Skip to content

Appendix B: Notation reference

A symbol in this book is always defined the first time it appears in a chapter. This appendix lists every reservation, organized by the part that introduces it, and flags the letters whose meaning shifts across parts.

When a symbol carries a subscript (like rFRIr_\mathrm{FRI} versus rFSr_\mathrm{FS}), the bare letter is reserved only in the chapter that introduces the decoration, and the decorations are never elided.

The book reuses a handful of letters across parts. Each occurrence is defined locally, but a reader moving between parts should confirm the context before interpreting the letter. A cell names the Part’s reserved meaning and the chapters that carry it. “Not reserved” means the Part introduces no book-level reservation for that letter, and never that no chapter uses it: a letter defined inside one construction, such as Chapter 32’s toy parameters or Chapter 33’s Schnorr example, is a legitimate local use and appears below only where a reader could carry the wrong meaning into it.

SymbolPart IPart IIPart IIIPart IVPart VI
nnModulus in modular arithmeticLattice dimension / polynomial degreeHash output lengthCode length (Ch 19 to Ch 21), reset in Ch 24 to the MQ variable countSubgroup order in Ch 33’s Schnorr example, trace length in Ch 34 E3
qqRSA large prime (Ch 4)ML-KEM modulus 3329 (Ch 11), ML-DSA modulus 8380417 (Ch 12)Signatures observed by the adversary (Ch 16, Ch 18)Field order (codes)Quantum query budget (Ch 33, Ch 34), and the field order in Ch 32’s scalar toy
rrShor’s period (Ch 4), first half of an ECDSA signature (Ch 4)Regev encryption randomness (Ch 10), ML-KEM coin seed (Ch 11)XMSS per-signature randomizer (Ch 15)Received word (Ch 19)Schnorr nonce (Ch 33). Decorated as rFRIr_\mathrm{FRI}, rFSr_\mathrm{FS}, routr_\mathrm{out} from Ch 34 on, never elided
ssSecond half of an ECDSA signature (Ch 4)LWE secret vectorOne-time secret-key slotSyndrome (Ch 19)Not reserved
eeRSA public exponent (Ch 4)LWE error vectorNot reservedError pattern in a received wordSchnorr challenge (Ch 33)
ddRSA private exponent / ECDSA private keyML-DSA dropped-bit count 13 (Ch 12), lattice dimension (Ch 13)Digest, MSS depth (Ch 14); WOTS+ digit (Ch 15); hypertree layers (Ch 17)Minimum distance of a codeDegree bound in Ch 32’s toy
kkECDSA per-message nonce (Ch 4, Ch 6)Module rank (Ch 9), ML-DSA matrix rows (Ch 12)FORS trees per signature (Ch 16)Code dimensionTarget PQ soundness in bits (Ch 34), and the commitment dimension in Ch 32’s scalar toy
ccNot reservedML-DSA challenge polynomial (Ch 12)Not reservedTransmitted codeword (Ch 19)Reed-Solomon codeword (Ch 34)
hhNot reservedML-DSA hint vector (Ch 12)Merkle / XMSS tree height (Ch 15)HQC quasi-cyclic public element (Ch 19, Ch 21)Schnorr public relation h=gxh = g^x (Ch 33)
μ\muNot reservedML-DSA message representative (Ch 12)Not reservedNot reservedFRI query paths (Ch 34)
ρ\rhoNot reservedML-DSA matrix seed (Ch 12)Not reservedNot reservedCode rate (Ch 34)
ttNot reserved bareNot reserved bareFORS leaves per tree (Ch 16)Error-correcting capability (Ch 19), MQ target vector (Ch 24)Not reserved bare
ggGenerator of a cyclic group (Ch 2)Not reservedNot reservedNot reservedGrinding-bit count on the Fiat-Shamir transcript (Ch 34), and the Schnorr group generator (Ch 33)
BBLattice basis matrix in Ch 3’s exerciseLattice basis matrix (Ch 7); also the scalar noise bound ermB\lvert e^\top r \rvert \leq mB in Regev-style LWE correctness arguments (Ch 8, Ch 10)Not reservedNot reservedNot reserved
HHHash in an abstract game (Ch 5)SHA3-256 in ML-KEM’s function table (Ch 11), ML-DSA’s general hash SHAKE-256 (Ch 12)Cryptographic hash function (Ch 14)Parity-check matrix (Ch 19)Random-oracle hash (Ch 33)
TTNot reservedNot reservedMerkle authentication path (Ch 14)Not reservedTrace domain (Ch 34)
β\betaInteger coefficient in Ch 3’s lattice definitionML-DSA box margin τη\tau\eta (Ch 12), BKZ block size (Ch 13)Not reservedNot reservedFRI fold challenge
δ0\delta_0Not reservedNot reservedNot reservedNot reservedProximity-gap threshold in Hamming distance (Ch 34)
ζ\zetaNot reservedML-KEM’s primitive 256th root of unity ζ=17\zeta = 17 in Z3329\mathbb{Z}_{3329} (Ch 11, FIPS 203); ML-DSA’s primitive 512th root ζ=1753\zeta = 1753 in Z8380417\mathbb{Z}_{8380417} (Ch 12, FIPS 204). Not used in Ch 13. The LWE secret-error standard deviation in Ch 13’s primal and dual sections is σ\sigma, matching the Kyber Round 3 submission.Not reservedNot reservedNot reserved

