English

Module Lattice Security (Part IV): Probabilistic Polynomial Quantum Attack on Module-LWE over 2-Power Cyclotomics

Quantum Physics 2026-05-26 v2 Cryptography and Security Combinatorics Rings and Algebras

Abstract

We present a quantum attack on ML-KEM and related 2-power cyclotomic lattice schemes. Combining with Parts I-III, we provide an algorithm and verify the resulting approximation factor satisfies γ21<q/2=1664.5\gamma\le 21 < q/2=1664.5 for ML-KEM-1024, with a success probability 0.99\ge 0.99. We apply a tower decomposition of the Principal Ideal Problem (PIP) through the chain \Q\Q(ζ8)\Q(ζ2k)\Q\subset \Q(\zeta_8)\subset\cdots\subset \Q(\zeta_{2^k}) which yields a polynomial-time quantum algorithm costing O(n3log2n)O(n^3 \log^2 n) gates, O(n2logn)O(n^2 \log n) qubits, and poly(n)(n) classical bit operations. We extend the analysis to Falcon, Hawk, and NTRU over 2-power cyclotomic rings with polynomial-time quantum algorithms.

Cite

@article{arxiv.2605.17412,
  title  = {Module Lattice Security (Part IV): Probabilistic Polynomial Quantum Attack on Module-LWE over 2-Power Cyclotomics},
  author = {Ming-Xing Luo},
  journal= {arXiv preprint arXiv:2605.17412},
  year   = {2026}
}

Comments

You have to read previous three parts (Parts I, II, III, arXiv:2604.15858, arXiv:2604.22900, arXiv:2605.17404) before understanding this part. I will upload simulations of main results (https://github.com/Postquantumcheck/Test/issues)