CS255 Introduction to Cryptography

Course Syllabus

Winter 2019

Optional readings can be found in the textbooks denoted by KL and AC in the syllabus below. The optional AC book, by Boneh and Shoup, is more advanced (and free) and is intended for students wishing to go deeper. The online version of the course is another resource for the material covered in class.


Lecture 1:
1/ 7/19
Overview of cryptography. What is a cipher?
Reading: AC ch.2;   KL ch 2.
Basic symmetric-key encryption
Lecture 2:
1/ 9/19
One time pad and stream ciphers
perfect secrecy and the one time pad.
semantic security and stream ciphers.
Reading: AC ch.3;   KL 3.2.1-3.4.2.
Lecture 3:
Block ciphers
Feistel networks and iterated Even-Mansour ciphers
Case studies: AES and 3DES.
Reading: AC ch. 4.1, 4.2;   KL ch 6.1-6.2.
Lecture 4:
Block cipher abstractions: PRPs and PRFs   [pdf]
Pseudo Random Permutations (PRP); Pseudo Random Functions (PRF);
security against chosen plaintext attacks (CPA);
Modes of operation: CBC and counter mode.
Reading: AC. ch. 4.4, 5;   KL ch 3.5
MLK: no classes
Lecture 5:
Attacks on block ciphers
exhaustive search, time-space tradeoffs,
differential & linear cryptanalysis, meet in the middle, side channels.
Reading: AC ch. 4.3;   KL ch 3.4.2,3.6
Message integrity
Lecture 6:
Message integrity: definition and applications
Reading: AC ch. 6;   KL ch 4.1-4.3
Lecture 7:
Collision resistant hashing
Merkle-Damgard and Davies-Meyer. MACs from collision resistance.
Case studies: SHA and HMAC.
Reading: AC ch. 8.1-8.9;   KL ch 5.1-5.3
Lecture 8:
2/ 4/19
Authenticated encryption: security against active attacks
also: intro to session setup using a key distribution center (KDC).
Reading: AC ch. 9;   KL ch 4.5
Public key cryptography
Lecture 9:
2/ 6/19
Arithmetic modulo primes
Reading: KL ch 8.
Summary of relevant facts: pdf.
Lecture 10:
Cryptography using arithmetic modulo primes
vanilla key exchange (Diffie-Hellman); the CDH and discrete-log assumptions
Reading: AC ch. 10;   KL ch 9, 11.4.1
Lecture 11:
Public key encryption
semantically secure ElGamal encryption; CCA security
Reading: AC ch. 11;   KL ch 9, 11.4.1
President's day: no classes.
Lecture 12:
Arithmetic modulo composites   [pdf]
RSA and Rabin functions.
how to encrypt with trapdoor permutations.
Reading: AC ch. 10.2, 10.3;   KL ch 11.5
Summary of relevant facts: pdf.
Digital signatures
Lecture 13:
Digital signatures: definitions and applications
How to sign using RSA.
Reading: AC ch. 13;   KL ch 12.1-12.4
Lecture 14:
More signature schemes and applications   [pdf]
Hash based signatures.
certificates, certificate transparency, certificate revocation.
Reading: AC ch. 13.8, ch. 14;   KL ch 12.5-12.8
Final topics
Lecture 15:
3/ 4/19
Identification protocols   [pdf]
Password protocols, salts; one time passwords (S/Key and SecurID);
challenge response authentication.
Reading: AC ch. 18;
Lecture 16:
3/ 6/19
Authenticated key exchange and SSL/TLS session setup   [pdf]
Reading: AC ch. 21;
Lecture 17:
Zero knowledge protocols
Reading: AC ch. 19;
Lecture 18:
Advanced topics. TBD