individually with an instructor to present one problem selected by the instructors from any previously assigned problem set. The problem will not be announced in advance. Students may use their notes during the review. Oral reviews will be scheduled after the midterm and before the final exam.
Problem set
01Problem set
02Problem set
03Problem set
04Problem set
05Submission
Solutions should be typeset in LaTeX and submitted as PDF by 11:59:59 PM ET on the due date.
Late days
Students have ten total late days, with at most five used on any one problem set.
Collaboration
Discussion in groups of up to three is encouraged. Every student must write their own solution and name all collaborators. The final write-up must be entirely in their own words.
Attribution
Published material may be used when acknowledged. Looking for or using solutions from previous years is not permitted.
For the use of AI tools on problem sets, see the AI use policy above.
Five modules, twenty-five lectures, one midterm exam, and a final exam. Fall classes begin September 9; this course’s final meeting is December 9. Topics remain tentative.
Module 01
Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.
Wed · Sep 09
Secure communication, Shannon’s definition, the one-time pad, and Shannon’s lower bound.
Pset 1 outMon · Sep 14
Computational adversaries, pseudorandom generators, and stateful secret-key encryption.
Wed · Sep 16
The hybrid argument, PRG length extension, pseudorandom functions, and encryption from PRFs.
Mon · Sep 21
Formal PRF security, the GGM construction, and the definition of IND-CPA security.
Wed · Sep 23
Identification protocols, message-authentication codes, and CCA-secure symmetric encryption.
Pset 1 due · Pset 2 outMon · Sep 28
Hard-core bits, pseudorandom generators, and the Goldreich–Levin theorem.
Wed · Sep 30
A complexity-theoretic view of Goldreich–Levin through local list decoding.
Module 02
Key exchange, public-key encryption, signatures, and collision-resistant hashing.
Mon · Oct 05
Key exchange and the number-theoretic ideas behind it.
Wed · Oct 07
Key exchange, continued, and the hardness assumptions that support it.
Pset 2 due · Pset 3 outMon · Oct 12
Tue · Oct 13
From key exchange to probabilistic public-key encryption. Monday schedule of classes held Tuesday.
Wed · Oct 14
Trapdoor permutations, RSA, and further constructions for public-key encryption.
Mon · Oct 19
Wed · Oct 21
Signature syntax, security, and the leftover hash lemma.
Mon · Oct 26
Signature constructions and collision-resistant hash functions.
Wed · Oct 28
Hash-and-sign, random oracles, and compact signature schemes.
Pset 3 due · Pset 4 outMon · Nov 02
Module 03
Proofs that reveal nothing beyond validity, from interactive definitions to non-interactive systems.
Wed · Nov 04
Definitions, examples, simulation, and the knowledge-complexity viewpoint.
Mon · Nov 09
Placing NP in zero knowledge and the GMW paradigm.
Wed · Nov 11
Mon · Nov 16
Non-interactive zero knowledge, non-malleability, and applications.
Module 04
How mutually distrustful parties compute together: from secret sharing to fully homomorphic encryption.
Wed · Nov 18
Secret sharing and oblivious transfer.
Pset 4 due · Pset 5 outMon · Nov 23
Secure two-party and multi-party computation in the semi-honest setting.
Wed · Nov 25
Mon · Nov 30
Wed · Dec 02
Mon · Dec 07
Information-theoretic multi-party computation.
Module 05
A view toward the frontiers of modern cryptography.
Wed · Dec 09
Date · TBA
Lecture notes
Textbooks