{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T16:52:35Z","timestamp":1779900755116,"version":"3.53.1"},"publisher-location":"Cham","reference-count":56,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031385476","type":"print"},{"value":"9783031385483","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-38548-3_1","type":"book-chapter","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T19:02:27Z","timestamp":1691521347000},"page":"3-36","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["Fast Practical Lattice Reduction Through Iterated Compression"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5846-2046","authenticated-orcid":false,"given":"Keegan","family":"Ryan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7904-7295","authenticated-orcid":false,"given":"Nadia","family":"Heninger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"key":"1_CR1","unstructured":"Albrecht, M., Ducas, L.: Lattice attacks on NTRU and LWE: a history of refinements. Cryptology ePrint Archive, Report 2021\/799 (2021). https:\/\/eprint.iacr.org\/2021\/799"},{"key":"1_CR2","doi-asserted-by":"publisher","unstructured":"Backendal, M., Haller, M., Paterson, K.G.: MEGA: malleable encryption goes awry. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 450\u2013467, May 2023. https:\/\/doi.org\/10.1109\/SP46215.2023.00026","DOI":"10.1109\/SP46215.2023.00026"},{"key":"1_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-642-42045-0_18","volume-title":"Advances in Cryptology - ASIACRYPT 2013","author":"DJ Bernstein","year":"2013","unstructured":"Bernstein, D.J., et al.: Factoring RSA keys from certified smart cards: coppersmith in the wild. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013. LNCS, vol. 8270, pp. 341\u2013360. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-42045-0_18"},{"key":"1_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-642-54631-0_11","volume-title":"Public-Key Cryptography \u2013 PKC 2014","author":"J Bi","year":"2014","unstructured":"Bi, J., Coron, J.-S., Faug\u00e8re, J.-C., Nguyen, P.Q., Renault, G., Zeitoun, R.: Rounding and chaining LLL: finding faster small roots of univariate polynomial congruences. In: Krawczyk, H. (ed.) PKC 2014. LNCS, vol. 8383, pp. 185\u2013202. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-642-54631-0_11"},{"key":"1_CR5","doi-asserted-by":"publisher","unstructured":"Biasse, J.F., Song, F.: Efficient quantum algorithms for computing class groups and solving the principal ideal problem in arbitrary degree number fields. In: Krauthgamer, R. (ed.) 27th SODA, pp. 893\u2013902. ACM-SIAM, January 2016. https:\/\/doi.org\/10.1137\/1.9781611974331.ch64","DOI":"10.1137\/1.9781611974331.ch64"},{"issue":"4","key":"1_CR6","doi-asserted-by":"publisher","first-page":"407","DOI":"10.3934\/amc.2014.8.407","volume":"8","author":"JF Biasse","year":"2014","unstructured":"Biasse, J.F.: Subexponential time relations in the class group of large degree number fields. Adv. Math. Commun. 8(4), 407\u2013425 (2014). https:\/\/doi.org\/10.3934\/amc.2014.8.407","journal-title":"Adv. Math. Commun."},{"key":"1_CR7","doi-asserted-by":"publisher","unstructured":"Biasse, J.F., Fieker, C.: Subexponential class group and unit group computation in large degree number fields. LMS J. Comput. Math. 17(A), 385\u2013403 (2014). https:\/\/doi.org\/10.1112\/S1461157014000345","DOI":"10.1112\/S1461157014000345"},{"key":"1_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/3-540-45682-1_3","volume-title":"Advances in Cryptology \u2014 ASIACRYPT 2001","author":"D Boneh","year":"2001","unstructured":"Boneh, D., Halevi, S., Howgrave-Graham, N.: The modular inversion hidden number problem. In: Boyd, C. (ed.) ASIACRYPT 2001. LNCS, vol. 2248, pp. 36\u201351. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45682-1_3"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Chang, X.W., Stehl\u00e9, D., Villard, G.: Perturbation analysis of the QR factor R in the context of LLL lattice basis reduction. Math. Comput. 81(279), 1487\u20131511 (2012). https:\/\/hal-ens-lyon.archives-ouvertes.fr\/ensl-00529425","DOI":"10.1090\/S0025-5718-2012-02545-2"},{"key":"1_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-25385-0_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2011","author":"Y Chen","year":"2011","unstructured":"Chen, Y., Nguyen, P.Q.: BKZ 2.0: better lattice security estimates. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 1\u201320. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25385-0_1"},{"key":"1_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/978-3-642-38348-9_20","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2013","author":"JH Cheon","year":"2013","unstructured":"Cheon, J.H., et al.: Batch fully homomorphic encryption over the integers. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 315\u2013335. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_20"},{"key":"1_CR12","doi-asserted-by":"publisher","unstructured":"Cohn, H., Heninger, N.: Approximate common divisors via lattices. ANTS X p. 271 (2012). https:\/\/doi.org\/10.2140\/obs.2013.1.271","DOI":"10.2140\/obs.2013.1.271"},{"issue":"4","key":"1_CR13","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/s001459900030","volume":"10","author":"D Coppersmith","year":"1997","unstructured":"Coppersmith, D.: Small solutions to polynomial equations, and low exponent RSA vulnerabilities. J. Cryptol. 10(4), 233\u2013260 (1997). https:\/\/doi.org\/10.1007\/s001459900030","journal-title":"J. Cryptol."},{"key":"1_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/3-540-44670-2_3","volume-title":"Cryptography and Lattices","author":"D Coppersmith","year":"2001","unstructured":"Coppersmith, D.: Finding small solutions to small degree polynomials. In: Silverman, J.H. (ed.) CaLC 2001. LNCS, vol. 2146, pp. 20\u201331. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44670-2_3"},{"key":"1_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1007\/3-540-69053-0_5","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201997","author":"D Coppersmith","year":"1997","unstructured":"Coppersmith, D., Shamir, A.: Lattice attacks on NTRU. In: Fumy, W. (ed.) EUROCRYPT 1997. LNCS, vol. 1233, pp. 52\u201361. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/3-540-69053-0_5"},{"key":"1_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"476","DOI":"10.1007\/978-3-642-40041-4_26","volume-title":"Advances in Cryptology \u2013 CRYPTO 2013","author":"J-S Coron","year":"2013","unstructured":"Coron, J.-S., Lepoint, T., Tibouchi, M.: Practical multilinear maps over the integers. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013. LNCS, vol. 8042, pp. 476\u2013493. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40041-4_26"},{"key":"1_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/978-3-642-54631-0_18","volume-title":"Public-Key Cryptography \u2013 PKC 2014","author":"J-S Coron","year":"2014","unstructured":"Coron, J.-S., Lepoint, T., Tibouchi, M.: Scale-invariant fully homomorphic encryption over the integers. In: Krawczyk, H. (ed.) PKC 2014. LNCS, vol. 8383, pp. 311\u2013328. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-642-54631-0_18"},{"key":"1_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/978-3-642-22792-9_28","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"J-S Coron","year":"2011","unstructured":"Coron, J.-S., Mandal, A., Naccache, D., Tibouchi, M.: Fully homomorphic encryption over the integers with shorter public keys. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 487\u2013504. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22792-9_28"},{"key":"1_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"446","DOI":"10.1007\/978-3-642-29011-4_27","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2012","author":"J-S Coron","year":"2012","unstructured":"Coron, J.-S., Naccache, D., Tibouchi, M.: Public key compression and modulus switching for fully homomorphic encryption over the integers. In: Pointcheval, D., Johansson, T. (eds.) EUROCRYPT 2012. LNCS, vol. 7237, pp. 446\u2013464. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-29011-4_27"},{"key":"1_CR20","unstructured":"Ducas, L., van Woerden, W.: A note on a claim of Eldar & Hallgren: LLL already solves it. Cryptology ePrint Archive, Report 2021\/1391 (2021). https:\/\/eprint.iacr.org\/2021\/1391"},{"key":"1_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-92068-5_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"L Ducas","year":"2021","unstructured":"Ducas, L., van Woerden, W.: NTRU fatigue: how stretched is overstretched? In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 3\u201332. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_1"},{"key":"1_CR22","doi-asserted-by":"publisher","unstructured":"Galbraith, S.D., Gebregiyorgis, S.W., Murphy, S.: Algorithms for the approximate common divisor problem. LMS J. Comput. Math. 19(A), 58\u201372 (2016). https:\/\/doi.org\/10.1112\/S1461157016000218","DOI":"10.1112\/S1461157016000218"},{"key":"1_CR23","doi-asserted-by":"publisher","unstructured":"Gentry, C.: Fully homomorphic encryption using ideal lattices. In: Mitzenmacher, M. (ed.) 41st ACM STOC, pp. 169\u2013178. ACM Press (2009). https:\/\/doi.org\/10.1145\/1536414.1536440","DOI":"10.1145\/1536414.1536440"},{"key":"1_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-642-20465-4_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2011","author":"C Gentry","year":"2011","unstructured":"Gentry, C., Halevi, S.: Implementing Gentry\u2019s fully-homomorphic encryption scheme. In: Paterson, K.G. (ed.) EUROCRYPT 2011. LNCS, vol. 6632, pp. 129\u2013148. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-20465-4_9"},{"key":"1_CR25","doi-asserted-by":"publisher","unstructured":"Goldstein, D., Mayer, A.: On the equidistribution of Hecke points 15(2), 165\u2013189 (2003). https:\/\/doi.org\/10.1515\/form.2003.009","DOI":"10.1515\/form.2003.009"},{"key":"1_CR26","doi-asserted-by":"crossref","unstructured":"Higham, N.J.: Accuracy and Stability of Numerical Algorithms, 2nd edn. Society for Industrial and Applied Mathematics, Philadelphia, PA, USA (2002)","DOI":"10.1137\/1.9780898718027"},{"key":"1_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/BFb0024458","volume-title":"Crytography and Coding","author":"N Howgrave-Graham","year":"1997","unstructured":"Howgrave-Graham, N.: Finding small roots of univariate modular equations revisited. In: Darnell, M. (ed.) Cryptography and Coding 1997. LNCS, vol. 1355, pp. 131\u2013142. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0024458"},{"key":"1_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/3-540-44670-2_6","volume-title":"Cryptography and Lattices","author":"N Howgrave-Graham","year":"2001","unstructured":"Howgrave-Graham, N.: Approximate integer common divisors. In: Silverman, J.H. (ed.) CaLC 2001. LNCS, vol. 2146, pp. 51\u201366. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44670-2_6"},{"key":"1_CR29","unstructured":"Kirchner, P., Espitau, T., Fouque, P.A.: Algebraic and Euclidean lattices: optimal lattice reduction and beyond. Cryptology ePrint Archive, Report 2019\/1436 (2019). https:\/\/eprint.iacr.org\/2019\/1436"},{"key":"1_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-030-56880-1_6","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"P Kirchner","year":"2020","unstructured":"Kirchner, P., Espitau, T., Fouque, P.-A.: Fast reduction of algebraic lattices over cyclotomic fields. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12171, pp. 155\u2013185. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_6"},{"key":"1_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"760","DOI":"10.1007\/978-3-030-84245-1_26","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"P Kirchner","year":"2021","unstructured":"Kirchner, P., Espitau, T., Fouque, P.-A.: Towards faster polynomial-time lattice reduction. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12826, pp. 760\u2013790. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84245-1_26"},{"key":"1_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-56620-7_1","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"P Kirchner","year":"2017","unstructured":"Kirchner, P., Fouque, P.-A.: Revisiting lattice attacks on overstretched NTRU parameters. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10210, pp. 3\u201326. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56620-7_1"},{"key":"1_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/3-540-44670-2_7","volume-title":"Cryptography and Lattices","author":"H Koy","year":"2001","unstructured":"Koy, H., Schnorr, C.P.: Segment LLL-reduction of lattice bases. In: Silverman, J.H. (ed.) CaLC 2001. LNCS, vol. 2146, pp. 67\u201380. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44670-2_7"},{"key":"1_CR34","doi-asserted-by":"publisher","unstructured":"Lagarias, J.C., Odlyzko, A.M.: Solving low-density subset sum problems. In: 24th FOCS, pp. 1\u201310. IEEE Computer Society Press (1983). https:\/\/doi.org\/10.1109\/SFCS.1983.70","DOI":"10.1109\/SFCS.1983.70"},{"key":"1_CR35","unstructured":"Lee, M.S.: On the sparse subset sum problem from gentry-Halevi\u2019s implementation of fully homomorphic encryption. Cryptology ePrint Archive, Report 2011\/567 (2011). https:\/\/eprint.iacr.org\/2011\/567"},{"issue":"4","key":"1_CR36","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"AK Lenstra","year":"1982","unstructured":"Lenstra, A.K., Lenstra, H.W., Lov\u00e1sz, L.: Factoring polynomials with rational coefficients. Math. Ann. 261(4), 515\u2013534 (1982). https:\/\/doi.org\/10.1007\/BF01457454","journal-title":"Math. Ann."},{"key":"1_CR37","doi-asserted-by":"publisher","unstructured":"May, A.: Using LLL-reduction for solving RSA and factorization problems. In: Nguyen, P., Vall\u00e9e, B. (eds.) ISC, pp. 315\u2013348. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-02295-10","DOI":"10.1007\/978-3-642-02295-10"},{"key":"1_CR38","doi-asserted-by":"publisher","unstructured":"Micciancio, D., Regev, O.: Lattice-based cryptography. In: Bernstein, D.J., Buchmann, J., Dahmen, E. (eds.) Post-Quantum Cryptography, pp. 147\u2013191. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-540-88702-7_5","DOI":"10.1007\/978-3-540-88702-7_5"},{"key":"1_CR39","doi-asserted-by":"publisher","unstructured":"Morel, I., Stehl\u00e9, D., Villard, G.: H-LLL: using householder inside LLL. In: Proceedings of the 2009 International Symposium on Symbolic and Algebraic Computation, ISSAC 2009, pp. 271\u2013278. Association for Computing Machinery, New York (2009). https:\/\/doi.org\/10.1145\/1576702.1576740","DOI":"10.1145\/1576702.1576740"},{"key":"1_CR40","doi-asserted-by":"publisher","unstructured":"Nemec, M., S\u00fds, M., Svenda, P., Klinec, D., Matyas, V.: The return of coppersmith\u2019s attack: practical factorization of widely used RSA moduli. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017, pp. 1631\u20131648. ACM Press (2017). https:\/\/doi.org\/10.1145\/3133956.3133969","DOI":"10.1145\/3133956.3133969"},{"key":"1_CR41","doi-asserted-by":"publisher","unstructured":"Neumaier, A., Stehl\u00e9, D.: Faster LLL-type reduction of lattice bases. In: Proceedings of the ACM on International Symposium on Symbolic and Algebraic Computation, ISSAC 2016, pp. 373\u2013380. Association for Computing Machinery, New York (2016). https:\/\/doi.org\/10.1145\/2930889.2930917","DOI":"10.1145\/2930889.2930917"},{"key":"1_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/3-540-45537-X_24","volume-title":"Selected Areas in Cryptography","author":"PQ Nguyen","year":"2001","unstructured":"Nguyen, P.Q.: The two faces of lattices in cryptology. In: Vaudenay, S., Youssef, A.M. (eds.) SAC 2001. LNCS, vol. 2259, p. 313. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45537-X_24"},{"key":"1_CR43","doi-asserted-by":"publisher","unstructured":"Nguyen, P.Q.: Hermite\u2019s constant and lattice algorithms. In: Nguyen, P., Vall\u00e9e, B. (eds.) The LLL Algorithm. Information Security and Cryptography, ISC, pp. 19\u201369. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-02295-1","DOI":"10.1007\/978-3-642-02295-1"},{"key":"1_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1007\/11792086_18","volume-title":"Algorithmic Number Theory","author":"PQ Nguyen","year":"2006","unstructured":"Nguyen, P.Q., Stehl\u00e9, D.: LLL on the average. In: Hess, F., Pauli, S., Pohst, M. (eds.) ANTS 2006. LNCS, vol. 4076, pp. 238\u2013256. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11792086_18"},{"key":"1_CR45","doi-asserted-by":"publisher","unstructured":"Nguyen, P.Q., Stehl\u00e9, D.: An LLL algorithm with quadratic complexity. SIAM J. Comput. 39(3), 874\u2013903 (2009). https:\/\/doi.org\/10.1137\/070705702","DOI":"10.1137\/070705702"},{"key":"1_CR46","doi-asserted-by":"publisher","unstructured":"Novocin, A., Stehl\u00e9, D., Villard, G.: An LLL-reduction algorithm with quasi-linear time complexity: extended abstract. In: Proceedings of the Forty-Third Annual ACM Symposium on Theory of Computing, STOC 2011, pp. 403\u2013412. Association for Computing Machinery, New York (2011). https:\/\/doi.org\/10.1145\/1993636.1993691","DOI":"10.1145\/1993636.1993691"},{"key":"1_CR47","doi-asserted-by":"publisher","unstructured":"Pataki, G., Tural, M.: On sublattice determinants in reduced bases (2008). https:\/\/doi.org\/10.48550\/ARXIV.0804.4014","DOI":"10.48550\/ARXIV.0804.4014"},{"issue":"2","key":"1_CR48","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/s10623-014-9957-1","volume":"76","author":"T Plantard","year":"2014","unstructured":"Plantard, T., Susilo, W., Zhang, Z.: LLL for ideal lattices: re-evaluation of the security of Gentry\u2013Halevi\u2019s FHE scheme. Des. Codes Crypt. 76(2), 325\u2013344 (2014). https:\/\/doi.org\/10.1007\/s10623-014-9957-1","journal-title":"Des. Codes Crypt."},{"key":"1_CR49","unstructured":"Ryan, K., Heninger, N.: Fast practical lattice reduction through iterated compression. Cryptology ePrint Archive, Report 2023\/237 (2023). https:\/\/eprint.iacr.org\/2023\/237"},{"key":"1_CR50","doi-asserted-by":"publisher","unstructured":"Saruchi, Morel, I., Stehl\u00e9, D., Villard, G.: LLL reducing with the most significant bits. In: Proceedings of the 39th International Symposium on Symbolic and Algebraic Computation, ISSAC 2014, pp. 367\u2013374. Association for Computing Machinery, New York (2014). https:\/\/doi.org\/10.1145\/2608628.2608645","DOI":"10.1145\/2608628.2608645"},{"key":"1_CR51","doi-asserted-by":"publisher","unstructured":"Schnorr, C.P., Euchner, M.: Lattice basis reduction: improved practical algorithms and solving subset sum problems. Math. Programm. 66(1), 181\u2013199 (1994). https:\/\/doi.org\/10.1007\/BF01581144","DOI":"10.1007\/BF01581144"},{"key":"1_CR52","doi-asserted-by":"publisher","unstructured":"Sch\u00f6nhage, A.: Fast reduction and composition of binary quadratic forms. In: Proceedings of the 1991 International Symposium on Symbolic and Algebraic Computation, ISSAC 1991. Association for Computing Machinery, New York (1991). https:\/\/doi.org\/10.1145\/120694.120711","DOI":"10.1145\/120694.120711"},{"key":"1_CR53","doi-asserted-by":"crossref","unstructured":"Stewart, G.W., Sun, J.G.: Matrix perturbation theory (1990)","DOI":"10.1137\/1032121"},{"key":"1_CR54","unstructured":"The FPLLL development team: FPLLL, a lattice reduction library, Version: 5.4.2 (2022). https:\/\/github.com\/fplll\/fplll"},{"key":"1_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1007\/978-3-642-13190-5_2","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2010","author":"M van Dijk","year":"2010","unstructured":"van Dijk, M., Gentry, C., Halevi, S., Vaikuntanathan, V.: Fully homomorphic encryption over the integers. In: Gilbert, H. (ed.) EUROCRYPT 2010. LNCS, vol. 6110, pp. 24\u201343. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13190-5_2"},{"issue":"2","key":"1_CR56","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/s10623-019-00685-y","volume":"88","author":"J Xu","year":"2019","unstructured":"Xu, J., Hu, L., Sarkar, S.: Cryptanalysis of elliptic curve hidden number problem from PKC 2017. Des. Codes Crypt. 88(2), 341\u2013361 (2019). https:\/\/doi.org\/10.1007\/s10623-019-00685-y","journal-title":"Des. Codes Crypt."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-38548-3_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T22:02:18Z","timestamp":1753567338000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-38548-3_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031385476","9783031385483"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-38548-3_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"9 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 August 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"43","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"479","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"124","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}