Cryptography and Information Security Lab

Department of Computer Science and Automation

CSA E0 235 : Cryptography
(August - December 2026)


Instructor: Arpita Patra (Email: arpita AT iisc DOT ac DOT in)

Timings: 03:30 pm - 05:00 pm on Monday and Wednesday.

Venue: CSA 112

Study Materials

  • [KL] “Introduction to Modern Cryptography” by Jonathan Katz and Yehuda Lindell, second edition 2014, CRC Press.
  • [Gol] “Foundations of Cryptography” by Oded Goldreich.
  • [BS] “A Graduate Course in Applied Cryptography” by Dan Boneh and Victor Shoup. [Link]
  • [Sti] “Cryptography: Theory and Practice” by Douglas R. Stinson, third edition 2003, CRC.
  • [MOV] “Handbook of Applied Cryptography” by Alfred J. Menezes, Paul C. van Oorschot and Scott A. Vanstone, first edition 1997, CRC Press.

Course Description

  • One way Functions (Permutations), Hard-core Predicates, Pseudo-random Generators, (Strong) Pseudo-random Functions (Permutations).
  • Secret Key Encryptions (SKE): Various security notions such as Perfect Security, Semantic Security, Indistinguishability based Security, CPA Security, CCA Security, Constructions, Block Cipher Mode of Operations.
  • Message Authentication Codes (MAC): Various Security notions such as CMA Security, (weak/strong) CMVA security, Domain Extension, CBC-MAC.
  • Advanced Encryption Schemes: Authenticated Encryptions.
  • Introduction to Secure Computation (Yao’s 2PC protocol and Circuit Garbling).
  • Number Theory: Preliminaries, Modular arithmetic, elementary group theory, CRT, hardness assumptions.
  • Trapdoor permutations: definitions, construction based on factoring, CR Hash functions based on number-theoretic assumptions.
  • Public-key encryption: Implications of Semantic Security, Textbook RSA, Padded RSA, ElGamal, CCA secure public key encryption.
  • Digital signatures: definitions, hash-and-sign paradigm, Lamport’s scheme, RSA signatures.
  • Protocols: Identification protocols, proving properties in zero knowledge, non-interactive proof systems and applications.

Grading

  • Two midterm exam (25+25 points)
  • One reading project (10 points)
  • Endterm exam (40 points)

Announcements

  • First midterm will be held on 16th September, 2026 from 03:30 pm - 05:00 pm in CSA 112.
  • Tutorial sessions will be held on every Friday, 10:00 am - 11:30 am in CSA 112.
Academic Integrity
  • Improper academic behaviour: Copying during exams, copying of homework assignments, term papers or manuscripts, verbatim or paraphrased. Allowing or facilitating copying, or writing a report or exam for someone else. Using unauthorized material and collaborating when not authorized. [Details]
  • Action: In the case of a violation of the academic integrity, the student’s ID will be reported to the Office of Career Counselling and Placement (OCCaP).

