Lune

CRYPTO2020顶会

Lattice Reduction for Modules, or How to Reduce ModuleSVP to ModuleSVP

Tamalika Mukherjee, Noah Stephens-Davidowitz

2020年份
16被引次数

摘要

We show how to generalize lattice reduction algorithms to module lattices. Specifically, we reduce γ\gamma-approximate ModuleSVP over module lattices with rank k≥2k \geq2 to γ′\gamma'-approximate ModuleSVP over module lattices with rank 2≤β≤k2 \leq \beta \leq k. To do so, we modify the celebrated slide-reduction algorithm of Gama and Nguyen to work with module filtrations, a high-dimensional generalization of the (Z\Z-)basis of a lattice.

The particular value of γ\gamma that we achieve depends on the underlying number field KK, the order R⊆OKR \subseteq \mathcal{O}_K, and the embedding (as well as, of course, kk, β\beta, and γ′\gamma'). However, for reasonable choices of these parameters, the resulting value of γ\gamma is surprisingly close to the one achieved by ``plain'' lattice reduction algorithms, which require an arbitrary SVP oracle in the same dimension. In other words, we show that ModuleSVP oracles are nearly as useful as SVP oracles for solving higher-rank instances of approximate ModuleSVP.

Our result generalizes the recent independent result of Lee, Pellet-Mary, Stehlé, and Wallet, which works in the important special case when β=2\beta = 2 and R=OKR = \mathcal{O}_K is the ring of integers of KK under the canonical embedding. Our reduction works for any β\beta dividing kk, as well as arbitrary orders R⊆OKR \subseteq \mathcal{O}_K and a larger class of embeddings. Indeed, at a high level our reduction can be thought of as a generalization of theirs in roughly the same way that block reduction generalizes LLL reduction.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get f44c8efc-2c1a-42f7-9ff5-c9d26c193341

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