ReferenceNotation and further reading

Notation

August 25, 20267 min readbeginner

Every symbol used in the book, with the note that introduces it. Ordered roughly as the book meets them.

Every symbol used in the book, with the note that introduces it. Ordered roughly as the book meets them.

01.Sets and numbers

SymbolMeaningIntroduced in
∈\inis an element ofSets and Notation
⊆\subseteqis a subset ofSets and Notation
{x:P(x)}\{x : P(x)\}the set of xx satisfying PPSets and Notation
N,Z,Q,R\mathbb{N}, \mathbb{Z}, \mathbb{Q}, \mathbb{R}naturals, integers, rationals, realsSets and Notation
∣A∣\lvert A \rvertthe number of elements of a finite setSets and Notation

02.Modular arithmetic

SymbolMeaningIntroduced in
a mod na \bmod nthe remainder in {0,…,n−1}\{0, \ldots, n-1\}Modular Arithmetic
a≡b(modn)a \equiv b \pmod naa and bb are in the same residue classModular Arithmetic
mod⁡\operatorname{mod}the operator itself, named rather than appliedModular Arithmetic
Zn\mathbb{Z}_nthe integers modulo nn, as a ringThe Ring Zn\mathbb{Z}_n
Fq\mathbb{F}_qthe finite field with qq elements, qq prime hereThe Ring Zn\mathbb{Z}_n
Fq×\mathbb{F}_q^{\times}the non-zero elements under multiplicationRoots of Unity in a Finite Field
a−1a^{-1}the multiplicative inverse of aaThe Ring Zn\mathbb{Z}_n

03.Polynomials and the ring

SymbolMeaningIntroduced in
Zq[X]\mathbb{Z}_q[X]polynomials in XX with coefficients in Zq\mathbb{Z}_qPolynomials and the Polynomial Ring
deg⁡a\deg athe degree of a polynomialPolynomials and the Polynomial Ring
RqR_qZq[X]/(Xn+1)\mathbb{Z}_q[X]/(X^n+1), the ring everything lives inThe Target Ring RqR_q
Xn=−1X^n = -1the negacyclic reduction rule defining RqR_qQuotient Rings and Ideals
nnthe ring degree, 256256 in both standardsThe Target Ring RqR_q
qqthe modulus: 33293329 for ML-KEM, 83804178380417 for ML-DSAThe Target Ring RqR_q

04.Lattices

SymbolMeaningIntroduced in
L(B)\mathcal{L}(B)the lattice generated by the columns of BBWhat a Lattice Is
∥v∥\lVert v \rVertEuclidean normShort Vectors: SVP and CVP
∥v∥∞\lVert v \rVert_\inftyinfinity norm, the largest coefficient in absolute valueRejection Sampling, or Fiat-Shamir With Aborts
det⁡L\det \mathcal{L}lattice determinant, the volume per lattice pointMeasuring a Lattice: Determinant and Minkowski's Theorem
λ1\lambda_1the length of the shortest non-zero vectorExercises
UUa unimodular matrix, det⁡U=±1\det U = \pm 1Good and Bad Bases
γ\gammaapproximation factor in γ\gamma-SVPShort Vectors: SVP and CVP

05.Learning With Errors

SymbolMeaningIntroduced in
⟨a,s⟩\langle a, s \rangleinner product, multiply componentwise and addNoise Breaks Linear Algebra
χ\chithe error distributionThe Learning With Errors Problem
←\leftarrowis drawn at random fromThe Learning With Errors Problem
CBDη\text{CBD}_\etacentred binomial distribution with parameter η\etaWhere the Noise Comes From
η\etathe centred binomial widthWhere the Noise Comes From
kkmodule rank, how many polynomials in the secretModule-LWE
ℓ\ellthe second module rank, ML-DSA onlyThe Parameter Sets

