2MMC10 Cryptology - Fall 2026
Tanja Lange
Coding Theory and Cryptology
Eindhoven Institute for the Protection of Information
Department of Mathematics and Computer Science
Room MF 5.062
Technische Universiteit Eindhoven
P.O. Box 513
5600 MB Eindhoven
Netherlands
Phone: +31 (0) 40 247 4764
The easiest ways to reach me wherever I am:
e-mail:tanja@hyperelliptic.org
-
This page belongs to course 2MMC10 - Cryptology. This course is
offered at TU/e and aimed at students of mathematics and computer science,
incl. students in the cybersecurity track/IST.
Contents
- The general structure of block ciphers, Feistel ciphers like DES, AES, the most suitable modes-of-use, e.g. CBC or OFB.
- Hash functions, Message Authentication Codes.
- The principle of public key cryptography.
- Basics of finite fields and their arithmetic
- Diffie-Hellman key exchange, El Gamal, several methods to compute discrete logarithms (baby-step giant-step method, the Pohlig-Hellman method, Pollard-rho and the index calculus method).
- Elliptic curves in different representations, cryptosystems and signature schemes based on elliptic cures.
- The RSA system for encryption and signing, generating prime numbers by means of probabilistic primality tests, primality proof, several factorization algorithms (Pollard-(p-1), Pollard-rho, the random square method, the quadratic sieve method) lattice methods for breaking special keys.
- Code-based cryptography.
Announcements
Note that one of the course requirements is algebra. I will not repeat
basic background on groups, rings and fields in class. If you don't
have the necessary background, take the summer and work through the "Number Theory and Algebra" script
or more from my draft book
Discrete Mathematics.
-
Lectures at TU/e start in the week of 31 August 2026.
-
The lecture slots are Tuesdays 13:30 - 15:15 (mix of rooms in Gemini Noord)
and Thursdays 10:45 - 12:30 (mostly Gemini Noord 1.710).
Students have requested instructions and we're making this work.
The instruction slot is Tuesday 15:30 - 17:15 and for most weeks we offer the
instruction in one big room with two instructors, these are mostly in Neuron.
Because of the different rooms please check the
timetable for the course and note that room assignments may change.
-
This year the lectures will not be recorded but you can find the recordings
from 2022 online. In 2021 I offered this course online and
recorded the material in short videos, one video per topic. You can find those
on its own
YouTube Channel
-
There will be weekly homeworks as an opportunity for you to check
your understanding and how to formally write up things.
We do not have capacity to send feedback for everybody, so please team up in
groups of 2 or 3 and first discuss in your group how to solve the problem and
which of your solutions to submit.
The teaching assistants will send you feedback and corrections.
Note that the homeworks do not count towards the final grade.
Take this as an offer for you to check your understanding. Do not spam them
with output by AI.
-
Your teaching assistants this year are
- Jonathan Levin
- Elisa Pioldi
You can send an email to crypto.course@tue.nl to reach
both of them if you have questions.
-
The exam will take place on campus on 27 Oct 2026 13:30 - 16:30..
The best preparation for the exam is to try yourself at the
old exams. We are back to the pre-Covid modality
of written exams with notebook; this was not possible 2020 – 2022.
This means that you should prepare your programmable
calculator to cover
- exponentiation modulo some number; use square and multiply and reduce
after each multiplication or squaring; test your implementation with a large
base and exponent
- Chinese remainder theorem
- inverse modulo some number via XGCD
I do not expect that you implement LLL or elliptic curve operations, so in
particular I expect to see intermediate steps in the calculations there.
There will also be some university laptops with Pari-GP for you to use.
Literature
It is not necessary to purchase a book to follow the course.
Previous versions of this course used
Henk van Tilborg's "Fundamentals of Cryptology", Kluwer academic
Publishers, Boston, 2000. But the book is out of print.
A preliminary author's copy by Henk can be downloaded in pdf form
here
and as a mathematica worksheet here.
Other books you might find useful (in alphabetical order):
-
Jean-Philippe Aumasson "Serious Cryptography", no starch press,
-
Dan Boneh and Victor Shoup A Graduate Course in Applied Cryptography. Whole book is online.
-
Steven Galbraith Mathematics of Public Key Cryptography, Cambridge University Press 2012. All chapters are online (even extended versions).
-
Jonathan Katz and Yehuda Lindell "Introduction to Modern Cryptography",
CRC Press
-
Neal Koblitz "A course in Number Theory and Cryptography",
Springer, 1994.
- Tanja Lange "Number Theory and Algebra" (
Chapter of draft book "Discrete Mathematics")
- Tanja Lange "Finite Fields" (Chapter of draft book "Discrete Mathematics")
-
Christof Paar and Jan Pelzl "Understanding Cryptography", Springer, 2010
-
Bruce Schneier "Applied Cryptography", John Wiley & Sons, 1994. This book
does not have the mathematical rigor we use for this course but you might
like it for background. It is getting a bit outdated, though.
