Cryptography: From Theory to Practice
Fall 2026 · University of Illinois Urbana–Champaign
Instructor: Ning Luo
TA: Rajpal, Pranav
Time: Tue & Thu · 5:00–6:20 PM
Location: 3013 ECEB
Office Hour: By appointment
TA Office Hour: TBD
Overview
This course covers modern cryptography with a focus on symmetric-key and public-key primitives, security models, basic number theory, and proofs. Applications include authenticated encryption, signatures, zero-knowledge proof, and selected protocols.
Textbook: Katz & Lindell: Introduction to Modern Cryptography, 3rd Edition (or Revised 3rd Edition — same section numbering).
Course Schedule (Tentative)
Section numbers refer to Katz & Lindell, 3rd edition. Starred sections in the book (e.g. 8.1, 14.4, 15.1) are marked by the authors as optional; here they are assigned. A few late-semester topics are not covered by the textbook and will be taught from lecture notes.
The schedule is a wide table. On a narrow screen it scrolls sideways; you can also focus it and scroll with the arrow keys.
| Week | Tue date | Tuesday topic | Thu date | Thursday topic |
|---|---|---|---|---|
| 1 | 8.25 | Introduction and background on cryptographyReading: KL 1 | 8.27 | One-time pad, information-theoretic securityReading: KL 2 |
| 2 | 9.1 | Stream ciphers, PRGReading: KL 3.1–3.3, 3.6.1–3.6.2 | 9.3 | Pseudorandomness, CPAReading: KL 3.4–3.5 |
| 3 | 9.8 | Block ciphers; DES and attacks, AESReading: KL 7.2 | 9.10 | PRP, PRF, block ciphers from PRGReading: KL 3.5.1, 8.5–8.6 |
| 4 | 9.15 | One-time key vs. many-time key; modes of operationReading: KL 3.4.1, 3.6 | 9.17 | Padding-oracle attacksReading: KL 5.1 |
| 5 | 9.22 | Message Authentication Codes (MAC)Reading: KL 4.1–4.4 | 9.24 | Generic birthday attack, cryptographic hashReading: KL 6.1, 6.4, Appendix A.4 |
| 6 | 9.29 | Merkle–Damgård paradigm; Merkle hash treeReading: KL 6.2, 6.6.2 | 10.1 | HMAC, authenticated encryptionReading: KL 6.3, 5.2–5.3 |
| 7 | 10.6 | Midterm reviewNote: covers weeks 1–6 | 10.8 | MidtermNote: in class, 5:00–6:20 PM |
| 8 | 10.13 | Number theoryReading: KL 9.1–9.3, Appendix B | 10.15 | Diffie–Hellman key exchangeReading: KL 9.3.2, 11.3 |
| 9 | 10.20 | Trapdoor permutations; public-key encryptionReading: KL 12.1–12.2, 15.1 | 10.22 | RSA-based public-key encryptionReading: KL 9.2.4, 12.5 |
| 10 | 10.27 | Discrete-log–based public-key encryptionReading: KL 12.4 | 10.29 | Digital signaturesReading: KL 13.1–13.3 |
| 11 | 11.3 | RSA signature and BLS signatureReading: KL 13.4. BLS is not in KL — lecture notes; background in KL 9.3.4 | 11.5 | One-way functions, Lamport signatureReading: KL 8.1, 14.4 |
| 12 | 11.10 | Blind signaturesNote: not in KL — lecture notes only | 11.12 | Multi-party computation (MPC)Note: not in KL — lecture notes; related material in KL 15.3 |
| 13 | 11.17 | Zero-knowledge proofReading: KL 13.5.1 only (partial) — lecture notes | 11.19 | Fully homomorphic encryptionNote: not in KL — lecture notes only |
| 14 | 11.24 | Fall Break — no class | 11.26 | Fall Break — no class |
| 15 | 12.1 | Final project presentationsNote: worth 20% of the course grade | 12.3 | Final project presentations |
| 16 | 12.8 | Final exam review | No date | No class. December 9 is the last day of instruction; December 10 is Reading Day. |
Instruction begins Monday, August 24, 2026. Fall Break runs November 21–29. The last day of instruction is Wednesday, December 9; Reading Day is Thursday, December 10; the final examination period is December 11–17. Our final exam slot will be posted by the Registrar on October 14.
Policies
Grading: the course grade is composed as follows.
- In-class quiz 10%
- The final grade is the average score of the selected quizzes, scaled to 100.
- Homework 20%
- 5 assignments.
- Submit a single PDF compiled from LaTeX. No Word, Google Docs, or photographs of handwritten work.
- No late submission allowed.
- AI-based tools are NOT allowed unless specified.
- Midterm exam 20%
- In class, 5:00–6:20 PM, Thursday, October 8.
- Final exam 30%
- Cumulative. Date set by the Registrar; the final exam period is December 11–17.
- Final project 20%
- Design a cryptographic application of the course contents.
- AI-based tools are allowed for the project.
- Presentations are in week 15 (December 1 and 3).
Academic Integrity: Academic dishonesty is a serious offense. The University of Illinois Urbana-Champaign Student Code is considered a part of this syllabus. If you are ever in doubt of what constitutes plagiarism or cheating, do not hesitate to ask me.
Accessibility and Accommodations
Disability accommodations: To obtain disability-related academic adjustments and/or auxiliary aids, students with disabilities must contact the course instructor and Disability Resources and Educational Services (DRES) as soon as possible. To contact DRES, you may visit 1207 S. Oak St., Champaign, call 217-333-1970, e-mail disability@illinois.edu, or go to the DRES website.
Talk to me early: So that disability-related concerns are addressed from the beginning, students who require accommodations to participate in this class are encouraged to see me as soon as possible. You do not need to disclose a diagnosis, and I will not discuss your accommodations in class. Accommodations are not retroactive, so the earlier we talk, the more I can do.
Course materials: If any course material — slides, homework, the textbook, or this website — is difficult for you to read or use, tell me and I will provide an alternative format. Requests for captioning, alternative text for figures, or accessible versions of problem sets are welcome at any point in the semester, with or without a Letter of Academic Accommodations.