Lectures
  • Lecture 1 :  Introduction, Classical Crypto vs. Modern Crypto, Three Pillars of Modern crypto (definition + assumption + proof), Classical ciphers and pitfalls. Inroad towards Modern Crypto.
  • References : [Slides], Chapter 1 of KL and BS
  • Date : 05-08-2026
  • Lecture 2 :  Perfect Security for SKE: Definition, Construction (Vernam Cipher), Proof; Drawbacks of OTP.
  • References : [Slides], Chapter 2 of KL and BS
  • Date : 10-08-2026
  • Lecture 3 :  More definitions of Perfect Security and their equivalence with Shannon's perfect security definition. Shannon's Theorem. Perfect Indistinguishability-- game-based definition. Proof of limitations on key space/length and key reusability.
  • References : [Slides], Chapter 2 of KL and BS
  • Date : 12-08-2026
  • Lecture 4 :  Perfect Security for Secret Sharing: Definition. Threshold Secret Sharing: Constructions (Additive Secret Sharing, Ito-Saito-Nishizeki Secret Sharing), Analysis.
  • References : [Slides], Chapter 13 of Sti, Chapter 13 of KL and Chapter 22 of BS
  • Date : 17-08-2026
  • Lecture 5 :  Basics concept of Abstract Algebra. Polynomials over Field. Lagrange Interpolation. Shamir Secret Sharing. Perfectly-Secure Message Transmission (PSMT). BGW MPC Protocol for Linear Functions.
  • References : [Slides], Chapter 13 of Sti, Chapter 13 of KL and Chapter 22 of BS
  • Date : 19-08-2026
  • Lecture 6 :  Introduction to Computational Security. Definitions of PPT and negligible functions, Security Parameter. Asymptotic Approach. Ind(istinguishability) Security and its relation to weaker security notions of Parity Prediction (pr) and Message Recovery (mr). Introduction to Reduction-based proofs and the proof of 'ind-security implies parity-prediction security'. Necessity of the relaxations in threat and break models to overcome the hurdles of perfect secrecy.
  • References : [Slides], Chapter 3 of KL and Chapter 2 of BS
  • Date : 24-08-2026 & 31-08-2026
  • Lecture 7 :  Pseudorandomness and Pseudo-random Generators (PRG), Indistinguishability Security, Statistical Tests, Next-bit Prediction Security, Impossibility of PRG against unbounded adversary, ind-secure SKE from PRG, Proof of security.
  • References : [Slides],Chapter 3 of KL and BS
  • Date : 31-08-2026 & 02-09-2026
  • Lecture 8 :  Multiple Message Security vs. Single Message Security, Applications of ind-secure SKE -- Anonymous Message Transfer/Onion Routing, PRG with one-bit expansion implies PRG with many-bit expansion, Hybrid Arguments.
  • References : [Slides], Chapter 3 of KL and BS
  • Date : 02-09-2026 & 04-09-2026
  • Lecture 9 :  Applications of PRG -- Coin-tossing and Commitment Schemes, Chosen Plaintext Attack (CPA), CPA-security, Pseudo-random Functions (PRF).
  • References : [Slides], Chapter 3 of KL and Chapter 4 of BS
  • Date : 07-09-2026
  • Lecture 10 :  SKE based on PRF, Proof for CPA-security, PRG implies PRF -- GGM/tree construction.
  • References : [Slides], Chapter 3 of KL and Chapter 4,5 of BS
  • Date : 09-09-2026
  • Supplementary Lecture 1 :   Practical Instantiation of PRGs: LFSR, Trivium, and RC4.
  • References : [Slides [PRG]], Chapter 6 of KL
  • Date : 21-09-2026
  • Supplementary Lecture 2 :   Practical Instantiation of PRFs: Confussion and Diffusion Paradigm, SPNs, FN, and DES.
  • References : [Slides [PRF]], Chapter 6 of KL
  • Date : 23-09-2026
  • Lecture 11 :  Yao's 2PC, Circuit Garbling as an application of CPA-secure SKE.
  • References : [Slides], A Proof of Yao's Protocol for Secure Two-Party Computation' by Yehuda Lindell and Benny Pinkas (available online)
  • Date : 26-09-2026
  • Lecture 12 :  One-way Functions (OWF), One-way Permutations (OWP), Hard-core Predicates, Partial proof of Goldreich-Levin, OWP + Hardcore predicates imply PRG with one bit expansion.
  • References : [Slides], Chapter 7 of KL
  • Date : 28-09-2026
  • Lecture 13 :  CCA Security, Padding Oracle attack on CBC Mode, Authenticated Encryption, MAC Syntax and Security definition, Construction of MAC from PRF.
  • References : [Slides], Chapter 3,4 of KL
  • Date : 05-10-2026
Tutorials
  • Tutorial 1 :  Classical Cryptography and Perfect Security for SKE.
  • Question Set : [Tutorial 1]
  • Date : 14-08-2026
  • Tutorial 2 :  Perfect Security for SKE and Secret Sharing.
  • Question Set : [Tutorial 2]
  • Date : 21-08-2026
  • Tutorial 3 :  IND-security and PRGs.
  • Question Set : [Tutorial 3]
  • Date : 04-09-2026
  • Tutorial 4 :  Pseudorandom Functions (PRF) and Chosen Plaintext Attacks (CPA).
  • Question Set : [Tutorial 4]
  • Date : 11-09-2026
  • First Mid-Semester Problems :   Midterm-1 Solution Discussion.
  • Date : 18-09-2026
  • Tutorial 5 :   Stream Ciphers and Block Ciphers.
  • Question Set : [Tutorial 5]
  • Date : 25-09-2026
  • Tutorial 6 & 7 :   OWFs, Yao's Protocol, and MACs.
  • Question Set : [Tutorial 6 ] and [Tutorial 7 ]
  • Date : 09-10-2026
Reading Projects
    1. Packed Secret Sharing   Reference: [Paper].
    1. Impossibility of Commitment Scheme with Unconditional Binding and Unconditional Hiding   Reference: [Paper].
    1. Construction and Security Proof of CTR Mode of Block Cipher   Reference: Section 3.6.2 of KL Book.
    1. AES Block Cipher   Reference: Section 6.2.5 of KL Book.
    1. Point-and-Permute in Garbled Circuit   Reference: Section 3.1.1 of [EKR Book].
    1. FreeXOR in Garbled Circuit   Reference: Section 4.1.2 of [EKR Book].
    1. Luby Rackoff Construction   Reference: Section 7.6 of KL Book.
    1. Secret Sharing Made Short   Reference: [Paper].
    1. Information-Theoretic MACs   Reference: Section 4.6 of KL Book