40 chapters7 parts4 appendices252 runnable code blocks248 cited sources
By the end of this book you will have implemented one member of every major post-quantum family from scratch. You will know why each scheme exists, what attacks it survives, and how to migrate a real system to use it. You will be prepared to reason about post-quantum zero knowledge proofs as an open problem.
For more on who this is for and the assumed background, see About this book and Prerequisites.
Seven Parts and four appendices. Each Part progresses from intuition to construction to attacks to tradeoffs.
The book is releasing one chapter at a time. None of the 40 chapters are published yet.
Part I: Foundations
1 The quantum threat Not yet published 2 Mathematical preliminaries Not yet published 3 Hard problems at a glance Not yet published 4 From classical to post-quantum Not yet published 5 KEMs vs key agreement vs public-key encryption Not yet published 6 Digital signatures reconsidered Not yet published
Part II: Lattice-Based Cryptography
7 Lattices for programmers Not yet published 8 The LWE problem Not yet published 9 Ring-LWE and Module-LWE Not yet published 10 Regev encryption from scratch Not yet published 11 ML-KEM (FIPS 203) from scratch Not yet published 12 Lattice cryptanalysis Not yet published
Part III: Hash-Based Signatures
13 One-time signatures from hash Not yet published 14 Many-time signatures Not yet published 15 FORS and the Stateless Hypertree Not yet published 16 SLH-DSA (FIPS 205) from scratch Not yet published 17 Hash-based signature cryptanalysis Not yet published
Part IV: Code-Based & Isogeny
18 Coding theory for cryptographers Not yet published 19 McEliece: the original PQC Not yet published 20 HQC from scratch Not yet published 21 Isogenies for programmers Not yet published 22 SQIsign from scratch Not yet published 23 The other families Not yet published
Part V: Migration & Deployment
24 Inventory first: CBOM Not yet published 25 Crypto agility Not yet published 26 Hybrid schemes in practice Not yet published 27 TLS 1.3 migration Not yet published 28 PKI and code signing Not yet published 29 Running a PQ migration program Not yet published
Part VI: Post-Quantum Zero-Knowledge
30 The four-layer decomposition Not yet published 31 PQ-secure commitment schemes Not yet published 32 Fiat-Shamir in the QROM Not yet published 33 STARKs and FRI revisited Not yet published 34 Case studies: Zcash, ZKsync, Starknet Not yet published
Part VII: PQC for Blockchain
35 Blockchain threat model under quantum Not yet published 36 Layer 1 signature migration: Bitcoin and Ethereum Not yet published 37 Wallets, addresses, and key rotation Not yet published 38 Consensus and staking signatures Not yet published 39 ZK rollups under quantum Not yet published 40 Governance, hard forks, and migration case studies Not yet published
Draft complete across all seven Parts. Editorial walkthrough is rolling out chapter by chapter; the mechanical CI gates pass and the NIST KAT suites for ML-KEM and SLH-DSA pass byte-for-byte.
Written by the Encryptorium team. Grounded in published blog posts, the Post-Quantum Readiness Assessment framework, and an in-progress research paper on post-quantum zero knowledge proof systems.