Instructors
Massachusetts Institute of Technology
Fall 2026 · Graduate course
MIT 6.5620 / 6.875 / 18.425
Foundations of Cryptography
About the course
Cryptography gives us a precise technical language for security, privacy, and integrity; a mathematical toolkit for encryption, digital signatures, zero-knowledge proofs, homomorphic encryption, and secure multiparty computation; and a complexity-theoretic framework for proving security by reduction.
This fast-paced graduate course travels from the classical
foundations to recent developments. The emphasis is not only on
constructing mechanisms, but on learning how to state what security
means—and how to prove that a construction achieves it. A particular focus of
the course this year will be on thinking about the content of the course in the
age of generative AI: both in the context of using AI to do cryptography, as well
as using cryptographic thinking to solve problems in reliable, secure and trustworthy
AI.
Prerequisites: Fluency in algorithms (6.1220), complexity theory (6.1400), and
discrete probability (6.1200). Mathematical maturity and comfort
writing proofs are assumed right from the first lecture.
Course information
Teaching assistants
-
Noga Amit
nogamit at mit dot edu
Office hours: Time TBD · Location TBD
Review Material
-
Sep 08
Probability review Time TBD · Location TBD
-
Sep 15
Complexity & reductions Time TBD · Location TBD
-
Oct 06
Number theory review Time TBD · Location TBD
Assignments & grading
Grading is based on five problem sets (10%), a midterm exam (30%), a final exam (40%), an oral problem-set review (10%), and class participation (10%).
Oral problem-set review
Each student will meet individually with an instructor to present one problem selected by the instructors from any previously assigned problem set. The problem will not be announced in advance. Students may use their notes during the review. Oral reviews will be scheduled after the midterm and before the final exam.
Problem set
01- Released
- Sep 09
- Due
- Sep 23
Problem set
02- Released
- Sep 23
- Due
- Oct 07
Problem set
03- Released
- Oct 07
- Due
- Nov 04
Problem set
04- Released
- Nov 04
- Due
- Nov 18
Problem set
05- Released
- Nov 18
- Due
- Dec 02
Submission
Solutions should be typeset in LaTeX and submitted as PDF by 11:59:59 PM ET on the due date.
Late days
Students have ten total late days, with at most five used on any one problem set.
Collaboration
Discussion in groups of up to three is encouraged. Every student must write their own solution and name all collaborators. The final write-up must be entirely in their own words.
Attribution
Published material may be used when acknowledged. Looking for or using solutions from previous years is not permitted.
For the use of AI tools on problem sets, see the AI use policy above.
Schedule
Five modules, twenty-five lectures, one midterm exam, and a final exam. Fall classes begin September 9; this course’s final meeting is December 9. Topics remain tentative.
Module 01
Basics & private-key cryptography
Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.
Wed · Sep 09
Introduction & perfect secrecy
Secure communication, Shannon’s definition, the one-time pad, and Shannon’s lower bound.
Pset 1 outMon · Sep 14
Computational security & PRGs
Computational adversaries, pseudorandom generators, and stateful secret-key encryption.
Wed · Sep 16
Hybrids, PRGs & PRFs
The hybrid argument, PRG length extension, pseudorandom functions, and encryption from PRFs.
Mon · Sep 21
Pseudorandom functions
Formal PRF security, the GGM construction, and the definition of IND-CPA security.
Wed · Sep 23
Authentication & chosen-ciphertext security
Identification protocols, message-authentication codes, and CCA-secure symmetric encryption.
Pset 1 due · Pset 2 outMon · Sep 28
One-way functions
Hard-core bits, pseudorandom generators, and the Goldreich–Levin theorem.
Wed · Sep 30
Goldreich–Levin, continued
A complexity-theoretic view of Goldreich–Levin through local list decoding.
Module 02
Public-key cryptography
Key exchange, public-key encryption, signatures, and collision-resistant hashing.
Mon · Oct 05
Public-key cryptography I
Key exchange and the number-theoretic ideas behind it.
Wed · Oct 07
Public-key cryptography II
Key exchange, continued, and the hardness assumptions that support it.
Pset 2 due · Pset 3 outMon · Oct 12
Tue · Oct 13
Public-key cryptography III
From key exchange to probabilistic public-key encryption. Monday schedule of classes held Tuesday.
Wed · Oct 14
Public-key encryption IV
Trapdoor permutations, RSA, and further constructions for public-key encryption.
Mon · Oct 19
Wed · Oct 21
Digital signatures I
Signature syntax, security, and the leftover hash lemma.
Mon · Oct 26
Digital signatures II
Signature constructions and collision-resistant hash functions.
Wed · Oct 28
Digital signatures III
Hash-and-sign, random oracles, and compact signature schemes.
Module 03
Zero knowledge
Proofs that reveal nothing beyond validity, from interactive definitions to non-interactive systems.
Mon · Nov 02
Zero knowledge I
Definitions, examples, simulation, and the knowledge-complexity viewpoint.
Wed · Nov 04
Zero knowledge II
Placing NP in zero knowledge and the GMW paradigm.
Pset 3 due · Pset 4 outMon · Nov 09
Zero knowledge III
Non-interactive zero knowledge, non-malleability, and applications.
Wed · Nov 11
Module 04
Secure computation
How mutually distrustful parties compute together: from secret sharing to fully homomorphic encryption.
Mon · Nov 16
Secure computation: the toolkit
Secret sharing and oblivious transfer.
Wed · Nov 18
The GMW protocol
Secure two-party and multi-party computation in the semi-honest setting.
Pset 4 due · Pset 5 outMon · Nov 23
Yao’s garbled circuits
Wed · Nov 25
Fully homomorphic encryption I
Mon · Nov 30
Fully homomorphic encryption II
Wed · Dec 02
The BGW protocol
Information-theoretic multi-party computation.
Pset 5 dueModule 05
Advanced topics
A view toward the frontiers of modern cryptography.
Mon · Dec 07
Identity-based encryption
Wed · Dec 09
AI / Obfuscation
Date · TBA
Resources
Lecture notes
Textbooks