Integral Matrix Gram Root and Lattice Gaussian Sampling Without Floats
Léo Ducas, Steven D. Galbraith, Thomas Prest, Yang Yu
Abstract
Many advanced lattice based cryptosystems require to sample lattice points from Gaussian distributions. One challenge for this task is that all current algorithms resort to floating-point arithmetic (FPA) at some point, which has numerous drawbacks in practice: it requires numerical stability analysis, extra storage for high-precision, lazy/backtracking techniques for efficiency, and may suffer from weak determinism which can completely break certain schemes. In this paper, we give techniques to implement Gaussian sampling over general lattices without using FPA. To this end, we revisit the approach of Peikert, using perturbation sampling. Peikert’s approach uses continuous Gaussian sampling and some decomposition minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentΣ=AAt of the target covariance matrix minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentΣ. The suggested decomposition, e.g. the Cholesky decomposition, gives rise to a square matrix minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentA with real (not integer) entries. Our idea, in a nutshell, is to replace this decomposition by an integral one. While there is in general no integer solution if we restrict minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentA to being a square matrix, we show that such a decomposition can be efficiently found by allowing minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentA to be wider (say minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentn×9n). This can be viewed as an extension of Lagrange’s four-square theorem to matrices. In addition, we adapt our integral decomposition algorithm to the ring setting: for power-of-2 cyclotomics, we can exploit the tower of rings structure for improved complexity and compactness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ac8c9c1-6e49-47b1-9902-9b73fe006249Cited by top-tier papers5
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- GALACTICS: Gaussian Sampling for Lattice-Based Constant- Time Implementation of Cryptographic Signatures, RevisitedGilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque et al.CCS 2019 · 37 citations
- Compact Lattice Gadget and Its Applications to Hash-and-Sign SignaturesYang Yu, Huiwen Jia, Xiaoyun WangCRYPTO 2023 · 35 citations
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
- Toward a Secure Fixed-Point Implementation of the Falcon Signature SchemeDaniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas PrestCRYPTO 2026 · 1 citation
Related papers
- Maskaglia: A New, Efficient Approach to Masked Discrete Gaussian SamplingCalvin Abou Haidar, Thomas Espitau, Clément Hoffmann, Mehdi TibouchiCRYPTO 2026
- Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its ConsequencesXiuhan Lin, Mehdi Tibouchi, Yang Yu, Shiduo ZhangEUROCRYPT 2025 · 4 citations
- On Gaussian Sampling for q-ary Lattices and Linear Codes with Lee WeightMaiara F. Bollauf, Maja Lie, Cong LingCRYPTO 2025 · 1 citation
- Λολ: Functional Lattice CryptographyEric Crockett, Chris PeikertCCS 2016 · 21 citations
- HAWK with Hint: Algebraic Key Recovery from Side-Channel LeakageByoungchan Chi, Changmin Lee, Inhun LeeCCS 2026
