Papers in Order

Cryptography

From Shannon's information-theoretic secrecy to post-quantum lattices — the mathematical primitives, security definitions, and protocols that secure modern systems.

22 papers 7 levels Included papers 1948 – 2023 MVRP 3 papers
0 of 22 papers read. Progress stays in this browser.

Minimum viable reading path

The 3 papers that give you most of the field's mental model, in reading order.

  1. Communication Theory of Secrecy Systems
  2. New Directions in Cryptography (Diffie–Hellman)
  3. Bitcoin: A Peer-to-Peer Electronic Cash System
Level 0 Foundations
01 Communication Theory of Secrecy Systems MVRP
TL;DR

Defines perfect secrecy, the unicity distance, and the entropy framework for analysing ciphers.

Why read this

The mathematical bedrock of cryptography; every modern security definition descends from this.

Prerequisites

Probability, basic information theory

Key takeaway

Perfect secrecy requires a key as long as the message — and that's a theorem, not an opinion.

Read the paper
Level 1 Public-key revolution
02 New Directions in Cryptography (Diffie–Hellman) MVRP
TL;DR

Introduces public-key cryptography and key exchange without prior shared secrets.

Why read this

The single most important paper in modern cryptography. Read it once and recognise it everywhere.

Prerequisites

Modular arithmetic, basic group theory

Key takeaway

You can establish a shared secret over a public channel using only one-way mathematical operations.

Read the paper
03 A Method for Obtaining Digital Signatures and Public-Key Cryptosystems (RSA)
TL;DR

The first concrete public-key cryptosystem, based on the difficulty of factoring large integers.

Why read this

The first practical instantiation of Diffie–Hellman's vision; everywhere in deployed crypto.

Prerequisites

Diffie–Hellman, modular exponentiation

Key takeaway

Hardness of factoring is enough to bootstrap encryption and digital signatures.

Read the paper
04 A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms (ElGamal)
TL;DR

A public-key cryptosystem based on the discrete logarithm problem rather than factoring.

Why read this

The conceptual ancestor of every elliptic-curve-based system in deployed crypto.

Prerequisites

Diffie–Hellman, cyclic groups

Key takeaway

Hardness of discrete log is another viable foundation for public-key crypto.

Read the paper
Level 2 Provable security
05 Probabilistic Encryption
TL;DR

Defines semantic security and shows that deterministic encryption can't achieve it.

Why read this

The paper that brought rigour to "what does secure mean" — the start of modern provable security.

Prerequisites

RSA, basic complexity theory

Key takeaway

Encryption must be randomised to be meaningfully secure.

Read the paper
06 The Knowledge Complexity of Interactive Proof Systems (Zero-Knowledge)
TL;DR

Defines zero-knowledge proofs: convincing a verifier that you know something without revealing what.

Why read this

A foundational and counter-intuitive idea; the seed of every ZK protocol since.

Prerequisites

Probability, complexity theory, basic crypto

Key takeaway

You can prove you know a secret while revealing exactly nothing about it.

Read the paper
07 Random Oracles are Practical: A Paradigm for Designing Efficient Protocols
TL;DR

Models hash functions as ideal random oracles to enable proofs of practical schemes.

Why read this

The proof technique that underlies most security arguments for deployed protocols.

Prerequisites

Probabilistic encryption, hash functions

Key takeaway

Idealising hashes as random oracles makes practical schemes provably secure (with caveats).

Read the paper
Level 3 Symmetric & hashing
08 The Design of Rijndael (AES)
TL;DR

A substitution-permutation block cipher selected as the AES standard in 2001.

Why read this

The block cipher under nearly every TLS connection on Earth; useful design study.

Prerequisites

Linear algebra over finite fields

Key takeaway

Simple, well-understood algebraic structure resists nearly two decades of cryptanalysis.

Read the paper
09 The MD5 Message-Digest Algorithm
TL;DR

A 128-bit hash function once ubiquitous; later broken by collision attacks.

Why read this

A cautionary tale about hash design; useful contrast against SHA-2/SHA-3.

Prerequisites

Basic block cipher constructions

Key takeaway

Cryptographic hashes age — every deployed primitive has a shelf life.

Read the paper
Level 4 Advanced primitives
10 Identity-Based Encryption from the Weil Pairing
TL;DR

A practical identity-based encryption scheme using bilinear pairings on elliptic curves.

Why read this

The opening of the pairing-based crypto era; broad implications well beyond IBE.

Prerequisites

Elliptic curves, basic algebraic geometry

Key takeaway

Bilinear pairings make new cryptographic capabilities possible.

Read the paper
11 On Lattices, Learning with Errors, Random Linear Codes, and Cryptography
TL;DR

Introduces the Learning With Errors problem and reduces lattice problems to it.

