Master's Degree in Data Science · Sapienza University of Rome

Data Privacy and Security

An interactive companion to Prof. Daniele Venturi's Fall 2025 course. Eight chapters and twenty-four lectures, rebuilt as pages with reader-driven animations, interactive worked examples and exercises whose answers can be revealed.

8 chapters 24 lectures 819 source slides Runs fully offline

Much of cryptography is easier to understand in motion. Bits are XORed, blocks are chained, a state matrix is permuted, noise is added to a query answer and a blockchain forks before its branches converge. A PDF can show only one frame at a time. These pages let the reader advance each process step by step.

All chapter pages follow the same structure, so familiarity with one page carries over to the others:

How to use this

These pages accompany the official slides in the parent folder. Only material in Venturi's slides is examinable. Where the pages and the slides differ in emphasis, the slides are authoritative. The / key opens search; arrow keys step through any animation that has focus.

The CourseChapters

Chapter 1 Secret-Key Cryptography Perfect secrecy and why it cannot scale. AES (Advanced Encryption Standard) and Rijndael's field. Modes of operation. Message Authentication Codes (MACs), hashing, Merkle-Damgård, sponges, Hash-Based Message Authentication Code (HMAC). Authenticated encryption and the case for encrypt-then-MAC. Lectures 1 to 4 · 64 slides Chapter 2 Public-Key Cryptography An overview of Minicrypt: one-way functions, Pseudorandom Generators (PRGs), Pseudorandom Functions (PRFs), Pseudorandom Permutations (PRPs). Number theory. RSA and its textbook insecurity. ElGamal and the Diffie-Hellman assumptions. Pairings. Signatures, Public-Key Infrastructure (PKI) and identity-based encryption. Lectures 5 to 6 · 38 slides Chapter 3 Key Exchange Protocols Diffie-Hellman key exchange and the Canetti-Krawczyk model. ISO 9697, SKEME (Secure Key Exchange Mechanism), Sign-and-MAC (SIGMA), MQV (Menezes-Qu-Vanstone) and Hashed MQV (HMQV). Key derivation with HMAC. Passwords, Bloom filters and password-authenticated key exchange. TLS (Transport Layer Security) 1.3. Lectures 8 to 9 · 74 slides Chapter 4 Post-Quantum Cryptography Lattices, Short Integer Solution (SIS) and Learning with Errors (LWE). Lattice trapdoors. Falcon. Canonical identification and Crystals-Dilithium. Regev encryption, Fujisaki-Okamoto and Crystals-Kyber. Fully-homomorphic encryption, Identity-Based Encryption (IBE) and Attribute-Based Encryption (ABE) from lattices. Lectures 10 to 13 · 107 slides Chapter 5 Differential Privacy Pure and approximate differential privacy and their properties. Randomized response. The Laplace, Gaussian and exponential mechanisms. Advanced composition. SmallDB. Information-theoretic and computational lower bounds. Lectures 13 to 15 · 104 slides Chapter 6 Bitcoin Bitcoin's design: transactions, scripts, the blockchain, proof of work and difficulty. Mining pools and reward systems. Selfish mining. Eventual consensus and security. Lightning networks. Lectures 16 to 18 · 153 slides Chapter 7 Alternative Currencies Ethereum and smart contracts. Proof-of-stake: Cardano's Ouroboros and Algorand's Byzantine agreement. Litecoin. Proofs of space and Filecoin. Anonymity and Zerocash. Lectures 19 to 20 · 133 slides Chapter 8 Secure Multiparty Computation The MPC problem and its security definitions. Coin tossing and oblivious transfer. Yao's garbled circuits, semi-honest and malicious. Secret sharing. MPC with honest majority. Redactable blockchain. Lectures 21 to 24 · 140 slides

ReferenceSupporting Pages

Reference Notation & Glossary Symbols and terms used across the eight chapters, collected in one place: security parameters, hardness assumptions, differential privacy parameters and the blockchain and Multiparty Computation (MPC) vocabulary. Linked from every chapter Aside Lecture 7 (Invited) Richard Stallman on free software and freedom in the digital society. Outside the chapter structure, with no deck and not examinable. 13/10/25

ReferenceLecture Schedule

The official Fall 2025 schedule, with the chapter for each lecture. Lecture 7 was an invited lecture by Richard Stallman on free software and freedom in the digital society; it sits outside the chapter structure.

