Crypto Lab

Course module

Library privacy, for iSchools

Fits an undergraduate or graduate LIS course on information ethics, privacy, or library systems and technology, as a two-meeting unit: about 69 minutes of core lab time, which fits two 50-minute meetings with room to discuss, while a single meeting works only in a 75-minute slot and leaves almost none. The shelf-oracle extension suits students who also take a technical or information-security elective.

Audience
Library and information science students in an iSchool, with no mathematics or cryptography background, who need to reason about who can learn what about a patron from a catalog search, a request log, or a published statistic.
Class time
About 69 minutes of class time for the core sequence, plus about 25 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Last checked
2026-09-22

Ready to teach

Class time
About 69 minutes for the core sequence, plus about 25 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Checked in
Chromium 153, Firefox 155 and WebKit 26.6, at desktop width and phone width.
Known issues
None recorded in the checks below.

Prerequisites

Learning outcomes

  1. Students will be able to identify, for a catalog search, which party learns the requested title and which learns who asked, under a plain search, two-server private retrieval (patron-shield), and a relay-plus-gateway split (blind-relay).
  2. Students will be able to predict what two cooperating operators can reconstruct by combining what each already holds, and explain why the patron cannot confirm from their own device that the operators are staying apart.
  3. Students will be able to distinguish what these designs conceal (which record was requested; the link between a patron's address and their request) from what they leave visible (that a query happened, when, how often, and its size or timing).
  4. Students will be able to demonstrate how two published totals can reveal one person's value, and describe how calibrated noise, a declared cap on one person's contribution, and a finite query budget limit what published statistics reveal about an individual while leaving group-level conclusions visible.
  5. Students will be able to evaluate a vendor's or institution's privacy claim by naming the assumption it rests on (operators not combining their records, a trusted holder of the raw data, a budget that is enforced) and the party who must be trusted for it to hold.

Sequence

Patron Shield: Runs about 22 minutes against the 15 this module planned for. The published 15 covered Do and Record only: its own notes say Explain was never counted, in any modality, so the overrun is the debrief that was always going to happen and was never in the figure.

Blind Relay: Runs about 23 minutes against the 20 planned. Its Explain was priced below even a spoken rate — under a minute for each of five multi-part questions — so the overrun is what those questions actually cost to discuss, not new material.

DP Noise: Outcome 4's declared-cap clause is met in the worksheet's Fix / Extend items, not in the class sequence: at this budget the cap can be described in class but not demonstrated.

Each exhibit opens in its own site. Roles: Intro builds the idea, Break it has students cause the failure, Fix shows the construction that holds, and Extension is optional depth.

ExhibitRoleTimeWorksheet
Patron ShieldIntro22 minWorksheet for Patron Shield
Choose a book, run a private query and watch each of two simulated servers receive its own random request, read what each server saw, press the collusion button to see the two requests combined into the book's name, and switch between the naive and PIR views to compare what a server logs.
Cite this exhibit: Clark, P. A. Patron Shield [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-patron-shield/
Blind RelayBreak it23 minWorksheet for Blind Relay
Type a search query, run the exchange and step it from client through relay and gateway to see which party holds your address and which holds your request, flip the switch that lets relay and gateway compare notes, then simulate several clients at once and join the relay's and gateway's logs on size and on timing, with padding off and then on.
Cite this exhibit: Clark, P. A. Blind Relay [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-blind-relay/
DP NoiseFix24 minWorksheet for DP Noise
On the guided route, run the differencing attack to recover one employee's exact salary from two totals and re-run it with noise added, move the privacy setting ε and watch the with-Alice and without-Alice results slide together, declare a salary cap and decide what happens to a new hire above it, then average many noisy answers to recover the payroll and spend a query budget until the page refuses to answer.
Cite this exhibit: Clark, P. A. DP Noise [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-dp-noise/
Shelf OracleExtension25 minWorksheet for Shelf Oracle
Pick a book from the shelf, try to guess which encrypted entry hides your choice before and after deliberately breaking the encryption's randomness, fold the records into the answer step by step while the measured noise budget falls, run one-server and two-server retrieval head to head and make the two servers compare notes, then shrink the modulus until the answer decrypts to garbage and watch what a network observer still logs.
Cite this exhibit: Clark, P. A. Shelf Oracle [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-shelf-oracle/

Hand-out: every worksheet in this module, in sequence order

What students hand in

Vendor claim review. A short review of one privacy claim a vendor could make about a library catalog, saying what the arrangement behind it actually conceals, what it leaves visible, and which party has to be trusted for the claim to hold. It has to cite the student's own recorded observation for each part, and say what two published totals differing by one person would still give away.

It is drawn from what the worksheets already produce, so it adds no new task. Values differ from run to run, so there is no key to mark against: what a marker is reading is whether each claim is tied to something the student recorded, and whether the reasoning from it holds.

Discussion questions

  1. Patron Shield and Blind Relay each protect a patron as long as two organizations keep what they hold apart. If a library contracted two vendors to play those roles, what would you want to know about their ownership, contracts and jurisdiction, and what could the library actually verify?
  2. Blind Relay's correlation exhibit joins a relay's log with a gateway's log without the two operators cooperating, the way a court order, a breach or an acquisition might. What does that suggest about which request logs a library or its vendors should keep, for how long, and in whose custody?
  3. Patron Shield hides which book was requested but not that a patron searched, when, or how often. For a patron researching a medical or political topic, which of those remaining facts matters most, and what policy or practice outside the protocol could reduce it?
  4. DP Noise recovers one person's salary by subtracting two published totals. How could the same subtraction apply to circulation or program statistics a library publishes, and how would a privacy budget change how many reports the library could release?
  5. Differential privacy, as DP Noise demonstrates it, protects what is published while a curator still holds the raw records. Which library records would that help with, and which would still depend on retention and access policy?

Instructor notes

These notes are public, and they are conceptual on purpose: they describe what students should notice and why, never the specific values a run produces.

Expected observations

Common misconceptions

Conceptual answers

Checks

Browser support. Every exhibit in this module, and every step of its worksheet, was run in Chromium, Firefox and WebKit at a desktop width and at a phone width (1280 by 720 and 390 by 720), checked 2026-09-22. No exhibit had a problem at either width.

Privacy. Opening these exhibits sends nothing to anyone but the site they are served from: no exhibit sets a cookie, and none stores anything beyond the setting that pins its dark theme. The exception:

Detailed check results — engine versions, every step run, transfer sizes, and the source line behind each run-specific verdict. The worksheet drift check reads this module’s anchors manifest.

For your syllabus

Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data. https://crypto-lab.systemslibrarian.dev/teach/library-privacy/

How to cite this module’s exhibits

Each exhibit's citation is in the Sequence table above, in that exhibit's own row. Exhibits change as they are improved, so the retrieval date is what says which version you used; it is filled in from your device's clock when the page loads.

BibTeX
@misc{clark_patron_shield,
  author       = {Clark, Paul A.},
  title        = {Patron Shield},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-patron-shield/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_blind_relay,
  author       = {Clark, Paul A.},
  title        = {Blind Relay},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-blind-relay/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_dp_noise,
  author       = {Clark, Paul A.},
  title        = {DP Noise},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-dp-noise/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_shelf_oracle,
  author       = {Clark, Paul A.},
  title        = {Shelf Oracle},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-shelf-oracle/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

To cite the whole collection, see How to cite.