Below you can find the lecture notes. Since they are written by you as the course develops, some notes still contain typos and possle mistakes! So please forgive the inaccuracies, keep checking for continuous updates, and notify the instructor of the mistake you find.

Lecture 1: (Sep 9) Password Authentication, Leakage-Resilient OWFs, Symmetric-Key ID Schemes. (.ps).

Lecture 2: (Sep 16) Symmetric-Key and Public-Key ID schemes, Schnorr's protocol, PoK property (.ps).

Lecture 3: (Sep 23) Sigma Protocols, Witness Indistinguishability, Active ID schemes, Okamoto Scheme (.ps).

Lecture 4: (Sep 30) OR Proofs, Trapdoor Commitments, On-line/off-line and Chameleon Signatures (.ps).

Lecture 5: (Oct 7) CRHFs, One-Time Signatures, Fiat-Shamir Signatures in ROM, Intro to ZK (.ps).

Lecture 6: (Oct 14) ZK, Fiat-Shamir and ZK, ZK of Sigma-protocols, round-optimal ZK for NP (.ps).

Lecture 7: (Oct 21) Witness-Hiding, Concurrent ZK with CRS, Sigma-protocol for HC, NIZK with RO (.ps).

Lecture 8: (Oct 28) Non-programmable RO, Omega-protocols, 2-round ZK in NPRO, NIZK in CRS model (.ps).

Lecture 9: (Nov 4) NIZK for NP in CRS, Adaptive/unbounded ZK, FLS construction, NIZK-PoK (.ps).

Lecture 10: (Nov 11) (One-Time) Simulation-Soundness, CCA from CPA encryption: DDN vs. NY (.ps).

Lecture 11: (Nov 18) Designated Verifier SS-NIZK, Universal Hash Proof Systems, Cramer-Shoup Scheme (.ps).

Lecture 12: (Nov 25) Leakage-Resilient CPA and CCA Encryption, Kurosawa-Desmedt CCA Scheme (.ps).

Lecture 13: (Nov 30) SS-NIZK, Simulation Extractability, (Leakage-Resilient) Signatures from SE-NIZK (.ps).

Lecture 14: (Dec 9) UC Security, UC-ZK, CRS model, UC-ZK from (a) wSE-NIZK; (b) Omega-protocols (.ps).

Other Handouts

Last modified: December 17, 2009