{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T06:46:00Z","timestamp":1776149160270,"version":"3.50.1"},"reference-count":44,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2023YFB4403500"],"award-info":[{"award-number":["2023YFB4403500"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272362"],"award-info":[{"award-number":["62272362"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["12441104"],"award-info":[{"award-number":["12441104"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012165","name":"Key Technologies Research and Development Program","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012165","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Theoretical Computer Science"],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1016\/j.tcs.2026.115926","type":"journal-article","created":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T07:51:01Z","timestamp":1774338661000},"page":"115926","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Quantum collision search for ternary LWE keys"],"prefix":"10.1016","volume":"1073","author":[{"given":"Runxi","family":"Cao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3247-5620","authenticated-orcid":false,"given":"Baocang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juntao","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.tcs.2026.115926_bib0001","series-title":"Proceedings of the 35th Annual ACM Symposium on Theory of Computing, June 9\u201311, 2003, San Diego, CA, USA","first-page":"407","article-title":"New lattice based cryptographic constructions","author":"Regev","year":"2003"},{"key":"10.1016\/j.tcs.2026.115926_bib0002","series-title":"Advances in Cryptology - EUROCRYPT 2010, 29th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Monaco \/ French Riviera, May 30, - June 3, 2010. Proceedings","first-page":"1","article-title":"On ideal lattices and learning with errors over rings","volume":"6110","author":"Lyubashevsky","year":"2010"},{"key":"10.1016\/j.tcs.2026.115926_bib0003","series-title":"Advances in Cryptology - ASIACRYPT 2009, 15th International Conference on the Theory and Application of Cryptology and Information Security, Tokyo, Japan, December 6\u201310, 2009. Proceedings","first-page":"617","article-title":"Efficient public key encryption based on ideal lattices","volume":"5912","author":"Stehl\u00e9","year":"2009"},{"key":"10.1016\/j.tcs.2026.115926_bib0004","series-title":"2018 IEEE European Symposium on Security and Privacy, EuroS&P 2018, London, United Kingdom, April 24\u201326, 2018","first-page":"353","article-title":"CRYSTALS - Kyber: A CCA-secure module-lattice-based KEM","author":"Bos","year":"2018"},{"key":"10.1016\/j.tcs.2026.115926_bib0005","series-title":"Proceedings of the 41st Annual ACM Symposium on Theory of Computing, STOC 2009, Bethesda, MD, USA, May 31, - June 2, 2009","first-page":"169","article-title":"Fully homomorphic encryption using ideal lattices","author":"Gentry","year":"2009"},{"key":"10.1016\/j.tcs.2026.115926_bib0006","series-title":"Advances in Cryptology - EUROCRYPT 2012 - 31st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Cambridge, UK, April 15\u201319, 2012. Proceedings","first-page":"738","article-title":"Lattice signatures without trapdoors","volume":"7237","author":"Lyubashevsky","year":"2012"},{"key":"10.1016\/j.tcs.2026.115926_bib0007","series-title":"Proceedings of the 41st Annual ACM Symposium on Theory of Computing, STOC 2009, Bethesda, MD, USA, May 31, - June 2, 2009","first-page":"333","article-title":"Public-key cryptosystems from the worst-case shortest vector problem: extended abstract","author":"Peikert","year":"2009"},{"key":"10.1016\/j.tcs.2026.115926_bib0008","series-title":"Proceedings of the 37th Annual ACM Symposium on Theory of Computing, Baltimore, MD, USA, May 22\u201324, 2005","first-page":"84","article-title":"On lattices, learning with errors, random linear codes, and cryptography","author":"Regev","year":"2005"},{"key":"10.1016\/j.tcs.2026.115926_bib0009","series-title":"Selected Areas in Cryptography - SAC 2017 - 24th International Conference, Ottawa, on, Canada, August 16\u201318, 2017, Revised Selected Papers","first-page":"235","article-title":"NTRU prime: reducing attack surface at low cost","volume":"10719","author":"Bernstein","year":"2017"},{"key":"10.1016\/j.tcs.2026.115926_bib0010","series-title":"Advances in Cryptology - CRYPTO 2013 - 33Rd Annual Cryptology Conference, Santa Barbara, CA, USA, August 18\u201322, 2013. Proceedings, Part I","first-page":"40","article-title":"Lattice signatures and bimodal Gaussians","volume":"8042","author":"Ducas","year":"2013"},{"key":"10.1016\/j.tcs.2026.115926_bib0011","series-title":"Cryptographic Hardware and Embedded Systems - CHES 2012 - 14th International Workshop, Leuven, Belgium, September 9\u201312, 2012. Proceedings","first-page":"530","article-title":"Practical lattice-based cryptography: a signature scheme for embedded systems","volume":"7428","author":"G\u00fcneysu","year":"2012"},{"key":"10.1016\/j.tcs.2026.115926_bib0012","series-title":"Cryptographic Hardware and Embedded Systems - CHES 2017 - 19th International Conference, Taipei, Taiwan, September 25\u201328, 2017, Proceedings","first-page":"232","article-title":"High-speed key encapsulation from NTRU","volume":"10529","author":"H\u00fclsing","year":"2017"},{"key":"10.1016\/j.tcs.2026.115926_bib0013","series-title":"Symposium on Theory of Computing Conference, STOC\u201913, Palo Alto, CA, USA, June 1\u20134, 2013","first-page":"575","article-title":"Classical hardness of learning with errors","author":"Brakerski","year":"2013"},{"key":"10.1016\/j.tcs.2026.115926_bib0014","series-title":"Advances in Cryptology - CRYPTO 2007, 27th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19\u201323, 2007, Proceedings","first-page":"150","article-title":"A hybrid lattice-reduction and meet-in-the-middle attack against NTRU","volume":"4622","author":"Howgrave-Graham","year":"2007"},{"key":"10.1016\/j.tcs.2026.115926_bib0015","series-title":"Advances in Cryptology - CRYPTO 2021 - 41st Annual International Cryptology Conference, CRYPTO 2021, Virtual Event, August 16\u201320, 2021, Proceedings, Part II","first-page":"701","article-title":"How to meet ternary LWE keys","volume":"12826","author":"May","year":"2021"},{"key":"10.1016\/j.tcs.2026.115926_bib0016","series-title":"Advances in Cryptology - ASIACRYPT 2020 - 26th International Conference on the Theory and Application of Cryptology and Information Security, Daejeon, South Korea, December 7\u201311, 2020, Proceedings, Part II","first-page":"633","article-title":"Improved classical and quantum algorithms for subset-Sum","volume":"12492","author":"Bonnetain","year":"2020"},{"key":"10.1016\/j.tcs.2026.115926_bib0017","series-title":"Advances in Cryptology - EUROCRYPT 2011 - 30th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tallinn, Estonia, May 15\u201319, 2011. Proceedings","first-page":"364","article-title":"Improved generic algorithms for hard knapsacks","volume":"6632","author":"Becker","year":"2011"},{"key":"10.1016\/j.tcs.2026.115926_bib0018","series-title":"Advances in Cryptology - EUROCRYPT 2010, 29th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Monaco \/ French Riviera, May 30, - June 3, 2010. Proceedings","first-page":"235","article-title":"New generic algorithms for hard knapsacks","volume":"6110","author":"Howgrave-Graham","year":"2010"},{"key":"10.1016\/j.tcs.2026.115926_bib0019","unstructured":"L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, P. Schwabe, G. Seiler, D. Stehl\u00e9, Crystals-dilithium, algorithm specifications and supporting documentation, 2019, Round-3 submission to the NIST pqc project."},{"key":"10.1016\/j.tcs.2026.115926_bib0020","series-title":"Advances in Cryptology - ASIACRYPT 2023 - 29th International Conference on the Theory and Application of Cryptology and Information Security, Guangzhou, China, December 4\u20138, 2023, Proceedings, Part IV","first-page":"72","article-title":"Memory-efficient attacks on small LWE keys","volume":"14441","author":"Esser","year":"2023"},{"key":"10.1016\/j.tcs.2026.115926_bib0021","series-title":"Post-Quantum Cryptography - 12th International Workshop, PQCrypto 2021, Daejeon, South Korea, July 20\u201322, 2021, Proceedings","first-page":"117","article-title":"Quantum key search for ternary LWE","volume":"12841","author":"van Hoof","year":"2021"},{"key":"10.1016\/j.tcs.2026.115926_bib0022","series-title":"Advances in Cryptology - EUROCRYPT 2023 - 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, April 23\u201327, 2023, Proceedings, Part v","first-page":"221","article-title":"Finding many collisions via reusable quantum walks - application to lattice sieving","volume":"14008","author":"Bonnetain","year":"2023"},{"key":"10.1016\/j.tcs.2026.115926_bib0023","series-title":"ASIACRYPT","first-page":"1","article-title":"BKZ 2.0: better lattice security estimates","volume":"7073","author":"Chen","year":"2011"},{"issue":"1","key":"10.1016\/j.tcs.2026.115926_bib0024","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1007\/s00145-024-09527-0","article-title":"A complete analysis of the BKZ lattice reduction algorithm","volume":"38","author":"Li","year":"2025","journal-title":"J. Cryptol."},{"key":"10.1016\/j.tcs.2026.115926_bib0025","series-title":"CRYPTO (1)","first-page":"385","article-title":"Refined attack on LWE with hints: constructing lattice via Gaussian elimination","volume":"16000","author":"Cao","year":"2025"},{"key":"10.1016\/j.tcs.2026.115926_bib0026","series-title":"Proceedings of the Twenty-Seventh Annual ACM-SIAM Symposium on Discrete Algorithms, SODA 2016, Arlington, VA, USA, January 10\u201312, 2016","first-page":"10","article-title":"New directions in nearest neighbor searching with applications to lattice sieving","author":"Becker","year":"2016"},{"key":"10.1016\/j.tcs.2026.115926_bib0027","series-title":"Advances in Cryptology - EUROCRYPT 2018 - 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29, - May 3, 2018 Proceedings, Part I","first-page":"125","article-title":"Shortest vector from lattice sieving: a few dimensions for free","volume":"10820","author":"Ducas","year":"2018"},{"key":"10.1016\/j.tcs.2026.115926_bib0028","unstructured":"B. Cho, M. Hhan, T. Kim, J. Lee, Y. Shen, Does quantum lattice sieving require quantum RAM?, 2024, https:\/\/arxiv.org\/abs\/2410.15565. arXiv: 2410.15565."},{"key":"10.1016\/j.tcs.2026.115926_bib0029","series-title":"ACISP","first-page":"168","article-title":"Hybrid dual and meet-LWE attack","volume":"13494","author":"Bi","year":"2022"},{"key":"10.1016\/j.tcs.2026.115926_bib0030","series-title":"CANS","first-page":"75","article-title":"How to enumerate LWE keys as narrow as in Kyber\/Dilithium","volume":"14342","author":"Glaser","year":"2023"},{"key":"10.1016\/j.tcs.2026.115926_bib0031","series-title":"EUROCRYPT (6)","first-page":"256","article-title":"Provable dual attacks on learning with errors","volume":"14656","author":"Pouly","year":"2024"},{"key":"10.1016\/j.tcs.2026.115926_bib0032","series-title":"EUROCRYPT (3)","first-page":"372","article-title":"Quantum algorithms for variants of average-case lattice problems via filtering","volume":"13277","author":"Chen","year":"2022"},{"key":"10.1016\/j.tcs.2026.115926_bib0033","series-title":"CRYPTO (2)","first-page":"513","article-title":"LWE With quantum amplitudes: algorithm, hardness, and oblivious sampling","volume":"16001","author":"Chen","year":"2025"},{"key":"10.1016\/j.tcs.2026.115926_bib0034","series-title":"PQCrypto (2)","first-page":"231","article-title":"Reducing the number of qubits in solving