ReferenceNotation and further reading

Further Reading

August 25, 20266 min readbeginner

Sources for every substantive claim in the book, grouped by where they are used. Anything asserted about the standards can be checked against the FIPS documents, which are short…

Sources for every substantive claim in the book, grouped by where they are used. Anything asserted about the standards can be checked against the FIPS documents, which are short, free, and more readable than their reputation suggests.

01.The standards themselves

These are the authoritative texts. Where this book and a FIPS document disagree, the FIPS document is right.

NIST. FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard, 2024. The ML-KEM specification, including every parameter set, the exact serialisation, and the test vectors.

NIST. FIPS 204: Module-Lattice-Based Digital Signature Standard, 2024. ML-DSA, likewise.

NIST. FIPS 205: Stateless Hash-Based Digital Signature Standard, 2024. SLH-DSA, the hash-based backup this book names and does not develop.

NIST. FIPS 202: SHA-3 Standard, 2015. The Keccak sponge and its parameterisations, underneath all three of the above.

02.Chapter 1, the algebra

J. H. Silverman. A Friendly Introduction to Number Theory, 4th ed. Pearson, 2012. Chapters 1 to 3 cover clock arithmetic, congruences, the Euclidean algorithm and primitive roots at exactly this book's level, and at a gentler pace.

D. S. Dummit and R. M. Foote. Abstract Algebra, 3rd ed. Wiley, 2004. The standard reference for groups, rings and fields. Considerably heavier than needed here, and the place to go when a definition in Chapter 1 feels too informal.

03.Chapter 2, the motivation

W. Diffie and M. Hellman. "New directions in cryptography." IEEE Transactions on Information Theory, 1976. The paper that introduced public-key cryptography. Still worth reading, and short.

R. Rivest, A. Shamir, L. Adleman. "A method for obtaining digital signatures and public-key cryptosystems." CACM, 1978.

P. W. Shor. "Algorithms for quantum computation: discrete logarithms and factoring." FOCS 1994. The algorithm that made this whole book necessary.

M. Nielsen and I. Chuang. Quantum Computation and Quantum Information. Cambridge, 2010. The standard text, and where to go for the interference argument Chapter 2 only sketches.

NIST. Report on the Second Round of the Post-Quantum Cryptography Standardization Process, NISTIR 8309, 2020, and the third-round report NISTIR 8413, 2022. These document why candidates were kept or dropped, which is the most direct evidence about how the decisions were actually made.

04.Chapter 3, lattices and LWE

O. Regev. "On lattices, learning with errors, random linear codes, and cryptography." STOC 2005, and JACM 56(6), 2009. The worst-case-to-average-case reduction that gives lattice cryptography its foundation.

C. Peikert. A Decade of Lattice Cryptography. Foundations and Trends in Theoretical Computer Science, 2016. The best single survey. Chapters 2 to 4 cover everything in this book's Chapter 3 and considerably more.

D. Micciancio and O. Regev. "Lattice-based cryptography." In Post-Quantum Cryptography, Springer, 2009.

D. Micciancio and S. Goldwasser. Complexity of Lattice Problems: A Cryptographic Perspective. Kluwer, 2002. The reference for SVP and CVP hardness.

A. K. Lenstra, H. W. Lenstra Jr., L. Lovász. "Factoring polynomials with rational coefficients." Math. Ann. 261, 1982. The LLL basis reduction algorithm, whose approximation factor of roughly 2n/22^{n/2} is why bad bases stay bad in high dimension.

T. Laarhoven. "Sieving for shortest vectors in lattices using angular locality-sensitive hashing." CRYPTO 2015. Current best practice on the attack side.

05.Chapter 4, the transform

J. W. Cooley and J. W. Tukey. "An algorithm for the machine calculation of complex Fourier series." Math. Comp., 1965.

V. Lyubashevsky, C. Peikert, O. Regev. "On ideal lattices and learning with errors over rings." EUROCRYPT 2010. The Ring-LWE paper, including why Xn+1X^n + 1 with nn a power of two is the safe choice.

A. Langlois and D. Stehlé. "Worst-case to average-case reductions for module lattices." Designs, Codes and Cryptography, 2015. The Module-LWE foundation.

