The Ring Learning-With-Errors (RLWE) problem shows great promise for post-quantum cryptography and homomorphic encryption. We describe a new attack on the non-dual search RLWE problem with small error widths, using ring homomorphisms to finite fields and the chi-squared statistical test. In particular, we identify a ``subfield vulnerability\u27\u27 (Section 5.2) and give a new attack which finds this vulnerability by mapping to a finite field extension and detecting non-uniformity with respect to the number of elements in the subfield. We use this attack to give examples of vulnerable RLWE instances in Galois number fields. We also extend the well-known search-to-decision reduction result to Galois fields with any unramified prime modulus ...
The Learning with Errors (LWE) problem has been widely utilized as a foundation for numerous cryptog...
Abstract. In this paper, we survey the status of attacks on the ring and polynomial learning with er...
The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which ha...
Abstract. We describe a new attack on the Search Ring Learning-With-Errors (RLWE) problem based on t...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
© International Association for Cryptologic Research 2016. In CRYPTO 2015, Elias, Lauter, Ozman and ...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
The ring variant of learning with errors (Ring-LWE) problem has provided efficient post-quantum cryp...
Abstract. The ring and polynomial learning with errors problems (Ring-LWE and Poly-LWE) have been pr...
The Ring Learning With Errors problem (RLWE) comes in various forms. Vanilla RLWE is the decision du...
© The Author(s) 2016. Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring le...
We describe a decisional attack against a version of the PLWE problem in which the samples are take...
The Ring-LWE over two-to-power cyclotomic integer rings has been the hard computational problem for ...
Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring learning with errors pro...
The Learning with Errors (LWE) problem has been widely utilized as a foundation for numerous cryptog...
Abstract. In this paper, we survey the status of attacks on the ring and polynomial learning with er...
The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which ha...
Abstract. We describe a new attack on the Search Ring Learning-With-Errors (RLWE) problem based on t...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
© International Association for Cryptologic Research 2016. In CRYPTO 2015, Elias, Lauter, Ozman and ...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
The ring variant of learning with errors (Ring-LWE) problem has provided efficient post-quantum cryp...
Abstract. The ring and polynomial learning with errors problems (Ring-LWE and Poly-LWE) have been pr...
The Ring Learning With Errors problem (RLWE) comes in various forms. Vanilla RLWE is the decision du...
© The Author(s) 2016. Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring le...
We describe a decisional attack against a version of the PLWE problem in which the samples are take...
The Ring-LWE over two-to-power cyclotomic integer rings has been the hard computational problem for ...
Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring learning with errors pro...
The Learning with Errors (LWE) problem has been widely utilized as a foundation for numerous cryptog...
Abstract. In this paper, we survey the status of attacks on the ring and polynomial learning with er...
The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which ha...