Pre-2012: Various LWE & RLWE encryption (KEM) schemes with large ciphertext
size. Framework of DH-like key exchange construction appeared. No concrete
error reconciliation mechanism
2012: Ding et al. invented the first complete LWE & RLWE-based
Diffie-Hellman-like key exchange protocols (DING12)
2014: Peikert tweaked DING12 reconciliation slightly
2015: Bos et al. implemented PKT14 (BCNS)
2016: Alkim et al. improved BCNS (NewHope)
1