On the Lattice Isomorphism Problem, Quadratic Forms, Remarkable Lattices, and Cryptography
Léo Ducas, Wessel P. J. van Woerden
Abstract
A natural and recurring idea in the knapsack/lattice cryptography literature is to start from a lattice with remarkable decoding capability as your private key, and hide it somehow to make a public key. This is also how the code-based encryption scheme of McEliece (1978) proceeds. This idea has never worked out very well for lattices: ad-hoc approaches have been proposed, but they have been subject to ad-hoc attacks, using tricks beyond lattice reduction algorithms. On the other hand the framework offered by the Short Integer Solution (SIS) and Learning With Errors (LWE) problems, while convenient and well founded, remains frustrating from a coding perspective: the underlying decoding algorithms are rather trivial, with poor decoding performance. In this work, we provide generic realizations of this natural idea (independently of the chosen remarkable lattice) by basing cryptography on the lattice isomorphism problem (LIP). More specifically, we provide:
a worst-case to average-case reduction for search-LIP and distinguish-LIP within an isomorphism class, by extending techniques of Haviv and Regev (SODA 2014). a zero-knowledge proof of knowledge (ZKPoK) of an isomorphism.
This implies an identification scheme based on search-LIP. a key encapsulation mechanism (KEM) scheme and a hash-then-sign signature scheme, both based on distinguish-LIP. The purpose of this approach is for remarkable lattices to improve the security and performance of lattice-based cryptography. For example, decoding within poly-logarithmic factor from Minkowski's bound in a remarkable lattice would lead to a KEM resisting lattice attacks down to poly-logarithmic approximation factor, provided that the dual lattice is also close to Minkowski's bound. Recent works have indeed reached such decoders for certain lattices (Chor-Rivest, Barnes-Sloan), but these do not perfectly fit our need as their duals have poor minimal distance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e43830a-6bdc-4b12-85b6-bda4c0218eb3Cited by top-tier papers5
- Compact Lattice Gadget and Its Applications to Hash-and-Sign SignaturesYang Yu, Huiwen Jia, Xiaoyun WangCRYPTO 2023 · 35 citations
- Cryptanalysis of Rank-2 Module-LIP in Totally Real Number FieldsGuilhem Mureau, Alice Pellet-Mary, Georgii Pliatsok, Alexandre WalletEUROCRYPT 2024 · 17 citations
- Solving the Shortest Vector Problem in 20.63269n+o(n) Time on Random LatticesAmaury Pouly, Yixin ShenEUROCRYPT 2026 · 9 citations
- Solving the Tensor Isomorphism Problem for Special Orbits with Low Rank Points: Cryptanalysis and Repair of an Asiacrypt 2023 Commitment SchemeValerie Gilchrist, Laurane Marco, Christophe Petit, Gang TangCRYPTO 2024 · 4 citations
- Advanced Cryptography from Lattice Isomorphism - New Constructions of IBE and FHEHuck Bennett, Zhengnan Lai, Noah Stephens-DavidowitzCRYPTO 2026 · 1 citation
Related papers
- Exploiting the Complexity of Lattice Isomorphism Problem via Irreducible DecompositionKaijie Jiang, Yinchen LiuCRYPTO 2026
- Cryptanalysis of Definite and Indefinite Lattice Isomorphism Problems with Applications to DEFIMarkus Kirschmer, Cong Ling, Ali SadreddinCRYPTO 2026
- Key-Homomorphic Computations for RAM: Fully Succinct Randomised Encodings and MoreDamiano Abram, Giulio Malavolta, Lawrence RoyCRYPTO 2025 · 6 citations
- Hollow LWE: A New Spin - Unbounded Updatable Encryption from LWE and PCEMartin R. Albrecht, Benjamin Bencina, Russell W. F. LaiEUROCRYPT 2025 · 6 citations
- Reduction from Sparse LPN to LPN, Dual Attack 3.0Kévin Carrier, Thomas Debris-Alazard, Charles Meyer-Hilfiger, Jean-Pierre TillichEUROCRYPT 2024 · 13 citations
