Adeline Langlois and Damien Stehlé. “Worst-case to average-case reductions for module lattices.” Designs, Codes and Cryptography, 75(3):565–599, 2015.
Introduced Module LWE (MLWE), which generalizes Ring LWE by considering rank- modules over a polynomial ring . When this recovers Ring LWE; when this recovers plain LWE. The module structure interpolates between the two extremes, yielding a flexible parameter trade-off between efficiency and security assumptions. Kyber (ML-KEM) and Dilithium (ML-DSA), the NIST post-quantum standards, are based on Module LWE.