06.The transform

SymbolMeaningIntroduced in
ζ\zetaa primitive 2n2nth root of unityRoots of Unity in a Finite Field
a^\hat{a}aa in the transformed domainThe Negacyclic NTT
⊙\odotpointwise multiplicationThe Negacyclic NTT
tta twiddle factor inside a butterflyThe Butterfly and Bit Reversal
circ⁡−(a)\operatorname{circ}_-(a)the negacyclic circulant of aaRing-LWE

07.ML-KEM

SymbolMeaningIntroduced in
AAthe public matrix, k×kk \times kKey Generation
ρ\rhothe 32-byte seed that regenerates AAKey Generation
s,e\mathbf{s}, \mathbf{e}secret and error vectorsKey Generation
t\mathbf{t}the public value As+eA\mathbf{s} + \mathbf{e}Key Generation
r,e1,e2\mathbf{r}, \mathbf{e}_1, e_2the encryptor's ephemeral secret and errorsEncryption
u,v\mathbf{u}, vthe two ciphertext componentsEncryption
Encode(m)\text{Encode}(m)a message bit as 00 or ⌈q/2⌉\lceil q/2 \rceilEncryption
δ,δ′\delta, \delta'the decryption error, without and with compressionWhy Decryption Works
du,dvd_u, d_vcompression widths in bitsCompression and Ciphertext Size
zzthe implicit-rejection seedThe Fujisaki-Okamoto Wrapper

08.ML-DSA

SymbolMeaningIntroduced in
s1,s2\mathbf{s}_1, \mathbf{s}_2the signing secret and its errorKey Generation
t1,t0\mathbf{t}_1, \mathbf{t}_0the public and retained halves of t\mathbf{t}Key Generation
ddthe truncation width, 1313Key Generation
y\mathbf{y}the ephemeral commitment randomnessSigning
w,w1\mathbf{w}, \mathbf{w}_1the commitment and its high bitsSigning
ccthe challenge, τ\tau coefficients of ±1\pm 1Signing
τ\tauthe challenge weightThe Parameter Sets
z\mathbf{z}the response y+cs1\mathbf{y} + c\mathbf{s}_1Signing
h\mathbf{h}the hint vectorSigning
γ1\gamma_1the range of y\mathbf{y}The Parameter Sets
γ2\gamma_2the bucket width for high and low bitsThe Parameter Sets
β\betathe bound τη\tau\eta on cs1c\mathbf{s}_1The Parameter Sets
ω\omegathe cap on hint weightThe Parameter Sets

09.Reduction and hashing

SymbolMeaningIntroduced in
mmthe Barrett constant ⌊2k/q⌋\lfloor 2^k/q \rfloorBarrett Reduction
RRthe Montgomery radix, a power of twoMontgomery Reduction
x~\tilde{x}xx in Montgomery form, xR mod qxR \bmod qMontgomery Reduction
q′q'the Montgomery constant, qq′≡−1(modR)qq' \equiv -1 \pmod RMontgomery Reduction
r,cr, csponge rate and capacity, summing to 1600The Sponge Construction
θ,ρ,π,χ,ι\theta, \rho, \pi, \chi, \iotathe five Keccak round stepsInside Keccak-f[1600]
⊕,∧,¬\oplus, \wedge, \lnotXOR, AND, NOTInside Keccak-f[1600]

10.Two collisions worth knowing

Some letters are reused across chapters with different meanings, which is unavoidable because the source standards use them that way.

ρ\rho is a 32-byte seed in ML-KEM and ML-DSA key generation, and separately the name of Keccak's rotation step. They are unrelated.

cc is the challenge polynomial in ML-DSA and the sponge capacity in Keccak. Also the ciphertext in ML-KEM.

rr is the sponge rate, and also the encryption randomness in ML-KEM's wrapper.

mm is the Barrett constant and also the message.

Context disambiguates all of them, and no note uses two senses at once.

FeedbackBook mode
post-quantum-cryptographycryptographymathematics