{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T00:34:20Z","timestamp":1781656460089,"version":"3.54.5"},"publisher-location":"Berlin, Heidelberg","reference-count":45,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642253843","type":"print"},{"value":"9783642253850","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-25385-0_1","type":"book-chapter","created":{"date-parts":[[2011,12,1]],"date-time":"2011-12-01T18:18:18Z","timestamp":1322763498000},"page":"1-20","source":"Crossref","is-referenced-by-count":388,"title":["BKZ 2.0: Better Lattice Security Estimates"],"prefix":"10.1007","author":[{"given":"Yuanmi","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Phong Q.","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"1_CR1","unstructured":"Ajtai, M.: Generating random lattices according to the invariant distribution (draft of March 2006)"},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Ajtai, M.: Generating hard instances of lattice problems. In: Proc. STOC 1996, pp. 99\u2013108. ACM (1996)","DOI":"10.1145\/237814.237838"},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"Ajtai, M., Kumar, R., Sivakumar, D.: A sieve algorithm for the shortest lattice vector problem. In: Proc. 33rd STOC 2001, pp. 601\u2013610. ACM (2001)","DOI":"10.1145\/380752.380857"},{"key":"1_CR4","unstructured":"Cad\u00e9, D., Pujol, X., Stehl\u00e9, D.: FPLLL library, version 3.0 (September 2008)"},{"key":"1_CR5","doi-asserted-by":"crossref","unstructured":"Devroye, L.: Non-uniform random variate generation (1986), http:\/\/cg.scs.carleton.ca\/~luc\/rnbookindex.html","DOI":"10.1007\/978-1-4613-8643-8"},{"issue":"170","key":"1_CR6","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1090\/S0025-5718-1985-0777278-8","volume":"44","author":"U. Fincke","year":"1985","unstructured":"Fincke, U., Pohst, M.: Improved methods for calculating vectors of short length in a lattice, including a complexity analysis. Mathematics of Computation\u00a044(170), 463\u2013471 (1985)","journal-title":"Mathematics of Computation"},{"key":"1_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/11818175_7","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"N. Gama","year":"2006","unstructured":"Gama, N., Howgrave-Graham, N., Koy, H., Nguy\u00ean, P.Q.: Rankin\u2019s Constant and Blockwise Lattice Reduction. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol.\u00a04117, pp. 112\u2013130. Springer, Heidelberg (2006)"},{"key":"1_CR8","doi-asserted-by":"crossref","unstructured":"Gama, N., Nguyen, P.Q.: Finding short lattice vectors within Mordell\u2019s inequality. In: Proc. STOC 2008. ACM (2008)","DOI":"10.1145\/1374376.1374408"},{"key":"1_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/978-3-540-78967-3_3","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2008","author":"N. Gama","year":"2008","unstructured":"Gama, N., Nguyen, P.Q.: Predicting Lattice Reduction. In: Smart, N.P. (ed.) EUROCRYPT 2008. LNCS, vol.\u00a04965, pp. 31\u201351. Springer, Heidelberg (2008)"},{"key":"1_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/978-3-642-13190-5_13","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2010","author":"N. Gama","year":"2010","unstructured":"Gama, N., Nguyen, P.Q., Regev, O.: Lattice Enumeration Using Extreme Pruning. In: Gilbert, H. (ed.) EUROCRYPT 2010. LNCS, vol.\u00a06110, pp. 257\u2013278. Springer, Heidelberg (2010)"},{"key":"1_CR11","unstructured":"Gentry, C., Halevi, S.: Public challenges for fully-homomorphic encryption (2010), http:\/\/researcher.ibm.com\/researcher\/view_project.php?id=1548"},{"key":"1_CR12","unstructured":"Goldreich, O., Goldwasser, S., Halevi, S.: Challenges for the GGH cryptosystem (1997), http:\/\/theory.lcs.mit.edu\/~shaih\/challenge.html"},{"issue":"2","key":"1_CR13","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1515\/form.2003.009","volume":"15","author":"D. Goldstein","year":"2003","unstructured":"Goldstein, D., Mayer, A.: On the equidistribution of Hecke points. Forum Math.\u00a015(2), 165\u2013189 (2003)","journal-title":"Forum Math."},{"key":"1_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1007\/978-3-642-22792-9_25","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"G. Hanrot","year":"2011","unstructured":"Hanrot, G., Pujol, X., Stehl\u00e9, D.: Analyzing Blockwise Lattice Algorithms Using Dynamical Systems. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol.\u00a06841, pp. 447\u2013464. Springer, Heidelberg (2011)"},{"key":"1_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1007\/978-3-540-74143-5_10","volume-title":"Advances in Cryptology - CRYPTO 2007","author":"G. Hanrot","year":"2007","unstructured":"Hanrot, G., Stehl\u00e9, D.: Improved Analysis of Kannan\u2019s Shortest Lattice Vector Algorithm. In: Menezes, A. (ed.) CRYPTO 2007. LNCS, vol.