Attacks on the Search-RLWE problem with small errors
Hao Chen, Kristin Lauter, Katherine E. Stange

TL;DR
This paper introduces a novel attack on the search RLWE problem with small errors, exploiting subfield vulnerabilities and extending existing reductions, demonstrating practical vulnerabilities in certain cryptographic instances.
Contribution
The paper presents a new attack method on small-error RLWE, identifying subfield vulnerabilities and extending search-to-decision reductions to broader Galois fields.
Findings
Identified subfield vulnerabilities in Galois RLWE instances.
Successfully attacked multiple vulnerable RLWE instances.
Extended reduction results to general Galois fields with unramified primes.
Abstract
The Ring Learning-With-Errors (RLWE) problem shows great promise for post-quantum cryptography and homomorphic encryption. We describe a new attack on the non-dual search RLWE problem with small error widths, using ring homomorphisms to finite fields and the chi-squared statistical test. In particular, we identify a "subfield vulnerability" (Section 5.2) and give a new attack which finds this vulnerability by mapping to a finite field extension and detecting non-uniformity with respect to the number of elements in the subfield. We use this attack to give examples of vulnerable RLWE instances in Galois number fields. We also extend the well-known search-to-decision reduction result to Galois fields with any unramified prime modulus q, regardless of the residue degree f of q, and we use this in our attacks. The time complexity of our attack is O(nq2f), where n is the degree of K and f is…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Complexity and Algorithms in Graphs · Coding theory and cryptography