Part II reuses three symbols across its own chapters. β\beta is the ML-DSA box margin τη\tau\eta in Chapter 12 and the BKZ block size in Chapter 13. ζ\zeta is ML-KEM’s primitive 256th root of unity in Chapter 11 and ML-DSA’s primitive 512th root in Chapter 12. The modulus qq is 3329 for ML-KEM and 8380417 for ML-DSA. Each is defined at its point of use. The Part II reservation table below splits β\beta across two rows.

Chapter 14 reuses dd internally for two quantities: the message digest d=H(m)d = H(m) in the Lamport sections and the MSS tree depth from the many-time signature section onward. Part III reuses dd in two more chapters. Ch 15 uses dd for the WOTS+ digit value, the base-ww encoding of the message digest. Ch 17 uses dd for the SLH-DSA hypertree layer count per FIPS 205 (for example, d=7d = 7 for SLH-DSA-SHA2-192s). The Part III reservation table splits these uses across rows. Ch 15 reserves hh for XMSS tree height per RFC 8391.

Introduced in Chapters 1 through 6. These symbols propagate into every later part.

SymbolMeaningFirst used
nnModulus for modular arithmetic (also overloaded in later parts)Chapter 2
Z/nZ\mathbb{Z}/n\mathbb{Z}Ring of integers modulo nnChapter 2
Fp\mathbb{F}_pFinite field with pp elements, pp primeChapter 2
Fp\mathbb{F}_p^*Multiplicative group of Fp\mathbb{F}_pChapter 2
ggGenerator of a cyclic groupChapter 2
φ(n)\varphi(n)Euler totient functionChapter 2
Fp[x]\mathbb{F}_p[x]Polynomial ring over Fp\mathbb{F}_pChapter 2
Fp[x]/(f(x))\mathbb{F}_p[x]/(f(x))Quotient ring by the ideal (f(x))(f(x))Chapter 2
Φm(x)\Phi_m(x)mmth cyclotomic polynomial; for nn a power of two, Φ2n(x)=xn+1\Phi_{2n}(x) = x^n + 1Chapter 2
deg(f)\deg(f)Degree of a polynomial, with deg(0)=\deg(0) = -\infty by conventionChapter 2
(p,q,n,e,d)(p, q, n, e, d)RSA key-parameter tuple: distinct primes p,qp, q; modulus n=pqn = pq; public exponent ee; private exponent ddChapter 4
rrMultiplicative order of a base mod nn, Shor’s period in the toy factoring walkChapter 4
λ\lambdaSecurity parameter, in bitsChapter 5 (introduced alongside the key-agreement API, where the chapter separates it from the shared-secret length K\ell_K); also appears as the chord slope in Chapter 4’s EC group law
K\ell_KBit length of a KEM or key-agreement shared secret; matched to λ\lambda at design time but a separate quantity, since ML-KEM outputs 256 bits at every parameter setChapter 5
Pr[E]\Pr[E]Probability of event EEChapter 5
negl(λ)\mathsf{negl}(\lambda)Negligible function in λ\lambdaChapter 6
(d,k,r,s,N)(d, k, r, s, N)ECDSA signature tuple: private key dd; nonce kk; signature pair (r,s)(r, s); curve group order NNChapter 4 (built there), reused in Chapter 6’s nonce-reuse recovery
X,Y,ZX, Y, ZMosca’s inequality: XX the useful lifetime of the secret in years, YY the time to migrate, ZZ the time until a CRQC exists. The asset is exposed when X+Y>ZX + Y > ZChapter 1, specialized and reused throughout Part VII

Introduced in Chapters 7 through 13. Centered on LWE, Module-LWE, ML-KEM, and ML-DSA. Letters marked with \dagger collide with a letter reserved in another part or, for β\beta, with a second use inside Part II. The collision table at the top gives the resolution.

