@dalias @risottobias @khm @ambiguous_yelp @sammi @joelanman What exaxtly do you mean "unproven"?
The consensus among lattice experts and cryptanalysts is that, while there is some algebraic structure to some schemes that might be interesting targets for future attacks, their security is pretty well understood. NTRU and whatnot have been around for longer than AES. Is AES "unproven"?