Skip to content

Repository files navigation

Crypto Lab

🥇 Crypto Lab · 2026 Cybersecurity Excellence Awards — Gold Winner

Browser-based cryptography demos — no backends, no accounts, just the math.*

* ⚡ One deliberate exception: Blind Oracle runs a live Rust/TFHE-rs server to demonstrate real fully homomorphic encryption — it adds your two encrypted numbers and still mathematically cannot read them.

A curated collection of single-concept cryptography demonstrations. Each one isolates a real primitive or protocol and makes it interactive in the browser. Classic algorithms, post-quantum schemes, zero-knowledge proofs — all grounded in real specifications, not toy reimplementations.

Live → https://crypto-lab.systemslibrarian.dev/


Featured

Project Concept Primitives
Quantum Vault KpqC Post-Quantum AES-256-GCM · Shamir SSS · SMAUG-T · HAETAE
Corrupted Oracle Backdoored RNG Dual_EC_DRBG · HMAC-DRBG · ChaCha20-DRBG · P-256
Padding Oracle CBC Padding Oracle AES-CBC · PKCS#7 · Vaudenay 2002 · POODLE
Nonce Lattice Lattice Attack ECDSA · Hidden Number Problem · LLL Reduction · secp256k1

Learning Paths

Curated, ordered journeys through the catalog. Pick one on the live site and follow it step by step.

Path Focus Journey
Developer A builder's journey — from primitives to the protocols you actually ship. Babel Hash → AES Modes → KDF Chain → Educational RSA → RSA Forge → Point Arithmetic → Curve Lens → Signed Bytes → DH MITM → X3DH Wire → Noise Pipe → OPAQUE Gate → WebAuthn → SSH Handshake → TLS Handshake → PQ TLS Handshake
Cryptanalyst An attacker's lens — classical ciphers to post-quantum side channels. Dead Sea Cipher → Biham Lens → Padding Oracle → Timing Oracle → Power Trace → Salamander → Nonce Collision → Entropy Collapse → Nonce Lattice → Frozen Heart → KyberSlash → Lattice Fault
Post-Quantum A focused track on PQ KEMs, signatures, hybrids, and migration. PQ Families → Kyber Vault → KEM Trap → Dilithium Seal → Hybrid Wire → Hybrid PQC → Downgrade Wire → PQ TLS Handshake → PQ Rotation → Harvest Timeline
Key Exchange How two parties agree on a secret — classical ECDH to hybrid post-quantum handshakes. Key Exchange → Curve Lens → DH MITM → X3DH Wire → Ratchet Wire → Noise Pipe → OPAQUE Gate → TLS Handshake → Kyber Vault → Hybrid Wire → PQ TLS Handshake

