English
Related papers

Related papers: Provably weak instances of Ring-LWE

200 papers

Learning with Errors is one of the fundamental problems in computational learning theory and has in the last years become the cornerstone of post-quantum cryptography. In this work, we study the quantum sample complexity of Learning with…

Quantum Physics · Physics 2019-03-27 Alex B. Grilo , Iordanis Kerenidis , Timo Zijlstra

We discuss the advantages and limitations of cyclotomic fields to have fast polynomial arithmetic within homomorphic encryption, and show how these limitations can be overcome by replacing cyclotomic fields by a family that we refer to as…

Cryptography and Security · Computer Science 2023-06-08 Iván Blanco-Chacón , Alberto Pedrouzo-Ulloa , Rahinatou Yuh Njah Nchiwo , Beatriz Barbero-Lucas

We show direct and conceptually simple reductions between the classical learning with errors (LWE) problem and its continuous analog, CLWE (Bruna, Regev, Song and Tang, STOC 2021). This allows us to bring to bear the powerful machinery of…

Cryptography and Security · Computer Science 2022-11-03 Aparna Gupte , Neekon Vafa , Vinod Vaikuntanathan

Learning with Errors (LWE) is a hard math problem used in post-quantum cryptography. Homomorphic Encryption (HE) schemes rely on the hardness of the LWE problem for their security, and two LWE-based cryptosystems were recently standardized…

Cryptography and Security · Computer Science 2023-10-30 Cathy Yuanchen Li , Emily Wenger , Zeyuan Allen-Zhu , Francois Charton , Kristin Lauter

The Learning with Errors (LWE) problem is a hard math problem in lattice-based cryptography. In the simplest case of binary secrets, it is the subset sum problem, with error. Effective ML attacks on LWE were demonstrated in the case of…

Cryptography and Security · Computer Science 2026-04-07 Alberto Alfarano , Eshika Saxena , Emily Wenger , François Charton , Kristin Lauter

We describe a decisional attack against a version of the PLWE problem in which the samples are taken from a certain proper subring of large dimension of the cyclotomic ring $\mathbb{F}_q[x]/(\Phi_{p^k}(x))$ with $k>1$ in the case where…

Cryptography and Security · Computer Science 2024-02-14 Iván Blanco-Chacón , Raúl Durán-Díaz , Rahinatou Yuh Njah Nchiwo , Beatriz Barbero-Lucas

We prove that the Ring Learning With Errors (RLWE) and the Polynomial Learning With Errors (PLWE) problems over the cyclotomic field $\mathbb{Q}(\zeta_n)$ are not equivalent. Precisely, we show that reducing one problem to the other…

Number Theory · Mathematics 2022-01-13 Antonio J. Di Scala , Carlo Sanna , Edoardo Signorini

Sparse binary LWE secrets are under consideration for standardization for Homomorphic Encryption and its applications to private computation. Known attacks on sparse binary LWE secrets include the sparse dual attack and the hybrid sparse…

Cryptography and Security · Computer Science 2024-10-11 Niklas Nolte , Mohamed Malhou , Emily Wenger , Samuel Stevens , Cathy Li , François Charton , Kristin Lauter

Learning with Errors (LWE) is a hard math problem underpinning many proposed post-quantum cryptographic (PQC) systems. The only PQC Key Exchange Mechanism (KEM) standardized by NIST is based on module~LWE, and current publicly available PQ…

Cryptography and Security · Computer Science 2023-11-01 Cathy Li , Jana Sotáková , Emily Wenger , Mohamed Malhou , Evrard Garcelon , Francois Charton , Kristin Lauter

Block ciphers are in widespread use since the 1970s. Their iterated structure is prone to numerous round invariant attacks for example in Linear Cryptanalysis (LC). The next step is to look at non-linear polynomial invariants cf.…

Cryptography and Security · Computer Science 2020-02-11 Nicolas T. Courtois

Currently deployed public-key cryptosystems will be vulnerable to attacks by full-scale quantum computers. Consequently, "quantum resistant" cryptosystems are in high demand, and lattice-based cryptosystems, based on a hard problem known as…

Cryptography and Security · Computer Science 2023-04-25 Emily Wenger , Mingjie Chen , François Charton , Kristin Lauter

Learning with Errors (LWE) is a hard math problem underlying recently standardized post-quantum cryptography (PQC) systems for key exchange and digital signatures. Prior work proposed new machine learning (ML)-based attacks on LWE problems…

Cryptography and Security · Computer Science 2024-02-05 Samuel Stevens , Emily Wenger , Cathy Li , Niklas Nolte , Eshika Saxena , François Charton , Kristin Lauter

Linear (or differential) cryptanalysis may seem dull topics for a mathematician: they are about super simple invariants characterized by say a word on n=64 bits with very few bits at 1, the space of possible attacks is small, and basic…

Cryptography and Security · Computer Science 2019-05-14 Nicolas T. Courtois , Aidan Patrick

The Learning with Errors (LWE) problem underlies modern lattice-based cryptography and is assumed to be quantum hard. Recent results show that estimating entanglement entropy is as hard as LWE, creating tension with quantum gravity and…

Quantum Physics · Physics 2025-10-20 Yunfei Wang , Xin Jin , Junyu Liu

In this paper, we propose an encrypted dynamic controller that executes an unlimited number of recursive homomorphic multiplications on a Ring Learning With Errors (Ring-LWE) based cryptosystem without bootstrapping. The proposed controller…

Systems and Control · Electrical Eng. & Systems 2025-12-30 Yeongjun Jang , Joowon Lee , Seonhong Min , Hyesun Kwak , Junsoo Kim , Yongsoo Song

We study the equivalence between the Ring Learning With Errors and Polynomial Learning With Errors problems for cyclotomic number fields,namely: we prove that both problems are equivalent via a polynomial noise increase as long as the…

Number Theory · Mathematics 2020-04-16 Iván Blanco Chacón

Any ideal in a number field can be factored into a product of prime ideals. In this paper we study the prime ideal shortest vector problem (SVP) in the ring $ \Z[x]/(x^{2^n} + 1) $, a popular choice in the design of ideal lattice based…

Cryptography and Security · Computer Science 2021-03-03 Yanbin Pan , Jun Xu , Nick Wadleigh , Qi Cheng

We provide a reduction of the Ring-LWE problem to Ring-LWE problems in subrings, in the presence of samples of a restricted form (i.e. $(a,b)$ such that $a$ is restricted to a multiplicative coset of the subring). To create and exploit such…

Cryptography and Security · Computer Science 2020-07-14 Katherine E. Stange

LWE-based cryptosystems are an attractive alternative to traditional ones in the post-quantum era. To minimize the storage cost of part of its public key - a $256 \times 640$ integer matrix, $\textbf{T}$ - a binary version of $\textbf{T}$…

Cryptography and Security · Computer Science 2019-04-10 Tikaram Sanyashi , M. Bhargav Sri Venkatesh , Kapil Agarwal , Manish Verma , Bernard Menezes

Lattice cryptography schemes based on the learning with errors (LWE) hardness assumption have been standardized by NIST for use as post-quantum cryptosystems, and by HomomorphicEncryption.org for encrypted compute on sensitive data. Thus,…

Cryptography and Security · Computer Science 2024-10-11 Emily Wenger , Eshika Saxena , Mohamed Malhou , Ellie Thieu , Kristin Lauter