-
Doug Stinson "Cryptography: Theory and Practice", CRC Press, 1995
You can also find a lot of information (though not written as a textbook)
in the Handbook of Applied Cryptography.
Note that the authors were so nice to offer chapters of HAC online for download.
Examination
The first exam is on 27 Oct 12:30 - 16:30.
The retake is on 26 Jan 18:00 - 21:00.
Videos
The videos from this course appear on
TU/e's
Yuja page.
Note that this page requires a TU/e account to log in and shows lectures
from multiple years and that there are some differences between the
course versions; I taught the course with recordings in 2022 and 2019 and my colleague Andreas
Hülsing taught it in 2018, so you can get different explanations.
For the 2021 edition of the course I recorded a lot of short videos
which you can find on the YouTube Channel.
The
course page for 2021 has short descriptions of all videos, slides,
and no-cookie links to the YouTube videos. Watch them
from there if you're on a low-cookie diet.
Class notes & exercises
This section is extended through the course with notes of what
happened in class and links to blackboard pictures.
01 Sep 2026
This lecture was covered by Jonathan Levin because I was sick.
General introduction to cryptography; concepts public key
and symmetric key cryptography.
Jonathan covered Diffie-Hellman key exchange with some generic P and showed that A
and B both compute abP while E sees P, aP, and bP.
Then he covered the clock group over the reals (or rational numbers) as a bad example
where the attacker can easily solve the discrete logarithm problem by observing
how large the power of 5 grows when using P=(3/5,4/5), but this study
also gave us the addition formulas for the clock group which we then used to consider
the clock group over the integers modulo a prime.
He showed that the addition law has (0,1) as neutral element, -(x,y) = (-x,y)
and that the law is commutative. In the instruction you'll show that the
resulting point is on the clock. He skipped associativity as it is not
particularly illuminating.
Clocks modulo primes are an example of cryptosystems
against which the best attacks have subexponential (but superpolynomial) complexity; we
will get to this attack much later. If possible, we would like to have systems
where the best attacks are exponential.
Pictures of blackboards are here.
Thanks to a student for taking the pictures.
Here is the
sheet for the instruction session (block 7 & 8).
Submitting homework is optional. If you want feedback, please submit by next
Tue (08 Sep)
before 13:30 through Canvas. Please submit in groups of 2-3 people; we do not have
capacity to grade everybody individually.
To explain the 'optional':
I do expect that you look at the exercises (homework and instructions, in
particular if they cover pieces we leave out in the lectures. In general it's a
good idea to engage with the material.
Here is the first homework sheet.
03 Sep 2026
This lecture was covered by Jonathan Levin because I was sick.
Jonathan showed Edwards curves and the addition law and how much it resembles addition
on the clock.
He started with a recap of the Diffie–Hellman key exchange and cleanly
defined the related problems of computational Diffie–Hellman problem,
decisional Diffie–Hellman problem, and discrete logarithm problem.
For computing aP he explained the double-and-add method with examples 5P and
23P. If this went too fast§, watch ECC II from the
YouTube
Channel
Consideration of what points are bad starting points for the clock; you'll have
a similar proof for Edwards curves in the homework,but remember that you cannot
argue about angles there, so you need to use the formulas.
Definition of order of a group element (this should be a recap for you.
He covered the following "interesting" points on the clock: points (0,1) has order 1,
(0,-1) has order 2, and (-1,0) and (1,0) have order 4 and are thus bad starting
points for clock-group Diffie–Hellman.
Then he showed the Edwards addition law and what Edwards curve look like over the
reals.
The addition law is similar to that on the circle but has denominators.
He showed that -(x,y) = (-x,y) continues to hold on
Edwards curves and that (0,1) remains the neutral element.
He showed that denominators are never 0 over the reals if d is negative.
These arguments do not make sense over a finite
field, as we cannot argue about sizes there. The matching properties are that
negative d means that it's not a square and that a positive d is a square.
Being a square or not is a property that makes sense over a finite field.
We'll pick that up next week.
For the proof that there are no exceptions over F_p for p>2 and d a non-square
please watch ECC III from the
YouTube
Channel. I will not show this in proof in class.
.
To prove that the Edwards addition law is a group law we still miss showing
that addition is associative and that the sum of two points
is on the curve, but given that there are no exceptions to the addition law
this is something you can ask your computer to check. Taken together, these
show that the points on Edwards curves form a group under this addition.
The group is commutative.'
From the pictures and the addition formula it is clear that the number of
points on an Edwards curve are a multiple of 4, because for every point (x,y)
also the points (-x,y),(x,-y) and (-x,-y) are on the curve and they are
distinct if x and y are nonzero. There are also the above-mentioned 4 points of
order 1,2,4, and 4 which have one of their coordinates equal to zero.
A different way to see that the group order is divisible by 4 is by Lagrange
because we have points of order 4 (the hands of the starfish)
and Lagrange says that the order of a group element divides the group order.
