{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:39:30Z","timestamp":1781285970955,"version":"3.54.1"},"reference-count":187,"publisher":"Emerald","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,3,24]]},"abstract":"<jats:p>Lattice-based cryptography is the use of conjectured hard problems on point lattices in \u211dn as the foundation for secure cryptographic systems. Attractive features of lattice cryptography include apparent resistance to quantum attacks (in contrast with most number-theoretic cryptography), high asymptotic efficiency and parallelism, security under worst-case intractability assumptions, and solutions to long-standing open problems in cryptography.<\/jats:p>\n                  <jats:p>This work surveys most of the major developments in lattice cryptography over the past ten years. The main focus is on the foundational short integer solution (SIS) and learning with errors (LWE) problems (and their more efficient ring-based variants), their provable hardness assuming the worst-case intractability of standard lattice problems, and their many cryptographic applications.<\/jats:p>","DOI":"10.1561\/0400000074","type":"journal-article","created":{"date-parts":[[2016,3,24]],"date-time":"2016-03-24T11:24:09Z","timestamp":1458818649000},"page":"283-424","source":"Crossref","is-referenced-by-count":387,"title":["A Decade of Lattice Cryptography"],"prefix":"10.1108","volume":"10","author":[{"given":"Chris","family":"Peikert","sequence":"first","affiliation":[{"name":"University of Michigan Computer Science and Engineering, ,","place":["United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2016,3,24]]},"reference":[{"key":"2026040314121823500_ref001","first-page":"733","article-title":"Solving the shortest vector problem in 2n time using discrete Gaussian sampling","author":"Aggarwal","year":"2015","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref002","first-page":"553","article-title":"Efficient lattice (H)IBE in the standard model","author":"Agrawal","year":"2010","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref003","author":"Agrawal"},{"issue":"5","key":"2026040314121823500_ref004","doi-asserted-by":"crossref","first-page":"749","DOI":"10.1145\/1089023.1089025","article-title":"Lattice problems in NP coNP","volume":"52","author":"Aharonov","year":"2005","journal-title":"J. ACM"},{"key":"2026040314121823500_ref005","article-title":"The shortest vector problem in L2 is NP-hard for randomized reductions (extended abstract)","author":"Ajtai","year":"1998","journal-title":"In STOC"},{"key":"2026040314121823500_ref006","first-page":"1","article-title":"Generating hard instances of the short basis problem","author":"Ajtai","year":"1999","journal-title":"In ICALP, pages"},{"key":"2026040314121823500_ref007","first-page":"1","article-title":"Generating hard instances of lattice problems","volume":"13","author":"Ajtai","year":"2004","journal-title":"Quaderni di Matematica"},{"key":"2026040314121823500_ref008","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1145\/1060590.1060604","article-title":"Representing hard lattices with bits","author":"Ajtai","year":"2005","journal-title":"In STOC"},{"key":"2026040314121823500_ref009","first-page":"284","article-title":"A public-key cryptosystem with worst-case\/average-case equivalence","author":"Ajtai","year":"1997","journal-title":"In STOC, pages"},{"issue":"97","key":"2026040314121823500_ref010","article-title":"The first and fourth public-key cryptosystems with worst-case\/average-case equivalence","volume":"14","author":"Ajtai","year":"2007","journal-title":"ECCC"},{"key":"2026040314121823500_ref011","first-page":"601","article-title":"A sieve algorithm for the shortest lattice vector problem","author":"Ajtai","year":"2001","journal-title":"In STOC"},{"key":"2026040314121823500_ref012","first-page":"298","article-title":"More on average case vs approximation complexity","author":"Alekhnovich","year":"2003","journal-title":"In FOCS, pages"},{"key":"2026040314121823500_ref013","first-page":"236","article-title":"Short signatures with short public keys from homomorphic trapdoor functions","author":"Alperin-Sheriff","year":"2015","journal-title":"In PKC"},{"key":"2026040314121823500_ref014","first-page":"334","article-title":"Circular and KDM security for identity-based encryption","author":"Alperin-Sheriff","year":"2012","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref015","first-page":"1","article-title":"Practical bootstrapping in quasilinear time","author":"Alperin-Sheriff","year":"2013","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref016","first-page":"297","article-title":"Faster bootstrapping with polynomial error","author":"Alperin-Sheriff","year":"2014","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref017","first-page":"57","article-title":"Learning with rounding, revisited - new reduction, properties and applications","author":"Alwen","year":"2013","journal-title":"In CRYPTO, pages"},{"issue":"3","key":"2026040314121823500_ref018","doi-asserted-by":"crossref","first-page":"535","DOI":"10.1007\/s00224-010-9278-3","article-title":"Generating