On the Hardness of Module-LWE with Binary Secret

Katharina Boudgoust, Corentin Jeudy, Adeline Roux-Langlois, Weiqiang Wen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We prove that the Module Learning With Errors (M - LWE ) problem with binary secrets and rank d is at least as hard as the standard version of M - LWE with uniform secret and rank k, where the rank increases from k to d≥ (k+ 1 ) log 2q+ ω(log 2n), and the Gaussian noise from α to β=α·Θ(n2d), where n is the ring degree and q the modulus. Our work improves on the recent work by Boudgoust et al. in 2020 by a factor of md in the Gaussian noise, where m is the number of given M - LWE samples, when q fulfills some number-theoretic requirements. We use a different approach than Boudgoust et al. to achieve this hardness result by adapting the previous work from Brakerski et al. in 2013 for the Learning With Errors problem to the module setting. The proof applies to cyclotomic fields, but most results hold for a larger class of number fields, and may be of independent interest.

Original languageEnglish
Title of host publicationTopics in Cryptology-CT-RSA 2021 - Cryptographers’ Track at the RSA Conference, Proceedings
EditorsKenneth G. Paterson
PublisherSpringer Science and Business Media Deutschland GmbH
Pages503-526
Number of pages24
ISBN (Print)9783030755386
DOIs
Publication statusPublished - 1 Jan 2021
Externally publishedYes
EventCryptographer's Track at the RSA Conference, CT-RSA 2021 - Virtual, Online
Duration: 17 May 202120 May 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12704 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceCryptographer's Track at the RSA Conference, CT-RSA 2021
CityVirtual, Online
Period17/05/2120/05/21

Keywords

  • Binary secret
  • Lattice-based cryptography
  • Module learning with errors

Fingerprint

Dive into the research topics of 'On the Hardness of Module-LWE with Binary Secret'. Together they form a unique fingerprint.

Cite this