{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T18:39:56Z","timestamp":1779907196011,"version":"3.53.1"},"reference-count":103,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2015,4,21]],"date-time":"2015-04-21T00:00:00Z","timestamp":1429574400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"DFG Research Training Group GRK 1817\/1"},{"name":"the German Research Foundation"},{"name":"European Union H2020 SAFEcrypto project","award":["644729"],"award-info":[{"award-number":["644729"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2015,5,21]]},"abstract":"<jats:p>Digital signatures are an important primitive for building secure systems and are used in most real-world security protocols. However, almost all popular signature schemes are either based on the factoring assumption (RSA) or the hardness of the discrete logarithm problem (DSA\/ECDSA). In the case of classical cryptanalytic advances or progress on the development of quantum computers, the hardness of these closely related problems might be seriously weakened. A potential alternative approach is the construction of signature schemes based on the hardness of certain lattice problems that are assumed to be intractable by quantum computers. Due to significant research advancements in recent years, lattice-based schemes have now become practical and appear to be a very viable alternative to number-theoretic cryptography. In this article, we focus on recent developments and the current state of the art in lattice-based digital signatures and provide a comprehensive survey discussing signature schemes with respect to practicality. Additionally, we discuss future research areas that are essential for the continued development of lattice-based cryptography.<\/jats:p>","DOI":"10.1145\/2724713","type":"journal-article","created":{"date-parts":[[2015,4,22]],"date-time":"2015-04-22T13:57:35Z","timestamp":1429711055000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":43,"title":["Practical Lattice-Based Digital Signature Schemes"],"prefix":"10.1145","volume":"14","author":[{"given":"James","family":"Howe","sequence":"first","affiliation":[{"name":"Centre for Secure Information Technologies (CSIT), Queen's University Belfast, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"P\u00f6ppelmann","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M\u00e1ire","family":"O'neill","sequence":"additional","affiliation":[{"name":"Centre for Secure Information Technologies (CSIT), Queen's University Belfast, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elizabeth","family":"O'sullivan","sequence":"additional","affiliation":[{"name":"Centre for Secure Information Technologies (CSIT), Queen's University Belfast, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"G\u00fcneysu","sequence":"additional","affiliation":[{"name":"Horst G\u00f6rtz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,4,21]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Michel Abdalla Jee Hea An Mihir Bellare and Chanathip Namprempre. 2002. From identification to signatures via the fiat-shamir transform: Minimizing assumptions for security and forward-security. In EUROCRYPT. 418--433. Michel Abdalla Jee Hea An Mihir Bellare and Chanathip Namprempre. 2002. From identification to signatures via the fiat-shamir transform: Minimizing assumptions for security and forward-security. In EUROCRYPT. 418--433.","DOI":"10.1007\/3-540-46035-7_28"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29011-4_34"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_28"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/237814.237838"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/380752.380857"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00224-010-9278-3"},{"key":"e_1_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Aydin Aysu Cameron Patterson and Patrick Schaumont. 2013. Low-cost and area-efficient FPGA implementations of lattice-based cryptography. In HOST. 81--86. Aydin Aysu Cameron Patterson and Patrick Schaumont. 2013. Low-cost and area-efficient FPGA implementations of lattice-based cryptography. In HOST. 81--86.","DOI":"10.1109\/HST.2013.6581570"},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Shi Bai and Steven D. Galbraith. 2014. An improved compression technique for signatures based on learning with errors. In CT-RSA. 28--47. Shi Bai and Steven D. Galbraith. 2014. An improved compression technique for signatures based on learning with errors. In CT-RSA. 28--47.","DOI":"10.1007\/978-3-319-04852-9_2"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Rachid El Bansarkhani and Johannes Buchmann. 2013. Improvement and efficient implementation of a lattice-based signature scheme. In Selected Areas in Cryptography. 48--67. Rachid El Bansarkhani and Johannes Buchmann. 2013. Improvement and efficient implementation of a lattice-based signature scheme. In Selected Areas in Cryptography. 48--67.","DOI":"10.1007\/978-3-662-43414-7_3"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168596"},{"key":"e_1_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Richard E. Blahut. 2010. Fast Algorithms for Signal Processing. Cambridge University Press. Richard E. Blahut. 2010. Fast Algorithms for Signal Processing. Cambridge University Press.","DOI":"10.1017\/CBO9780511760921"},{"key":"e_1_2_1_12_1","volume-title":"TCC.","author":"Boneh Dan"},{"key":"e_1_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Dan Boneh and Mark Zhandry. 2013. Secure signatures and chosen ciphertext security in a quantum computing world. In CRYPTO (2). 361--379. Dan Boneh and Mark Zhandry. 2013. Secure signatures and chosen ciphertext security in a quantum computing world. In CRYPTO (2). 361--379.","DOI":"10.1007\/978-3-642-40084-1_21"},{"key":"e_1_2_1_14_1","first-page":"78","article-title":"Implementation and comparison of lattice-based identification protocols on smart cards and microcontrollers","volume":"2014","author":"Boorghany Ahmad","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_15_1","first-page":"514","article-title":"On constrained implementation of lattice-based cryptographic primitives and schemes on smart cards","volume":"2014","author":"Boorghany Ahmad","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13013-7_29"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36594-2_8"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488608.2488680"},{"key":"e_1_2_1_19_1","volume-title":"Selected Areas in Cryptography","author":"Buchmann Johannes"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00607-009-0042-y"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32928-9_4"},{"key":"e_1_2_1_22_1","first-page":"646","article-title":"High-speed polynomial multiplication architecture for ring-LWE and SHE cryptosystems","volume":"2014","author":"Chen Donald Donglong","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_23_1","first-page":"1300","article-title":"Efficient FPGA implementation of FFT based multipliers","volume":"2005","author":"Cheng Lo Sing","year":"2005","journal-title":"Electrical and Computer Engineering"},{"key":"e_1_2_1_24_1","first-page":"725","article-title":"Efficient software implementation of ring-LWE encryption","volume":"2014","author":"de Clercq Ruan","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1965-0178586-1"},{"key":"e_1_2_1_26_1","unstructured":"Thomas H. Cormen Charles E. Leiserson Ronald L. Rivest and Clifford Stein. 2009. Introduction to Algorithms (3rd ed.). MIT Press. Thomas H. Cormen Charles E. Leiserson Ronald L. Rivest and Clifford Stein. 2009. Introduction to Algorithms (3rd ed.). MIT Press."},{"key":"e_1_2_1_27_1","doi-asserted-by":"crossref","unstructured":"\u00d6zg\u00fcr Dagdelen Marc Fischlin and Tommaso Gagliardoni. 2013. The Fiat-Shamir transformation in a quantum world. In ASIACRYPT (2). 62--81. \u00d6zg\u00fcr Dagdelen Marc Fischlin and Tommaso Gagliardoni. 2013. The Fiat-Shamir transformation in a quantum world. In ASIACRYPT (2). 62--81.","DOI":"10.1007\/978-3-642-42045-0_4"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00493-003-0019-y"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352533.1352539"},{"key":"e_1_2_1_31_1","first-page":"874","article-title":"Accelerating Bliss: The geometry of ternary polynomials","volume":"2014","author":"Ducas L\u00e9o","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_32_1","doi-asserted-by":"crossref","unstructured":"L\u00e9o Ducas Alain Durmus Tancr\u00e8de Lepoint and Vadim Lyubashevsky. 2013. Lattice signatures and bimodal Gaussians. In CRYPTO (1). 40--56. Retrieved from https:\/\/eprint.iacr.org\/2013\/383.pdf. L\u00e9o Ducas Alain Durmus Tancr\u00e8de Lepoint and Vadim Lyubashevsky. 2013. Lattice signatures and bimodal Gaussians. In CRYPTO (1). 40--56. Retrieved from https:\/\/eprint.iacr.org\/2013\/383.pdf.","DOI":"10.1007\/978-3-642-40041-4_3"},{"key":"e_1_2_1_33_1","doi-asserted-by":"crossref","unstructured":"L\u00e9o Ducas Vadim Lyubashevsky and Thomas Prest. 2014. Efficient identity-based encryption over NTRU lattices. In ASIACRYPT. 22--41. L\u00e9o Ducas Vadim Lyubashevsky and Thomas Prest. 2014. Efficient identity-based encryption over NTRU lattices. In ASIACRYPT. 22--41.","DOI":"10.1007\/978-3-662-45608-8_2"},{"key":"e_1_2_1_34_1","doi-asserted-by":"crossref","unstructured":"L\u00e9o Ducas and Daniele Micciancio. 2014. Improved short lattice signatures in the standard model. In CRYPTO. 335--352. L\u00e9o Ducas and Daniele Micciancio. 2014. Improved short lattice signatures in the standard model. In CRYPTO. 335--352.","DOI":"10.1007\/978-3-662-44371-2_19"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-34961-4_26"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-34961-4_27"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00200-014-0218-3"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03644-6_11"},{"key":"e_1_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Amos Fiat and Adi Shamir. 1986. How to prove yourself: Practical solutions to identification and signature problems. In CRYPTO. 186--194. Amos Fiat and Adi Shamir. 1986. How to prove yourself: Practical solutions to identification and signature problems. In CRYPTO. 186--194.","DOI":"10.1007\/3-540-47721-7_12"},{"key":"e_1_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Steven D. Galbraith. 2012. Mathematics of Public-Key Cryptography. Cambridge University Press. xiv 452--459. Steven D. Galbraith. 2012. Mathematics of Public-Key Cryptography. Cambridge University Press. xiv 452--459.","DOI":"10.1017\/CBO9781139012843"},{"key":"e_1_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Craig Gentry. 2009a. A Fully Homomorphic Encryption Scheme. Ph.D. Dissertation. Stanford University. Craig Gentry. 2009a. A Fully Homomorphic Encryption Scheme. Ph.D. Dissertation. Stanford University.","DOI":"10.1145\/1536414.1536440"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"e_1_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Craig Gentry Jakob Jonsson Jacques Stern and Michael Szydlo. 2001. Cryptanalysis of the NTRU signature scheme (NSS). In ASIACRYPT. 1--20. Craig Gentry Jakob Jonsson Jacques Stern and Michael Szydlo. 2001. Cryptanalysis of the NTRU signature scheme (NSS). In ASIACRYPT. 1--20.","DOI":"10.1007\/3-540-45682-1_1"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374407"},{"key":"e_1_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Craig Gentry and Michael Szydlo. 2002. Cryptanalysis of the revised NTRU signature scheme. In EUROCRYPT. 299--320. Craig Gentry and Michael Szydlo. 2002. Cryptanalysis of the revised NTRU signature scheme. In EUROCRYPT. 299--320.","DOI":"10.1007\/3-540-46035-7_20"},{"key":"e_1_2_1_46_1","unstructured":"Oded Goldreich Shafi Goldwasser and Shai Halevi. 