shorter bases for hard random lattices","volume":"48","author":"Alwen","year":"2011","journal-title":"Theory of Comput. Sys"},{"key":"2026040314121823500_ref019","first-page":"595","article-title":"Fast cryptographic primitives and circular-secure encryption based on hard learning problems","author":"Applebaum","year":"2009","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref020","article-title":"New algorithms for learning in presence of errors","volume":"1","author":"Arora","journal-title":"In ICALP"},{"issue":"1","key":"2026040314121823500_ref021","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/BF02579403","article-title":"On Lov\u00e1sz' lattice reduction and the nearest lattice point problem","volume":"6","author":"Babai","year":"1986","journal-title":"Combinatorica"},{"issue":"4","key":"2026040314121823500_ref022","doi-asserted-by":"crossref","first-page":"625","DOI":"10.1007\/BF01445125","article-title":"New bounds in some transference theorems in the geometry of numbers","volume":"296","author":"Banaszczyk","year":"1993","journal-title":"Mathematische Annalen"},{"key":"2026040314121823500_ref023","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1007\/BF02574039","article-title":"Inequalites for convex bodies and polar reciprocal lattices in Rn","volume":"13","author":"Banaszczyk","year":"1995","journal-title":"Discrete & Computational Geometry"},{"key":"2026040314121823500_ref024","first-page":"38","article-title":"SPRING: Fast pseudorandom functions from rounded ring products","author":"Banerjee","year":"2014","journal-title":"In FSE, pages"},{"key":"2026040314121823500_ref025","first-page":"31","article-title":"Key-homomorphic constrained pseudorandom functions","author":"Banerjee","year":"2015","journal-title":"In TCC, pages"},{"key":"2026040314121823500_ref026","first-page":"353","article-title":"New and improved keyhomomorphic pseudorandom functions","author":"Banerjee","year":"2014","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref027","first-page":"719","article-title":"Pseudorandom functions and lattices","author":"Banerjee","year":"2012","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref028","unstructured":"Website for the Bar-Ilan winter school on lattice-based cryptography and applications, 2012. http:\/\/crypto.biu.ac.il\/winterschool2012\/"},{"key":"2026040314121823500_ref029","first-page":"1","article-title":"Bounded-width polynomial-size branching programs recognize exactly those languages in","author":"Barrington","year":"1986","journal-title":"STOC"},{"key":"2026040314121823500_ref030","first-page":"228","article-title":"Identitybased (lossy) trapdoor functions and applications","author":"Bellare","year":"2012","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref031","first-page":"62","article-title":"Random oracles are practical: A paradigm for designing efficient protocols","author":"Bellare","year":"1993","journal-title":"In CCS, pages"},{"key":"2026040314121823500_ref032","first-page":"278","article-title":"Cryptographic primitives based on hard learning problems","author":"Blum","year":"1993","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref033","first-page":"209","article-title":"On the hardness of learning with rounding over small modulus","author":"Bogdanov","year":"2016","journal-title":"In TCC, pages"},{"issue":"3","key":"2026040314121823500_ref034","doi-asserted-by":"crossref","first-page":"586","DOI":"10.1137\/S0097539701398521","article-title":"Identity-based encryption from the Weil pairing","volume":"32","author":"Boneh","year":"2003","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref035","first-page":"1","article-title":"Linearly homomorphic signatures over binary fields and new tools for lattice-based signatures","author":"Boneh","year":"2011","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref036","first-page":"533","article-title":"Fully key-homomorphic encryption, arithmetic circuit ABE and compact garbled circuits","author":"Boneh","year":"2014","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref037","first-page":"647","article-title":"Space-efficient identity based encryption without pairings","author":"Boneh","year":"2007","journal-title":"In FOCS, pages"},{"key":"2026040314121823500_ref038","first-page":"410","article-title":"Key homomorphic PRFs and their applications","author":"Boneh","year":"2013","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref039","first-page":"280","article-title":"Constrained pseudorandom functions and their applications","author":"Boneh","year":"2013","journal-title":"ASIACRYPT, pages"},{"key":"2026040314121823500_ref040","first-page":"499","article-title":"Lattice mixing and vanishing trapdoors: A framework for fully secure short signatures and more","author":"Boyen","year":"2010","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref041","first-page":"501","article-title":"Functional signatures and pseudorandom functions","author":"Boyle","year":"2014","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref042","first-page":"868","article-title":"Fully homomorphic encryption without modulus switching from classical