All Demos

Project Category Stack
ORAM Vault Access-Pattern Privacy Path ORAM · Position Map · Stash · Access Patterns
Paillier Gate Additive Homomorphic Encryption Paillier · Additive HE · Private Voting · Aggregation
Credential Veil Anonymous Credentials BBS+ · Selective Disclosure · Unlinkability · Range Proof
Iron Letter Asymmetric Encryption ECIES P-256 · RSA-OAEP · AES-256-GCM
X3DH Wire Asynchronous Key Agreement X3DH · X25519 · HKDF-SHA-256 · Signal Protocol
AEGIS Gate Authenticated Encryption AEGIS-256 · AES Round Function · 6-State Sponge · Test Vectors
Kerberos v5 Authentication Protocol RFC 4120 · Needham-Schroeder · Lowe Attack · AES-256-CTS
Corrupted Oracle Backdoored RNG Dual_EC_DRBG · HMAC-DRBG · ChaCha20-DRBG · P-256
Bitcoin Script Bitcoin Script secp256k1 · P2PKH · ECDSA · Stack Machine
Blind Sign Blind Signatures Chaum RSA · Schnorr EC · e-Cash · Unlinkability
Iron Serpent Block Cipher Serpent · AES-256 · SPN
World Ciphers Block Cipher Camellia · ARIA · SM4 · Kuznyechik
AES Modes Block Cipher Modes AES · AES-GCM · AES-CBC · Authenticated Encryption
Traitor Trace Broadcast Encryption NNL Subset-Cover · Broadcast Encryption · Traitor Tracing · AES-256-GCM
Padding Oracle CBC Padding Oracle AES-CBC · PKCS#7 · Vaudenay 2002 · POODLE
Time Trust Clock-Dependent Security Ed25519 · X.509 · JWT · TOTP
BIKE Vault Code-Based KEM BIKE · QC-MDPC · Post-Quantum · KEM
HQC Vault Code-Based KEM HQC · Reed-Muller · Reed-Solomon · Post-Quantum
Commit Gate Commitment Schemes Hash Commitment · Pedersen · Binding & Hiding · Homomorphic
Hybrid Sign Composite Signatures Ed25519 · ML-DSA-65 · Composite Signatures · IETF LAMPS
Model Breach Cryptanalysis Threat Modeling · Candidate Enumeration · MITM Recovery · Guess-and-Determine
DRBG Arena CSPRNG HMAC_DRBG · CTR_DRBG · Hash_DRBG · NIST SP 800-90A
Web of Trust Decentralized Trust PGP · OpenPGP · GnuPG · Key Signing · Trust Graph
Shadow Vault Deniable Encryption Argon2id · ChaCha20-Poly1305 · SHA-256
Biham Lens Differential Cryptanalysis Differential Cryptanalysis · SPN · DDT · Chosen-Plaintext
DH MITM Diffie-Hellman + MITM Diffie-Hellman · Modular Arithmetic · MITM · Key Exchange
ECDSA Forge Digital Signatures ECDSA · secp256k1 · RFC 6979 · Nonce Reuse
Ed25519 Forge Digital Signatures Ed25519 · EdDSA · Deterministic Nonces · ZIP215 · Cofactor
Schnorr Forge Digital Signatures BIP-340 · secp256k1 · Nonce Reuse · Aggregation
DKG Gate Distributed Key Generation Pedersen DKG · GJKR 1999 · Feldman VSS · ristretto255
Downgrade Wire Downgrade Attacks TLS 1.3 · Transcript Binding · X25519MLKEM768 · Downgrade
Curve Lens Elliptic Curves ECC · Curve25519 · ECDH · P-256
Point Arithmetic Elliptic Curves Group Law · Chord-and-Tangent · Scalar Mult · secp256k1
Dad Mode Morse Encrypted Morse AES-256-GCM · Argon2id · HKDF-SHA-256 · Ed25519
E91 Entanglement-Based QKD E91 · Entanglement · CHSH Bell Test · QKD
Envelope KMS Envelope Encryption RFC 3394 · AES Key Wrap · DEK/KEK · Key Rotation
Jevil Few-Time Signatures Jevil · Hash-Based · Goldilocks Field · Lagrange Interpolation
Format Ward Format-Preserving Encryption FF1 · FF3-1 · AES-256 · Tokenization
Ratchet Wire Forward-Secret Messaging Double Ratchet · X25519 · HKDF · AES-256-GCM
MLS Group Group Messaging Security MLS (RFC 9420) · TreeKEM · Epoch Key Schedule · Forward Secrecy
Collision Vault Hash Collisions MD5 · SHA-1 · SHAttered · Chosen-Prefix Collision
Hash Zoo Hash Construction SHA-256 · SHA3-256 · BLAKE3 · Merkle-Damgård
Babel Hash Hash Functions SHA-256 · SHA3-256 · BLAKE3 · HMAC