1996. Public-key cryptosystems from lattice reduction problems. Electron. Colloquium Comput. Complexity (ECCC) 3 56 (1996). Oded Goldreich Shafi Goldwasser and Shai Halevi. 1996. Public-key cryptosystems from lattice reduction problems. Electron. Colloquium Comput. Complexity (ECCC) 3 56 (1996)."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1137\/0217017"},{"key":"e_1_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Samuel Dov Gordon Jonathan Katz and Vinod Vaikuntanathan. 2010. A group signature scheme from lattice assumptions. In ASIACRYPT. 395--412. Samuel Dov Gordon Jonathan Katz and Vinod Vaikuntanathan. 2010. A group signature scheme from lattice assumptions. In ASIACRYPT. 395--412.","DOI":"10.1007\/978-3-642-17373-8_23"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33027-8_30"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33027-8_31"},{"key":"e_1_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Tim G\u00fcneysu Tobias Oder Thomas P\u00f6ppelmann and Peter Schwabe. 2013. Software speed records for lattice-based signatures. In PQCrypto. 67--82. Tim G\u00fcneysu Tobias Oder Thomas P\u00f6ppelmann and Peter Schwabe. 2013. Software speed records for lattice-based signatures. In PQCrypto. 67--82.","DOI":"10.1007\/978-3-642-38616-9_5"},{"key":"e_1_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Nils Gura Arun Patel Arvinderpal Wander Hans Eberle and Sheueling Chang Shantz. 2004. Comparing elliptic curve cryptography and RSA on 8-bit CPUs. In CHES. 119--132. Nils Gura Arun Patel Arvinderpal Wander Hans Eberle and Sheueling Chang Shantz. 2004. Comparing elliptic curve cryptography and RSA on 8-bit CPUs. In CHES. 119--132.","DOI":"10.1007\/978-3-540-28632-5_9"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSD.2013.136"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/6566.6567"},{"key":"e_1_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Jeffrey Hoffstein Nick Howgrave-Graham Jill Pipher Joseph H. Silverman and William Whyte. 2003. NTRUSign: Digital signatures using the NTRU lattice. In CT-RSA. 122--140. Jeffrey Hoffstein Nick Howgrave-Graham Jill Pipher Joseph H. Silverman and William Whyte. 2003. NTRUSign: Digital signatures using the NTRU lattice. In CT-RSA. 122--140.","DOI":"10.1007\/3-540-36563-X_9"},{"key":"e_1_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Jeffrey Hoffstein Jill Pipher and Joseph H. Silverman. 1998. NTRU: A ring-based public key cryptosystem. In ANTS. 267--288. Jeffrey Hoffstein Jill Pipher and Joseph H. Silverman. 1998. NTRU: A ring-based public key cryptosystem. In ANTS. 267--288.","DOI":"10.1007\/BFb0054868"},{"key":"e_1_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Jeffrey Hoffstein Jill Pipher and Joseph H. Silverman. 2001. NSS: An NTRU lattice-based signature scheme. In EUROCRYPT. 211--228. Jeffrey Hoffstein Jill Pipher and Joseph H. Silverman. 2001. NSS: An NTRU lattice-based signature scheme. In EUROCRYPT. 211--228.","DOI":"10.1007\/3-540-44987-6_14"},{"key":"e_1_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Abdel Alim Kamal and Amr M. Youssef. 2009. An FPGA implementation of the NTRUEncrypt cryptosystem. In ICM. 209--212. Abdel Alim Kamal and Amr M. Youssef. 2009. An FPGA implementation of the NTRUEncrypt cryptosystem. In ICM. 209--212.","DOI":"10.1109\/ICM.2009.5418649"},{"key":"e_1_2_1_59_1","first-page":"595","article-title":"Multiplication of multidigit numbers on automata","volume":"7","author":"Karatsuba Anatoly A.","year":"1963","journal-title":"Soviet Phys. Doklady"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"e_1_2_1_61_1","doi-asserted-by":"crossref","unstructured":"Paul C. Kocher Joshua Jaffe and Benjamin Jun. 1999. Differential power analysis. In CRYPTO. 388--397. Paul C. Kocher Joshua Jaffe and Benjamin Jun. 1999. Differential power analysis. In CRYPTO. 388--397.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"e_1_2_1_62_1","doi-asserted-by":"crossref","unstructured":"Fabien Laguillaumie Adeline Langlois Beno\u00eet Libert and Damien Stehl\u00e9. 