We propose a generalization of the celebrated Ring Learning with Errors (RLWE) problem (Lyubashevsky, Peikert and Regev, Eurocrypt 2010, Eurocrypt 2013), wherein the ambient ring is not the ring of integers of a number field, but rather an *order* (a full rank subring). We show that our Order-LWE problem enjoys worst-case hardness with respect to short-vector problems in invertible-ideal lattices *of the order*. The definition allows us to provide a new analysis for the hardness of the abundantly used Polynomial-LWE (PLWE) problem (Stehlë et al., Asiacrypt 2009), different from the one recently proposed by Rosca, Stehlë and Wallet (Eurocrypt 2018). This suggests that Order-LWE may be used to analyze and possibly *design* useful relaxation...
Several works have characterized weak instances of the Ring-LWE problem by exploring vulnerabilities...
Since its proposal by Regev in 2005, the Learning With Errors (LWE) problem was used as the underlyi...
The Ring Learning With Errors problem (RLWE) comes in various forms. Vanilla RLWE is the decision du...
The hardness of the Ring Learning with Errors problem (RLWE) is a central building block for efficie...
The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which ha...
We extend the known pseudorandomness of Ring-LWE to be based on lattices that do not correspond to a...
International audienceThe "learning with errors" (LWE) problem is to distinguish random linear equat...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
In this paper, we propose a new assumption, the Computational Learning With Rounding over rings, whi...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
Efficient lattice-based cryptography usually relies on the intractability of problems on lattices wi...
In this work, we describe an integer version of ring-LWE over the polynomial rings and prove that it...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
The Ring-LWE over two-to-power cyclotomic integer rings has been the hard computational problem for ...
International audienceMost lattice-based cryptographic schemes are built upon the assumed hardness o...
Several works have characterized weak instances of the Ring-LWE problem by exploring vulnerabilities...
Since its proposal by Regev in 2005, the Learning With Errors (LWE) problem was used as the underlyi...
The Ring Learning With Errors problem (RLWE) comes in various forms. Vanilla RLWE is the decision du...
The hardness of the Ring Learning with Errors problem (RLWE) is a central building block for efficie...
The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which ha...
We extend the known pseudorandomness of Ring-LWE to be based on lattices that do not correspond to a...
International audienceThe "learning with errors" (LWE) problem is to distinguish random linear equat...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
In this paper, we propose a new assumption, the Computational Learning With Rounding over rings, whi...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
Efficient lattice-based cryptography usually relies on the intractability of problems on lattices wi...
In this work, we describe an integer version of ring-LWE over the polynomial rings and prove that it...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
The Ring-LWE over two-to-power cyclotomic integer rings has been the hard computational problem for ...
International audienceMost lattice-based cryptographic schemes are built upon the assumed hardness o...
Several works have characterized weak instances of the Ring-LWE problem by exploring vulnerabilities...
Since its proposal by Regev in 2005, the Learning With Errors (LWE) problem was used as the underlyi...
The Ring Learning With Errors problem (RLWE) comes in various forms. Vanilla RLWE is the decision du...