Massachusetts Institute of Technology

Fall 2026 · Graduate course

MIT 6.5620 / 6.875 / 18.425

Foundations of Cryptography

Cryptography gives us a precise technical language to define important notions such as security, privacy and integrity; a mathematical toolkit to construct mechanisms for encryption, digital signatures, zero-knowledge proofs, homomorphic encryption and secure multiparty computation; and a complexity-theoretic framework to prove security using reductions. Together, they help us enforce the rules of the road in digital interactions.

This fast-paced graduate course travels from the classical foundations to recent developments. The emphasis is not only on constructing mechanisms, but on learning how to state what security means—and how to prove that a construction achieves it.

Prerequisites: Fluency in algorithms (6.1220), complexity theory (6.1400), and discrete probability (6.1200). Mathematical maturity and comfort writing proofs are assumed right from the first lecture.

Teaching assistants

  • Noga Amit

    nogamit at mit dot edu

    Office hours: Time TBD · Location TBD

Review Material

  • Sep 10
    Probability review Time TBD · Location TBD
  • Sep 18
    Complexity & reductions Time TBD · Location TBD
  • Oct 02
    Number theory review Time TBD · Location TBD
03 Assignments & grading

Grading is based on five problem sets (10%), a midterm exam (30%), a final exam (40%), an oral problem-set review (10%), and class participation (10%).

Oral problem-set review

Each student will meet individually with an instructor to present one problem selected by the instructors from any previously assigned problem set. The problem will not be announced in advance. Students may use their notes during the review. Oral reviews will be scheduled after the midterm and before the final exam.

Problem set

01
Released
Sep 09
Due
Sep 23

Problem set

02
Released
Sep 23
Due
Oct 07

Problem set

03
Released
Oct 07
Due
Oct 28

Problem set

04
Released
Oct 28
Due
Nov 18

Problem set

05
Released
Nov 18
Due
Dec 02

Submission

Solutions should be typeset in LaTeX and submitted as PDF by 11:59:59 PM ET on the due date.

Late days

Students have ten total late days, with at most five used on any one problem set.

Collaboration

Discussion in groups of up to three is encouraged. Every student must write their own solution and name all collaborators. The final write-up must be entirely in their own words.

Attribution

Published material may be used when acknowledged. Looking for or using solutions from previous years is not permitted.

For the use of AI tools on problem sets, see the AI use policy above.

Five modules, twenty-five lectures, one midterm exam, and a final exam. Fall classes begin September 9; this course’s final meeting is December 9. Topics remain tentative.

Module 01

Basics & private-key cryptography

Perfect secrecy, computational security, pseudorandomness, and the foundations of symmetric encryption.