2013. Lattice-based group signatures with logarithmic signature size. In ASIACRYPT (2). 41--61. Fabien Laguillaumie Adeline Langlois Beno\u00eet Libert and Damien Stehl\u00e9. 2013. Lattice-based group signatures with logarithmic signature size. In ASIACRYPT (2). 41--61.","DOI":"10.1007\/978-3-642-42045-0_3"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-014-9938-4"},{"key":"e_1_2_1_64_1","doi-asserted-by":"crossref","unstructured":"Richard Lindner and Chris Peikert. 2011. Better key sizes (and attacks) for LWE-based encryption. In CT-RSA. 319--339. Richard Lindner and Chris Peikert. 2011. Better key sizes (and attacks) for LWE-based encryption. In CT-RSA. 319--339.","DOI":"10.1007\/978-3-642-19074-2_21"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10366-7_35"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29011-4_43"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_34"},{"key":"e_1_2_1_68_1","volume-title":"SWIFFT: A modest proposal for FFT hashing. In FSE. 54--72.","author":"Lyubashevsky Vadim","year":"2008"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_1"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535925"},{"key":"e_1_2_1_71_1","doi-asserted-by":"crossref","unstructured":"Vadim Lyubashevsky Chris Peikert and Oded Regev. 2013b. A toolkit for ring-LWE cryptography. In EUROCRYPT. 35--54. Vadim Lyubashevsky Chris Peikert and Oded Regev. 2013b. A toolkit for ring-LWE cryptography. In EUROCRYPT. 35--54.","DOI":"10.1007\/978-3-642-38348-9_3"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TASSP.1976.1162806"},{"key":"e_1_2_1_73_1","volume-title":"PQCrypto","author":"Melchor Carlos Aguilar","year":"2014"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00037-007-0234-9"},{"key":"e_1_2_1_75_1","unstructured":"Daniele Micciancio. 2008. Efficient reductions among lattice problems. In SODA. 84--93. Daniele Micciancio. 2008. Efficient reductions among lattice problems. In SODA. 84--93."},{"key":"e_1_2_1_76_1","doi-asserted-by":"crossref","unstructured":"Daniele Micciancio and Petros Mol. 2011. Pseudorandom knapsacks and the sample complexity of LWE search-to-decision reductions. In CRYPTO. 465--484. Daniele Micciancio and Petros Mol. 2011. Pseudorandom knapsacks and the sample complexity of LWE search-to-decision reductions. In CRYPTO. 465--484.","DOI":"10.1007\/978-3-642-22792-9_26"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29011-4_41"},{"key":"e_1_2_1_78_1","doi-asserted-by":"crossref","unstructured":"Daniele Micciancio and Chris Peikert. 2013. Hardness of SIS and LWE with small parameters. In CRYPTO (1). 21--39. Daniele Micciancio and Chris Peikert. 2013. Hardness of SIS and LWE with small parameters. In CRYPTO (1). 21--39.","DOI":"10.1007\/978-3-642-40041-4_2"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2004.72"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539705447360"},{"key":"e_1_2_1_81_1","doi-asserted-by":"crossref","unstructured":"Victor S. Miller. 1986. Use of elliptic curves in cryptography. In CRYPTO. 417--426. Victor S. Miller. 1986. Use of elliptic curves in cryptography. In CRYPTO. 417--426.","DOI":"10.1007\/3-540-39799-X_31"},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/800205.806332"},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-008-9031-0"},{"key":"e_1_2_1_84_1","doi-asserted-by":"crossref","unstructured":"Henri Nussbaumer. 1980. Fast Fourier Transform and Convolution Algorithms. Springer-Verlag. Henri Nussbaumer. 1980. Fast Fourier Transform and Convolution Algorithms. Springer-Verlag.","DOI":"10.1007\/978-3-662-00551-4"},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2593098"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/321450.321457"},{"key":"e_1_2_1_87_1","unstructured":"Chris Peikert. 2008. Public-key cryptosystems from the worst-case shortest vector problem. Electron. Colloquium Comput. Complexity (ECCC) 15 100 (2008). Chris Peikert. 