\u00a04622, pp. 170\u2013186. Springer, Heidelberg (2007)"},{"key":"1_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"437","DOI":"10.1007\/978-3-642-01957-9_27","volume-title":"Applied Cryptography and Network Security","author":"P.S. Hirschhorn","year":"2009","unstructured":"Hirschhorn, P.S., Hoffstein, J., Howgrave-Graham, N., Whyte, W.: Choosing NTRUEncrypt Parameters in Light of Combined Lattice Reduction and MITM Approaches. In: Abdalla, M., Pointcheval, D., Fouque, P.-A., Vergnaud, D. (eds.) ACNS 2009. LNCS, vol.\u00a05536, pp. 437\u2013455. Springer, Heidelberg (2009)"},{"key":"1_CR17","doi-asserted-by":"crossref","unstructured":"Hoffstein, J., Howgrave-Graham, N., Pipher, J., Whyte, W.: Practical lattice-based cryptography: NTRUEncrypt and NTRUSign. In: [35] (2010)","DOI":"10.1007\/978-3-642-02295-1_11"},{"key":"1_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/BFb0054868","volume-title":"Algorithmic Number Theory","author":"J. Hoffstein","year":"1998","unstructured":"Hoffstein, J., Pipher, J., Silverman, J.H.: NTRU: A Ring-Based Public Key Cryptosystem. In: Buhler, J.P. (ed.) ANTS 1998. LNCS, vol.\u00a01423, pp. 267\u2013288. Springer, Heidelberg (1998)"},{"key":"1_CR19","unstructured":"Hoffstein, J., Silverman, J.H., Whyte, W.: Estimated breaking times for ntru lattices. Technical report, NTRU Cryptosystems, Report #012, v2 (October 2003)"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Kannan, R.: Improved algorithms for integer programming and related lattice problems. In: STOC 1983, pp. 193\u2013206. ACM (1983)","DOI":"10.1145\/800061.808749"},{"key":"1_CR21","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/s11786-009-0018-5","volume":"3","author":"M.S. Lee","year":"2010","unstructured":"Lee, M.S., Hahn, S.G.: Cryptanalysis of the GGH cryptosystem. Mathematics in Computer Science\u00a03, 201\u2013208 (2010)","journal-title":"Mathematics in Computer Science"},{"key":"1_CR22","first-page":"513","volume":"261","author":"A.K. Lenstra","year":"1982","unstructured":"Lenstra, A.K., Lenstra Jr., H.W., Lov\u00e1sz, L.: Factoring polynomials with rational coefficients. Mathematische Ann.\u00a0261, 513\u2013534 (1982)","journal-title":"Mathematische Ann."},{"key":"1_CR23","doi-asserted-by":"crossref","unstructured":"Lindner, R., Peikert, C.: Better key sizes (and attacks) for lwe-based encryption. Cryptology ePrint Archive, Report 2010\/613, Full version of the CT-RSA 2011","DOI":"10.1007\/978-3-642-19074-2_21"},{"key":"1_CR24","unstructured":"Lindner, R., R\u00fcckert, M.: TU Darmstadt lattice challenge, http:\/\/www.latticechallenge.org\/"},{"key":"1_CR25","doi-asserted-by":"crossref","unstructured":"May, A.: Cryptanalysis of NTRU\u2013107. Draft of 1999, available on May\u2019s webpage (1999)","DOI":"10.1289\/ehp.99107a450"},{"key":"1_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1007\/3-540-44670-2_10","volume-title":"Cryptography and Lattices","author":"A. May","year":"2001","unstructured":"May, A., Silverman, J.H.: Dimension Reduction Methods for Convolution Modular Lattices. In: Silverman, J.H. (ed.) CaLC 2001. LNCS, vol.\u00a02146, pp. 110\u2013125. Springer, Heidelberg (2001)"},{"key":"1_CR27","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/BF01571276","volume":"17","author":"J.E. Mazo","year":"1990","unstructured":"Mazo, J.E., Odlyzko, A.M.: Lattice points in high dimensional spheres. Monatsheft Mathematik\u00a017, 47\u201361 (1990)","journal-title":"Monatsheft Mathematik"},{"key":"1_CR28","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-540-88702-7_5","volume-title":"Post-Quantum Cryptography","author":"D. Micciancio","year":"2009","unstructured":"Micciancio, D., Regev, O.: Lattice-based cryptography. In: Post-Quantum Cryptography, pp. 147\u2013191. Springer, Berlin (2009)"},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"Micciancio, D., Voulgaris, P.: A deterministic single exponential time algorithm for most lattice problems based on Voronoi cell computations. In: STOC 2010. ACM (2010)","DOI":"10.1145\/1806689.1806739"},{"key":"1_CR30","doi-asserted-by":"crossref","unstructured":"Micciancio, D., Voulgaris, P.: Faster exponential time algorithms for the shortest vector problem. In: SODA 2010, pp. 1468\u20131480. ACM-SIAM (2010)","DOI":"10.1137\/1.9781611973075.119"},{"key":"1_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1007\/3-540-48405-1_18","volume-title":"Advances in Cryptology - CRYPTO \u201999","author":"P.Q. Nguy\u00ean","year":"1999","unstructured":"Nguy\u00ean, P.Q.: Cryptanalysis of the Goldreich-Goldwasser-Halevi Cryptosystem from Crypto\u201997. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol.\u00a01666, pp. 288\u2013304. Springer, Heidelberg (1999)"},{"key":"1_CR32","doi-asserted-by":"crossref","unstructured":"Nguyen, P.Q.: Public-key cryptanalysis. In: Luengo, I. (ed.) Recent Trends in Cryptography. Contemporary Mathematics, vol.\u00a0477. AMS\u2013RSME (2009)","DOI":"10.1090\/conm\/477\/09304"},{"key":"1_CR33","doi-asserted-by":"crossref","unstructured":"Nguyen, P.Q.: Hermite\u2019s constant and lattice algorithms. In: [35] (2010)","DOI":"10.1007\/978-3-642-02295-1_2"},{"key":"1_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1007\/11792086_18","volume-title":"Algorithmic Number Theory","author":"P.Q. Nguy\u00ean","year":"2006","unstructured":"Nguy\u00ean, P.Q., Stehl\u00e9, D.: LLL on the Average. In: Hess, F., Pauli, S., Pohst, M. (eds.) ANTS 2006. LNCS, vol.\u00a04076, pp. 238\u2013256. Springer, Heidelberg (2006)"},{"key":"1_CR35","volume-title":"The LLL Algorithm: Survey and Applications. Information Security and Cryptography","year":"2010","unstructured":"Nguyen, P.Q., Vall\u00e9e, B. (eds.): The LLL Algorithm: Survey and Applications. Information Security and Cryptography. Springer, Heidelberg (2010)"},{"issue":"2","key":"1_CR36","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1515\/JMC.2008.009","volume":"2","author":"P.Q. Nguyen","year":"2008","unstructured":"Nguyen, P.Q., Vidick, T.: Sieve algorithms for the shortest vector problem are practical. J. of Mathematical Cryptology\u00a02(2), 181\u2013207 (2008)","journal-title":"J. of Mathematical Cryptology"},{"key":"1_CR37","doi-asserted-by":"crossref","unstructured":"Novocin, A., Stehl\u00e9, D., Villard, G.: An LLL-reduction algorithm with quasi-linear time complexity. In: Proc. STOC 2011. ACM (2011)","DOI":"10.1145\/1993636.1993691"},{"issue":"1","key":"1_CR38","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1145\/1089242.1089247","volume":"15","author":"M. Pohst","year":"1981","unstructured":"Pohst, M.: On the computation of lattice vectors of minimal length, successive minima and reduced bases with applications. SIGSAM Bull.\u00a015(1), 37\u201344 (1981)","journal-title":"SIGSAM Bull."},{"key":"1_CR39","unstructured":"R\u00fcckert, M., Schneider, M.: Estimating the security of lattice-based cryptosystems. Cryptology ePrint Archive, Report 2010\/137 (2010)"},{"key":"1_CR40","unstructured":"Schneider, M., Gama, N.: SVP challenge, http:\/\/www.latticechallenge.org\/svp-challenge\/"},{"issue":"2-3","key":"1_CR41","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1016\/0304-3975(87)90064-8","volume":"53","author":"C.-P. Schnorr","year":"1987","unstructured":"Schnorr, C.-P.: A hierarchy of polynomial lattice basis reduction algorithms. Theoretical Computer Science\u00a053(2-3), 201\u2013224 (1987)","journal-title":"Theoretical Computer Science"},{"key":"1_CR42","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/BF01581144","volume":"66","author":"C.-P. Schnorr","year":"1994","unstructured":"Schnorr, C.-P., Euchner, M.: Lattice basis reduction: improved practical algorithms and solving subset sum problems. Math. Programming\u00a066, 181\u2013199 (1994)","journal-title":"Math. Programming"},{"key":"1_CR43","series-title":"Lecture Notes in Computer Science","first-page":"1","volume-title":"Advances in Cryptology - EUROCRYPT \u201995","author":"C.-P. Schnorr","year":"1995","unstructured":"Schnorr, C.-P., H\u00f6rner, H.H.: Attacking the Chor-Rivest Cryptosystem by Improved Lattice Reduction. In: Guillou, L.C., Quisquater, J.-J. (eds.) EUROCRYPT 1995. LNCS, vol.\u00a0921, pp. 1\u201312. Springer, Heidelberg (1995)"},{"key":"1_CR44","unstructured":"Shoup, V.: Number Theory C++ Library (NTL) version 5.4.1, http:\/\/www.shoup.net\/ntl\/"},{"key":"1_CR45","doi-asserted-by":"crossref","unstructured":"Wang, X., Liu, M., Tian, C., Bi, J.: Improved Nguyen-Vidick heuristic sieve algorithm for shortest vector problem. In: Cryptology ePrint Archive, Report 2010\/647 (2010)","DOI":"10.1145\/1966913.1966915"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 ASIACRYPT 2011"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-25385-0_1.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,18]],"date-time":"2021-12-18T07:41:41Z","timestamp":1639813301000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-25385-0_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642253843","9783642253850"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-25385-0_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011]]}}}