Jonathan showed the additional symmetry that with (x,y) also (y,x) is on the
curve, along with it's 3 mirror images.
Pictures of blackboards are here.
Thanks to a student for taking the pictures.
If anybody is looking for more intuition on the Edwards addition law. There is no
adding of angles or pizza pieces to explain it, but here is a link to a
blog
post describing a unified way of addition on circles and Edwards curves by
Thomas Hales. I prefer the simple and intuitive addition law on the circle
which we've seen to be a special case of the Edwards addition law for d = 0.
He goes the other way around – starting with a geometric interpretation
of the addition law that I worked out with Arene, Naehrig, and Ritzenthaler,
and then showing that that can also be used for the circle. But tastes differ,
so you might like his presentation better.
For our paper, Michael Naehrig recorded a video about it together with his kids
which you can find
here.
8 Sep 2026
Hopefully back to me.
What's next?
Here are a few courses that you might find interesting:
- To find out how crypto is used in practice take
2DMI10 - Applied Cryptography
taught by Andreas Hülsing in Q2.
-
2DMI00 - Cryptographic protocols by Berry Schoenmakers in Q3 covers more advanced
crypto, building on the primitives RSA, DL and symmetric crypto that we covered
in this course.
-
2DM100 - Cryptographic engineering by Roberto Blanco in q4 to learn how to
implement cryptography securely.
-
2IMS60 - Provable security by Kathrin Hövelmanns and Sven Schä in Q4
to learn about reduction profs linking cryptographic protocols to the building
blocks we analyze in 2MMC10.
-
If you want to learn more about cryptography make sure
to take the MasterMath course
Selected Areas in Cryptology. The course is given
in Spring 2027 by Lorenzo Grassi and Marc Stevens.
- Coding theory is another application area for finite fields and discrete
math in general. Alberto Ravagnani will offer a semester-long course on
Coding Theory
in Spring.
-
2MMQ10 - Quantum Computing and Algorithms by Subhasreee Patro in Q2.
If you want to understand how quantum computers break RSA and ECC and what else
they can do. This is the first year we offer a local course in Quantum Computing
- Finally, to defend against quantum computers, we're working on
Post-Quantum Cryptography.
Old exams
Old exams by me:
-
Exam from 04 Feb 2025 here
-
Exam from 29 Oct 2024 here
-
Exam from 23 Jan 2024 here
-
Exam from 30 Oct 2023 here
-
Exam from Jan 24, 2023 here.
This was another online exam under the same conditions as below.
-
Exam from 01 Nov 2022 here
This was another online exam under the same conditions as below.
The values are
n=8802480753545133742961614830369231016786934739808948821413906980918012852299263049997643868903076370469472928300916191513
h(m)=84382310455796615550407481393886585806223820180906281913225649154728756027652
s=7678423411571991838207630428856799461357777327526663279512861135218978467269521732475043119537044221598589640922989519745
-
Exam from Jan 25, 2022 here.
This was another online exam under the same conditions as below.
-
Exam from 02 Nov 2021 here
This was another online exam under the same conditions as below.
-
Exam from Jan 19, 2021 here.
This was another online exam under the same conditions as below.
-
Exam from Oct 27, 2020 here.
This was an open-book open-Internet exam so the last exercise doesn't give as many
details as normally. The inspiration this time was
The Long and
Winding Path to Secure Implementation of GlobalPlatform SCP10, though that
system was worse than what I made out of it (apart from having a longer
key).
-
Exam from Jan 21, 2020 here.
-
Exam from Oct 29, 2019 here.
-
Exam from Jan 23, 2018 here.
-
Exam from Oct 31, 2017, here.
-
Exam from Jan 24, 2017, here.
-
Exam from Dec 14, 2016, here.
Note that the g in exercise 3b is the same as in exercise 2, i.e. g=3.
The curve equation in exercise 6b is y^2=x^3-3x+5.
-
Exam from Nov 01, 2016, here.
-
Exam from Jan 19 2016, here.
-
Exam from Oct 27 2015, here.
-
Exam from Apr 14 2015, here.
-
Exam from Jan 27 2015, here.
-
Exam from Apr 15 2013, here.
-
Exam from Jan 28 2014, here.
-
Exam from Apr 13 2012, here.
-
Exam from Jan 27 2012, here.
-
Exam from Apr 28 2011, here.
-
Exam from Jan 28 2011, here.
Note that in exercise 5 the definition of PA should be [a]P.
-
Exam from Jan 21 2011: here.
-
Practice exam 2010/2011: here.
-
Exam from Apr 15 2010, here.
-
Exam from Jan 29 2010: here.
-
Practice exam 2009/2010: here.
Andreas Hülsing gave the course in 2018. His exams are available online
-
Second exam for students from Eindhoven and the TRU/e security master and first for MasterMath, Jan 25, 2019, here
-
First exam for students from Eindhoven and the TRU/e security master Oct 30, 2018,
here.
Henk van Tilborg has agreed that I put up his old exams for you to
practice: