A Hybrid Gaussian Sampler for Lattices over Rings

نویسندگان

  • Léo Ducas
  • Thomas Prest
چکیده

Gaussian sampling over lattices is a cornerstone of latticebased cryptography as it allows to build numerous cryptographic primitives. There are two main algorithms performing this task. The rst one is due to Klein (SODA 2000) and Gentry, Peikert and Vaikuntanathan (STOC 2008), and outputs vectors of good quality but runs rather slowly, in quadratic time. The second one is due to Peikert (CRYPTO 2010) and outputs vectors of slightly worse quality, but can be made to run in quasilinear time in the ring setting. We present a Gaussian Sampler optimized for lattices over the ring of integer of a cyclotomic number eld. At a high-level it works as Klein's sampler but uses an e cient variant of Peikert's sampler as a subroutine. The result is a new sampler that samples vectors with a quality close to Klein's sampler and achieves the same quasilinear complexity as Peikert's sampler. In practice, we get close to the best of both worlds.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A New Ring-Based SPHF and PAKE Protocol On Ideal Lattices

emph{ Smooth Projective Hash Functions } ( SPHFs ) as a specific pattern of zero knowledge proof system are fundamental tools to build many efficient cryptographic schemes and protocols. As an application of SPHFs, emph { Password - Based Authenticated Key Exchange } ( PAKE ) protocol is well-studied area in the last few years. In 2009, Katz and Vaikuntanathan described the first lattice-based ...

متن کامل

Completeness results for metrized rings and lattices

The Boolean ring $B$ of measurable subsets of the unit interval, modulo sets of measure zero, has proper radical ideals (for example, ${0})$ that are closed under the natural metric, but has no prime ideal closed under that metric; hence closed radical ideals are not, in general, intersections of closed prime ideals. Moreover, $B$ is known to be complete in its metric. Togethe...

متن کامل

Extending dark optical trapping geometries.

New counterpropagating geometries are presented for localizing ultracold atoms in the dark regions created by the interference of Laguerre-Gaussian laser beams. In particular dark helices, an "optical revolver," axial lattices of rings, and axial lattices of ring lattices of rings are considered and a realistic scheme for achieving phase stability is explored. The dark nature of these traps wil...

متن کامل

New complex and quaternion-hyperbolic re ection groups

We consider the automorphism groups of various Lorentzian lattices over the Eisenstein, Gaussian, and Hurwitz integers, and in some of them we nd reeection groups of nite index. These provide explicit constructions of new nite-covolume reeection groups acting on complex and quaternionic hyperbolic spaces of high dimensions. Speciically, we provide groups acting on C H n for all n < 6 and n = 7,...

متن کامل

An Efficient and Parallel Gaussian Sampler for Lattices

At the heart of many recent lattice-based cryptographic schemes is a polynomial-time algorithm that, given a ‘high-quality’ basis, generates a lattice point according to a Gaussian-like distribution. Unlike most other operations in lattice-based cryptography, however, the known algorithm for this task (due to Gentry, Peikert, and Vaikuntanathan; STOC 2008) is rather inefficient, and is inherent...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2015  شماره 

صفحات  -

تاریخ انتشار 2015