{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T04:20:31Z","timestamp":1778127631388,"version":"3.51.4"},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540741428","type":"print"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-74143-5_9","type":"book-chapter","created":{"date-parts":[[2007,8,9]],"date-time":"2007-08-09T13:51:33Z","timestamp":1186667493000},"page":"150-169","source":"Crossref","is-referenced-by-count":119,"title":["A Hybrid Lattice-Reduction and Meet-in-the-Middle Attack Against NTRU"],"prefix":"10.1007","author":[{"given":"Nick","family":"Howgrave-Graham","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"9_CR1","first-page":"284","volume-title":"Proc. of 29th STOC","author":"M. Ajtai","year":"1997","unstructured":"Ajtai, M., Kumar, R., Sivakumar, D.: A sieve algorithm for the shortest lattice vector problem. In: Proc. of 29th STOC, pp. 284\u2013293. ACM Press, New York (1997)"},{"key":"9_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/BF02579403","volume":"6","author":"L. Babai","year":"1986","unstructured":"Babai, L.: On Lov\u00e1sz lattice reduction and the nearest lattice point problem. Combinatorica\u00a06, 1\u201313 (1986)","journal-title":"Combinatorica"},{"key":"9_CR3","unstructured":"Cassels, J.W.S.: An introduction to the geometry of numbers, Springer-Verlag, Reprint of the 1st ed. Berlin Heidelberg New York, Corr. 2nd printing 1971, 1997, VIII (1959)"},{"key":"9_CR4","doi-asserted-by":"crossref","unstructured":"Conway, J.H., Sloane, N.J.A.: Sphere Packings, Lattices and Groups. Grundlehren der mathematischen Wissenschaften, 290 (1993)","DOI":"10.1007\/978-1-4757-2249-9"},{"key":"9_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1007\/3-540-69053-0_5","volume-title":"Advances in Cryptology - EUROCRYPT \u201997","author":"D. Coppersmith","year":"1997","unstructured":"Coppersmith, D., Shamir, A.: Lattice Attacks on NTRU. In: Fumy, W. (ed.) EUROCRYPT 1997. LNCS, vol.\u00a01233, pp. 52\u201361. Springer, Heidelberg (1997)"},{"key":"9_CR6","doi-asserted-by":"publisher","first-page":"463","DOI":"10.2307\/2007966","volume":"44","author":"U. Fincke","year":"1985","unstructured":"Fincke, U., Pohst, M.: Improved methods for calculating vectors of short length in a lattice, including a complexity analysis. Math. Comp.\u00a044, 463\u2013471 (1985)","journal-title":"Math. Comp."},{"key":"9_CR7","doi-asserted-by":"crossref","unstructured":"Furst, M.L., Kannan, R.: Succinct certificates for almost all subset sum problems. SIAM Journal on Computing, pp. 550\u2013558 (1989)","DOI":"10.1137\/0218037"},{"key":"9_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/11818175_7","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"N. Gama","year":"2006","unstructured":"Gama, N., Howgrave-Graham, N., Nguyen, P.Q.: Rankin\u2019s Constant and Blockwise Lattice Reduction. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol.\u00a04117, pp. 112\u2013130. Springer, Heidelberg (2006)"},{"key":"9_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/11761679_15","volume-title":"Advances in Cryptology - EUROCRYPT 2006","author":"N. Gama","year":"2006","unstructured":"Gama, N., Howgrave-Graham, N., Nguyen, P.Q.: Symplectic Lattice Reduction and NTRU. In: Vaudenay, S. (ed.) EUROCRYPT 2006. LNCS, vol.\u00a04004, pp. 233\u2013253. Springer, Heidelberg (2006)"},{"key":"9_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/BFb0054868","volume-title":"Algorithmic Number Theory","author":"J. Hoffstein","year":"1998","unstructured":"Hoffstein, J., Pipher, J., Silverman, J.H.: NTRU: A Ring-Based Public Key Cryptosystem. In: Buhler, J.P. (ed.) Algorithmic Number Theory. LNCS, vol.\u00a01423, pp. 267\u2013288. Springer, Heidelberg (1998)"},{"key":"9_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1007\/978-3-540-45146-4_14","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"N. Howgrave-Graham","year":"2003","unstructured":"Howgrave-Graham, N., Nguyen, P.Q., Pointcheval, D., Proos, J., Silverman, J.H., Singer, A., Whyte, W.: The Impact of Decryption Failures on the Security of NTRU Encryption. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol.\u00a02729, pp. 226\u2013246. Springer, Heidelberg (2003)"},{"key":"9_CR12","unstructured":"Howgrave-Graham, N.: Computational Mathematics Inspired by RSA, PhD. Thesis, University of Bath (1998)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Howgrave-Graham, N.: Finding Small Roots of Univariate Modular Equations Revisited. In: IMA Int. Conf. pp. 131\u2013142 (1997)","DOI":"10.1007\/BFb0024458"},{"key":"9_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"118","DOI":"10.1007\/978-3-540-30574-3_10","volume-title":"Topics in Cryptology \u2013 CT-RSA 2005","author":"N. Howgrave-Graham","year":"2005","unstructured":"Howgrave-Graham, N., Silverman, J.H., Whyte, W.: Choosing Parameter Sets for NTRUEncrypt with NAEP and SVES-3. In: Menezes, A.J. (ed.) CT-RSA 2005. LNCS, vol.\u00a03376, pp. 118\u2013135. Springer, Heidelberg (2005), http:\/\/www.ntru.com\/cryptolab\/articles.htm"},{"key":"9_CR15","unstructured":"Howgrave-Graham, N., Silverman, J.H., Whyte, W.: A Meet-In-The-Middle Attack on an NTRU Private Key, http:\/\/www.ntru.com\/cryptolab\/tech_notes.htm"},{"key":"9_CR16","unstructured":"Whyte, W. (ed.): IEEE P1363, 1\/D9 Draft Standard for Public-Key Cryptographic Techniques Based on Hard Problems over Lattices"},{"key":"9_CR17","first-page":"99","volume-title":"STOC 1983","author":"R. Kannan","year":"1983","unstructured":"Kannan, R.: Improved algorithms for integer programming and related lattice problems. In: STOC 1983. Proc. of the 15th Symposium on the Theory of Computing, pp. 99\u2013108. ACM Press, New York (1983)"},{"key":"9_CR18","first-page":"937","volume-title":"Proceedings, ACM-SIAM Symposium on Discrete Algorithms","author":"N. Philip","year":"2000","unstructured":"Philip, N.: Finding the closest lattice vector when it\u2019s unusually close. In: Proceedings, ACM-SIAM Symposium on Discrete Algorithms, pp. 937\u2013941. ACM, New York (2000)"},{"issue":"4","key":"9_CR19","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1007\/s00145-001-0009-4","volume":"14","author":"A. Lenstra","year":"2001","unstructured":"Lenstra, A., Verheul, E.: Selecting Cryptographic Key Sizes. Journal of Cryptology\u00a014(4), 255\u2013293 (2001)","journal-title":"Journal of Cryptology"},{"key":"9_CR20","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1145\/1089242.1089247","volume":"15","author":"M. Pohst","year":"1981","unstructured":"Pohst, M.: On the computation of lattice vectors of minimal length, successive minima and reduced bases with applications. ACM SIGSAM Bull.\u00a015, 37\u201344 (1981)","journal-title":"ACM SIGSAM Bull."},{"key":"9_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1007\/3-540-36494-3_14","volume-title":"STACS 2003","author":"C.P. Schnorr","year":"2003","unstructured":"Schnorr, C.P.: Lattice Reduction by Random Sampling and Birthday Methods. In: Alt, H., Habib, M. (eds.) STACS 2003. LNCS, vol.\u00a02607, pp. 145\u2013156. Springer, Heidelberg (2003)"},{"key":"9_CR22","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/BF01581144","volume":"66","author":"C.P. Schnorr","year":"1994","unstructured":"Schnorr, C.P., Euchner, M.: Lattice Basis Reduction: Improved Practical Algorithms and Solving Subset Sum Problems. Mathematical Programming\u00a066, 181\u2013191 (1994)","journal-title":"Mathematical Programming"},{"key":"9_CR23","unstructured":"Shoup, V.: NTL: A Library for doing Number Theory, Version 5.4, http:\/\/www.shoup.net\/ntl"},{"key":"9_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1007\/3-540-45708-9_19","volume-title":"Advances in Cryptology - CRYPTO 2002","author":"D. Wagner","year":"2002","unstructured":"Wagner, D.: A Generalized Birthday Problem. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol.\u00a02442, pp. 288\u2013303. Springer, Heidelberg (2002), http:\/\/www.cs.berkeley.edu\/daw\/papers"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology - CRYPTO 2007"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-74143-5_9.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T10:12:12Z","timestamp":1619518332000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-74143-5_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540741428"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-74143-5_9","relation":{},"subject":[]}}