Cryptography
From Shannon's information-theoretic secrecy to post-quantum lattices — the mathematical primitives, security definitions, and protocols that secure modern systems.
Minimum viable reading path
The 3 papers that give you most of the field's mental model, in reading order.
01 Communication Theory of Secrecy Systems MVRP
Defines perfect secrecy, the unicity distance, and the entropy framework for analysing ciphers.
The mathematical bedrock of cryptography; every modern security definition descends from this.
Probability, basic information theory
Perfect secrecy requires a key as long as the message — and that's a theorem, not an opinion.
02 New Directions in Cryptography (Diffie–Hellman) MVRP
Introduces public-key cryptography and key exchange without prior shared secrets.
The single most important paper in modern cryptography. Read it once and recognise it everywhere.
Modular arithmetic, basic group theory
You can establish a shared secret over a public channel using only one-way mathematical operations.
03 A Method for Obtaining Digital Signatures and Public-Key Cryptosystems (RSA)
The first concrete public-key cryptosystem, based on the difficulty of factoring large integers.
The first practical instantiation of Diffie–Hellman's vision; everywhere in deployed crypto.
Diffie–Hellman, modular exponentiation
Hardness of factoring is enough to bootstrap encryption and digital signatures.
04 A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms (ElGamal)
A public-key cryptosystem based on the discrete logarithm problem rather than factoring.
The conceptual ancestor of every elliptic-curve-based system in deployed crypto.
Diffie–Hellman, cyclic groups
Hardness of discrete log is another viable foundation for public-key crypto.
05 Probabilistic Encryption
Defines semantic security and shows that deterministic encryption can't achieve it.
The paper that brought rigour to "what does secure mean" — the start of modern provable security.
RSA, basic complexity theory
Encryption must be randomised to be meaningfully secure.
06 The Knowledge Complexity of Interactive Proof Systems (Zero-Knowledge)
Defines zero-knowledge proofs: convincing a verifier that you know something without revealing what.
A foundational and counter-intuitive idea; the seed of every ZK protocol since.
Probability, complexity theory, basic crypto
You can prove you know a secret while revealing exactly nothing about it.
07 Random Oracles are Practical: A Paradigm for Designing Efficient Protocols
Models hash functions as ideal random oracles to enable proofs of practical schemes.
The proof technique that underlies most security arguments for deployed protocols.
Probabilistic encryption, hash functions
Idealising hashes as random oracles makes practical schemes provably secure (with caveats).
08 The Design of Rijndael (AES)
A substitution-permutation block cipher selected as the AES standard in 2001.
The block cipher under nearly every TLS connection on Earth; useful design study.
Linear algebra over finite fields
Simple, well-understood algebraic structure resists nearly two decades of cryptanalysis.
09 The MD5 Message-Digest Algorithm
A 128-bit hash function once ubiquitous; later broken by collision attacks.
A cautionary tale about hash design; useful contrast against SHA-2/SHA-3.
Basic block cipher constructions
Cryptographic hashes age — every deployed primitive has a shelf life.
10 Identity-Based Encryption from the Weil Pairing
A practical identity-based encryption scheme using bilinear pairings on elliptic curves.
The opening of the pairing-based crypto era; broad implications well beyond IBE.
Elliptic curves, basic algebraic geometry
Bilinear pairings make new cryptographic capabilities possible.
11 On Lattices, Learning with Errors, Random Linear Codes, and Cryptography
Introduces the Learning With Errors problem and reduces lattice problems to it.
The hard problem under most post-quantum proposals; foundational for modern crypto.
Linear algebra, basic number theory
Hard lattice problems are a sturdy alternative to factoring and discrete log — and may resist quantum attack.
12 Fully Homomorphic Encryption Using Ideal Lattices
The first fully homomorphic encryption scheme — compute on ciphertexts without decrypting.
A landmark theoretical result and the seed of modern privacy-preserving computation.
Lattice-based crypto, bootstrapping concept
You can do arbitrary computation on encrypted data — a problem that was open for 30 years.
13 Differential Privacy
A formal privacy definition based on indistinguishable behaviour on neighbouring datasets.
The privacy framework now used by the US Census, Apple, Google, and others.
Probability, basic statistics
Privacy is best defined as a property of the algorithm, not of the data.
14 The Second-Generation Onion Router (Tor)
A low-latency anonymity network that routes traffic through encrypted overlay circuits.
A clean systems paper from the privacy world; what real-world anonymity actually requires.
Public-key crypto, networking basics
Anonymity needs both layered encryption and a careful threat model.
15 The Double Ratchet Algorithm (Signal)
A protocol providing forward secrecy and post-compromise security via continuously-rotated keys.
The cryptography behind every secure messenger you actually use.
Diffie–Hellman, symmetric crypto
You can recover security after key compromise if your protocol is designed for it.
16 Bitcoin: A Peer-to-Peer Electronic Cash System MVRP
Combines hash-linked blocks, proof-of-work, and longest-chain consensus into a decentralised ledger.
Whatever you think of cryptocurrency, this paper redrew the map of distributed systems.
Hashing, digital signatures, basic distributed consensus
Economic incentives plus a clever hash-chain solve Byzantine consensus without identities.
17 Pinocchio: Nearly Practical Verifiable Computation (zk-SNARKs)
Succinct non-interactive arguments of knowledge with constant-size proofs and fast verification.
The proof system under most modern blockchain privacy and verifiable-computation systems.
Pairings, zero-knowledge proofs
You can verify huge computations in milliseconds — once you accept a trusted setup.
18 Scalable, Transparent, and Post-Quantum Secure Computational Integrity (zk-STARKs)
Succinct, transparent (no trusted setup), post-quantum-secure proofs of arbitrary computation.
A cleaner, more future-proof alternative to SNARKs.
zk-SNARKs, hash-based crypto
You can have succinct ZK proofs without trusted setup, at some cost in proof size.
19 CRYSTALS-Kyber: A Lattice-Based Key Encapsulation Mechanism
A practical lattice-based KEM selected by NIST as a post-quantum standard.
The key-exchange algorithm that will replace ECDH in the next decade.
LWE, ring-LWE
Module-LWE gives a clean, efficient post-quantum KEM.
20 CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme
A lattice-based signature scheme standardised alongside Kyber by NIST.
The signature counterpart to Kyber; will eventually replace ECDSA and Ed25519.
Kyber, rejection sampling
Lattice-based signatures are now competitive in size and speed with classical ones.
21 How to Generate and Exchange Secrets (Yao's Garbled Circuits)
Introduces secure multiparty computation via garbled circuits, allowing joint computation on private inputs.
The foundation of modern MPC; conceptually still under every multi-party private computation.
Public-key crypto, oblivious transfer
You can compute on multiple parties' secret inputs without anyone learning anything but the result.
22 Differentially Private Federated Learning
Combines federated learning with differential-privacy noise on aggregated updates.
A modern systems paper that synthesises classical DP with on-device training.
Differential privacy, federated learning
Privacy mechanisms compose — and DP is the right composable primitive for federated systems.