World Hashes Hash Functions SM3 · Streebog · Kupyna · SHA-256
LMS/XMSS Hash-Based Signatures LMS · LM-OTS · HSS · NIST SP 800-208
SPHINCS+ Ledger Hash-Based Signatures SLH-DSA · FIPS 205 · SPHINCS+ · SHA-256 · WOTS+
Bitcoin Wallet HD Wallet Mechanics secp256k1 · BIP-32 · BIP-39 · Bech32
Curve448 High-Security Curves X448 · Ed448 · RFC 7748 · RFC 8032
Dead Sea Cipher Historical Cipher Substitution · Vigenère · Atbash
Blind Oracle Homomorphic Encryption FHE · TFHE-rs · Rust · Encrypted Compute
CKKS Lab Homomorphic Encryption CKKS · RLWE · Approximate FHE · Encrypted Inference
FHE Arena Homomorphic Encryption BGV/BFV · RLWE · Noise Budget · SIMD Batching
HPKE Envelope Hybrid Encryption DHKEM X25519 · HKDF-SHA256 · AES-GCM · RFC 9180
Hybrid Wire Hybrid Key Exchange X25519 · ML-KEM-768 · HKDF-SHA256 · AES-256-GCM
Hybrid PQC Hybrid Key Exchange & Signatures X25519 · ML-KEM-768 · Ed25519 · ML-DSA-65
Hybrid Guide Hybrid PQC KEM Combiner · X25519 · ML-KEM-768 · X-Wing
IBE Gate Identity-Based Encryption Boneh-Franklin · BLS12-381 · Identity-Based Encryption · Key Escrow
Oblivious Shelf IT-PIR XOR PIR · Chor et al. 1995 · 2-Server PIR · Privacy Audit
KDF Arena KDF Benchmarks HKDF · PBKDF2 · scrypt · Argon2id
KEM Trap KEM Misuse ML-KEM-768 · FIPS 203 · FO Transform · Implicit Rejection
Salamander Key Commitment AES-GCM · GHASH · GF(2¹²⁸) · Message Franking
KDF Chain Key Derivation HKDF · PBKDF2 · scrypt · Argon2id
Key Exchange Key Exchange Overview Diffie-Hellman · ECDH · X25519 · ML-KEM
Key Mirror Key Transparency Merkle Tree · VRF · Ed25519 · KEYTRANS
Nonce Lattice Lattice Attack ECDSA · Hidden Number Problem · LLL Reduction · secp256k1
LWE Hints Lattice Cryptanalysis LWE · Sparse Ternary Secrets · Approximate Hints · Lattice
NTRU Classic Lattice Cryptography NTRU · Polynomial Rings · Lattice · EESS#1
Broken Trust Leakage Cryptanalysis ML-DSA · Bit Leakage · Hill-Climbing · Subkey Recovery
Patron Shield Library Privacy IT-PIR · XOR Secret Sharing · Chor et al. 1995
Ascon Lightweight Cryptography Ascon-AEAD128 · Ascon-Hash256 · Lightweight Crypto · IoT
Poly1305 MAC MAC Primitive Poly1305 · GF(2¹³⁰−5) · Key-Reuse Attack · Polynomial Stepper
SPDZ Forge Malicious-Secure MPC SPDZ · Beaver Triples · SPDZ MACs · Dishonest Majority
Merkle Proofs Merkle Inclusion Proofs SHA-256 · Merkle Proof · RFC 6962 · CVE-2012-2459
Merkle Vault Merkle Trees SHA-256 · Merkle Tree · Inclusion Proofs · Certificate Transparency
MAC Race Message Authentication HMAC · CMAC · Poly1305 · GHASH
Blind Relay Metadata Privacy OHTTP · HPKE · Binary HTTP · RFC 9458
PQ Rotation Migration Operations Hybrid X.509 · CNSA 2.0 · Key Rotation · Migration Planner
Harvest Timeline Migration Planning Mosca Inequality · CRQC Scenarios · Cost of Delay · PQC Migration
Dilithium Reject ML-DSA Internals ML-DSA · Rejection Sampling · FIPS 204 · Timing Tradeoffs
Syndrome Drain Multi-Instance Degradation DOOM · BIKE · HQC · Classic McEliece
Multivariate UOV Multivariate Signatures UOV · GF(256) · MQ Problem · Beullens Attack
Noise Pipe Noise Protocol Framework X25519 · HKDF · WireGuard · Handshake Patterns
Nonce Guard Nonce Misuse Resistance AES-GCM · AES-GCM-SIV · RFC 8452 · Synthetic IV
Nonce Collision Nonce Reuse AES-GCM · ChaCha20-Poly1305 · Forbidden Attack · Crib Dragging
OT Gate Oblivious Transfer Simplest OT · Chou-Orlandi 2015 · Edwards25519 · AES-256-GCM
Pairing Gate Pairing Cryptography BLS12-381 · BLS Signatures · Signature Aggregation · Rogue Key Attack
PAKE Gate PAKE Family SRP-6a · J-PAKE · CPace · Dragonfly
WebAuthn Passkeys & Authentication WebAuthn · FIDO2 · Passkeys · Assertion
Bcrypt Forge Password Hashing bcrypt · Blowfish · Cost Factor · Timing-Safe
OPAQUE Gate Password-Authenticated Key Exchange OPAQUE · OPRF · 3DH · HKDF
SPAKE Gate Password-Authenticated KX SPAKE2 · SPAKE2+ · P-256 · PAKE
OTP Vault Perfect Secrecy One-Time Pad · Perfect Secrecy · Two-Time Pad · Crib Dragging
Chain of Trust PKI & Certificates X.509 · RFC 5280 · ECDSA P-256 · nameConstraints
PKI Chain PKI & Certificates X.509 · Certificate Transparency · CA Compromise · ML-DSA
Vigenère Break Polyalphabetic Cipher Vigenère · Kasiski Examination · Index of Coincidence · Frequency Analysis
Quantum Vault KpqC Post-Quantum AES-256-GCM · Shamir SSS · SMAUG-T · HAETAE
Grover Post-Quantum Cryptanalysis Grover's Algorithm · Amplitude Amplification · Phase Kickback · AES Key Search
LLL Break Post-Quantum Cryptanalysis LLL · BKZ · Gram-Schmidt · Toy LWE
Shor Post-Quantum Cryptanalysis Shor's Algorithm · Period Finding · QFT · RSA Factorization
Isogeny Gate Post-Quantum Isogeny SIDH · CSIDH · SQIsign · Castryck-Decru
Frodo Vault Post-Quantum KEM FrodoKEM · LWE · Lattice · Post-Quantum
Kyber Vault Post-Quantum KEM ML-KEM · FIPS 203 · CRYSTALS-Kyber · Lattice · AES-256-GCM
McEliece Gate Post-Quantum KEM Classic McEliece · Goppa Codes · Post-Quantum
Scloud+ Vault Post-Quantum KEM Scloud+ · LWE KEM · BW32 Coding · Ternary Secrets
PQ Families Post-Quantum Overview Lattice · Code-Based · Hash-Based · Multivariate · Isogeny
Ciphertext Mirror Post-Quantum Side-Channel ML-KEM · FO Transform · LDPC Decoder · NTT Blinding
HQC Timing Post-Quantum Side-Channel HQC · BCH Decoder · Timing Oracle · Constant-Time
HQC Timing Break Post-Quantum Side-Channel HQC · Cache Timing · Reed-Muller · Soft-ISD
KyberSlash Post-Quantum Side-Channel ML-KEM · KyberSlash · Timing Attack · Barrett Reduction
Lattice Fault Post-Quantum Side-Channel ML-KEM · ML-DSA · KyberSlash · Fault Injection
Dilithium Seal Post-Quantum Signatures ML-DSA · FIPS 204 · CRYSTALS-Dilithium · Lattice
Falcon Seal Post-Quantum Signatures Falcon · FN-DSA · NTRU · FFT Sampling · Post-Quantum
HAWK Post-Quantum Signatures HAWK · Lattice Signatures · Gaussian Sampling · NIST Round 2
MPCitH Sign Post-Quantum Signatures MPC-in-the-Head · Fiat-Shamir · SHA-256 Commitments · Merkle Proofs
PQ TLS Handshake Post-Quantum TLS TLS 1.3 · X25519MLKEM768 · Key Schedule · Hybrid PQC
Power Trace Power Side-Channel CPA · DPA · AES-128 · Hamming Weight
PSI Gate Private Set Intersection DH-PSI · ristretto255 · Hash-to-Curve · Contact Discovery
Reshare Circle Proactive Secret Sharing Shamir · Feldman VSS · HJKY 1995 · Mobile Adversary
Frozen Heart Proof Forgery Fiat-Shamir · Schnorr · ristretto255 · NIZK
Protocol Compose Protocol Composition MAC-then-Encrypt · Encrypt-then-MAC · CRIME · TLS 1.3
Educational RSA Public-Key Cryptography RSA · Key Generation · Modular Exponentiation · OAEP
RSA Forge Public-Key Cryptography RSA · OAEP · PSS · PKCS#1
ElGamal Plain Public-Key Encryption ElGamal · RFC 3526 Group 14 · Homomorphism · Re-randomization
BB84 Quantum Key Distribution Photon Polarization · Basis Sifting · QBER · Privacy Amplification
Quantum Entropy Quantum RNG QRNG · Min-Entropy · Toeplitz Extractor · SP 800-90B
Harvest Vault Quantum Threat HNDL · Mosca's Theorem · Q-Day Timeline · PQC Migration
Entropy Collapse Randomness Failures HMAC_DRBG · Seed Provenance · VM Cloning · Nonce Reuse
Ring Sign Ring Signatures LSAG · Key Image · Group Signatures · Monero
Enigma Forge Rotor Machine Enigma · Rotors · Plugboard · Bombe