GapSVP","author":"Brakerski","year":"2012","journal-title":"In CRYPTO, pages"},{"issue":"3","key":"2026040314121823500_ref043","first-page":"2014","article-title":"(Leveled) fully homomorphic encryption without bootstrapping","volume":"6","author":"Brakerski","journal-title":"TOCT"},{"key":"2026040314121823500_ref044","first-page":"575","article-title":"Classical hardness of learning with errors","author":"Brakerski","year":"2013","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref045","first-page":"505","article-title":"Fully homomorphic encryption from ring-LWE and security for key dependent messages","author":"Brakerski","year":"2011","journal-title":"In CRYPTO, pages"},{"issue":"2","key":"2026040314121823500_ref046","doi-asserted-by":"crossref","first-page":"831","DOI":"10.1137\/120868669","article-title":"Efficient fully homomorphic encryption from (standard) LWE","volume":"43","author":"Brakerski","year":"2014","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref047","first-page":"1","article-title":"Lattice-based FHE as secure as PKE","author":"Brakerski","year":"2014","journal-title":"In ITCS, pages"},{"key":"2026040314121823500_ref048","first-page":"1","article-title":"Constrained keyhomomorphic PRFs from standard lattice assumptions - or: How to secretly embed a circuit in your PRF","author":"Brakerski","year":"2015","journal-title":"In TCC, pages"},{"issue":"4","key":"2026040314121823500_ref049","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1145\/1008731.1008734","article-title":"The random oracle methodology, revisited","volume":"51","author":"Canetti","year":"2004","journal-title":"J. ACM"},{"issue":"4","key":"2026040314121823500_ref050","doi-asserted-by":"crossref","first-page":"601","DOI":"10.1007\/s00145-011-9105-2","article-title":"Bonsai trees, or how to delegate a lattice basis","volume":"25","author":"Cash","year":"2012","journal-title":"J. Cryptology"},{"key":"2026040314121823500_ref051","first-page":"1","article-title":"BKZ 2.0: Better lattice security estimates","author":"Chen","year":"2011","journal-title":"In ASIACRYPT, pages"},{"key":"2026040314121823500_ref052","first-page":"315","article-title":"Batch fully homomorphic encryption over the integers","author":"Cheon","year":"2013","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref053","first-page":"3","article-title":"Cryptanalysis of the multilinear map over the integers","author":"Cheon","year":"2015","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref054","unstructured":"Jung Hee\n              Cheon\n             and ChangminLee. Cryptanalysis of the multilinear map on the ideal lattices. Cryptology ePrint Archive, Report 2015\/461, 2015. http:\/\/eprint.iacr.org\/."},{"key":"2026040314121823500_ref055","author":"Clifford Cocks"},{"key":"2026040314121823500_ref056","first-page":"52","article-title":"Lattice attacks on NTRU","author":"Coppersmith","year":"1997","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref057","first-page":"247","article-title":"Zeroizing without low-level zeroes: New MMAP attacks and their limitations","author":"Coron","year":"2015","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref058","first-page":"476","article-title":"Practical multilinear maps over the integers","author":"Coron","year":"2013","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref059","first-page":"267","article-title":"New multilinear maps over the integers","author":"Coron","year":"2015","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref060","first-page":"487","article-title":"Fully homomorphic encryption over the integers with shorter public keys","author":"Coron","year":"2011","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref061","first-page":"446","article-title":"Public key compression and modulus switching for fully homomorphic encryption over the integers","author":"Coron","year":"2012","journal-title":"In EUROCRYPT, pages"},{"issue":"6","key":"2026040314121823500_ref062","first-page":"644","article-title":"New directions in cryptography. IEEE Trans. Inf. Theory","volume":"22","author":"Diffie","year":"1976","journal-title":"IT"},{"key":"2026040314121823500_ref063","first-page":"361","article-title":"Public-key encryption schemes with auxiliary inputs","author":"Dodis","year":"2010","journal-title":"In TCC, pages"},{"key":"2026040314121823500_ref064","first-page":"18","article-title":"Lossy codes and a new variant of the learning-with-errors problem","author":"D\u00f6ttling","year":"2013","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref065","first-page":"34","article-title":"Ring-LWE in polynomial rings","author":"Ducas","year":"2012","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref066","first-page":"40","article-title":"Lattice signatures and bimodal gaussians","author":"Ducas","year":"2013","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref067","first-page":"335","article-title":"Improved short lattice signatures in the standard model","author":"Ducas","year":"2014","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref068","first-page":"617","article-title":"FHEW: Bootstrapping homomorphic