SymbolMeaningFirst used
L(B)L(B)Lattice generated by basis BBChapter 7
BBBasis matrix, columns are basis vectors (distinct from the scalar noise bound BB used in Ch 8 and Ch 10 LWE correctness arguments, and the collision table at the top of this appendix records the split)Chapter 7
bib_iThe ii-th basis vectorChapter 7
UUUnimodular change-of-basis matrixChapter 7
GLn(Z)\mathrm{GL}_n(\mathbb{Z})Group of n×nn \times n unimodular integer matricesChapter 7
det(L)\det(L)Determinant of a latticeChapter 7
P(B)\mathcal{P}(B)Fundamental parallelepiped of basis BBChapter 7
LL^*Dual lattice of LLChapter 7
BTB^{-T}Dual basis, (B1)T(B^{-1})^TChapter 7
λi(L)\lambda_i(L)The ii-th successive minimum of LLChapter 7
ss \daggerLWE secret vectorChapter 8
ee \daggerLWE error vectorChapter 8
χ\chiError distribution, usually centered binomialChapter 8
qq \daggerRing modulus in the lattice construction, 3329 for ML-KEMChapter 8
AAPublic-key sample matrix in (A,As+e)(A, As + e)Chapter 8
aaA row of AA, LWE public vectorChapter 8
ζ2n\zeta_{2n}Primitive 2n2nth root of unity, cyclotomic framing of Ring-LWEChapter 9
RqR_qPolynomial ring Zq[x]/(xn+1)\mathbb{Z}_q[x]/(x^n+1)Chapter 9
kk \daggerModule rank, Module-LWE and ML-KEMChapter 9
η1,η2\eta_1, \eta_2Centered binomial noise widths in ML-KEM (η1=η2=2\eta_1 = \eta_2 = 2 for ML-KEM-768)Chapter 11
ζ\zetaML-KEM’s primitive 256th root of unity in Z3329\mathbb{Z}_{3329}, ζ=17\zeta = 17Chapter 11
du,dvd_u, d_vCiphertext compression widths in ML-KEM (du=10,dv=4d_u = 10, d_v = 4 for ML-KEM-768)Chapter 11
\ellML-DSA column dimension: columns of A\mathbf{A}, height of s1,y,z\mathbf{s}_1, \mathbf{y}, \mathbf{z}Chapter 12
η\etaML-DSA secret coefficient bound: s1,s2\mathbf{s}_1, \mathbf{s}_2 have coefficients in [η,η][-\eta, \eta]Chapter 12
τ\tauML-DSA challenge weight: number of ±1\pm 1 coefficients in the challenge ccChapter 12
γ1\gamma_1ML-DSA mask bound: y\mathbf{y} has coefficients in (γ1,γ1](-\gamma_1, \gamma_1]Chapter 12
γ2\gamma_2ML-DSA low-order rounding window used by DecomposeChapter 12
β\beta \daggerML-DSA box margin β=τη\beta = \tau\eta, bounding the challenge-times-secret product cs1\lVert c\mathbf{s}_1 \rVert_\infty and supplying the rejection margin, so an accepted response is bounded by γ1β\gamma_1 - \beta rather than by β\beta (distinct from the BKZ block size β\beta in Chapter 13, and the collision table records the split)Chapter 12
ω\omegaML-DSA hint budget: maximum number of set bits in the hint h\mathbf{h}Chapter 12
ddML-DSA dropped-bit count in Power2Round (d=13d = 13)Chapter 12
t,t1,t0\mathbf{t}, \mathbf{t}_1, \mathbf{t}_0ML-DSA public vector t=As1+s2\mathbf{t} = \mathbf{A}\mathbf{s}_1 + \mathbf{s}_2 and its Power2Round splitChapter 12
s1,s2\mathbf{s}_1, \mathbf{s}_2ML-DSA secret and error vectorsChapter 12
y,z\mathbf{y}, \mathbf{z}ML-DSA signing mask and response z=y+cs1\mathbf{z} = \mathbf{y} + c\mathbf{s}_1Chapter 12
w,w1\mathbf{w}, \mathbf{w}_1ML-DSA commitment w=Ay\mathbf{w} = \mathbf{A}\mathbf{y} and its high bits HighBits(w)\mathrm{HighBits}(\mathbf{w})Chapter 12
cc \daggerML-DSA challenge polynomial: exactly τ\tau nonzero ±1\pm 1 coefficientsChapter 12
c~\tilde cML-DSA challenge hash c~=H(μw1Encode(w1))\tilde c = H(\mu \mathbin\Vert \mathrm{w1Encode}(\mathbf{w}_1))Chapter 12
h\mathbf{h} \daggerML-DSA hint vector, one bit per coefficientChapter 12
μ\mu \daggerML-DSA message representative μ=H(trM)\mu = H(\mathrm{tr} \mathbin\Vert M')Chapter 12
ρ,ρ,ρ\rho, \rho', \rho'' \daggerML-DSA matrix seed, noise seed, and per-signature mask seedChapter 12
κ\kappaML-DSA mask counter, advances by \ell on each abort iterationChapter 12
mod±α\bmod^{\pm}\alphaCentered modular reduction, representative in (α/2,α/2](-\alpha/2, \alpha/2]Chapter 12
\lVert\cdot\rVert_\inftyInfinity norm on centered representativesChapter 12
β\beta \daggerBKZ block sizeChapter 13
δ(β)\delta(\beta)Root-Hermite factor at block size β\betaChapter 13

