Crypto Lab

Course module

Post-quantum transition

Upper-division undergraduate or graduate courses in computer security, applied cryptography or network security, covering the quantum threat to public-key cryptography and the move to ML-KEM and hybrid key exchange. About 117 minutes of core lab time: two meetings of 75 minutes, or three of 50 — not two of 50, which it overruns.

Audience
Upper-division undergraduate or graduate security students, including motivated newcomers to quantum algorithms and lattice-based cryptography.
Class time
About 117 minutes of class time for the core sequence, plus about 21 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Last checked
2026-09-22

Ready to teach

Class time
About 117 minutes for the core sequence, plus about 21 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Checked in
Chromium 153, Firefox 155 and WebKit 26.6, at desktop width and phone width.
Known issues
None recorded in the checks below.

Prerequisites

Learning outcomes

  1. Students will be able to explain how Shor's algorithm turns factoring into period finding, and show from a lab run how a recovered even period r yields the factors through gcd(a^(r/2) ± 1, N).
  2. Students will be able to contrast the impact of Shor's and Grover's algorithms on public-key and symmetric primitives, and justify why symmetric primitives mostly need larger parameters while RSA, ECC and Diffie-Hellman need replacement.
  3. Students will be able to demonstrate, using the toy LWE and toy-Kyber exhibits, how added noise defeats exact linear algebra and how noise past the decryption threshold makes decryption fail.
  4. Students will be able to trace an ML-KEM key establishment through KeyGen, Encaps and Decaps, and distinguish what a KEM provides from message encryption and from peer authentication.
  5. Students will be able to predict and then verify the outcome of an X25519 + ML-KEM-768 hybrid session when one or both key-establishment wires are broken, and explain why a hybrid is a hedge rather than a doubling of security.

Sequence

Each exhibit opens in its own site. Roles: Intro builds the idea, Break it has students cause the failure, Fix shows the construction that holds, and Extension is optional depth.

ExhibitRoleTimeWorksheet
ShorBreak it18 minWorksheet for Shor
Enter a composite N or pick a preset, press Run Shor's Algorithm several times, and follow the step log, period chart, QFT distribution with retunable phasor wheels, and continued-fraction table to the gcd step that recovers the factors.
Cite this exhibit: Clark, P. A. Shor [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-shor/
GroverBreak it26 minWorksheet for Grover
Set the qubit count, step Grover iterations with the oracle + diffusion sub-steps and prediction mode on, watch the state vector rotate toward and then past the target, sample with Measure ×100, and compare AES key sizes in the impact panels.
Cite this exhibit: Clark, P. A. (2026). Grover [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-grover/
Lattice GentleIntro33 minWorksheet for Lattice Gentle
Work through Guided mode: drag a 2D basis and decode a target by rounding, compare a good and a bad basis for the shortest vector, step Gauss and LLL, type LWE and SIS candidates, push toy-Kyber's noise past q/4 and tamper with toy-KEM ciphertexts and toy-Dilithium signatures, then answer the exit check.
Cite this exhibit: Clark, P. A. Lattice Gentle [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-lattice-gentle/
Kyber VaultFix20 minWorksheet for Kyber Vault
Pick an ML-KEM parameter set and step KeyGen, Encaps and Decaps until both secrets match, encrypt a message through the ML-KEM + AES-256-GCM hybrid and tamper with the ML-KEM ciphertext, then solve the toy LWE system clean versus noisy.
Cite this exhibit: Clark, P. A. Kyber Vault [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-kyber-vault/
Hybrid WireFix20 minWorksheet for Hybrid Wire
Step the X25519 + ML-KEM-768 handshake to the HKDF combiner, send encrypted chat messages and tamper with the session, then toggle either or both wires to broken in the Threat model tab and read the measured verdict.
Cite this exhibit: Clark, P. A. Hybrid Wire [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-hybrid-wire/
Harvest VaultExtension21 minWorksheet for Harvest Vault
In the Prove it panel, send a message over the toy handshake, deploy the PQC upgrade, send again and run Q-Day to compare the recorded sessions, then work the Mosca X + Y > Z calculator with sector presets and Q-Day scenarios.
Cite this exhibit: Clark, P. A. (2026). Harvest Vault [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-harvest-vault/

Hand-out: every worksheet in this module, in sequence order

What students hand in

Migration memo. A memo to a service owner naming, for each system the student ran, whether Shor breaks it outright or Grover only forces a larger parameter, what would replace it, and which breaks a hybrid replacement would still survive. Each call has to cite a value or verdict the student recorded, and to keep key establishment separate from the cipher protecting the data.

It is drawn from what the worksheets already produce, so it adds no new task. Values differ from run to run, so there is no key to mark against: what a marker is reading is whether each claim is tied to something the student recorded, and whether the reasoning from it holds.

Discussion questions

  1. In Shor's algorithm the quantum computer's job is finding the period r; the rest is ordinary arithmetic. Which cryptosystems does that expose, which does it leave alone, and why?
  2. Grover's algorithm also speeds up key search. Why is the usual response to Grover to choose larger symmetric parameters, while the response to Shor is to replace RSA, ECC and Diffie-Hellman outright?
  3. The lattice exhibits start from a picture of good and bad bases, then warn that ML-KEM never gives honest users a secret good basis. What is the secret in ML-KEM, where does the hardness it relies on actually live, and why do the 2D demonstrations not show that hardness?
  4. The ML-KEM lab stresses that a KEM establishes a key but neither encrypts a chosen message nor authenticates the peer. If its flow were copied unchanged into a real protocol, what could an active attacker do, and what would the protocol have to add?
  5. A hybrid session is claimed to survive as long as either wire holds. What does the hybrid cost, which failures can still sink it, and why does the way the two secrets are combined matter?

Instructor notes

These notes are public, and they are conceptual on purpose: they describe what students should notice and why, never the specific values a run produces.

Expected observations

Common misconceptions

Conceptual answers

Checks

Browser support. Every exhibit in this module, and every step of its worksheet, was run in Chromium, Firefox and WebKit at a desktop width and at a phone width (1280 by 720 and 390 by 720), checked 2026-09-22. No exhibit had a problem at either width.

Privacy. Opening these exhibits sends nothing to anyone but the site they are served from: no exhibit sets a cookie, and none stores anything beyond the setting that pins its dark theme.

Detailed check results — engine versions, every step run, transfer sizes, and the source line behind each run-specific verdict. The worksheet drift check reads this module’s anchors manifest.

For your syllabus

Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data. https://crypto-lab.systemslibrarian.dev/teach/post-quantum/

How to cite this module’s exhibits

Each exhibit's citation is in the Sequence table above, in that exhibit's own row. Exhibits change as they are improved, so the retrieval date is what says which version you used; it is filled in from your device's clock when the page loads.

BibTeX
@misc{clark_shor,
  author       = {Clark, Paul A.},
  title        = {Shor},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-shor/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_grover,
  author       = {Clark, Paul A.},
  title        = {Grover},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-grover/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_lattice_gentle,
  author       = {Clark, Paul A.},
  title        = {Lattice Gentle},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-lattice-gentle/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_kyber_vault,
  author       = {Clark, Paul A.},
  title        = {Kyber Vault},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-kyber-vault/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_hybrid_wire,
  author       = {Clark, Paul A.},
  title        = {Hybrid Wire},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-hybrid-wire/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_harvest_vault,
  author       = {Clark, Paul A.},
  title        = {Harvest Vault},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-harvest-vault/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

To cite the whole collection, see How to cite.