Results 1  10
of
81,276
On the Efficacy of Solving LWE by Reduction to UniqueSVP
"... Abstract. We present a study of the concrete complexity of solving instances of the unique shortest vector problem (uSVP). In particular, we study the complexity of solving the Learning with Errors (LWE) problem by reducing the BoundedDistance Decoding (BDD) problem to uSVP and attempting to solve ..."
Abstract

Cited by 5 (1 self)
 Add to MetaCart
Abstract. We present a study of the concrete complexity of solving instances of the unique shortest vector problem (uSVP). In particular, we study the complexity of solving the Learning with Errors (LWE) problem by reducing the BoundedDistance Decoding (BDD) problem to uSVP and attempting to solve
LWE Hardness
, 2013
"... We sketch the proof due to Regev [Reg09] and Peikert [Pei09] that (under certain conditions) it is possible to relate the averagecase hardness of the learning with errors problem (LWE) to the worstcase hardness of bounded distance decoding in a given lattice (BDD). Preliminaries. We have the follo ..."
Abstract
 Add to MetaCart
vector z ∈ L has probability mass proportional to Ds(z). 1 The Main Lemma In addition to an oracle that solves LWE, the reduction from BDD in a lattice L to the averagecase LWE, also needs access to an oracle that samples short vectors in L ∗. (Regev [Reg09] and
Mahabir Prasad JhanwarDefinition LWE problem Hardness of LWE Cryptographic Applications
, 2012
"... Fix a size parameter n ≥ 1, a modulus q ≥ 2, and an “error " probability distribution χ: Zq → R + on Zq. For a s ∈R Z n q, let As,χ be a probability distribution on Z n q × Zq obtained by choosing a vector a ∈R Z n q, choosing e ∈χ Zq and outputting the pair (a, 〈a, s 〉 + e mod q) We say that a ..."
Abstract
 Add to MetaCart
that an algorithm solves LWEq,χ if, for any s ∈ Z n q, given an arbitrary number of independent samples from As,χ it outputs s with high probability.
A Generator for LWE and RingLWE Instances
"... Abstract. We introduce software for the generation of instances of the LWE and RingLWE problems, allowing both the generation of generic instances and also particular instances closelyrelated to those arising from cryptomania proposals in the literature. Our goal is to allow researchers to attack ..."
Abstract
 Add to MetaCart
Abstract. We introduce software for the generation of instances of the LWE and RingLWE problems, allowing both the generation of generic instances and also particular instances closelyrelated to those arising from cryptomania proposals in the literature. Our goal is to allow researchers to attack
On the Complexity of the BKW Algorithm on LWE
"... Abstract. In this paper we present a study of the complexity of the BlumKalaiWasserman (BKW) algorithm when applied to the Learning with Errors (LWE) problem, by providing refined estimates for the data and computational effort requirements for solving concrete instances of the LWE problem. We app ..."
Abstract

Cited by 3 (0 self)
 Add to MetaCart
Abstract. In this paper we present a study of the complexity of the BlumKalaiWasserman (BKW) algorithm when applied to the Learning with Errors (LWE) problem, by providing refined estimates for the data and computational effort requirements for solving concrete instances of the LWE problem. We
Hardness of decision (R)LWE for any modulus
, 2012
"... Abstract. The decision Learning With Errors problem has proven an extremely flexible foundation for devising provably secure cryptographic primitives. LWE can be expressed in terms of linear algebra over Z/qZ. This modulus q is the subject of study of the present work. When q is prime and small, or ..."
Abstract

Cited by 2 (0 self)
 Add to MetaCart
, or when it is exponential and composite with small factors, LWE is known to be at least as hard as standard worstcase problems over euclidean lattices (sometimes using quantum reductions). The Ring Learning With Errors problem is a structured variant of LWE allowing for more compact keys and more
Better Algorithms for LWE and LWR
"... Abstract. The Learning With Error problem (LWE) is becoming more and more used in cryptography, for instance, in the design of some fully homomorphic encryption schemes. It is thus of primordial importance to find the best algorithms that might solve this problem so that concrete parameters can be p ..."
Abstract

Cited by 2 (0 self)
 Add to MetaCart
Abstract. The Learning With Error problem (LWE) is becoming more and more used in cryptography, for instance, in the design of some fully homomorphic encryption schemes. It is thus of primordial importance to find the best algorithms that might solve this problem so that concrete parameters can
RingLWE in polynomial rings
 In Public Key Cryptography
, 2012
"... Abstract. The RingLWE problem, introduced by Lyubashevsky, Peikert, and Regev (Eurocrypt 2010), has been steadily finding many uses in numerous cryptographic applications. Still, the RingLWE problem defined in [LPR10] involves the fractional ideal R ∨ , the dual of the ring R, which is the source ..."
Abstract

Cited by 6 (0 self)
 Add to MetaCart
Abstract. The RingLWE problem, introduced by Lyubashevsky, Peikert, and Regev (Eurocrypt 2010), has been steadily finding many uses in numerous cryptographic applications. Still, the RingLWE problem defined in [LPR10] involves the fractional ideal R ∨ , the dual of the ring R, which is the source
Algebraic Algorithms for LWE Problems
"... Abstract. We analyse the complexity of algebraic algorithms for solving systems of linear equations with noise. Such systems arise naturally in the theory of errorcorrecting codes as well as in computational learning theory. More recently, linear systems with noise have found application in cryptog ..."
Abstract
 Add to MetaCart
in cryptography. The Learning with Errors (LWE) problem has proven to be a rich and versatile source of innovative cryptosystems, such as fully homomorphic encryption schemes. Despite the popularity of the LWE problem, the complexity of algorithms for solving it is not very well understood, particularly when
Results 1  10
of
81,276