encryption in less than a second","author":"Ducas","year":"2015","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref069","first-page":"415","article-title":"Faster Gaussian lattice sampling using lazy floating-point arithmetic","author":"Ducas","year":"2012","journal-title":"In ASIACRYPT, pages"},{"key":"2026040314121823500_ref070","first-page":"433","article-title":"Learning a zonotope and more: Cryptanalysis of NTRUSign countermeasures","author":"Ducas","year":"2012","journal-title":"In ASIACRYPT, pages"},{"key":"2026040314121823500_ref071","unstructured":"L\u00e9o\n              Ducas\n             and ThomasPrest. A hybrid Gaussian sampler for lattices over rings. Cryptology ePrint Archive, Report 2015\/660, 2015. http: \/\/eprint.iacr.org\/"},{"key":"2026040314121823500_ref072","first-page":"186","article-title":"How to prove yourself: Practical solutions to identification and signature problems","author":"Fiat","year":"1986","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref073","first-page":"53","article-title":"How to enhance the security of public-key encryption at minimum cost","author":"Fujisaki","year":"1999","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref074","first-page":"537","article-title":"Secure integration of asymmetric and symmetric encryption schemes","author":"Fujisaki","year":"1999","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref075","first-page":"31","article-title":"Predicting lattice reduction","author":"Gama","year":"2008","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref076","first-page":"257","article-title":"Lattice enumeration using extreme pruning","author":"Gama","year":"2010","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref077","first-page":"1","article-title":"Candidate multilinear maps from ideal lattices","author":"Garg","year":"2013","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref078","first-page":"40","article-title":"Candidate indistinguishability obfuscation and functional encryption for all circuits","author":"Garg","year":"2013","journal-title":"In FOCS, pages"},{"key":"2026040314121823500_ref079","unstructured":"Craig\n              Gentry\n            \n          . A fully homomorphic encryption scheme. PhD thesis, Stanford University, 2009. http:\/\/crypto.stanford.edu\/craig"},{"key":"2026040314121823500_ref080","first-page":"169","article-title":"Fully homomorphic encryption using ideal lattices","author":"Gentry","year":"2009","journal-title":"In STOC, pages"},{"issue":"3","key":"2026040314121823500_ref081","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1145\/1666420.1666444","article-title":"Computing arbitrary functions of encrypted data","volume":"53","author":"Gentry","year":"2010","journal-title":"Commun. ACM"},{"key":"2026040314121823500_ref082","first-page":"116","article-title":"Toward basing fully homomorphic encryption on worstcase hardness","author":"Gentry","year":"2010","journal-title":"In CRYPT, pages"},{"key":"2026040314121823500_ref083","first-page":"498","article-title":"Graph-induced multilinear maps from lattices","author":"Gentry","year":"2015","journal-title":"In TCC, pages"},{"key":"2026040314121823500_ref084","first-page":"107","article-title":"Fully homomorphic encryption without squashing using depth-3 arithmetic circuits","author":"Gentry","year":"2011","journal-title":"In FOCS, pages"},{"key":"2026040314121823500_ref085","first-page":"129","article-title":"Implementing Gentry's fully-homomorphic encryption scheme","author":"Gentry","year":"2011","journal-title":"In EUROCRYPT, pages"},{"issue":"5","key":"2026040314121823500_ref086","doi-asserted-by":"crossref","first-page":"663","DOI":"10.3233\/JCS-130480","article-title":"Field switching in BGV-style homomorphic encryption","volume":"21","author":"Gentry","year":"2013","journal-title":"J. Computer Security"},{"key":"2026040314121823500_ref087","first-page":"1","article-title":"Better bootstrapping in fully homomorphic encryption","author":"Gentry","year":"2012","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref088","first-page":"465","article-title":"Fully homomorphic encryption with polylog overhead","author":"Gentry","year":"2012","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref089","first-page":"197","article-title":"Trapdoors for hard lattices and new cryptographic constructions","author":"Gentry","year":"2008","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref090","first-page":"75","article-title":"Homomorphic encryption from learning with errors: Conceptually-simpler, asymptotically-faster, attribute-based","author":"Gentry","year":"2013","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref091","author":"Goldreich"},{"issue":"3","key":"2026040314121823500_ref092","doi-asserted-by":"crossref","first-page":"540","DOI":"10.1006\/jcss.1999.1686","article-title":"On the limits of nonapproximability of lattice problems","volume":"60","author":"Goldreich","year":"2000","journal-title":"J. Comput. Syst. Sci"},{"key":"2026040314121823500_ref093","first-page":"112","article-title":"Public-key cryptosystems from lattice reduction