Introduced in Chapters 14 through 18. Centered on Lamport, Merkle trees, WOTS+, FORS, and SLH-DSA. In this part, nn means hash output length, not lattice dimension. The unit splits across the part: Chapter 14 works nn in bits (matching the Lamport digest length); Chapters 15 through 18 work nn in bytes in the scheme descriptions (matching the FIPS 205 and SPHINCS+ convention), and return to bits in the generic hash-cost discussions, where Chapters 17 and 18 state the unit at the point of use. Chapter 18’s Blocks 1 and 3 introduce the explicit n_bytes / n_bits = 8 * n_bytes pair so the switch is local and visible where both units are in play. Block 4’s quantum-cost table labels its bit variable n_bits directly, and the remaining blocks need neither.

SymbolMeaningFirst used
HH \daggerCryptographic hash function (SHA-256, SHAKE)Chapter 14
nn \daggerHash output length: in bits in Chapter 14, in bytes in the scheme descriptions of Chapters 15 through 18, in bits in their hash-cost discussionsChapter 14
s0(i),s1(i)s_0^{(i)}, s_1^{(i)}Lamport secret-key slots at bit position iiChapter 14
p0(i),p1(i)p_0^{(i)}, p_1^{(i)}Lamport public-key slots at bit position iiChapter 14
dd \daggerMessage digest d=H(m)d = H(m) (Lamport sections) and MSS tree depth (many-time signature section)Chapter 14
TT \daggerMerkle authentication pathChapter 14
hhMerkle tree height, XMSS tree height (RFC 8391 convention)Chapter 15
dd \daggerWOTS+ digit value, base-ww encoding of the message digestChapter 15
wwWOTS+ base (Winternitz parameter), usually 16Chapter 15
1,2\ell_1, \ell_2WOTS+ chain counts: message and checksumChapter 15
kk \daggerFORS trees per signatureChapter 16
tt \daggerFORS leaves per treeChapter 16
ADRS\mathrm{ADRS}SLH-DSA address structure: 32 bytes in the general form (FIPS 205 Section 4.2), compressed to 22 bytes for the SHA2 parameter sets (Section 11.2)Chapter 17
PRFk\mathsf{PRF}_kKeyed pseudorandom function with key kkChapter 17
dd \daggerNumber of hypertree layers in SLH-DSA (FIPS 205); d=7d = 7 for SLH-DSA-SHA2-192s, d=22d = 22 for SLH-DSA-SHA2-128fChapter 17

