A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
—
| Subject name (Hungarian, English) |
Bizonyított biztonság
Provable Security
|
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Subject code | BMEVIHID022 | ||||||||||||
| Subject type | — | ||||||||||||
| Training Level | — | ||||||||||||
| Course types and hours (weekly/semester) |
|
||||||||||||
| Assessment type | vizsga | ||||||||||||
| Credits | 5 | ||||||||||||
| Subject coordinator |
Dr.Vajda István
contact:
vajda.istvan@vik.bme.hu
|
||||||||||||
| Responsible department |
Hálózati Rendszerek és Szolgáltatások Tanszék
|
||||||||||||
| Faculty | Villamosmérnöki és Informatikai Kar | ||||||||||||
| Subject website | — | ||||||||||||
| Primary curriculum type | — | ||||||||||||
| Direct prerequisites – Strong prerequisite | none | ||||||||||||
| Direct prerequisites – Weak prerequisite | none | ||||||||||||
| Direct prerequisites – Parallel prerequisite | none | ||||||||||||
| Direct prerequisites – Milestone prerequisite | none | ||||||||||||
| Direct prerequisites – Exclusion | none |
Objectives
Programme
1. week: Paradigms in provable security: Algorithmic reduction, algorithmic indistinguishability, simulatability. Security by indistingushability (security game) vs. security by simulation of ideal functionality.
2. week: Standard secure cryptographic primitives: Public key encryption: semantic security, message-indistinguishability (IND-CPA, IND-CCA2), non-malleability. Digital signature. Message authentication.
3. week: Standard secure cryptographic protocols: Stand-alone setting. GMW oblivious transfer protocol. Fiat-Shamir party authentication protocol.
4. week: Secure Multiparty Computation. Secure function evaluation.
5. week: Universal composability (UC): Modular composition. Concurrent setting. UC-security vs. non-concurent (stand-alone) security.
6. week: Models in the UC security framework: Computational model. Model of protocol execution. Bare model. Plain model. Trusted setups and trusted third parties. Adversarial models. Hybrid protocol.
7-10. week: Ideal functionalities and trusted setup models in the UC: Authenticated communication. Secure communication channel. Key exchange. Public key encryption. Digital signature. Commitment. Oblivious transfer. Remote coin tossing. Zero knowledge proofs (ZKP). Secure function evaluation. The Common Reference String and Key setup models.
11. week: The UC composition theorem.
12. week: UC with joint state (JUC).
13. week: Realizability issues in the UC framework.
14. week: Protocol applications: E-voting, E-auction.
2. week: Standard secure cryptographic primitives: Public key encryption: semantic security, message-indistinguishability (IND-CPA, IND-CCA2), non-malleability. Digital signature. Message authentication.
3. week: Standard secure cryptographic protocols: Stand-alone setting. GMW oblivious transfer protocol. Fiat-Shamir party authentication protocol.
4. week: Secure Multiparty Computation. Secure function evaluation.
5. week: Universal composability (UC): Modular composition. Concurrent setting. UC-security vs. non-concurent (stand-alone) security.
6. week: Models in the UC security framework: Computational model. Model of protocol execution. Bare model. Plain model. Trusted setups and trusted third parties. Adversarial models. Hybrid protocol.
7-10. week: Ideal functionalities and trusted setup models in the UC: Authenticated communication. Secure communication channel. Key exchange. Public key encryption. Digital signature. Commitment. Oblivious transfer. Remote coin tossing. Zero knowledge proofs (ZKP). Secure function evaluation. The Common Reference String and Key setup models.
11. week: The UC composition theorem.
12. week: UC with joint state (JUC).
13. week: Realizability issues in the UC framework.
14. week: Protocol applications: E-voting, E-auction.
This subject provides an introduction into the techniques of
constructions of cryptographic primitives and protocols with formally
provable security guarantees. In contrast to ad-hoc approaches in the
usual practice.
Learning outcomes
Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:
Knowledge
No learning outcomes recorded.
Skills
No learning outcomes recorded.
Attitudes
No learning outcomes recorded.
Autonomy and responsibility
No learning outcomes recorded.
Oktatási módszertan
lectures with plenty of analysis/construction examples
Tanulástámogató anyagok
Online források
- Goldreich: Foundations of Cryptography, Cambridge Press, 2004; - R.Canetti: Universally Composable Security: A New Paradigm for Cryptographic Protocols, 2005; - presentation slides
Recommended preliminary knowledge for completing the subject
Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
MSc level knowledge in Discrete Mathematics, Probability Theory and in Theory of Algorithms
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
MSc level knowledge in Discrete Mathematics, Probability Theory and in Theory of Algorithms
General rules
Requirements:
a. During the semester: One in-class test (ZH) in the second half of the semester.
Condition for the signature is the pass mark of ZH test (40% above). There is a possibility to rewrite the in-class test (ZH). In the rectification period (repeat period) there is another (final) possibility to rewrite the in-class test (ZH).
b. Examination: Oral exam.
Assessment methods
In-term assessments
No detailed assessments provided.
Weight of in-term assessments
No weights provided.
Exam-period assessments
No detailed assessments provided.
Weight of exam elements
No weights provided.
Grade calculation
No grade thresholds provided.
Attendance requirements
No attendance requirements provided.
Rules for retake and resubmission
Not provided.
Short description
Not provided.
Detailed description
Not provided.
Recommended courses
Not provided.
Workload to complete the subject
No workload breakdown provided.
Validity of subject requirements
Requirements valid from:
—
Requirements valid until:
—
Curriculum placement
No curriculum placements recorded for this subject version.