G. Seiler. "Faster AVX2 optimized NTT multiplication for Ring-LWE lattice cryptography." IACR ePrint 2018/039. The reference for how the transform is actually implemented fast, including the incomplete-NTT handling that ML-KEM's modulus forces.

06.Chapter 5, ML-KEM

R. Avanzi, J. Bos, L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, J. M. Schanck, P. Schwabe, G. Seiler, D. Stehlé. CRYSTALS-Kyber: Algorithm Specifications and Supporting Documentation. NIST PQC Round 3 submission, 2020. The design rationale, which FIPS 203 does not repeat.

J. W. Bos et al. "CRYSTALS-Kyber: a CCA-secure module-lattice-based KEM." EuroS&P 2018.

E. Fujisaki and T. Okamoto. "Secure integration of asymmetric and symmetric encryption schemes." CRYPTO 1999.

D. Hofheinz, K. Hövelmanns, E. Kiltz. "A modular analysis of the Fujisaki-Okamoto transformation." TCC 2017. The variant ML-KEM actually uses, with the tight proof.

07.Chapter 6, ML-DSA

C. P. Schnorr. "Efficient identification and signatures for smart cards." CRYPTO 1989.

A. Fiat and A. Shamir. "How to prove yourself: practical solutions to identification and signature problems." CRYPTO 1986.

V. Lyubashevsky. "Fiat-Shamir with aborts: applications to lattice and factoring-based signatures." ASIACRYPT 2009. The rejection-sampling idea that makes lattice signatures possible.

V. Lyubashevsky. "Lattice signatures without trapdoors." EUROCRYPT 2012.

L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, P. Schwabe, G. Seiler, D. Stehlé. "CRYSTALS-Dilithium: a lattice-based digital signature scheme." TCHES, 2018.

E. Kiltz, V. Lyubashevsky, C. Schaffner. "A concrete treatment of Fiat-Shamir signatures in the quantum random oracle model." EUROCRYPT 2018.

08.Chapter 7, reduction and hashing

P. D. Barrett. "Implementing the Rivest Shamir and Adleman public key encryption algorithm on a standard digital signal processor." CRYPTO 1986.

P. Montgomery. "Modular multiplication without trial division." Math. Comp., 44, 1985.

T. Plantard. "Efficient word-size modular arithmetic." IEEE Transactions on Emerging Topics in Computing, 2021.

J. A. Solinas. Generalized Mersenne Numbers. Technical Report CORR-99-39, University of Waterloo, 1999. The prime shape that makes ML-DSA's reduction multiplication-free.

A. Menezes, P. van Oorschot, S. Vanstone. Handbook of Applied Cryptography. CRC Press, 1996. Chapter 14 is the reference for modular arithmetic algorithms, including the Barrett error analysis this book states without proving. Freely available online.

G. Bertoni, J. Daemen, M. Peeters, G. Van Assche. "Cryptographic sponge functions." keccak.team, 2011, and the Keccak Specifications Summary, 2013.

J.-P. Aumasson. Serious Cryptography. No Starch Press, 2017. Chapter 6 on hash functions is the friendliest available treatment of sponges.

09.Implementation and hardware

These matter for the engineering questions Chapter 4 and Chapter 7 leave open.

H. Ueno et al. "A lightweight Kyber hardware architecture." IEEE Access, 2021.

The reference implementations at github.com/pq-crystals, for both Kyber and Dilithium. Reading the C alongside FIPS 203 and 204 is the fastest way to see where the spec's abstractions land in practice, particularly the constant-time patterns this book keeps flagging.

The Open Quantum Safe project at openquantumsafe.org, for integration into TLS and for benchmarking across platforms.

10.On the migration itself

CNSA 2.0, the NSA's commercial national security algorithm suite update, which sets deployment deadlines and is the clearest public statement of what timeline institutional users are working to.

The IETF drafts on hybrid key exchange in TLS 1.3, which specify the X25519-plus-ML-KEM construction that Chapter 5 mentions and that most deployed post-quantum traffic currently uses.

FeedbackBook mode
post-quantum-cryptographycryptographymathematics