problems","author":"Goldreich","year":"1997","journal-title":"In CRYPTO, pages"},{"issue":"4","key":"2026040314121823500_ref094","doi-asserted-by":"crossref","first-page":"792","DOI":"10.1145\/6490.6503","article-title":"How to construct random functions","volume":"33","author":"Goldreich","year":"1986","journal-title":"J. ACM"},{"key":"2026040314121823500_ref095","first-page":"230","article-title":"Robustness of the learning with errors assumption","author":"Goldwasser","year":"2010","journal-title":"In ICS, pages"},{"issue":"2","key":"2026040314121823500_ref096","first-page":"270","volume":"28","author":"Goldwasser","year":"1984"},{"key":"2026040314121823500_ref097","first-page":"545","article-title":"Attributebased encryption for circuits","author":"Gorbunov","year":"2013","journal-title":"STOC, pages"},{"key":"2026040314121823500_ref098","first-page":"503","article-title":"Predicate encryption for circuits from LWE","author":"Gorbunov","year":"2015","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref099","first-page":"469","article-title":"Leveled fully homomorphic signatures from standard lattices","author":"Gorbunov","year":"2015","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref100","first-page":"89","article-title":"Attributebased encryption for fine-grained access control of encrypted data","author":"Goyal","year":"2006","journal-title":"In CCS, pages"},{"key":"2026040314121823500_ref101","first-page":"530","article-title":"Practical lattice-based cryptography: A signature scheme for embedded systems","author":"G\u00fcneysu","year":"2012","journal-title":"In CHES, pages"},{"issue":"4","key":"2026040314121823500_ref102","doi-asserted-by":"crossref","first-page":"1364","DOI":"10.1137\/S0097539793244708","article-title":"A pseudorandom generator from any one-way function","volume":"28","author":"H\u00e5stad","year":"1999","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref103","first-page":"469","article-title":"Tensor-based hardness of the shortest vector problem to within almost polynomial factors","author":"Haviv","year":"2007","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref104","first-page":"122","article-title":"NTRUSIGN: Digital signatures using the NTRU lattice","author":"Hoffstein","year":"2003","journal-title":"In CT-RSA, pages"},{"key":"2026040314121823500_ref105","first-page":"267","article-title":"NTRU: A ring-based public key cryptosystem","author":"Hoffstein","year":"1998","journal-title":"In ANTS, pages"},{"key":"2026040314121823500_ref106","first-page":"211","article-title":"NSS: an NTRU lattice-based signature scheme","author":"Hoffstein","year":"2001","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref107","unstructured":"Yupu\n              Hu\n             and HuiwenJia. Cryptanalysis of GGH map. Cryptology ePrint Archive, Report 2015\/301, 2015. http:\/\/eprint.iacr.org\/"},{"issue":"4","key":"2026040314121823500_ref108","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1007\/BF00189260","article-title":"Efficient cryptographic schemes provably as secure as subset sum","volume":"9","author":"Impagliazzo","year":"1996","journal-title":"J. Cryptology"},{"key":"2026040314121823500_ref109","first-page":"193","article-title":"Improved algorithms for integer programming and related lattice problems","author":"Kannan","year":"1983","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref110","author":"Katz"},{"key":"2026040314121823500_ref111","first-page":"372","article-title":"Concurrently secure identification schemes based on the worst-case hardness of lattice problems","author":"Kawachi","year":"2008","journal-title":"In ASIACRYPT, pages"},{"issue":"5","key":"2026040314121823500_ref112","doi-asserted-by":"crossref","first-page":"789","DOI":"10.1145\/1089023.1089027","article-title":"Hardness of approximating the shortest vector problem in lattices","volume":"52","author":"Khot","year":"2005","journal-title":"J. ACM"},{"key":"2026040314121823500_ref113","first-page":"669","article-title":"Delegatable pseudorandom functions and applications","author":"Kiayias","year":"2013","journal-title":"In CCS, pages"},{"key":"2026040314121823500_ref114","first-page":"937","article-title":"Finding the closest lattice vector when it's unusually close","author":"Klein","year":"2000","journal-title":"In SODA, pages"},{"issue":"2-3","key":"2026040314121823500_ref115","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1007\/s10623-015-0067-5","article-title":"Finding shortest lattice vectors faster using quantum search","volume":"77","author":"Laarhoven","year":"2015","journal-title":"Des. Codes Crypt"},{"issue":"3","key":"2026040314121823500_ref116","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1007\/s10623-014-9938-4","article-title":"Worst-case to average-case reductions for module lattices","volume":"75","author":"Langlois","year":"2015","journal-title":"Des. Codes Crypt"},{"issue":"4","key":"2026040314121823500_ref117","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1007\/BF01457454","article-title":"Factoring polynomials with rational coefficients","volume":"261","author":"Lenstra","year":"1982","journal-title":"Mathematische