Part IV: Code-based and isogeny-based cryptography

Section titled “Part IV: Code-based and isogeny-based cryptography”

Introduced in Chapters 19 through 24. Code-based notation in Chapters 19 through 21. Isogeny notation in Chapters 22 and 23. The codewords on the wire, the syndromes and the error vectors in Chapters 19 through 21 are binary, over GF(2)\mathrm{GF}(2). The Goppa polynomial in Chapter 20 and HQC’s outer Reed-Solomon code in Chapter 21 live over binary extension fields GF(2m)\mathrm{GF}(2^m), the isogeny chapters work over Fp\mathbb{F}_p and Fp2\mathbb{F}_{p^2}, and Chapter 24’s multivariate toy works over the prime field GF(7)\mathrm{GF}(7). The length-dimension-distance triple is written unsubscripted.

SymbolMeaningFirst used
F2m\mathbb{F}_{2^m}Binary extension field, mm the extension degree; Chapter 20 writes it GF(2m)\mathrm{GF}(2^m)Chapter 20
[n,k,d][n, k, d]Linear code parameters: length nn, dimension kk, minimum distance dd, over GF(2)\mathrm{GF}(2)Chapter 19
CCLinear code, subspace of GF(2)n\mathrm{GF}(2)^nChapter 19
GGGenerator matrix (k×nk \times n) of a linear codeChapter 19
HH \daggerParity-check matrix ((nk)×n(n-k) \times n), distinct from Part III’s hash functionChapter 19
rr \daggerReceived word r=c+er = c + e, where cc is the transmitted codewordChapter 19
ss \daggerSyndrome, s=HrTs = H \cdot r^T (column convention used throughout Part IV)Chapter 19
tt \daggerError-correcting capability of a code, t=(d1)/2t = \lfloor (d-1)/2 \rfloorChapter 19
Fp\mathbb{F}_p, Fp2\mathbb{F}_{p^2}Prime field and its quadratic extension, the fields the supersingular curves of Chapters 22 and 23 are defined overChapter 22
E0,E1,E_0, E_1, \ldotsSupersingular elliptic curves in an isogeny pathChapter 22
φ\varphiIsogeny map between elliptic curvesChapter 22
j(E)j(E)jj-invariant of an elliptic curveChapter 22
\ell-isogenyIsogeny of prime degree \ellChapter 22
O\mathcal{O}Order in a quaternion algebra (SQIsign)Chapter 23

Part V does not introduce new mathematical notation; it reuses Part II and Part III symbols when referencing the constructions those parts built.

Introduced in Chapters 31 through 35. Chapter 34 Section 3 (“AIR, LDE, and the Reed-Solomon lift”) and Chapter 35 Table 35.1 each publish explicit reservation tables. The Part VI entries below summarize those tables. Where a chapter row carries a configuration caveat or a worked count, read the chapter’s own row for it. Part VI reuses several Part II and Part III letters with new meanings (notably qq, TT, gg, β\beta). The table below flags those collisions with \dagger and the top-of-appendix collision table gives the full resolution.

SymbolMeaningFirst used
ppSTARK field primeChapter 34
LLTrace lengthChapter 34
NNLDE domain size, usually N=L/ρN = L / \rhoChapter 34
ρ\rhoCode rate, ρ=L/N\rho = L / NChapter 34
rFRIr_\mathrm{FRI}Number of FRI folding roundsChapter 34
rFSr_\mathrm{FS}Number of Fiat-Shamir rounds on the transcriptChapter 34
μ\muNumber of independent FRI query paths: each picks one LDE position and follows it through every fold layerChapter 34
gg \daggerGrinding-bit count on the Fiat-Shamir transcriptChapter 34
qq \daggerAdversary’s quantum query budgetChapter 33
kk \daggerTarget post-quantum soundness, in bitsChapter 34
δ0\delta_0 \daggerProximity-gap threshold in Hamming distanceChapter 34
βi\beta_i \daggerFRI folding challenge at layer ii, drawn from the transcript hashChapter 34
D\mathbb{D}LDE evaluation domainChapter 34
TT \daggerTrace domain, a multiplicative subgroup of Fp×\mathbb{F}_p^{\times}, disjoint from the LDE evaluation domain, which is a coset of a larger subgroupChapter 34
ccReed-Solomon codeword, c=LDE(t)c = \mathrm{LDE}(t)Chapter 34
t(x)t(x)Trace polynomial of degree <L< LChapter 34
(L2,L4)(L_2, L_4)Grid cell label in the four-layer decomposition, classified in Table 31.2 and drawn as Figure 35.1Chapter 31, reserved for the case studies in Chapter 35
ksysk_\mathrm{sys}Target PQ bit margin at the system levelChapter 35
qsysq_\mathrm{sys}Adversary’s quantum query budget at the system threat modelChapter 35
routr_\mathrm{out}Fiat-Shamir rounds on an outer wrapper proofChapter 35
nhashn_\mathrm{hash}Hash-output bit width in a Part VI protocolChapter 35

