# An Introduction to Cryptography, new and old | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 24:26
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt-E6u3uQGP9J4
- YouTube: https://www.youtube.com/watch?v=E6u3uQGP9J4

## Description

A beginner level view at what cryptography is, from signing, encryption, and hashing, to ZK, MPC, and FHE. We will answer "What do all these things mean?", "Why do they matter?", "What can you do with them?", and "How do they fit in the real world?".

Speaker(s): AtHeartEngineer, Ying Tong
Skill level: Beginner
Track: Applied Cryptography
Keywords: Zero-Knowledge, Cryptography, MPC, Homomorphic Encryption, education

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] [Music] hey I'm Tyler I go by at hard engineer on the internet and this is ying Tong um so I'm an engineer she's a cryptographer so we're going to kind of go back and forth between uh the mathematical View and then like the Layman's explanations for a lot of uh introductory cryptography so cryptography really is kind of a blend of Art and Science and it's the Art and Science Of Secrets um all right yep this one's you yeah and often times we think of the purpose of a cryptographic system in terms of um these three properties CIA um so firstly confidentiality um the property of keeping your messages secret and ensuring that they're only ever read by their intended recipient Integrity um being assured that the message at the time of reading has not been tampered with um from the time of sending and authenticity that the message was indeed uh sent by the expt expected sender and not forged um by someone else so a cryptographic system should provide Assurance of these three properties so this really comes down to uh you basically have these puzzles that are very easy to solve if you have the right key and very hard to solve if you don't have the key uh there's a little note at the bottom there's a lot of nuance here this is very hand wavy you're G to hang out on this side okay um but yeah so easy to solve with a key if you don't have the key very very hard so the topics we're going to go over are hashing encryption signing and what we're now calling programmable cryptography which is ZK MPC and fhe and you can kind of think of this breakdown as corresponding to the three properties that we discussed just now so hashing is a primitive that's often used um to provide Integrity assurances of Integrity um encryption helps us to preserve confidentiality and signing is a way to provide authenticity um and these three former Primitives and Protocols are what we consider first generation cryptography in the sense that they're purpose-built for a specific protocol um and um in the rest of Devcon on the applied cryptography track you're going to hear a lot more about programmable cryptography um which usually involve more heavyweight and more general purpose protocols all right so hashing is a one-way function that basically gives you a fingerprint of some data you can think of this as just this magic machine that you put data in one side and then that fingerprint comes out the other side so this is an example of what that machine looks like which is pretty gnarly but essentially it comes down to you put in you know for example a password it gets hashed and then some fingerprint comes out the other side um oh that's so weird yeah um this a good analogy for this is like uh blending fruits in a blender right like you can't get the fruits back out but you have a consistent like color right if you add just bananas in you're going to get the same color basically every time um so unique input unique output these are always fixed length so that's to stop certain types of attacks where you can try to like infer what kind of data went in and you can see so hi hell help and hello like they have very similar letters but they're totally different fingerprints you want to talk about this yeah so we've put in sort of Snippets of the relevant Devcon talks um throughout our slides to help you Orient um and actually um oh this talk already happened but it was an example of how you can build a general purpose proof system just using a hash function as a primitive so you can go back and watch this talk you can do a lot with hash functions cool so a common reason that hash functions are used is passwords but as you can see if two users had the same password they have the same password hash right so this allows an attack called a like rainbow table attack basically you just hash like all common passwords and then now you have this known fingerprint and you can you know use that to attack people's passwords but there's this thing called assault you can add which is essentially just tacking a random string that's specific to each user to the end of the password and then hashing it now you have a unique fingerprint for every password hash so this is just like a example of how um hashing is used very commonly so pretty much every popular website that has logins uses uh bcrypt with per user salts like this is a pretty pretty common technique all right this is all you yeah and I think hash functions are a great introduction um as a cryptographic primitive because they seem very simple the API is really straightforward but a cryptographic hash function actually has to fulfill a few properties um so we won't go over them in detail but um I think I put this in to highlight also that there exist non- cryptographic hash functions so um that are way more efficient than cryptographic hash functions and that are suitable for um use cases such as hash tables which are not um sort of high security so in hash tables for instance we don't need um the Collision resistance property in fact in hash tables we have many um techniques to handle collisions buckets um so and at the same time um cryptographic security of a hash function is I think literally defined as um for how long has this hash function remained unbroken for um and the that's that's where the art of cryptography comes in um Crypt analysis security analysis um and reasoning about the cryptographic security of a certain primitive so yeah hash functions we chose to as an introductory primitive um just to give you a taste of what they can be used for um how we reason about them um yeah another very common use case is in Merkel trees I'm sure we're all familiar um it's used in git to produce unique digests of a repository um it's used in blockchains um to produce L cryptographically linked headers from block to block um for instance in the ethereum state yeah all right so now we're going to go over encryption real quick um so one of the original like encryption algorithms that were used it's called a Caesar Cipher and it's terrible um but basically you take that alphabet and you shift it by you know some number and let's say if we want to write hello you're going to identify those letters and then basically just translate to the new code right um and if you want to reverse it you basically just shift it the other way and then you get the original message back out uh this is 4.6 bits of security so basically 26 letters minus one and it's terrible um we have much much better techniques nowadays um so symmetric key encryption which is basically what you know a Caesar Cipher is a type of symmetric key encryption um but it's when all the parties that are participating have the same key right so use the same key to encrypt and decrypt uh there's no authentication so you don't know who encrypted the message um and basically anyone with a key can decrypt it but it is fast and it's used very commonly with like data at rest or TLS like that St where you need like high bandwidth uh common examples AES for like an actual algorithm that's used all right so yeah secret key plain text go in you get some Cipher text out to decrypt you put in a secret key in your Cipher text you have a decrypt function and then you get your plain text back out all right um yeah and um yeah so symmetric encryption is suitable for when both parties are able to establish a common shared secret um and to use it both to encrypt and to decrypt but in many use cases we want the ability to say asynchronously and non-interactively encrypt a message to a recipient and in this case um asymmetric encryption comes in really handy because all you need to know is the public key of your recipient and they can decrypt the message at any time they want without um without your help so we put the API here I think what's important to note that's different um from symmetric encryption is that the encryption and decryption keys are different and the in particular um when we encrypt um we have when we encrypt we don't need any privileged information um and when we decrypt we need a private key that should absolutely stay secret um so a very closely related primitive in public key cryptography is signatures and you can think of a signature as a sort of Watermark so the API here changes slightly um in this case um we're using a private key to sign a message and using the public key to verify um um that it was indeed signed by who we expected so it's really interesting um for example like the same crypto system RSA can be used for both encryption and signing and often times well and it it just involves flipping actually which key you use um so I think something to note here is that um let's say in RSA to verify um a signature you're actually you actually decrypt it um using one of the RS a key Pairs and um this means that anyone can read the signed message so it's not this it does not give you the same um properties of confidentiality but it does give you uh authentic authenticity um and you can look out for oh this talk already ended but in ethereum um they're currently using a signature scheme that is not postquantum secure and they're actively um thinking about how to transition uh to postquantum yeah so a common Paradigm and like email for example is used uh like use signing and encryption right so you want to be able to prove that you're the one that created the message and you only want the recipient to be able to read it so in order to do this you would put in your private key in a message you would sign the message and you would take that sign message take the other party's public key and encrypt the message and then send it to them so they can take that decrypt it and then also verify that you are the sender all right so https everyone knows what this is it's little green lock you know make sure you're you have a secure connection to the server um this is a little handwavy but uh the general explanation is if you connect to a server you do this key exchange it's called Diffy Helman which I'll go into in the next slide and you get out a symmetric key right so public key cryptography is slow compared to symmetric key so um yeah basically to to make web pages load faster you would do this Diffy Helman key exchange and then get out a symmetric key that only you and the server know and then from there on you can do um faster messages so the way this works is you start with some shared paint right some shared colors and this is the paint analogy for for Diffy helmet but you start with some shared paint and then you each have some secret color and you combine those to create these two inputs you exchange the inputs you add back in your secrets and then you end up with the same paint color on either side but no one in the middle could know what your what your secrets are yeah so um we went through hashing encryption and signatures um and we were considering these to be sort of generation one purpose-built cryptography that are really lightweight and um just do their task really well as well um what's been emerging um and what you'll see a lot of at Devcon is programmable cryptography so um these include zero knowledge proofs um multi-party computation and fully homomorphic encryption and these Protocols are a lot more heavyweight in the sense that they involve usually lots more um assumptions security assumptions um but on the other hand they're a lot more general purpose in the sense that the end user is free to Define any