#DateTopicsChapter
123/09/25Introduction to the course. Modern cryptography. Message confidentiality and authenticity. Symmetric encryption. Perfect secrecy and Shannon's impossibility result.1
226/09/25The AES (Advanced Encryption Standard) blockcipher. Modes of operation: Electronic Codebook (ECB), Cipher-Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback (OFB) and Counter (CTR). Chosen-Plaintext Attack (CPA) security for symmetric encryption.1
330/09/25Message authentication codes and unforgeability. CBC-MAC and its security. Collision-resistant hash functions.1
402/10/25Merkle-Damgård and SHA-1 (Secure Hash Algorithm 1). The sponge construction and SHA-3. Hash-Based Message Authentication Code (HMAC). Chosen-Ciphertext Attack (CCA) security. Combining encryption and authentication.1
507/10/25A brief tour of Minicrypt: one-way functions, Pseudorandom Generators (PRGs), Pseudorandom Functions (PRFs), Pseudorandom Permutations (PRPs). Beginning of asymmetric cryptography: brush-up on number theory.2
609/10/25RSA and ElGamal encryption and their security. Diffie-Hellman assumptions. Pairings and bilinear groups. Digital signatures, RSA-FDH (RSA full-domain hash). Public-Key Infrastructure (PKI) and X.509. Identity-based encryption.2
713/10/25Free software and freedom in the digital society (invited lecture by Richard Stallman).None
816/10/25Key exchange protocols. Diffie-Hellman key exchange. Security in the Canetti-Krawczyk model. ISO 9697. IPsec (IP security) and IKE (Internet Key Exchange): SKEME (Secure Key Exchange Mechanism) and Sign-and-MAC (SIGMA). MQV (Menezes-Qu-Vanstone) and Hashed MQV (HMQV).3
921/10/25Key derivation functions using HMAC. Passwords. Bloom filters. Password-based encryption. Password-authenticated key exchange. TLS (Transport Layer Security) and TLS 1.3.3
1023/10/25Post-quantum cryptography. Lattices and hard problems: Short Integer Solution (SIS) and Learning with Errors (LWE). Basic lattice-based primitives. Lattice trapdoors.4
1128/10/25Falcon. Canonical identification schemes and Crystals-Dilithium. Regev public-key encryption. The Fujisaki-Okamoto transform and Crystals-Kyber.4
1230/10/25Fully-homomorphic encryption and advanced cryptographic applications.4
1304/11/25Identity-Based Encryption (IBE) and Attribute-Based Encryption (ABE) from lattices. Differential privacy and approximate differential privacy. Properties. Randomized responses. The Laplace and Gaussian mechanisms.4 + 5
1406/11/25Advanced composition. The exponential mechanism and its applications.5
1511/11/25The SmallDB mechanism. Information-theoretic lower bounds. Traitor tracing and computational lower bounds. Differential privacy and game theory.5
1613/11/25Introduction to Bitcoin. Basic design principles.6
1718/11/25Mining pools and attacks.6
1825/11/25Security of Bitcoin. Lightning networks.6
1927/11/25Altcoins: Ethereum, Cardano, Algorand, Litecoin.7
2002/12/25Altcoins: Filecoin, Zerocash.7
2104/12/25Introduction to multi-party computation. Coin tossing and oblivious transfer.8
2209/12/25Yao's protocol for semi-honest and malicious adversaries.8
2311/12/25Secret sharing. MPC with honest majority.8
2416/12/25Redactable blockchain.8

NotesProvenance and Caveats

The source slides sit in the parent directory, downloaded from the course site on 22 August 2026.

The course page moved

The long-standing URL danieleventuri.altervista.org/dps.shtml still serves Fall 2023 HTML and performs a client-side JavaScript redirect to the current site at dventuri83.github.io/projects/2_dps/. Tools that do not execute JavaScript (curl, wget, most scrapers) silently get the stale page. Collecting these slides requires a real browser.

Relative to the 2023 edition, Chapter 3 is now Key exchange protocols, and Chapter 4 is a new Post-quantum cryptography chapter replacing the former big-data-and-cloud material. Proofs of storage and verifiable computation have been dropped as standalone topics; identity-based and attribute-based encryption now appear as lattice applications. The Katz-Lindell reference is the third edition (2025).

A student of the course wrote these companion pages. The mathematics is restated in standard form, independent of the slide text, partly because slide superscripts do not survive text extraction and partly because a definition is easier to trust written out in full. Any errors are the student author's alone. When in doubt, the PDFs are authoritative.

ReferenceResources

Free references that cut across several chapters.

Further reading: