{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T01:04:26Z","timestamp":1772240666752,"version":"3.50.1"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput."],"published-print":{"date-parts":[[2018]]},"DOI":"10.1109\/tc.2018.2809723","type":"journal-article","created":{"date-parts":[[2018,2,27]],"date-time":"2018-02-27T19:39:51Z","timestamp":1519760391000},"page":"1-1","source":"Crossref","is-referenced-by-count":4,"title":["Optimizing polynomial convolution for NTRUEncrypt"],"prefix":"10.1109","author":[{"given":"Wei","family":"Dai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Whyte","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"zhenfei","family":"zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1515\/popets-2016-0037","article-title":"Circuit-extension handshakes for Tor achieving forward secrecy in a quantum world","volume":"4","author":"schanck","year":"2016","journal-title":"PoPETs"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"ref33","year":"0"},{"key":"ref32","first-page":"150","article-title":"A hybrid lattice-reduction and meet-in-the-middle attack against NTRU","author":"howgrave-graham","year":"2007","journal-title":"Proc 27th Annu Int Cryptology Conf Adv Cryptology"},{"key":"ref31","article-title":"Meet-in-the-middle Attack on an NTRU private key","author":"hoffstein","year":"2006"},{"key":"ref30","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1007\/BFb0054868","article-title":"NTRU: A ring-based public key cryptosystem","author":"hoffstein","year":"1998","journal-title":"3rd Algorithmic Number Theory Symp"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s00037-007-0234-9"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/2213977.2214086"},{"key":"ref35","article-title":"Comparison between subfield and straightforward attacks on NTRU","volume":"717","author":"kirchner","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref34","first-page":"573","article-title":"When constant-time source yields variable-time binary: Exploiting curve25519-donna built with MSVC 2015","author":"kaufmann","year":"0","journal-title":"Proc Int Conf Cryptology Netw Security"},{"key":"ref10","first-page":"207","article-title":"Curve25519: New Diffie-Hellman speed records","author":"bernstein","year":"2006","journal-title":"Proc 9th Int Conf Theory Practice Public-Key Cryptography"},{"key":"ref40","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1007\/3-540-58691-1_68","article-title":"Polynominal time algorithms for discrete logarithms and factoring on a quantum computer","author":"shor","year":"1994","journal-title":"Proc Algorithmic Number Theory Symp III"},{"key":"ref11","article-title":"A subfield-logarithm attack against ideal lattices","author":"bernstein","year":"2014"},{"key":"ref12","volume":"461","author":"bernstein","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref13","article-title":"Flush, gauss, and reload &#x2013; A cache attack on the bliss lattice-based signature scheme","author":"bruinderink","year":"2016"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.8105","article-title":"Report on post-quantum cryptography","author":"chen","year":"2016"},{"key":"ref15","first-page":"1","article-title":"BKZ 2.0: Better lattice security estimates","author":"chen","year":"2011","journal-title":"Proc Int Conf Theory Appl Cryptol Inf Secur"},{"key":"ref16","article-title":"An algorithm for NTRU problems and cryptanalysis of the GGH multilinear map without an encoding of zero","volume":"139","author":"cheon","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref17","first-page":"52","article-title":"Lattice attacks on NTRU","author":"coppersmith","year":"1997","journal-title":"Proc 26th Annu Int Conf Theory Appl Cryptograph Techn"},{"key":"ref18","first-page":"40","article-title":"Lattice signatures and bimodal Gaussians","author":"ducas","year":"2013","journal-title":"Proc Adv Cryptology"},{"key":"ref19","article-title":"Quantum cryptanalysis of NTRU","volume":"676","author":"fluhrer","year":"2015","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref28","first-page":"3","article-title":"Choosing parameters for NTRUEncrypt","author":"hoffstein","year":"2017","journal-title":"Proc The Cryptographer s Track at RSA Conf"},{"key":"ref4","year":"0"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"437","DOI":"10.1007\/978-3-642-01957-9_27","article-title":"Choosing NTRUEncrypt parameters in light of combined lattice reduction and MITM approaches","author":"hirschhorn","year":"2009","journal-title":"Proc 7th Int Conf Appl Cryptography Netw Security"},{"key":"ref3","year":"0"},{"key":"ref6","article-title":"IEEE Standard Specification for Public Key Cryptographic Techniques Based on Hard Problems over Lattices","year":"2008"},{"key":"ref29","article-title":"Choosing Parameters for NTRUEncrypt (full version)","volume":"708","author":"hoffstein","year":"2015","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref5","year":"0"},{"key":"ref8","first-page":"327","article-title":"Post-quantum key exchange - A new hope","author":"alkim","year":"2016","journal-title":"Proc 25th Usenix Security Symp"},{"key":"ref7","first-page":"153","article-title":"A subfield lattice attack on overstretched NTRU assumptions&#x2014;Cryptanalysis of some FHE and graded encoding schemes","author":"albrecht","year":"2016","journal-title":"Proc Adv Cryptology - 36th Annu Int Cryptology Conf"},{"key":"ref2","year":"0"},{"key":"ref9","article-title":"Tuple lattice sieving","volume":"713","author":"bai","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref1","year":"2012"},{"key":"ref20","year":"2015"},{"key":"ref22","first-page":"257","article-title":"Lattice enumeration using extreme pruning","author":"gama","year":"2010","journal-title":"Proc Int Conf Theory Appl Cryptographic Techn"},{"key":"ref21","first-page":"31","article-title":"Predicting lattice reduction","author":"gama","year":"2008","journal-title":"Proc Theory Appl Cryptographic Techn 27th Annu Int Conf Adv Cryptology"},{"key":"ref42","article-title":"Revisiting the hybrid attack: Improved analysis and refined security estimates","author":"wunderer","year":"2016"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/237814.237866"},{"key":"ref41","first-page":"27","article-title":"Making NTRU as secure as worst-case problems over ideal lattices","author":"stehl\u00e9","year":"2011","journal-title":"Proc 30th Annu Int Conf Theory Appl Cryptol Tech"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref44","author":"zhang","year":"0"},{"key":"ref26","article-title":"Faster arithmetic for number-theoretic transforms","author":"harvey","year":"2012","journal-title":"CoRR"},{"key":"ref43","article-title":"Lattice-Based Polynomial Public Key Establishment Algorithm for the Financial Services Industry, 201","year":"0"},{"key":"ref25","first-page":"189","author":"gueron","year":"2016","journal-title":"Software Optimizations of NTRUEncrypt for Modern Processor Architectures"}],"container-title":["IEEE Transactions on Computers"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/12\/4358213\/08303667.pdf?arnumber=8303667","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,14]],"date-time":"2022-08-14T23:46:13Z","timestamp":1660520773000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/8303667\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/tc.2018.2809723","relation":{},"ISSN":["0018-9340"],"issn-type":[{"value":"0018-9340","type":"print"}],"subject":[],"published":{"date-parts":[[2018]]}}}