2008. Public-key cryptosystems from the worst-case shortest vector problem. Electron. Colloquium Comput. Complexity (ECCC) 15 100 (2008)."},{"key":"e_1_2_1_88_1","doi-asserted-by":"crossref","unstructured":"Chris Peikert. 2010. An efficient and parallel gaussian sampler for lattices. In CRYPTO. 80--97. Chris Peikert. 2010. An efficient and parallel gaussian sampler for lattices. In CRYPTO. 80--97.","DOI":"10.1007\/978-3-642-14623-7_5"},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1971-0301966-0"},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44709-3_20"},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33481-8_8"},{"key":"e_1_2_1_92_1","volume-title":"Selected Areas in Cryptography","author":"P\u00f6ppelmann Thomas"},{"key":"e_1_2_1_93_1","doi-asserted-by":"crossref","unstructured":"Thomas P\u00f6ppelmann and Tim G\u00fcneysu. 2014. Area optimization of lightweight lattice-based encryption on reconfigurable hardware. In ISCAS. 2796--2799. Thomas P\u00f6ppelmann and Tim G\u00fcneysu. 2014. Area optimization of lightweight lattice-based encryption on reconfigurable hardware. In ISCAS. 2796--2799.","DOI":"10.1109\/ISCAS.2014.6865754"},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/1060590.1060603"},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/1568318.1568324"},{"key":"e_1_2_1_96_1","first-page":"591","article-title":"Compact and side channel secure discrete gaussian sampling","volume":"2014","author":"Roy Sujoy Sinha","year":"2014","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_97_1","unstructured":"Sujoy Sinha Roy Frederik Vercauteren Nele Mentens Donald Donglong Chen and Ingrid Verbauwhede. 2014. Compact hardware implementation of ring-LWE cryptosystems. In CHES. 371--391. Sujoy Sinha Roy Frederik Vercauteren Nele Mentens Donald Donglong Chen and Ingrid Verbauwhede. 2014. Compact hardware implementation of ring-LWE cryptosystems. In CHES. 371--391."},{"key":"e_1_2_1_98_1","volume-title":"Selected Areas in Cryptography","author":"Roy Sujoy Sinha"},{"key":"e_1_2_1_99_1","first-page":"137","article-title":"Estimating the security of lattice-based cryptosystems","volume":"2010","author":"R\u00fcckert Markus","year":"2010","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_100_1","doi-asserted-by":"crossref","unstructured":"Claus-Peter Schnorr. 1989. Efficient identification and signatures for smart cards. In CRYPTO. 239--252. Claus-Peter Schnorr. 1989. Efficient identification and signatures for smart cards. In CRYPTO. 239--252.","DOI":"10.1007\/0-387-34805-0_22"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795293172"},{"key":"e_1_2_1_102_1","first-page":"65","article-title":"Instantiating treeless signature schemes","volume":"2013","author":"Weiden Patrick","year":"2013","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_103_1","doi-asserted-by":"crossref","unstructured":"Franz Winkler. 1996. Polynomial Algorithms in Computer Algebra (Texts and Monographs in Symbolic Computation). Springer. Franz Winkler. 1996. Polynomial Algorithms in Computer Algebra (Texts and Monographs in Symbolic Computation). Springer.","DOI":"10.1007\/978-3-7091-6571-3"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2724713","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2724713","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:12:12Z","timestamp":1750227132000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2724713"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,4,21]]},"references-count":103,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2015,5,21]]}},"alternative-id":["10.1145\/2724713"],"URL":"https:\/\/doi.org\/10.1145\/2724713","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,4,21]]},"assertion":[{"value":"2014-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-04-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}