How lattice-based cryptography works
Picture a sheet of graph paper: the points where the lines cross form a lattice. Now imagine the same pattern in 500 or 1,000 dimensions, drawn with skewed, uneven axes. Questions that are easy on paper become extremely hard at that scale, such as finding the lattice point closest to a given spot.
Most modern schemes rest on a problem called Learning With Errors, introduced by Oded Regev in 2005.1 It works like this:
- Take a secret. A list of numbers only the key owner knows.
- Publish noisy equations. Mix the secret into many random linear equations, then add a small random error to each answer.
- Hide in the noise. Without the errors, ordinary algebra would recover the secret in moments. With them, recovering it is as hard as solving difficult lattice problems.1
The key owner can strip away the noise because they know the secret. Everyone else is left with a puzzle that has no known shortcut. ML-KEM uses a structured version called Module Learning With Errors, which keeps keys smaller and the math fast.2
Why lattices matter
Today’s public-key encryption, like RSA and X25519, rests on factoring and discrete logarithms, which Shor’s algorithm breaks on a large quantum computer. Lattice problems have been studied for decades without a quantum attack that works on them at real key sizes.3 They also give strong theoretical guarantees and run fast on ordinary hardware.
The main cost is size. Lattice keys and ciphertexts are measured in kilobytes, compared with 32 bytes for X25519. In practice that is a small price for most connections.
| Standard | Job | Built on |
|---|---|---|
| ML-KEM (FIPS 203) | Key exchange | Lattices2 |
| ML-DSA (FIPS 204) | Digital signatures | Lattices4 |
| SLH-DSA (FIPS 205) | Digital signatures | Hash functions |
| HQC (selected 2025) | Backup key exchange | Error-correcting codes5 |
NIST deliberately picked a backup based on different math, so the world isn’t relying on one family alone.5 Pairing lattice schemes with a classical algorithm, known as hybrid encryption, adds another layer of safety.
Where you’ll see it
- Web browsing, where hybrid key exchanges with ML-KEM are now on by default in major browsers.
- Messaging and SSH, which have added lattice-based key exchange to their protocols.
- Encrypted email and VPNs that protect data against future quantum computers.
Lattices in Secria
Secria’s post-quantum protection is lattice-based. Secria Mail uses ML-KEM-1024, the strongest ML-KEM parameter set, paired with X25519 on every plan. Secria VPN mixes an ML-KEM-1024 protected key into every WireGuard session and checks server identity with ML-DSA-65.
Related terms
Sources
- Oded Regev, On lattices, learning with errors, random linear codes, and cryptography, STOC 2005.
- NIST, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (August 2024).
- Chris Peikert, A Decade of Lattice Cryptography (2016).
- NIST, FIPS 204: Module-Lattice-Based Digital Signature Standard (August 2024).
- NIST, NIST selects HQC as fifth algorithm for post-quantum encryption (March 2025).
Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.
Questions about lattice-based cryptography
What is a lattice in cryptography?
A regular grid of points that repeats in every direction, but in hundreds of dimensions. Certain questions about these grids, like finding the closest point, are extremely hard to answer at that size.
Is lattice-based cryptography quantum resistant?
It is designed to be. No known quantum algorithm solves the lattice problems used in ML-KEM and ML-DSA efficiently, and they went through years of public review in NIST’s competition.
Is ML-KEM lattice-based?
Yes. ML-KEM rests on Module Learning With Errors, a lattice problem. So does the ML-DSA signature standard.
What are the downsides of lattice-based cryptography?
Mainly size. Keys and ciphertexts are larger than elliptic-curve ones, often more than a kilobyte. The math itself is fast.