Post Quantum Cryptography: An Introduction Shweta Agrawal IIT Madras 1 Introduction Cryptography is a rich and elegant field of study that has enjoyed enormous success over the last few decades. As reflected in NIST's April 2016 work on the development of post-quantum public-key cryptographic standards is underway, and the algorithm selection process is well in-hand. With almost 25% of round 2 submissions, code-based cryptography stands as a major candidate for post-quantum cryptography. Quantum computers will break the security of almost all the public-key cryptosystems used in practice. Pursuing multiple candidates is also appropriate as the post-quantum cryptography field is young, and many years of cryptanalysis are needed to determine whether any post-quantum proposal is secure. This book introduces the reader to the next generation of cryptographic algorithms, the systems that resist quantum-computer attacks: in particular, post-quantum public-key encryption systems and post-quantum public-key signature systems. Lattice-based Cryptography Daniele Micciancio∗ Oded Regev† July 22, 2008 1 Introduction In this chapter we describe some of the recent progress in lattice-based cryptography. Lattice-based cryptographic constructions hold a great promise for post-quantum cryptography, as they enjoy very strong security properties. Post-quantum cryptography is an active area of research. Introduction to post-quantum cryptography • 1994: Shor introduced an algorithm that factors any RSA modulus n using (lgn)2+o(1) simple operations on a quantum computer of size (lgn)1+o(1). Cryptosystems that can resist these emerging attacks are called quantum resistant or post-quantum cryptosystems. This book constitutes the refereed proceedings of the 9th International Workshop on Post-Quantum Cryptography, PQCrypto 2018, held in Fort Lauderdale, FL, USA, in April 2018. 