Instructors
Shafi Goldwasser
shafi at csail dot mit dot edu
Office hours: Time TBD · Location TBD
Massachusetts Institute of Technology
Fall 2026 · Graduate course
MIT 6.5620 / 6.875 / 18.425
Cryptography gives us a precise technical language for security, privacy, and integrity; a mathematical toolkit for encryption, digital signatures, zero-knowledge proofs, homomorphic encryption, and secure multiparty computation; and a complexity-theoretic framework for proving security by reduction.
This fast-paced graduate course travels from the classical
foundations to recent developments. The emphasis is not only on
constructing mechanisms, but on learning how to state what security
means—and how to prove that a construction achieves it. A particular focus of
the course this year will be on thinking about the content of the course in the
age of generative AI: both in the context of using AI to do cryptography, as well
as using cryptographic thinking to solve problems in reliable, secure and trustworthy
AI.
Pre-requisites: Fluency in algorithms (6.1220), complexity theory (6.1400), and
discrete probability (6.1200). Mathematical maturity and comfort
writing proofs are assumed right from the first lecture.
Instructors
shafi at csail dot mit dot edu
Office hours: Time TBD · Location TBD
Teaching assistants
Noga Amit
nogamit at mit dot edu
Office hours: Time TBD · Location TBD
Review Material
Grading is based on problem sets (20%) two midterm exams (40%), a final (30%), and class participation (10%). There are five problem sets. Students have ten total late days, with at most five used on any one set.
Solutions should be typeset in LaTeX and submitted as PDF by 11:59:59 PM ET on the due date.
Problem set
01Problem set
02Problem set
03Problem set
04Problem set
05Collaboration
Discussion in groups of up to three is encouraged. Every student must write their own solution and name all collaborators. The final write-up must be entirely in your own words. AI use policy!
Attribution
Published material may be used when acknowledged. Looking for or using solutions from previous years is not permitted. AI use policy!
Five modules, twenty-six class meetings. Fall classes begin September 9; this course’s final meeting is December 9. Topics remain tentative.
Module 01
Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.
Wed · Sep 09
Secure communication, Shannon’s definition, the one-time pad, and Shannon’s lower bound.
Pset 1 outMon · Sep 14
Computational adversaries, pseudorandom generators, and stateful secret-key encryption.
Wed · Sep 16
The hybrid argument, PRG length extension, pseudorandom functions, and encryption from PRFs.
Mon · Sep 21
Formal PRF security, the GGM construction, and the definition of IND-CPA security.
Wed · Sep 23
Identification protocols, message-authentication codes, and CCA-secure symmetric encryption.
Pset 1 due · Pset 2 outMon · Sep 28
Hard-core bits, pseudorandom generators, and the Goldreich–Levin theorem.
Wed · Sep 30
A complexity-theoretic view of Goldreich–Levin through local list decoding.
Module 02
Key exchange, public-key encryption, signatures, and collision-resistant hashing.
Mon · Oct 05
Key exchange and the number-theoretic ideas behind it.
Wed · Oct 07
Key exchange, continued, and the hardness assumptions that support it.
Pset 2 due · Pset 3 outMon · Oct 12
Tue · Oct 13
From key exchange to probabilistic public-key encryption. Monday schedule of classes held Tuesday.
Wed · Oct 14
Signature syntax, security, and the leftover hash lemma.
Mon · Oct 19
Signature constructions and collision-resistant hash functions.
Pset 3 due · Pset 4 outWed · Oct 21
Hash-and-sign, random oracles, and compact signature schemes.
Date · TBD
Module 03
Proofs that reveal nothing beyond validity, from interactive definitions to non-interactive systems.
Mon · Oct 26
Definitions, examples, simulation, and the knowledge-complexity viewpoint.
Wed · Oct 28
Placing NP in zero knowledge and the GMW paradigm.
Mon · Nov 02
Non-interactive zero knowledge, non-malleability, and applications.
Module 04
How mutually distrustful parties compute together: from secret sharing to fully homomorphic encryption.
Wed · Nov 04
Secret sharing and oblivious transfer.
Pset 4 due · Pset 5 outMon · Nov 09
Secure two-party and multi-party computation in the semi-honest setting.
Wed · Nov 11
Mon · Nov 16
Secure two-party computation, continued, against malicious adversaries.
Wed · Nov 18
Mon · Nov 23
Wed · Nov 25
Mon · Nov 30
Wed · Dec 02
Information-theoretic multi-party computation.
Pset 6 dueModule 05
A view toward the frontier: obfuscation, quantum cryptography, and complexity-theoretic foundations.
Mon · Dec 07
Wed · Dec 09
Guest lectures by Tina Zhang and Rahul Ilango.
Lecture notes
Textbooks