TTM4205

Secure Cryptographic Implementations

Autumn

Trondheim

English

Overview

41 candidates

Average grade

A

4.63

0.27

Pass rate

100%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

The course covers how to implement, analyse, attack, protect and securely compose cryptographic algorithms in practice. It goes in depth on how to implement computer arithmetic, attacking implementations using side-channel attacks and fault injection, exploit padding oracles and low-entropy randomness, utilise techniques to defend against these attacks, and how to securely design misuse-resistant APIs.

This course involves security of cryptographic software used in critical digital infrastructure across all of society, building up under the UN Sustainability Development Goals, by enabling financial services (8.10), facilitate resilient infrastructure (9.a), enhance scientific research and upgrade technological capabilities (9.5), ensure public access to information and protect fundamental freedoms (16.10), and enhance the use of enabling technology (17.8).

Learning outcomes

A. Knowledge: Advanced knowledge about the mathematical building blocks underlying modern cryptography, properties of and applications of cryptographic primitives, challenges and common mistakes when implementing cryptography, side-channel attacks and countermeasures, and high level design principles for secure use of cryptography in practice.

B. Skills: Able to implement the underlying mathematics and high-level protocols used in symmetric key and public key cryptosystems, perform simple side-channel attacks and implement countermeasures, analyse side-channel countermeasures and design misuse resistant APIs for cryptography.

C. General competence: Experience on how to organise projects in small groups, conduct experiments, and write academic reports.

Teaching methods

Lectures, individual assignments, group projects, and laboratory exercises.