CPSC 4440/5440 Β· Yale Computer Science

Real-World Cryptography

Announcements

  • Spring 2026 lecture slides and course materials are available below.

Course Information

Time/location

  • Monday and Wednesday, 11:35am–12:50pm
  • WTS A46, Watson Center, 60 Sachem Street

Instructor

Prof. Fan Zhang

Prof. Fan Zhang

Office hours: Wednesday, 4–5pm in AKW 503

πŸ“– Course Description

Cryptography provides strong security and privacy guarantees in well-defined mathematical models, but applying it to real-world systems is an art that must account for performance, cost, evolving adversarial threats, and user behavior. This course examines how cryptographic tools underpin digital infrastructure and protect users against powerful and evolving threats. Topics include TLS, anonymity systems such as Tor and DC nets, secure messaging, anonymous credentials, digital identity, and trusted execution environments.

Prerequisites
Familiarity with basic concepts in computer security and cryptography is recommended. The necessary background is reviewed in the first lectures.
Grading

Coursework includes homework and written responses to reading assignments. Graduate students will present at the end of the semester.

  • Undergraduate students: participation (20%), paper critiques (20%), problem sets and labs (60%)
  • Graduate students: participation (20%), paper critiques (20%), problem sets and labs (40%), presentation (20%)

Homeworks

Use the LaTeX homework template for submissions.

Late days

  • Each student gets one free late day.
  • One late day equals a 24-hour extension.
  • Each non-free late day incurs a 10% grade reduction.
  • Dean’s extensions are honored; no other late days will be granted.

Lecture Schedule

Section I: Foundations

Preview of Course introduction slides
Lecture 1 Jan 12

Course introduction

Preview of Crash course on useful cryptographic tools slides
Lecture 2 Jan 14

Crash course on useful cryptographic tools

Milestones:
  • Lab 1: Roll your own crypto β€” GCM implementation

Section II: TLS

Preview of Authenticated Key Exchange (AKE) slides
Lecture 3 Jan 21

Authenticated Key Exchange (AKE)

Preview of AKE instantiation: public-key encryption and signatures slides
Lecture 4 Jan 23

AKE instantiation: public-key encryption and signatures

Preview of Watching the Gatekeepers: Certificate Transparency slides
Lecture 6 Jan 28

Watching the Gatekeepers: Certificate Transparency

Section III: Messaging under Strong Adversaries

Preview of Anonymity and mixnets slides
Lecture 8 Feb 4

Anonymity and mixnets

Preview of Onion routing, Tor, and hidden services slides
Lecture 9 Feb 9

Onion routing, Tor, and hidden services

Preview of DC nets and Dissent slides
Lecture 10 Feb 11

DC nets and Dissent

Preview of End-to-end encrypted messaging slides
Lecture 11 Feb 16

End-to-end encrypted messaging

Section IV: Identity and Credentials

Preview of Passwords and Password Authenticated Key Exchange slides
Lecture 14 Feb 27

Passwords and Password Authenticated Key Exchange

Preview of Payments with unlinkability slides
Lecture 17 Mar 23

Payments with unlinkability

Section V: Securing Data in Use

Preview of Overview of Trusted Execution Environments slides
Lecture 19 Mar 30

Overview of Trusted Execution Environments

Preview of SGX deep dive: memory isolation slides
Lecture 20 Apr 1

SGX deep dive: memory isolation

Slides not released
Lecture 21 Apr 6

SGX deep dive: remote attestation and sealing

Canceled due to NSF duties

Preview of TEE side-channel attacks slides
Lecture 22 Apr 8

TEE side-channel attacks

Section VI: AI and Cryptography

Slides not released
Lecture 26 Apr 22

Final presentations