Estimated Cost for Solving Generalized Learning with Errors Problem via Embedding Techniques
Estimated Cost for Solving Generalized Learning with Errors Problem via Embedding Techniques
复制标题
通过嵌入技术解决广义学习错误问题的估计成本
DOI:
10.1007/978-3-319-97916-8_6
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Takagi Tsuyoshi
中科院分区:
文献类型:
--
作者:
Wang Weiyao;Wang Yuntao;Takayasu Atsushi;Takagi Tsuyoshi
Estimating for the computational cost of solvinglearning with errors (LWE)problem is an indispensable research topic to the lattice-based cryptography in practice. For this purpose, theembeddingapproach is usually employed. The technique first constructs a basis matrix by embedding an LWE instance. At this stage, Kannan’s and Bai-Galbraith’s embeddings are believed to be the most efficient approaches for the standard and the binary LWE with secret vectors inand, respectively. Indeed, both methods work well with sufficiently many LWE samples. After the embedding phase, solving the unique shortest vector problem (uSVP) in the lattice spanned by the basis matrix results in solving the LWE. Recently, there are several lattice-based schemes whose secret vectors have special distributions, e.g., small elements and/or sparse vectors, have been proposed to realize efficient implementations. In this paper, to capture such settings and more, we study the LWE problem in a general setting. We analyze the LWE problem whose secret vectors are sampled from arbitrary distributions. Furthermore, we also study the problem when the number of samples is restricted. We believe that our work provides more general understanding of the hardness of LWE. Moreover, we propose ahalf-twisted embeddingthat contains the existing two embedding methods as special cases. This proposal enables us to analyze the hardness of LWE in a generic manner and sometimes provides improved attacks.
影响因子:
1.6
作者:
Albrecht, Martin R.;Cid, Carlos;Perret, Ludovic
通讯作者:
Perret, Ludovic