Annalen"},{"key":"2026040314121823500_ref118","first-page":"319","article-title":"Better key sizes (and attacks) for LWE-based encryption","author":"Lindner","year":"2011","journal-title":"In CT-RSA, pages"},{"key":"2026040314121823500_ref119","article-title":"Hardness of k-LWE and applications in traitor tracing","volume":"315334","author":"Ling","year":"2014","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref120","first-page":"293","article-title":"Solving BDD by enumeration: An update","author":"Liu","year":"2013","journal-title":"In CT-RSA, pages"},{"key":"2026040314121823500_ref121","article-title":"On-the-fly multiparty computation on the cloud via multikey fully homomorphic encryption","author":"L\u00f3pez-Alt","year":"1219","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref122","first-page":"162","article-title":"Lattice-based identification schemes secure under active attacks","author":"Lyubashevsky","year":"2008","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref123","first-page":"598","article-title":"Fiat-Shamir with aborts: Applications to lattice and factoring-based signatures","author":"Lyubashevsky","year":"2009","journal-title":"In ASIACRYPT, pages"},{"key":"2026040314121823500_ref124","first-page":"738","article-title":"Lattice signatures without trapdoors","author":"Lyubashevsky","year":"2012","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref125","article-title":"Generalized compact knapsacks are collision resistant","volume":"2","author":"Lyubashevsky","journal-title":"In ICALP"},{"key":"2026040314121823500_ref126","first-page":"37","article-title":"Asymptotically efficient lattice-based digital signatures","author":"Lyubashevsky","year":"2008","journal-title":"In TCC, pages"},{"key":"2026040314121823500_ref127","first-page":"577","article-title":"On bounded distance decoding, unique shortest vectors, and the minimum distance problem","author":"Lyubashevsky","year":"2009","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref128","first-page":"54","article-title":"SWIFFT: A modest proposal for FFT hashing","author":"Lyubashevsky","year":"2008","journal-title":"In FSE, pages"},{"key":"2026040314121823500_ref129","first-page":"382","article-title":"Public-key cryptographic primitives provably as secure as subset sum","author":"Lyubashevsky","year":"2010","journal-title":"In TCC, pages"},{"issue":"6","key":"2026040314121823500_ref130","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2535925","article-title":"On ideal lattices and learning with errors over rings","volume":"60","author":"Lyubashevsky","journal-title":"J. ACM"},{"key":"2026040314121823500_ref131","first-page":"35","article-title":"A toolkit for ring-LWE cryptography","author":"Lyubashevsky","year":"2013","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref132","first-page":"716","article-title":"Simple lattice trapdoor sampling from a broad class of distributions","author":"Lyubashevsky","year":"2015","journal-title":"In PKC, pages"},{"key":"2026040314121823500_ref133","author":"Malkin"},{"key":"2026040314121823500_ref134","first-page":"42","article-title":"A public-key cryptosystem based on algebraic coding theory","author":"McEliece","journal-title":"DSN Progress Report"},{"issue":"6","key":"2026040314121823500_ref135","doi-asserted-by":"crossref","first-page":"2008","DOI":"10.1137\/S0097539700373039","article-title":"The shortest vector in a lattice is hard to approximate to within some constant","volume":"30","author":"Micciancio","year":"2000","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref136","first-page":"126","article-title":"Improving lattice based cryptosystems using the Hermite normal form","author":"Micciancio","year":"2001","journal-title":"In CaLC, pages"},{"issue":"4","key":"2026040314121823500_ref137","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1007\/s00037-007-0234-9","article-title":"Generalized compact knapsacks, cyclic lattices, and efficient one-way functions","volume":"16","author":"Micciancio","year":"2007","journal-title":"Comp. Complex"},{"key":"2026040314121823500_ref138","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-02295-1_13","article-title":"The LLL Algorithm: Survey and Applications, chapter Cryptographic functions from worst-case complexity assumptions, pages 427-452","author":"Micciancio","year":"2009","journal-title":"Information Security and Cryptography. Springer"},{"key":"2026040314121823500_ref139","author":"Micciancio"},{"key":"2026040314121823500_ref140","unstructured":"Daniele\n              Micciancio\n            \n          . Lecture notes on lattice algorithms and applications, 2014. Available at http:\/\/cseweb.ucsd.edu\/\u223cdaniele\/classes.html. last accessed 17 Oct, 2014."