The problem of designing a lattice-based encryption scheme secure against Chosen Ciphertext Attack (CCA) was first solved by Peikert and Waters in (3). The most efficient construction known to date is the one of (1). CCA secure encryption schemes can also be obtained using a generic transformation from Identity Based Encryption (IBE) described in Chosen-Ciphertext Security from Identity-Based Encryption.