Time-Lock Puzzle RSW Time-Lock RSW · Sequential Squaring · AES-256-GCM · Trapdoor
Shamir Gate Secret Sharing Shamir SSS · Lagrange Interpolation · GF(p)
Garbled Gate Secure MPC Garbled Circuits · Oblivious Transfer · Free XOR · Two-Party MPC
Silent Tally Secure MPC Shamir SSS · GF(2⁶¹−1) · Lagrange Interpolation · Additive Homomorphism
SSH Handshake Secure Shell Handshake X25519 · Ed25519 · TOFU · known_hosts
Signed Bytes Signature Canonicalization Ed25519 · JCS RFC 8785 · Parser Differential · Unicode NFC
LMS Ledger Stateful Hash-Based Signatures LMS · HSS · W-OTS+ · NIST SP 800-208
Phantom Vault Stateless Passwords PBKDF2-SHA-256 · HMAC-DRBG · Rejection Sampling
J-UNIWARD Steganography J-UNIWARD · DCT · Wavelet Distortion · Adaptive Embedding
Stego Suite Steganography LSB · DCT · Adaptive Embedding · Chi-Squared Steganalysis
ChaCha20 Stream Stream Cipher ChaCha20 · ARX · Nonce Reuse · Keystream
Snow 2 Stream Cipher XChaCha20-Poly1305 · Argon2id · HKDF-SHA-256 · Steganography
Isogeny Atlas Supersingular Isogeny Graph Isogeny Graphs · Modular Polynomials · Endomorphism Rings · CGL Hash
Protocol Checker Symbolic Analysis Dolev-Yao · Symbolic Model · Needham-Schroeder · Unification
Shamir vs FROST Threshold Crypto Compared Shamir SSS · FROST · Ed25519 · GF(256)
Threshold Decrypt Threshold Decryption ElGamal · P-256 · NIZK Proofs · t-of-n
GG20 Wallet Threshold ECDSA GG20 · Paillier · secp256k1 · Distributed Key Generation
FROST Threshold Threshold Signatures FROST (RFC 9591) · Ed25519 · Nonce Commitments · VSS Commitments
Threshold ML-DSA Threshold Signatures Threshold ML-DSA · Distributed Signing · Two-Party · Post-Quantum
Timing Oracle Timing Side-Channel Timing Attack · HMAC · RSA · Cache-Timing
Timing Side-Channel Timing Side-Channel Timing Attack · Constant-Time · Side-Channel · Secret Compare
TLS Handshake TLS 1.3 Walkthrough TLS 1.3 · X25519 · Ed25519 · AES-GCM
Blind Hello TLS Privacy TLS 1.3 · ECH · HPKE · SNI
JWT Forge Token Forgery JWT · JWS · alg:none · HS/RS Key Confusion
VDF Verifiable Delay Function VDF · Wesolowski · Modular Squaring · Randomness Beacon
VRF Gate Verifiable Randomness ECVRF P-256 · Wesolowski VDF · RANDAO · RFC 9381
VSS Gate Verifiable Secret Sharing Feldman VSS · Pedersen VSS · Commitment Verification · Cheating Detection
SNARK Arena Zero-Knowledge Proofs Groth16 · PLONK · Trusted Setup · zk-SNARK
STARK Tower Zero-Knowledge Proofs zk-STARK · AIR Constraints · FRI · Post-Quantum
ZK Arena Zero-Knowledge Proofs zk-SNARK · zk-STARK · Proof Systems · Comparison
ZK Proof Lab Zero-Knowledge Proofs Schnorr · SHA-256 Commitments · Fiat-Shamir · zk-SNARK
Bulletproofs Zero-Knowledge Range Proofs Bulletproofs · ristretto255 · Range Proofs · Inner-Product Argument

Related Projects

These sit outside the browser-demo scope of Crypto Lab but belong to the same collection:

  • Crypto Compare — Algorithm reference covering NIST and PQ-Safe standards.
  • Cipher Museum — An interactive museum spanning 3,900 years of cryptographic history. Thirteen halls, 140 exhibits, live encryption demos, and cryptanalysis labs.
  • Meow Decoder — Secure optical air-gap file transfer via QR-code GIFs. AES-256-GCM + Argon2id + ML-KEM-1024 + fountain codes. Python + Rust.

About

Each demo is self-contained: one concept, one repository, full source. Documentation and threat models are included where the attack surface warrants it.

Built by Paul Clark — IT Librarian & Systems Analyst.


So whether you eat or drink or whatever you do, do it all for the glory of God. — 1 Corinthians 10:31

Releases

Packages

Contributors

Languages