A Gaussian Leftover Hash Lemma for Modules over Number Fields
Martin R. Albrecht, Joël Felderhoff, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo
Abstract
Leftover Hash Lemma (LHL) states that for a Gaussian is an essentially independent Gaussian sample. It has seen numerous applications in cryptography for hiding sensitive distributions of . We generalise the Gaussian LHL initially stated over by Agrawal, Gentry, Halevi, and Sahai (2013) to modules over number fields. Our results have a sub-linear dependency on the degree of the number field and require only polynomial norm growth: . To this end, we also prove when is surjective (assuming the Generalised Riemann Hypothesis) and give bounds on the smoothing parameter of the kernel of . We also establish when the resulting distribution is independent of the geometry of and establish the hardness of the -SIS and -LWE problems over modules (-MSIS/-MLWE) based on the hardness of SIS and LWE over modules (MSIS/MLWE) respectively, which was assumed without proof in prior works.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Linear Hashing with ℓ∞ guarantees and two-sided Kakeya boundsManik Dhar, Zeev DvirFOCS 2022 · 3 citations
- Leftover Hash Lemma(s) Over Cyclotomic RingsKatharina Boudgoust, Oleksandra LapihaEUROCRYPT 2026 · 3 citations
- Average Hardness of SIVP for Module Lattices of Fixed RankKoen de Boer, Aurel Page, Radu Toma, Benjamin WesolowskiSTOC 2026 · 5 citations
- Continuous LWE is as Hard as LWE & Applications to Learning Gaussian MixturesAparna Gupte, Neekon Vafa, Vinod VaikuntanathanFOCS 2022 · 15 citations
- Hardness of Hinted ISIS from the Space-Time Hardness of Lattice ProblemsMartin R. Albrecht, Russell W. F. Lai, Eamonn W. PostlethwaiteCRYPTO 2026
