Start Here
August 25, 20265 min readbeginner
In 2024 NIST published its first post-quantum cryptography standards. Two of the three, ML-KEM and ML-DSA, are built on lattices, and both live inside a single algebraic object…
01.What this book is
In 2024 NIST published its first post-quantum cryptography standards. Two of the three, ML-KEM and ML-DSA, are built on lattices, and both live inside a single algebraic object written
Every key, every ciphertext and every signature those schemes produce is an element of it, and every operation they perform is addition or multiplication inside it.
This book takes that symbol apart, then builds the two standards back up from it, then goes underneath both to the arithmetic an implementation actually spends its time in.
02.Who it is for
Someone in their first semester of college who has never seen abstract algebra and has never studied cryptography.
That is meant literally, not as modesty. Groups, rings, fields, ideals and quotient rings are all built from nothing. So are public-key cryptography, one-way functions, quantum superposition and the sponge construction. Every new word is introduced with a small worked example first and the formal definition second, and no step is assumed obvious because it is standard.
The one prerequisite is arithmetic and a willingness to check things on paper.
03.How to read it
In order, and with a pencil. Every chapter builds on the one before, and almost every claim in the book is demonstrated on numbers small enough to verify by hand. The examples are small on purpose. Reading them is worth something. Doing them is worth considerably more.
Expect the pencil-sized version to be breakable. RSA is demonstrated with and , which you can factor in five trial divisions. Diffie-Hellman runs modulo 17, where you can read the answer off a table. ML-KEM's toy instance at actually fails to decrypt one of its coefficients. None of that is a flaw in the exposition. The gap between the pencil version and the deployed version is the entire subject, and watching security appear as the parameters grow is the point.
Each chapter opens with an overview saying what it is for and what it assumes. If a chapter feels like it is starting in the middle, that note is where the context is.
04.The through-line
Seven chapters, and each exists because the previous one raised a question it could not answer.
Chapter 1 builds from sets, through groups, rings, fields, modular arithmetic, polynomials and quotients. It offers no motivation at all, which is deliberate: the mathematics has to be in hand before the reason for it makes sense.
Chapter 2 gives the reason. What cryptography needs, how public-key cryptography solved it in the 1970s, the two arithmetic problems it has rested on since, why one quantum algorithm breaks both at once, and how the NIST competition arrived at lattices.
Chapter 3 says what a lattice is and states the new hard problem. Learning With Errors is simultaneous equations with a little noise added, and the noise is what turns an easy problem into one nobody can solve.
Chapter 4 makes it fast. Polynomial multiplication drops from to by evaluating at carefully chosen points, and this transform is where every implementation spends most of its time.
Chapter 5 assembles the key encapsulation standard, FIPS 203.
Chapter 6 assembles the signature standard, FIPS 204, which needs a technique the KEM does not: making published values leak nothing about the key that produced them.
Chapter 7 goes below both, to reducing a product modulo and to the permutation that supplies every random byte either scheme uses.
05.What is not covered
Hash-based and code-based post-quantum cryptography are named and not developed. SLH-DSA is standardised alongside the other two and is the conservative backup with different assumptions, and Classic McEliece has an unmatched security record and impractical key sizes. Both are worth knowing about, and neither is where the volume of Internet traffic will go.
Security proofs are also out of scope. The reductions from these schemes to their underlying lattice problems are real work and are not reproduced. What is given instead is the algebra of correctness, meaning why each scheme decrypts or verifies to the right answer, which is short enough to follow line by line and is what an implementer has to understand.
06.A note on how this was checked
Every worked number in this book was verified computationally before it was written down, rather than transcribed from the manuscript it was migrated out of.
That turned out to matter. The migration found three errors in the source.
A Barrett reduction constant is off by one, in a way that still passes its own worked example while breaking the bound the algorithm depends on. An exercise asks the reader to verify a congruence that is false, and false in exactly the way that explains one of ML-KEM's design quirks. And a worked example goes wrong and corrects itself mid-sentence. All three are fixed here, and the first two are written up where they occur, because the way each hid is more instructive than the correction.
07.Reference material
Notation collects every symbol the book uses, with the note that introduces it.
Further reading lists the primary sources, organised by chapter.