arbitrary relation uh they're not um limited to say signatures encryption um and in that sense um this Clause of Primitives are programmable yeah I think these talks happened already um but introduct to this Paradigm of programmable cryptography so we'll quickly go through the three categories um maybe the most popular one is zero knowledge um yeah that's great um so essentially zero knowledge ZK is a way for aover to prove some statement to somebody else and they can verify it so for example um you can have your picture and then some private data your age or your date of birth or whatever go into some ckp and then out comes a hash of your photo and then basically a thumbs up that you're like over 21 or whatever um so you need that hash your photo to make sure that someone can actually authenticate that it's you they can they can see the image make sure that it you know corresponds with your age um and yeah they can you know you can prove your over 21 without showing your license or your passport or whatever yeah so the over 21 relation is just one example of a relation that you can prove in zero knowledge the point here being that this is an arbitrary user defined relation and as Tyler said the pr can keep their secret witness um unknown to the verifier and yet still convince the verifier that it satisfies the relation um and corresponds to a certain agreed upon and publicly known output so another interesting property of many zero knowledge proof systems is sex synness and what this means is that the PR's communication is much smaller than the size of the relation that he proved and this comes in handy in ZK rollups which I think many of us have heard about where whereby we Outsource um very heavy computation to some um well resourced machine offchain um and then simply submit a very small proof of its validity onchain um the point here being that verifying the computation is a lot cheaper and we we don't have to pay that much gas for it um there's also many other um sort of developments in zero knowledge proof systems um so I think youf actually will talk about elliptic curves and SN right after us um and many more exciting examples of um applications that use ZK I think Prat right before us for example um so now if we sort of um if we introduce um this setting where the witness is no longer held by a single party namely the prer and we move to consider like multiple parties um working together to compete a relation um this would bring us into um MPC multi-party computation and um this is um a superet of zero knowledge um um so it is a way for multiple um parties to jointly compute a function over secret inputs so yeah I put this visual here to show that um well once again we have an arbitrary function um but what's changed is that the the witness the secret input is now split um across multiple parties um and we can actually combine um multi-party computation with Zer knowledge proofs um and get um publicly auditable NPC so we can have both an MPC and a su sync certificate that the NPC was done correctly um and you can Yeah we actually have a bunch of MPC talks um at this conference so yeah this ZK MPC is what I was talking about publicly auditable MPC um yeah so so this is a project that uh our colleague Andrew wrote so it's a game where you can play Rock a modified version of rock paper scissors over NPC so only you and the person you're playing with are like actually participating there's no like intermediate party and you can trust that each other aren't cheating so fun game right yeah these are some other applications of NPC that you can hear about so the final sort of I think the most heavyweight um um primitive in programmable cryptography is fully homomorphic encryption um and the API of this looks pretty different so in this case um um the holder um of the secret data um en Crypts it homomorphically so it transforms it um into this sort of um Cipher text um that preserves the privacy of the data but also preserves the structure of it such that any party um Can Transform it according to any arbitrary function so once again this is fully programmable um but all the work is kind of um outsourced um to this arbitrary third party um so this third party performs uh an arbitrary computation and then returns um uh so this third party is working completely blindly um and ends up only with a cipher text form of the output um and the point here is that only the holder of the secret key um is able to decrypt the output to some sensible plain text um and yeah there's actually been a bunch of cool experiments using FHA um by cursive so you can check that out uh no yeah that's already over as well um so yeah I think that's all we have and do we have time for questions questions thank you first maybe give a round of app off to the speakers for a very nice overview of cryptography um so it's a little bit over time so we have maybe time for one question but I think one that came in very early and was uploaded a lot very quickly was what are some good resources to dive deeper into formal cryptography as someone with no prior experience so there is a elliptic curve cryptography primer by Cloud flare that I would recommend um it's a little long but it's very understandable like you can you can get through that pretty well um three blue one brown did a video on how Bitcoin works that he Dives deep and it's like 20 minutes and he he goes over uh hashing and signing pretty deeply and yeah I think those are probably two good options oh also there's this legendary cryptographer Dan Bonet who's done a bunch of open courseware um courses with like videos and course materials um I think it's on corsera actually so I highly highly recommend that one cool I maybe watching back the talks that you linked as well so watching the videos back very nice so I think we're at time we have a few minutes to switch over for the next session but yeah we' like to thank the speakers again and we see you soon so uh we'll be back in four minutes but I was just advised to say and there's quite a lot of cans and stuff left around
