Beyond Lattices1Why Assumption Diversity Matters: The Systemic Risk of a Single-Family BreakWatch2Code-Based Cryptography: Classic McEliece, Syndrome Decoding, and a Sixty-Year Track RecordWatch3HQC and BIKE: Quasi-Cyclic Codes, the Backup-KEM Decision, and Decoding-Failure Trade-offsWatch4Multivariate Cryptography: The MQ Problem, Why Rainbow Fell, and What Still StandsWatch5When to Reach for a Non-Lattice Scheme: A Decision Framework over Size, Maturity, and RiskWatch
Homomorphic Encryption1Computing on Ciphertext: The FHE Promise, Noise Growth, and Why Bootstrapping Is the Central IdeaWatch2The Scheme Families: BGV/BFV Exact Integers versus CKKS Approximate RealsWatch3Bootstrapping and Its Cost: Refreshing Noise and the Parameter, Security, Performance TriangleWatch4Private Inference on Neural Networks: Approximating Non-Linearities Under FHEWatch5FHE versus TEEs versus MPC: An Honest Comparison for Confidential LLM ServingWatch
Lattice Foundations1Lattices and Their Hard Problems: SVP, CVP, and the Geometry of SecurityWatch2Learning With Errors: The Distribution, the Decision-Search Equivalence, and Regev's ReductionWatch3Ring-LWE and Module-LWE: Buying Efficiency with Algebraic StructureWatch4Parameters and the Security Estimate: Core-SVP, BKZ Block Size, and NIST LevelsWatch5Where the Assumptions Could Fail: Algebraic and Dual Attacks on Structured LatticesWatch
ML-KEM End to End1From LWE to a Public-Key Scheme: Compression, Rounding, and a Secret Hidden in NoiseWatch2KEMs and IND-CCA, Defined: What a Key-Encapsulation Mechanism Must SurviveWatch3The Fujisaki-Okamoto Transform: From Passive to Active Security by Re-EncryptionWatch4Decapsulation Failures and Their Consequences: Failure-Boosting AttacksWatch5Implementation Realities: The NTT, Constant-Time Decapsulation, and the Parameter SetsWatch
Secure Multi-Party Computation1The MPC Guarantee, Defined: Computing Without Revealing Inputs, and the Adversary ModelsWatch2Secret Sharing and Threshold Cryptography: Shamir, Additive Shares, and Threshold DecryptionWatch3Garbled Circuits and GMW: Two Routes to General Multi-Party Computation and Their Trade-offsWatch4Private Set Intersection and Federated Primitives: The Workhorses of Privacy-Preserving JoinsWatch5MPC for Machine Learning: Federated Learning, Secure Aggregation, and the Confidential-Computing TrioWatch
Post-Quantum Signatures1What a Signature Must Guarantee: EUF-CMA and the Two Roads to ItWatch2ML-DSA: Fiat-Shamir with Aborts and the Transcript That Leaks NothingWatch3SLH-DSA: Signing from Hashing Alone, and the Hypertree That Buys StatelessnessWatch4Stateful Hash-Based Signatures: XMSS, LMS, and the Rule That Must Never BreakWatch5Choosing a Signature: A Decision Framework over Assumptions, Size, and Operational RiskWatch
PQC Implementation Security1The Side-Channel Threat Model for Post-Quantum CryptographyWatch2Timing and the Decapsulation Oracle: When Non-Constant-Time Handling Leaks the PlaintextWatch3Power and Electromagnetic Attacks on the NTT and the SamplerWatch4Masking and Countermeasures: Arithmetic-to-Boolean Shares and the Cost of Provable ResistanceWatch5Verifying Constant-Time: Tooling and Methodology to Demonstrate a Leak-Free ImplementationWatch
Migrating to Post-Quantum1Hybrid Key Exchange, Done Right: Combining Classical and Post-Quantum So Either Can FailWatch2Post-Quantum in TLS 1.3: The X25519MLKEM768 Group and the MTU RealitiesWatch3Certificates and PKI Under Post-Quantum: Signature Bloat and Chain StrategiesWatch4Crypto-Agility as an Architecture Property: Escaping the Hard-Coded-Primitive TrapWatch5A Migration Methodology: Inventory, Shelf-Life Risk, Hybridize, and MeasureWatch
Threat Modeling PQC Migration1Framing the Post-Quantum Threat Model: Assets, Adversaries, and BoundariesWatch2Harvest-Now-Decrypt-Later as the Anchor Threat: Building a Data-at-Risk InventoryWatch3Downgrade, Rollback, and Negotiation Attacks: The Adversary That Strips the PQCWatch4The Migration's Own Attack Surface: Combiners, Dual Stacks, and Key-Management GapsWatch5A Post-Quantum Threat-Modeling Playbook: Inventory, Attack Trees, Controls, and a CI GateWatch
Quantum Threat Quantified1Shor's Algorithm, Structurally: Period-Finding and the Quantum Fourier TransformWatch2Grover and the Symmetric World: Why the Speedup Only Halves SecurityWatch3From Logical to Physical Qubits: The Surface-Code Cost of a Real RSA BreakWatch4Resource Estimates and Timelines: Reading the Numbers CriticallyWatch5Mosca's Inequality: Turning Data Shelf-Life into a Migration PriorityWatch
Symmetric Crypto Quantum Era1Grover Against Block Ciphers: The Quadratic Speedup, Double the Key Length, and the Parallelization CaveatsWatch2Hash Functions Under Quantum Search: Pre-image versus Collision, and Why Grover Does Not Halve Collision ResistanceWatch3AES-256 and SHA-384/512 as the Safe Floor: The Concrete Security Margins for the Top LevelsWatch4Authenticated Encryption and Key Commitment: AEAD Guarantees and the Commitment Gap for AgentsWatch5Where Symmetric Assumptions Are Load-Bearing: Hash-Based Signatures, KDFs, and the PQC Standards ThemselvesWatch
Zero-Knowledge Proofs1Interactive Proofs and Zero-Knowledge, Defined: Completeness, Soundness, and the SimulatorWatch2From Interactive to Non-Interactive: Fiat-Shamir, Commitments, and the Random-Oracle CaveatWatch3SNARKs: Succinct Arguments, the Arithmetic-Circuit Pipeline, and the Trusted-Setup QuestionWatch4STARKs and Transparency: Hash-Based, Post-Quantum-Plausible Proofs Without Trusted SetupWatch5Proving an ML Inference: zkML, the Committed-Input Guarantee, and the Honest CostWatch