首页> 外文期刊>Designs, Codes and Crytography >Worst-case to average-case reductions for module lattices
【24h】

Worst-case to average-case reductions for module lattices

机译:模块格的最坏情况到平均情况的减少

获取原文
获取原文并翻译 | 示例
       

摘要

Most lattice-based cryptographic schemes are built upon the assumed hardness of the Short Integer Solution (SIS) and Learning With Errors (LWE) problems. Their efficiencies can be drastically improved by switching the hardness assumptions to the more compact Ring-SIS and Ring-LWE problems. However, this change of hardness assumptions comes along with a possible security weakening: SIS and LWE are known to be at least as hard as standard (worst-case) problems on euclidean lattices, whereas Ring-SIS and Ring-LWE are only known to be as hard as their restrictions to special classes of ideal lattices, corresponding to ideals of some polynomial rings. In this work, we define the Module-SIS and Module-LWE problems, which bridge SIS with Ring-SIS, and LWE with Ring-LWE, respectively. We prove that these average-case problems are at least as hard as standard lattice problems restricted to module lattices (which themselves bridge arbitrary and ideal lattices). As these new problems enlarge the toolbox of the lattice-based cryptographer, they could prove useful for designing new schemes. Importantly, the worst-case to average-case reductions for the module problems are (qualitatively) sharp, in the sense that there exist converse reductions. This property is not known to hold in the context of Ring-SIS/Ring-LWE: Ideal lattice problems could reveal easy without impacting the hardness of Ring-SIS/Ring-LWE.
机译:大多数基于晶格的加密方案都基于短整数解(SIS)和带错误学习(LWE)问题的假定硬度。通过将硬度假设切换到更紧凑的Ring-SIS和Ring-LWE问题,可以大大提高其效率。但是,这种硬度假设的变化会伴随可能的安全性减弱:已知SIS和LWE至少与欧氏晶格上的标准(最坏情况)问题一样困难,而Ring-SIS和Ring-LWE仅已知于尽可能严格地限制理想格的特殊类别(对应于某些多项式环的理想)。在这项工作中,我们定义了Module-SIS和Module-LWE问题,它们分别将SIS与Ring-SIS以及LWE与Ring-LWE桥接在一起。我们证明了这些平均情况问题至少与限制于模块晶格(其自身桥接任意和理想晶格)的标准晶格问题一样困难。随着这些新问题扩大了基于格的密码学家的工具箱,它们可能被证明对设计新方案很有用。重要的是,就模数问题而言,从最坏情况到平均情况的减少在本质上是急剧的,从某种意义上说,存在相反的减少。在Ring-SIS / Ring-LWE的上下文中尚不知道该属性:理想的晶格问题可以很容易地揭示出来,而不会影响Ring-SIS / Ring-LWE的硬度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号