},{"key":"2026040314121823500_ref141","author":"Micciancio","year":"2002"},{"key":"2026040314121823500_ref142","first-page":"465","article-title":"Pseudorandom knapsacks and the sample complexity of LWE search-to-decision reductions","author":"Micciancio","year":"2011","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref143","first-page":"700","article-title":"Trapdoors for lattices: Simpler, tighter, faster, smaller","author":"Micciancio","year":"2012","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref144","first-page":"21","article-title":"Hardness of SIS and LWE with small parameters","author":"Micciancio","year":"2013","journal-title":"In CRYPTO, pages"},{"issue":"1","key":"2026040314121823500_ref145","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1137\/S0097539705447360","article-title":"Worst-case to average-case reductions based on Gaussian measures","volume":"37","author":"Micciancio","year":"2007","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref146","author":"Micciancio"},{"key":"2026040314121823500_ref147","first-page":"351","article-title":"A deterministic single exponential time algorithm for most lattice problems based on Voronoi cell computations","author":"Micciancio","year":"2010","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref148","first-page":"327","article-title":"Distributed pseudorandom functions and KDCs","author":"Naor","year":"1999","journal-title":"In EUROCRYPT, pages"},{"issue":"2","key":"2026040314121823500_ref149","doi-asserted-by":"crossref","first-page":"336","DOI":"10.1006\/jcss.1998.1618","article-title":"Synthesizers and their application to the parallel construction of pseudo-random functions","volume":"58","author":"Naor","year":"1999","journal-title":"J. Comput. Syst. Sci"},{"issue":"2","key":"2026040314121823500_ref150","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1145\/972639.972643","article-title":"Number-theoretic constructions of efficient pseudo-random functions","volume":"51","author":"Naor","year":"2004","journal-title":"J. ACM"},{"issue":"5","key":"2026040314121823500_ref151","first-page":"1383","volume":"31","author":"Naor","year":"2002"},{"key":"2026040314121823500_ref152","first-page":"288","article-title":"Cryptanalysis of the Goldreich-Goldwasser-Halevi cryptosystem from Crypto '97","author":"Nguyen","year":"1999","journal-title":"In CRYPTO, pages"},{"issue":"2","key":"2026040314121823500_ref153","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1007\/s00145-008-9031-0","article-title":"Learning a parallelepiped: Cryptanalysis of GGH and NTRU signatures","volume":"22","author":"Nguyen","year":"2009","journal-title":"J. Cryptology"},{"key":"2026040314121823500_ref154","first-page":"223","article-title":"Cryptanalysis of the Ajtai-Dwork cryptosystem","author":"Nguyen","year":"1998","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref155","first-page":"146","article-title":"The two faces of lattices in cryptology","author":"Nguyen","year":"2001","journal-title":"In CaLC, pages"},{"key":"2026040314121823500_ref156","first-page":"525","article-title":"Bi-deniable public-key encryption","author":"O'Neill","year":"2011","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref157","author":"Paillier"},{"issue":"2","key":"2026040314121823500_ref158","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1007\/s00037-008-0251-3","article-title":"Limits on the hardness of lattice problems in 1p norms","volume":"17","author":"Peikert","year":"2008","journal-title":"Comp. Complex"},{"key":"2026040314121823500_ref159","first-page":"333","article-title":"Public-key cryptosystems from the worst-case shortest vector problem","author":"Peikert","year":"2009","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref160","first-page":"80","article-title":"An efficient and parallel Gaussian sampler for lattices","author":"Peikert","year":"2010","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref161","first-page":"197","article-title":"Lattice cryptography for the Internet","author":"Peikert","year":"2014","journal-title":"In PQCrypto, pages"},{"key":"2026040314121823500_ref162","first-page":"145","article-title":"Efficient collision-resistant hashing from worst-case assumptions on cyclic lattices","author":"Peikert","year":"2006","journal-title":"In TCC, pages"},{"key":"2026040314121823500_ref163","first-page":"478","article-title":"Lattices that admit logarithmic worst-case to average-case connection factors","author":"Peikert","year":"2007","journal-title":"In STOC, pages"},{"key":"2026040314121823500_ref164","first-page":"536","article-title":"Noninteractive statistical zero-knowledge proofs for lattice problems","author":"Peikert","year":"2008","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref165","first-page":"554","article-title":"A framework for efficient and composable oblivious transfer","author":"Peikert","year":"2008","journal-title":"In CRYPTO, pages"},{"issue":"6","key":"2026040314121823500_ref166","doi-asserted-by":"crossref","first-page":"1803","DOI":"10.1137\/080733954","article-title":"Lossy trapdoor functions and their applications","volume":"40","author":"Peikert","year":"2011","journal-title":"SIAM J. Comput"},{"key":"2026040314121823500_ref167","unstructured":"Michael O.\n              Rabin\n            \n          . Digitalized signatures and public-key functions as intractable as factorization. Technical Report MIT\/LCS\/TR-212, MIT Laboratory for Computer Science, 1979."