LWE","volume":"15578","author":"Benedikt","year":"2025"},{"key":"10.1016\/j.tcs.2026.115926_bib0035","series-title":"Advances in Cryptology - EUROCRYPT 2019 - 38th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Darmstadt, Germany, May 19\u201323, 2019, Proceedings, Part III","first-page":"189","article-title":"On finding quantum multi-collisions","volume":"11478","author":"Liu","year":"2019"},{"key":"10.1016\/j.tcs.2026.115926_bib0036","series-title":"Advances in Cryptology - ASIACRYPT 2021 - 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, December 6\u201310, 2021, Proceedings, Part IV","first-page":"63","article-title":"Lattice sieving via quantum random walks","volume":"13093","author":"Chailloux","year":"2021"},{"key":"10.1016\/j.tcs.2026.115926_bib0037","series-title":"Proceedings of the 39th Annual ACM Symposium on Theory of Computing, San Diego, California, USA, June 11\u201313, 2007","first-page":"575","article-title":"Search via quantum walk","author":"Magniez","year":"2007"},{"key":"10.1016\/j.tcs.2026.115926_bib0038","series-title":"Post-Quantum Cryptography - 8th International Workshop, PQCrypto 2017, Utrecht, the Netherlands, June 26\u201328, 2017, Proceedings","first-page":"69","article-title":"Quantum information set decoding algorithms","volume":"10346","author":"Kachigar","year":"2017"},{"key":"10.1016\/j.tcs.2026.115926_bib0039","series-title":"Quantum Computation and Quantum Information (10th Anniversary edition)","author":"Nielsen","year":"2016"},{"key":"10.1016\/j.tcs.2026.115926_bib0040","series-title":"Post-Quantum Cryptography - 5th International Workshop, PQCrypto 2013, Limoges, France, June 4\u20137, 2013. Proceedings","first-page":"16","article-title":"Quantum algorithms for the subset-Sum problem","volume":"7932","author":"Bernstein","year":"2013"},{"issue":"A","key":"10.1016\/j.tcs.2026.115926_bib0041","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1112\/S1461157016000206","article-title":"Reduced memory meet-in-the-middle attack against the NTRU private key","volume":"19","author":"van Vredendaal","year":"2016","journal-title":"LMS J. Comput. Math."},{"key":"10.1016\/j.tcs.2026.115926_bib0042","doi-asserted-by":"crossref","first-page":"3457","DOI":"10.1103\/PhysRevA.52.3457","article-title":"Elementary gates for quantum computation","volume":"52","author":"Barenco","year":"1995","journal-title":"Phys. Rev. A"},{"issue":"3","key":"10.1016\/j.tcs.2026.115926_bib0043","doi-asserted-by":"crossref","first-page":"331","DOI":"10.1007\/BF01933667","article-title":"A Monte Carlo method for factorization","volume":"15","author":"Pollard","year":"1975","journal-title":"BIT Numeric. Math."},{"issue":"1","key":"10.1016\/j.tcs.2026.115926_bib0044","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/PL00003816","article-title":"Parallel collision search with cryptanalytic applications","volume":"12","author":"van Oorschot","year":"1999","journal-title":"J. Cryptol."}],"container-title":["Theoretical Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0304397526001854?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0304397526001854?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T05:51:26Z","timestamp":1776145886000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0304397526001854"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":44,"alternative-id":["S0304397526001854"],"URL":"https:\/\/doi.org\/10.1016\/j.tcs.2026.115926","relation":{},"ISSN":["0304-3975"],"issn-type":[{"value":"0304-3975","type":"print"}],"subject":[],"published":{"date-parts":[[2026,5]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Quantum collision search for ternary LWE keys","name":"articletitle","label":"Article Title"},{"value":"Theoretical Computer Science","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.tcs.2026.115926","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"115926"}}