High-Speed Masking for Polynomial Comparison in Lattice-based KEMs. (2020). IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(3), 483-507. https://doi.org/10.13154/tches.v2020.i3.483-507