Results 11 to 20 of about 5,975 (201)
The (decisional) learning with errors problem (LWE) asks to distinguish "noisy" inner products of a secret vector with random vectors from uniform. The learning parities with noise problem (LPN) is the special case where the elements of the vectors are bits. In recent years, the LWE and LPN problems have found many applications in cryptography.
Pietrzak, Krzysztof Z ; https://orcid.org/ +1 more
openaire +3 more sources
The Hardness of LWE and Ring-LWE: A Survey. [PDF]
The Learning with Errors (LWE) problem consists of distinguishing linear equations with noise from uniformly sampled values. LWE enjoys a hardness reduction from worst-case lattice problems, which are believed to be hard for classical and quantum ...
David Balbás
core +3 more sources
Fractional LWE: A Nonlinear Variant of LWE [PDF]
Many cryptographic constructions are based on the famous problem LWE [Reg05]. In particular, this cryptographic problem is currently the most relevant to build FHE [GSW13, BV11]. In [BV11], encrypting x consists of randomly choosing a vector \(\varvec{c}\) satisfying \(\langle \varvec{s},\varvec{c}\rangle =x+\textsf {noise}\pmod q\) where \(\varvec{s}\)
Gérald Gavin, Stéphane Bonnevay
core +4 more sources
Provably Weak Instances of Ring-LWE [PDF]
24 pages including computer code, minor modifications and typos ...
Yara Elias +3 more
core +7 more sources
Additively Homomorphic Ring-LWE Masking [PDF]
In this paper, we present a new masking scheme for ring-LWE decryption. Our scheme exploits the additively-homomorphic property of the existing ring-LWE encryption schemes and computes an additive-mask as an encryption of a random message. Our solution differs in several aspects from the recent masked ring-LWE implementation by Reparaz et al. presented
De Clercq, Ruan +4 more
openaire +5 more sources
Lossiness and Entropic Hardness for Ring-LWE
The hardness of the Ring Learning with Errors problem (RLWE) is a central building block for efficiency-oriented lattice-based cryptography. Many applications use an “entropic” variant of the problem where the so-called “secret” is not distributed uniformly as prescribed but instead comes from some distribution with sufficient min-entropy. However, the
Zvika Brakerski, Nico Döttling
openaire +3 more sources
Parallel Implementation of BDD Enumeration for LWE [PDF]
One of the most attractive problems for post-quantum secure cryptographic schemes is the LWE problem. Beside combinatorial and algebraic attacks, LWE can be solved by a lattice-based Bounded Distance Decoding (BDD) approach. We provide the first parallel implementation of an enumeration-based BDD algorithm that employs the Lindner-Peikert and Linear ...
Elena Kirshanova +2 more
core +4 more sources
Cryptanalysis of Compact-LWE. [PDF]
As an invited speaker of the ACISP 2017 conference, Dongxi Liu recently introduced a new lattice-based encryption scheme (joint work with Li, Kim and Nepal) designed for lightweight IoT applications, and announced plans to submit it to the NIST ...
Jonathan Bootle, Mehdi Tibouchi
core +3 more sources
We introduce a continuous analogue of the Learning with Errors (LWE) problem, which we name CLWE. We give a polynomial-time quantum reduction from worst-case lattice problems to CLWE, showing that CLWE enjoys similar hardness guarantees to those of LWE.
Joan Bruna +3 more
openaire +4 more sources
In this paper, we propose a masking scheme to protect ring-LWE decryption from first-order side-channel attacks. In an unprotected ring-LWE decryption, the recovered plaintext is computed by first performing polynomial arithmetic on the secret key and then decoding the result. We mask the polynomial operations by arithmetically splitting the secret key
De Clercq, Ruan +4 more
openaire +3 more sources