},{"key":"2026040314121823500_ref168","unstructured":"Oded\n              Regev\n            \n          . Lecture notes on lattices in computer science, 2004. Available at http:\/\/www.cs.tau.ac.il\/\u223codedr\/teaching\/lattices_ fall_2004\/index.html, last accessed 28 Feb, 2008."},{"issue":"6","key":"2026040314121823500_ref169","doi-asserted-by":"crossref","first-page":"899","DOI":"10.1145\/1039488.1039490","article-title":"New lattice-based cryptographic constructions","volume":"51","author":"Regev","year":"2004","journal-title":"J. ACM"},{"issue":"6","key":"2026040314121823500_ref170","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1568318.1568324","article-title":"On lattices, learning with errors, random linear codes, and cryptography","volume":"56","author":"Regev","year":"2009","journal-title":"J. ACM"},{"key":"2026040314121823500_ref171","first-page":"191","article-title":"The learning with errors problem (invited survey)","author":"Regev","year":"2010","journal-title":"In CCC, pages"},{"key":"2026040314121823500_ref172","author":"Rivest"},{"issue":"2","key":"2026040314121823500_ref173","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1145\/359340.359342","article-title":"A method for obtaining digital signatures and public-key cryptosystems","volume":"21","author":"Rivest","year":"1978","journal-title":"Commun. ACM"},{"key":"2026040314121823500_ref174","first-page":"457","article-title":"Fuzzy identity-based encryption","author":"Sahai","year":"2005","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref175","first-page":"475","article-title":"How to use indistinguishability obfuscation: deniable encryption, and more","author":"Sahai","year":"2014","journal-title":"STOC, pages"},{"key":"2026040314121823500_ref176","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1016\/0304-3975(87)90064-8","article-title":"A hierarchy of polynomial time lattice basis reduction algorithms","volume":"53","author":"Schnorr","year":"1987","journal-title":"Theor. Comput. Sci"},{"issue":"3","key":"2026040314121823500_ref177","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1007\/BF00196725","article-title":"Efficient signature generation by smart cards","volume":"4","author":"Schnorr","year":"1991","journal-title":"J. Cryptology"},{"issue":"5","key":"2026040314121823500_ref178","doi-asserted-by":"crossref","first-page":"1484","DOI":"10.1137\/S0097539795293172","article-title":"Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer","volume":"26","author":"Shor","year":"1997","journal-title":"SIAM J. Comput"},{"issue":"1","key":"2026040314121823500_ref179","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1007\/s10623-012-9720-4","article-title":"Fully homomorphic SIMD operations","volume":"71","author":"Smart","year":"2014","journal-title":"Des. Codes Crypt"},{"key":"2026040314121823500_ref180","first-page":"27","article-title":"Making NTRU as secure as worst-case problems over ideal lattices","author":"Stehl\u00e9","year":"2011","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref181","first-page":"617","article-title":"Efficient public key encryption based on ideal lattices","author":"Stehl\u00e9","year":"2009","journal-title":"In ASIACRYPT, pages"},{"key":"2026040314121823500_ref182","first-page":"5","article-title":"Computing blindfolded: New developments in fully homomorphic encryption","author":"Vaikuntanathan","year":"2011","journal-title":"In FOCS, pages"},{"key":"2026040314121823500_ref183","first-page":"24","article-title":"Fully homomorphic encryption over the integers","author":"van Dijk","year":"2010","journal-title":"In EUROCRYPT, pages"},{"key":"2026040314121823500_ref184","author":"Vershynin"},{"key":"2026040314121823500_ref185","unstructured":"Andrew\n              Wan\n            \n          . Learning, Cryptography and the Average Case. PhD thesis, Columbia University, 2010."},{"key":"2026040314121823500_ref186","first-page":"619","article-title":"Dual system encryption: Realizing fully secure IBE and HIBE under simple assumptions","author":"Waters","year":"2009","journal-title":"In CRYPTO, pages"},{"key":"2026040314121823500_ref187","first-page":"235","article-title":"Improved (hierarchical) inner-product encryption from lattices","author":"Xagawa","year":"2013","journal-title":"In PKC, pages"}],"container-title":["Foundations and Trends\u00ae in Theoretical Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/fttcs\/article-pdf\/10\/4\/283\/11133874\/0400000074en.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/fttcs\/article-pdf\/10\/4\/283\/11133874\/0400000074en.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:01:14Z","timestamp":1777489274000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/fttcs\/article\/10\/4\/283\/1331264\/A-Decade-of-Lattice-Cryptography"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,3,24]]},"references-count":187,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2016,3,24]]}},"URL":"https:\/\/doi.org\/10.1561\/0400000074","relation":{},"ISSN":["1551-305X","1551-3068"],"issn-type":[{"value":"1551-305X","type":"print"},{"value":"1551-3068","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,3,24]]}}}