Subfield Algorithms for Ideal- and Module-SVP Based on the Decomposition Group
Christian Porter, Andrew Mendelsohn, Cong Ling

TL;DR
This paper explores how the decomposition group of cyclotomic rings can be used to reduce the complexity of solving SVP, revealing potential vulnerabilities in lattice-based cryptography.
Contribution
It introduces a method leveraging the decomposition group of cyclotomic rings to lower the dimension of ideal lattices needed for SVP solutions, impacting cryptographic security.
Findings
Decomposition group can significantly reduce ideal lattice dimension for SVP.
Many primes lead to easier SVP instances when ideal factors lie over certain primes.
Work does not compromise Ring-LWE security due to its reduction from worst-case SVP.
Abstract
Whilst lattice-based cryptosystems are believed to be resistant to quantum attack, they are often forced to pay for that security with inefficiencies in implementation. This problem is overcome by ring- and module-based schemes such as Ring-LWE or Module-LWE, whose keysize can be reduced by exploiting its algebraic structure, allowing for faster computations. Many rings may be chosen to define such cryptoschemes, but cyclotomic rings, due to their cyclic nature allowing for easy multiplication, are the community standard. However, there is still much uncertainty as to whether this structure may be exploited to an adversary's benefit. In this paper, we show that the decomposition group of a cyclotomic ring of arbitrary conductor can be utilised to significantly decrease the dimension of the ideal (or module) lattice required to solve a given instance of SVP. Moreover, we show that there…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Coding theory and cryptography · Cryptographic Implementations and Security
