English

Trace-based cryptanalysis of cyclotomic $R_{q,0}\times R_q$-PLWE for the non-split case

Cryptography and Security 2024-02-14 v5

Abstract

We describe a decisional attack against a version of the PLWE problem in which the samples are taken from a certain proper subring of large dimension of the cyclotomic ring Fq[x]/(Φpk(x))\mathbb{F}_q[x]/(\Phi_{p^k}(x)) with k>1k>1 in the case where q1(modp)q\equiv 1\pmod{p} but Φpk(x)\Phi_{p^k}(x) is not totally split over Fq\mathbb{F}_q. Our attack uses the fact that the roots of Φpk(x)\Phi_{p^k}(x) over suitable extensions of Fq\mathbb{F}_q have zero-trace and has overwhelming success probability as a function of the number of input samples. An implementation in Maple and some examples of our attack are also provided.

Keywords

Cite

@article{arxiv.2209.11962,
  title  = {Trace-based cryptanalysis of cyclotomic $R_{q,0}\times R_q$-PLWE for the non-split case},
  author = {Iván Blanco-Chacón and Raúl Durán-Díaz and Rahinatou Yuh Njah Nchiwo and Beatriz Barbero-Lucas},
  journal= {arXiv preprint arXiv:2209.11962},
  year   = {2024}
}

Comments

20 pages; 1 figure; Minor updates as per referee's requests; formatted for publication