Modeling and simulating the sample complexity of solving LWE using BKW-style algorithms
نویسندگان
چکیده
Abstract The Learning with Errors (LWE) problem receives much attention in cryptography, mainly due to its fundamental significance post-quantum cryptography. Among solving algorithms, the Blum-Kalai-Wasserman (BKW) algorithm, originally proposed for Parity Noise (LPN) problem, performs well, especially certain parameter settings cryptographic importance. BKW algorithm consists of two phases, reduction phase and phase. In this work, we study performance distinguishers used We show that Fast Fourier Transform (FFT) distinguisher from Eurocrypt’15 has same sample complexity as optimal distinguisher, when making number hypotheses. also via simulation it better than previous theory predicts develop a model matches simulations better. introduce an improved, pruned version FFT distinguisher. Finally, indicate, extensive experiments, dependency both LF2 amplification is limited.
منابع مشابه
Coded-BKW: Solving LWE Using Lattice Codes
In this paper we propose a new algorithm for solving the Learning With Errors (LWE) problem based on the steps of the famous Blum-Kalai-Wasserman (BKW) algorithm. The new idea is to introduce an additional procedure of mapping subvectors into codewords of a lattice code, thereby increasing the amount of positions that can be cancelled in each BKW step. The procedure introduces an additional noi...
متن کاملOn the complexity of the BKW algorithm on LWE
This work presents a study of the complexity of the Blum-Kalai-Wasserman (BKW) algorithm when applied to the Learning with Errors (LWE) problem, by providing refined estimates for the data and computational effort requirements for solving concrete instances of the LWE problem. We apply this refined analysis to suggested parameters for various LWE-based cryptographic schemes from the literature ...
متن کاملOn the asymptotic complexity of solving LWE
We provide for the first time an asymptotic comparison of all known algorithms for the search version of the Learning with Errors (LWE) problem. This includes an analysis of several lattice-based approaches as well as the combinatorial BKW algorithm. Our analysis of the lattice-based approaches defines a general framework, in which the algorithms of Babai, Lindner-Peikert and several pruning st...
متن کاملthe effect of task complexity on lexical complexity and grammatical accuracy of efl learners’ argumentative writing
بر اساس فرضیه شناخت رابینسون (2001 و 2003 و 2005) و مدل ظرفیت توجه محدود اسکهان (1998)، این تحقیق تاثیر پیچیدگی تکلیف را بر پیچیدگی واژگان و صحت گرامری نوشتار مباحثه ای 60 نفر از دانشجویان زبان انگلیسی بررسی کرد. میزان پیچیدگی تکلیف از طریق فاکتورهای پراکندگی-منابع تعیین شد. همه ی شرکت کنندگان به صورت نیمه تصادفی به یکی از سه گروه: (1) گروه موضوع، (2) گروه موضوع + اندیشه و (3) گروه موضوع + اندی...
15 صفحه اولLazy Modulus Switching for the BKW Algorithm on LWE
Some recent constructions based on LWE do not sample the secret uniformly at random but rather from some distribution which produces small entries. The most prominent of these is the binary-LWE problem where the secret vector is sampled from {0, 1}∗ or {−1, 0, 1}∗. We present a variant of the BKW algorithm for binary-LWE and other small secret variants and show that this variant reduces the com...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Cryptography and Communications
سال: 2022
ISSN: ['1936-2455', '1936-2447']
DOI: https://doi.org/10.1007/s12095-022-00597-0