MIT EECS · LECTURE NOTES
Main course site
Massachusetts Institute of Technology

Foundations of
Cryptography

A rigorous introduction to modern cryptography.

COURSE6.5620 · 6.875 · 18.425
TERMFall 2026
INSTRUCTORSS. Goldwasser · V. Vaikuntanathan
ABOUT THESE NOTES

This site follows the course’s official twenty-five-lecture sequence. Detailed notes will be added lecture by lecture.

THE COURSE

Lecture sequence

25 lectures · 5 modules

MODULE 01

Basics & private-key cryptography

Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.

01SEP 09Introduction & perfect secrecySecure communication, Shannon’s definition, the one-time pad, and Shannon’s lower bound.READ
NOTES →
02SEP 14Computational security & PRGsComputational adversaries, pseudorandom generators, and stateful secret-key encryption.NOTES
FORTHCOMING
03SEP 16Hybrids, PRGs & PRFsThe hybrid argument, PRG length extension, pseudorandom functions, and encryption from PRFs.NOTES
FORTHCOMING
04SEP 21Pseudorandom functionsFormal PRF security, the GGM construction, and the definition of IND-CPA security.NOTES
FORTHCOMING
05SEP 23Authentication & chosen-ciphertext securityIdentification protocols, message-authentication codes, and CCA-secure symmetric encryption.NOTES
FORTHCOMING
06SEP 28One-way functionsHard-core bits, pseudorandom generators, and the Goldreich–Levin theorem.NOTES
FORTHCOMING
07SEP 30Goldreich–Levin, continuedA complexity-theoretic view of Goldreich–Levin through local list decoding.NOTES
FORTHCOMING
MODULE 02

Public-key cryptography

Key exchange, public-key encryption, signatures, and collision-resistant hashing.

08OCT 05Public-key cryptography IKey exchange and the number-theoretic ideas behind it.NOTES
FORTHCOMING
09OCT 07Public-key cryptography IIKey exchange, continued, and the hardness assumptions that support it.NOTES
FORTHCOMING
10OCT 13Public-key cryptography IIIFrom key exchange to probabilistic public-key encryption.NOTES
FORTHCOMING
11OCT 14Public-key cryptography IVTrapdoor permutations, RSA, and further constructions for public-key encryption.NOTES
FORTHCOMING
12OCT 21Digital signatures ISignature syntax, security, and the leftover hash lemma.NOTES
FORTHCOMING
13OCT 26Digital signatures IISignature constructions and collision-resistant hash functions.NOTES
FORTHCOMING
14OCT 28Digital signatures IIIHash-and-sign, random oracles, and compact signature schemes.NOTES
FORTHCOMING
15NOV 02Identity-based encryptionPublic-key encryption where a user’s identity can serve as a public key.NOTES
FORTHCOMING
MODULE 03

Zero knowledge

Proofs that reveal nothing beyond validity, from interactive definitions to non-interactive systems.

16NOV 04Zero knowledge IDefinitions, examples, simulation, and the knowledge-complexity viewpoint.NOTES
FORTHCOMING
17NOV 09Zero knowledge IIPlacing NP in zero knowledge and the GMW paradigm.NOTES
FORTHCOMING
18NOV 16Zero knowledge IIINon-interactive zero knowledge, non-malleability, and applications.NOTES
FORTHCOMING
MODULE 04

Secure computation

How mutually distrustful parties compute together: from secret sharing to fully homomorphic encryption.

19NOV 18Secure computation: the toolkitSecret sharing and oblivious transfer.NOTES
FORTHCOMING
20NOV 23The GMW protocolSecure two-party and multi-party computation in the semi-honest setting.NOTES
FORTHCOMING
21NOV 25Yao’s garbled circuitsSecure two-party computation through garbling and oblivious transfer.NOTES
FORTHCOMING
22NOV 30Fully homomorphic encryption IComputing on encrypted data: definitions and first constructions.NOTES
FORTHCOMING
23DEC 02Fully homomorphic encryption IIBootstrapping and the path to fully homomorphic evaluation.NOTES
FORTHCOMING
24DEC 07The BGW protocolInformation-theoretic multi-party computation.NOTES
FORTHCOMING
MODULE 05

Advanced topics

A view toward the frontiers of modern cryptography.

25DEC 09The frontiers of cryptographyRecent directions and open questions across modern cryptography.NOTES
FORTHCOMING