Massachusetts Institute of Technology

Fall 2026 · Graduate course

MIT 6.5620 / 6.875 / 18.425

Foundations of Cryptography

Cryptography gives us a precise technical language for security, privacy, and integrity; a mathematical toolkit for encryption, digital signatures, zero-knowledge proofs, homomorphic encryption, and secure multiparty computation; and a complexity-theoretic framework for proving security by reduction.

This fast-paced graduate course travels from the classical foundations to recent developments. The emphasis is not only on constructing mechanisms, but on learning how to state what security means—and how to prove that a construction achieves it. A particular focus of the course this year will be on thinking about the content of the course in the age of generative AI: both in the context of using AI to do cryptography, as well as using cryptographic thinking to solve problems in reliable, secure and trustworthy AI.

Pre-requisites: Fluency in algorithms (6.1220), complexity theory (6.1400), and discrete probability (6.1200). Mathematical maturity and comfort writing proofs are assumed right from the first lecture.

Teaching assistants

  • Noga Amit

    nogamit at mit dot edu

    Office hours: Time TBD · Location TBD

Grading is based on problem sets (20%) two midterm exams (40%), a final (30%), and class participation (10%). There are five problem sets. Students have ten total late days, with at most five used on any one set.

Solutions should be typeset in LaTeX and submitted as PDF by 11:59:59 PM ET on the due date.

Collaboration

Discussion in groups of up to three is encouraged. Every student must write their own solution and name all collaborators. The final write-up must be entirely in your own words. AI use policy!

Attribution

Published material may be used when acknowledged. Looking for or using solutions from previous years is not permitted. AI use policy!

Five modules, twenty-six class meetings. Fall classes begin September 9; this course’s final meeting is December 9. Topics remain tentative.

Module 01

Basics & private-key cryptography

Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.

Lecture 01

Wed · Sep 09

Introduction & perfect secrecy

Secure communication, Shannon’s definition, the one-time pad, and Shannon’s lower bound.

Pset 1 out
Lecture 02

Mon · Sep 14

Computational security & PRGs

Computational adversaries, pseudorandom generators, and stateful secret-key encryption.

Lecture 03

Wed · Sep 16

Hybrids, PRGs & PRFs

The hybrid argument, PRG length extension, pseudorandom functions, and encryption from PRFs.

Lecture 04

Mon · Sep 21

Pseudorandom functions

Formal PRF security, the GGM construction, and the definition of IND-CPA security.

Lecture 05

Wed · Sep 23

Authentication & chosen-ciphertext security

Identification protocols, message-authentication codes, and CCA-secure symmetric encryption.

Pset 1 due · Pset 2 out
Lecture 06

Mon · Sep 28

One-way functions

Hard-core bits, pseudorandom generators, and the Goldreich–Levin theorem.

Lecture 07

Wed · Sep 30

Goldreich–Levin, continued

A complexity-theoretic view of Goldreich–Levin through local list decoding.

Module 02

Public-key cryptography

Key exchange, public-key encryption, signatures, and collision-resistant hashing.

Lecture 08

Mon · Oct 05

Public-key cryptography I

Key exchange and the number-theoretic ideas behind it.

Lecture 09

Wed · Oct 07

Public-key cryptography II

Key exchange, continued, and the hardness assumptions that support it.

Pset 2 due · Pset 3 out

Mon · Oct 12

No lecture · Indigenous Peoples’ DayMonday schedule held Tue · Oct 13
Lecture 10

Tue · Oct 13

Public-key cryptography III

From key exchange to probabilistic public-key encryption. Monday schedule of classes held Tuesday.

Lecture 11

Wed · Oct 14

Digital signatures I

Signature syntax, security, and the leftover hash lemma.

Lecture 12

Mon · Oct 19

Digital signatures II

Signature constructions and collision-resistant hash functions.

Pset 3 due · Pset 4 out
Lecture 13

Wed · Oct 21

Digital signatures III

Hash-and-sign, random oracles, and compact signature schemes.

Date · TBD

Midterm examTime and location to be announced

Module 03

Zero knowledge

Proofs that reveal nothing beyond validity, from interactive definitions to non-interactive systems.

Lecture 14

Mon · Oct 26

Zero knowledge I

Definitions, examples, simulation, and the knowledge-complexity viewpoint.

Lecture 15

Wed · Oct 28

Zero knowledge II

Placing NP in zero knowledge and the GMW paradigm.

Lecture 16

Mon · Nov 02

Zero knowledge III

Non-interactive zero knowledge, non-malleability, and applications.

Module 04

Secure computation

How mutually distrustful parties compute together: from secret sharing to fully homomorphic encryption.

Lecture 17

Wed · Nov 04

Secure computation: the toolkit

Secret sharing and oblivious transfer.

Pset 4 due · Pset 5 out
Lecture 18

Mon · Nov 09

The GMW protocol

Secure two-party and multi-party computation in the semi-honest setting.

Wed · Nov 11

No lectureVeterans Day · Institute holiday
Lecture 19

Mon · Nov 16

Malicious security

Secure two-party computation, continued, against malicious adversaries.

Lecture 20

Wed · Nov 18

Yao’s garbled circuits

Pset 5 due · Pset 6 out
Lecture 21

Mon · Nov 23

Merkle trees & oblivious RAM

Lecture 22

Wed · Nov 25

Fully homomorphic encryption

Lecture 23

Mon · Nov 30

Security against malicious adversaries

Lecture 24

Wed · Dec 02

The BGW protocol

Information-theoretic multi-party computation.

Pset 6 due

Module 05

Advanced topics

A view toward the frontier: obfuscation, quantum cryptography, and complexity-theoretic foundations.

Lecture 25

Mon · Dec 07

Program obfuscation

Lecture 26

Wed · Dec 09

Quantum cryptography & complexity-theoretic foundations

Guest lectures by Tina Zhang and Rahul Ilango.