Why read this

The hard problem under most post-quantum proposals; foundational for modern crypto.

Prerequisites

Linear algebra, basic number theory

Key takeaway

Hard lattice problems are a sturdy alternative to factoring and discrete log — and may resist quantum attack.

Read the paper
12 Fully Homomorphic Encryption Using Ideal Lattices
TL;DR

The first fully homomorphic encryption scheme — compute on ciphertexts without decrypting.

Why read this

A landmark theoretical result and the seed of modern privacy-preserving computation.

Prerequisites

Lattice-based crypto, bootstrapping concept

Key takeaway

You can do arbitrary computation on encrypted data — a problem that was open for 30 years.

Read the paper
Level 5 Privacy & deployed protocols
13 Differential Privacy
TL;DR

A formal privacy definition based on indistinguishable behaviour on neighbouring datasets.

Why read this

The privacy framework now used by the US Census, Apple, Google, and others.

Prerequisites

Probability, basic statistics

Key takeaway

Privacy is best defined as a property of the algorithm, not of the data.

Read the paper
14 The Second-Generation Onion Router (Tor)
TL;DR

A low-latency anonymity network that routes traffic through encrypted overlay circuits.

Why read this

A clean systems paper from the privacy world; what real-world anonymity actually requires.

Prerequisites

Public-key crypto, networking basics

Key takeaway

Anonymity needs both layered encryption and a careful threat model.

Read the paper
15 The Double Ratchet Algorithm (Signal)
TL;DR

A protocol providing forward secrecy and post-compromise security via continuously-rotated keys.

Why read this

The cryptography behind every secure messenger you actually use.

Prerequisites

Diffie–Hellman, symmetric crypto

Key takeaway

You can recover security after key compromise if your protocol is designed for it.

Read the paper
Level 6 ZK, money & post-quantum
16 Bitcoin: A Peer-to-Peer Electronic Cash System MVRP
TL;DR

Combines hash-linked blocks, proof-of-work, and longest-chain consensus into a decentralised ledger.

Why read this

Whatever you think of cryptocurrency, this paper redrew the map of distributed systems.

Prerequisites

Hashing, digital signatures, basic distributed consensus

Key takeaway

Economic incentives plus a clever hash-chain solve Byzantine consensus without identities.

Read the paper
17 Pinocchio: Nearly Practical Verifiable Computation (zk-SNARKs)
TL;DR

Succinct non-interactive arguments of knowledge with constant-size proofs and fast verification.

Why read this

The proof system under most modern blockchain privacy and verifiable-computation systems.

Prerequisites

Pairings, zero-knowledge proofs

Key takeaway

You can verify huge computations in milliseconds — once you accept a trusted setup.

Read the paper
18 Scalable, Transparent, and Post-Quantum Secure Computational Integrity (zk-STARKs)
TL;DR

Succinct, transparent (no trusted setup), post-quantum-secure proofs of arbitrary computation.

Why read this

A cleaner, more future-proof alternative to SNARKs.

Prerequisites

zk-SNARKs, hash-based crypto

Key takeaway

You can have succinct ZK proofs without trusted setup, at some cost in proof size.

Read the paper
19 CRYSTALS-Kyber: A Lattice-Based Key Encapsulation Mechanism
TL;DR

A practical lattice-based KEM selected by NIST as a post-quantum standard.

Why read this

The key-exchange algorithm that will replace ECDH in the next decade.

Prerequisites

LWE, ring-LWE

Key takeaway

Module-LWE gives a clean, efficient post-quantum KEM.

Read the paper
20 CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme
TL;DR

A lattice-based signature scheme standardised alongside Kyber by NIST.

Why read this

The signature counterpart to Kyber; will eventually replace ECDSA and Ed25519.

Prerequisites

Kyber, rejection sampling

Key takeaway

Lattice-based signatures are now competitive in size and speed with classical ones.

Read the paper
21 How to Generate and Exchange Secrets (Yao's Garbled Circuits)
TL;DR

Introduces secure multiparty computation via garbled circuits, allowing joint computation on private inputs.

Why read this

The foundation of modern MPC; conceptually still under every multi-party private computation.

Prerequisites

Public-key crypto, oblivious transfer

Key takeaway

You can compute on multiple parties' secret inputs without anyone learning anything but the result.

Read the paper
22 Differentially Private Federated Learning
TL;DR

Combines federated learning with differential-privacy noise on aggregated updates.

Why read this

A modern systems paper that synthesises classical DP with on-device training.

Prerequisites

Differential privacy, federated learning

Key takeaway

Privacy mechanisms compose — and DP is the right composable primitive for federated systems.

Read the paper