Λολ: Functional Lattice Cryptography
Eric Crockett, Chris Peikert
Abstract
This work describes the design, implementation, and evaluation of Λ•λ, a general-purpose software framework for lattice-based cryptography. The Λ•λ framework has several novel properties that distinguish it from prior implementations of lattice cryptosystems, including the following. Generality, modularity, concision: Λ•λ defines a collection of general, highly composable interfaces for mathematical operations used across lattice cryptography, allowing for a wide variety of schemes to be expressed very naturally and at a high level of abstraction. For example, we implement an advanced fully homomorphic encryption (FHE) scheme in as few as 2-5 lines of code per feature, via code that very closely matches the scheme's mathematical definition. Theory affinity: Λ•λ is designed from the ground-up around the specialized ring representations, fast algorithms, and worst-case hardness proofs that have been developed for the Ring-LWE problem and its cryptographic applications. In particular, it implements fast algorithms for sampling from theoryrecommended error distributions over arbitrary cyclotomic rings, and provides tools for maintaining tight control of error growth in cryptographic schemes. Safety: Λ•λ has several facilities for reducing code complexity and programming errors, thereby aiding the correct implementation of lattice cryptosystems. In particular, it uses strong typing to statically enforce-i.e., at compile time-a wide variety of constraints among the various parameters. Advanced features: Λ•λ exposes the rich hierarchy of cyclotomic rings to cryptographic applications. We use this to give the first-ever implementation of a collection of FHE operations known as "ring switching," and also define and analyze a more efficient variant that we call "ring tunneling." Lastly, this work defines and analyzes a variety of mathematical objects and algorithms for the recommended usage of Ring-LWE in cyclotomic rings, which we believe will serve as a useful knowledge base for future implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fe496743-4417-4606-a89e-3303ff1d8bc6Cited by top-tier papers3
- SoK: Fully Homomorphic Encryption CompilersAlexander Viand, Patrick Jattke, Anwar HithnawiS&P 2021 · 117 citations
- ALCHEMY: A Language and Compiler for Homomorphic Encryption Made easYEric Crockett, Chris Peikert, Chad SharpCCS 2018 · 68 citations
- Fast Homomorphic Evaluation of LWR-based PRFsAmit Deo, Marc Joye, Benoît Libert, Benjamin R. Curtis et al.CCS 2025
Builds on2
Related papers
- Revisiting Shamir Secret Sharing for Threshold Fully Homomorphic EncryptionJiseung Kim, Seunghu Kim, Hyung Tae LeeCCS 2026
- HERMES: Efficient Ring Packing Using MLWE Ciphertexts and Application to TranscipheringYoungjin Bae, Jung Hee Cheon, Jaehyung Kim, Jai Hyun Park et al.CRYPTO 2023 · 36 citations
- Fully Homomorphic Encryption for Matrix ArithmeticCraig Gentry, Yongwoo LeeCRYPTO 2026 · 4 citations
- Libra: Pattern-Scheduling Co-Optimization for Cross-Scheme FHE Code Generation over GPGPUSong Bian, Yintai Sun, Zian Zhao, Haowen Pan et al.USENIX Security 2026
- ZHE: Efficient Zero-Knowledge Proofs for HE EvaluationsZhelei Zhou, Yun Li, Yuchen Wang, Zhaomin Yang et al.S&P 2025
