English

A Note on Discrete Gaussian Combinations of Lattice Vectors

Cryptography and Security 2014-01-13 v2 Combinatorics Probability

Abstract

We analyze the distribution of i=1mvi\bxi\sum_{i=1}^m v_i \bx_i where \bx1,...,\bxm\bx_1,...,\bx_m are fixed vectors from some lattice \cLRn\cL \subset \R^n (say Zn\Z^n) and v1,...,vmv_1,...,v_m are chosen independently from a discrete Gaussian distribution over Z\Z. We show that under a natural constraint on \bx1,...,\bxm\bx_1,...,\bx_m, if the viv_i are chosen from a wide enough Gaussian, the sum is statistically close to a discrete Gaussian over \cL\cL. We also analyze the case of \bx1,...,\bxm\bx_1,...,\bx_m that are themselves chosen from a discrete Gaussian distribution (and fixed). Our results simplify and qualitatively improve upon a recent result by Agrawal, Gentry, Halevi, and Sahai \cite{AGHS13}.

Keywords

Cite

@article{arxiv.1308.2405,
  title  = {A Note on Discrete Gaussian Combinations of Lattice Vectors},
  author = {Divesh Aggarwal and Oded Regev},
  journal= {arXiv preprint arXiv:1308.2405},
  year   = {2014}
}