Skip to content
A lattice-based cryptographic library in Go
Go Makefile
Branch: master
Clone or download
Type Name Latest commit message Commit time
Failed to load latest commit information.
bfv Fixed failing BFV relinearization test (closes #7) Aug 22, 2019
ckks Initial commit Aug 12, 2019
dbfv Fixed failing BFV relinearization test (closes #7) Aug 22, 2019
dckks Fixed self assigments with in ckks_test.go Aug 13, 2019
documentation Initial commit Aug 12, 2019
examples Fixed failing BFV relinearization test (closes #7) Aug 22, 2019
ring Fixed failing BFV relinearization test (closes #7) Aug 22, 2019
utils improvements on bfv/params.go Aug 15, 2019
.gitignore Initial commit Aug 12, 2019
.travis.yml Travis build for all branches Sep 2, 2019
LICENSE Initial commit Aug 12, 2019
Makefile Initial commit Aug 12, 2019
NOTICE Initial commit Aug 12, 2019 added Lattigo logo to README Aug 17, 2019
go.sum improvements on bfv/params.go Aug 15, 2019

Lattigo: lattice-based cryptographic library in Go

The Lattigo library unleashes the potential of lattice-based cryptography in secure multiparty computation for modern software stacks.

Build Status

Lattigo is a Go package implementing lattice-based cryptographic primitives. The library features:

  • A pure Go implementation bringing code-simplicity and easy builds.
  • A public interface for an efficient multiprecision polynomial arithmetic layer.
  • Comparable performance to state-of-the-art C++ libraries.

Lattigo aims at enabling fast prototyping of secure-multiparty computation solutions based on distributed homomorphic cryptosystems, by harnessing Go's natural concurrency model.

Library overview

The library comprises the following sub-packages:

  • lattigo/ring: RNS-accelerated modular arithmetic operations for polynomials, including: RNS basis extension; RNS rescaling; number theoretic transform (NTT); uniform, Gaussian and ternary sampling.

  • lattigo/bfv: RNS-accelerated Fan-Vercauteren version of Brakerski's scale invariant homomorphic encryption scheme. It provides modular arithmetic over the integers.

  • lattigo/ckks: RNS-accelerated version of the Homomorphic Encryption for Arithmetic for Approximate Numbers (HEAAN, a.k.a. CKKS) scheme. It provides approximate arithmetic over the complex numbers.

  • lattigo/dbfv and lattigo/dckks: Distributed (or threshold) versions of the BFV and CKKS schemes that enable secure multiparty computation solutions with secret-shared secret keys.

  • lattigo/examples: Executable Go programs demonstrating the usage of the Lattigo library. Note that each subpackage includes test files that further demonstrates the usage of Lattigo primitives.

  • lattigo/utils: Supporting structures and functions.


v1.0b (17 Aug. 2019)

  • First public beta release

v1.0 (Sept. 2019)

  • Full godoc documentation
  • Memory optimizations

Upcoming features

  • Bootstrapping for CKKS
  • Network layer implementation of SMC-supporting protocols


The library is still at an experimental stage and should be used for research purposes only.


Lattigo is licenced under the Apache 2.0 License.


If you want to contribute to Lattigo or you have any suggestion, do not hesitate to contact us at


Please use the following BibTex entry for citing Lattigo:

    title = {Lattigo 1.0},
    howpublished = {Online: \url{}},
    month = aug,
    year = 2019,
    note = {EPFL-LCA1}


  1. Somewhat Practical Fully Homomorphic Encryption (
  2. A Full RNS Variant of FV Like Somewhat Homomorphic Encryption Schemes (
  3. An Improved RNS Variant of the BFV Homomorphic Encryption Scheme (
  4. Homomorphic Encryption for Arithmetic of Approximate Numbers (
  5. A Full RNS Variant of Approximate Homomorphic Encryption (
  6. Improved Bootstrapping for Approximate Homomorphic Encryption (
  7. Post-quantum key exchange - a new hope (
  8. Faster arithmetic for number-theoretic transforms (
  9. Speeding up the Number Theoretic Transform for Faster Ideal Lattice-Based Cryptography (
  10. Gaussian sampling in lattice-based cryptography (
You can’t perform that action at this time.