English

Worst-Case Hermite-Korkine-Zolotarev Reduced Lattice Bases

Number Theory 2008-01-24 v2 Computational Complexity Cryptography and Security

Abstract

The Hermite-Korkine-Zolotarev reduction plays a central role in strong lattice reduction algorithms. By building upon a technique introduced by Ajtai, we show the existence of Hermite-Korkine-Zolotarev reduced bases that are arguably least reduced. We prove that for such bases, Kannan's algorithm solving the shortest lattice vector problem requires dd2\e(1+o(1))d^{\frac{d}{2\e}(1+o(1))} bit operations in dimension dd. This matches the best complexity upper bound known for this algorithm. These bases also provide lower bounds on Schnorr's constants αd\alpha_d and βd\beta_d that are essentially equal to the best upper bounds. Finally, we also show the existence of particularly bad bases for Schnorr's hierarchy of reductions.

Keywords

Cite

@article{arxiv.0801.3331,
  title  = {Worst-Case Hermite-Korkine-Zolotarev Reduced Lattice Bases},
  author = {Guillaume Hanrot and Damien Stehlé},
  journal= {arXiv preprint arXiv:0801.3331},
  year   = {2008}
}