Introduced in Chapters 36 through 41. Part VII does not build new mathematics. What it reserves is deployment notation, plus one specialization of a Part I reservation. Its dominant symbols are the Mosca triple XX, YY, ZZ from Chapter 1, which every chapter in the Part uses. Chapter 36 splits the first of them. For an asset on a public ledger, XX has an exposure lifetime, unbounded once a verification key is on-chain, and a value lifetime, which is how long that key still controls anything.

SymbolMeaningFirst used
XeffX_\mathrm{eff}Effective reuse window, substituted for XX in the breach check when a key or contract rotates on a fixed intervalChapter 40
NN \daggerValidator-set size in the normalized per-attestation byte budgetChapter 39
TT \daggerCosigner threshold in a threshold-signature proposalChapter 39
xxBLS signing scalar, xZqx \in \mathbb{Z}_qChapter 39
G1,G2G_1, G_2The two pairing source groups on BLS12-381; public keys in G1G_1, signatures in G2G_2Chapter 39
E1,E2E_1, E_2The curves underlying G1G_1 and G2G_2Chapter 39
qq \daggerOrder of the pairing groupsChapter 39
Kpar,GK_\mathrm{par}, GBIP-32 child-key derivation: parent point and curve generator, with Ki=Kpar+tGK_i = K_\mathrm{par} + tGChapter 38
tt \daggerBIP-32 tweak scalar in that derivationChapter 38
ξ\xi32-byte secret seed passed to ML-DSA.KeyGen_internal in the BIP-32-like seed schedule, distinct from the child chain code the same step producesChapter 38

Part VII reuses four letters that earlier Parts reserve, marked \dagger above and resolved here rather than in the top-of-appendix collision table, which is already six columns wide and would overflow the print measure with a seventh. NN is the LDE domain size in Part VI (Chapter 34) and the curve group order in Part I’s ECDSA tuple; in Chapter 39 it is the validator count. TT is the Merkle authentication path in Part III (Chapter 14) and the trace domain in Part VI (Chapter 34); in Chapter 39 it is a cosigner threshold. qq is the lattice modulus in Part II, the field order in Part IV, and the quantum query budget in Part VI; in Chapter 39 it is the pairing-group order. tt is the FORS leaf count in Part III and the error-correcting capability in Part IV; in Chapter 38 it is the BIP-32 tweak scalar. Each is defined at its point of use.

A few notation conventions hold throughout the book and are not individually reserved in any chapter:

  • In Parts II and VI, bold lowercase letters (s,e,a\mathbf{s}, \mathbf{e}, \mathbf{a}) denote vectors and bold uppercase (A,B\mathbf{A}, \mathbf{B}) denote matrices. Part IV follows the coding-theory convention and uses non-bold uppercase for matrices (GG, HH, AA). The dimension is always stated at first use.
  • Set-builder notation uses {xX:P(x)}\{ x \in X : P(x) \}, never the shorthand with a mid-line bar.
  • log\log without a base is base 2, matching the cryptographic convention. Natural log is written ln\ln.
  • Attack costs and security levels name their unit at the figure, because the book uses four that are not interchangeable: bits of classical work, idealized oracle queries (Chapter 18’s BHT and Grover figures), proxy operations under a stated model (Chapter 13’s core-SVP exponent), and soundness-error bits at a stated adversary budget (Part VI).
  • Gate, depth and memory counts under an explicit circuit model appear where a figure is compared against NIST’s security categories, and the MAXDEPTH bound belongs to that comparison model rather than to every quantum figure in the book.
  • Cryptographic hash output is written in lowercase hex throughout.