Lune

EUROCRYPT2026Top-tier venue

A Gaussian Leftover Hash Lemma for Modules over Number Fields

Martin R. Albrecht, Joël Felderhoff, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo

2026Year

Abstract

Leftover Hash Lemma (LHL) states that X⋅v\mathbf{X} \cdot \mathbf{v} for a Gaussian v\mathbf{v} is an essentially independent Gaussian sample. It has seen numerous applications in cryptography for hiding sensitive distributions of v\mathbf{v}. We generalise the Gaussian LHL initially stated over Z\mathbb{Z} by Agrawal, Gentry, Halevi, and Sahai (2013) to modules over number fields. Our results have a sub-linear dependency on the degree of the number field and require only polynomial norm growth: ∥v∥/∥X∥\lVert\mathbf{v}\rVert/\lVert\mathbf{X}\rVert. To this end, we also prove when X\mathbf{X} is surjective (assuming the Generalised Riemann Hypothesis) and give bounds on the smoothing parameter of the kernel of X\mathbf{X}. We also establish when the resulting distribution is independent of the geometry of X\mathbf{X} and establish the hardness of the kk-SIS and kk-LWE problems over modules (kk-MSIS/kk-MLWE) based on the hardness of SIS and LWE over modules (MSIS/MLWE) respectively, which was assumed without proof in prior works.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines