The ``learning with errors\u27\u27 (LWE) problem is to distinguish random linear equations, which have been perturbed by a small amount of noise, from truly uniform ones. The problem has been shown to be as hard as worst-case lattice problems, and in recent years it has served as the foundation for a plethora of cryptographic applications. Unfortunately, these applications are rather inefficient due to an inherent quadratic overhead in the use of LWE. A main open question was whether LWE and its applications could be made truly efficient by exploiting extra algebraic structure, as was done for lattice-based hash functions (and related primitives). We resolve this question in the affirmative by introducing an algebraic variant of LWE call...
In this paper, we propose a new assumption, the Computational Learning With Rounding over rings, whi...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
In this lecture the LWE and ring-LWE problems were introduced, and it was described how these can be...
International audienceThe "learning with errors" (LWE) problem is to distinguish random linear equat...
Lattice-based cryptography relies in great parts on the use of the Learning With Errors (LWE) proble...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
The Learning with Errors (LWE) problem has gained a lot of attention in recent years leading to a se...
Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring learning with errors pro...
The Learning with Errors (LWE) problem has been widely utilized as a foundation for numerous cryptog...
International audienceMost lattice-based cryptographic schemes are built upon the assumed hardness o...
We propose a generalization of the celebrated Ring Learning with Errors (RLWE) problem (Lyubashevsky...
In this work, we describe an integer version of ring-LWE over the polynomial rings and prove that it...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
Since its proposal by Regev in 2005, the Learning With Errors (LWE) problem was used as the underlyi...
© The Author(s) 2016. Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring le...
In this paper, we propose a new assumption, the Computational Learning With Rounding over rings, whi...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
In this lecture the LWE and ring-LWE problems were introduced, and it was described how these can be...
International audienceThe "learning with errors" (LWE) problem is to distinguish random linear equat...
Lattice-based cryptography relies in great parts on the use of the Learning With Errors (LWE) proble...
In CRYPTO 2015, Elias, Lauter, Ozman and Stange described an attack on the non-dual decision version...
The Learning with Errors (LWE) problem has gained a lot of attention in recent years leading to a se...
Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring learning with errors pro...
The Learning with Errors (LWE) problem has been widely utilized as a foundation for numerous cryptog...
International audienceMost lattice-based cryptographic schemes are built upon the assumed hardness o...
We propose a generalization of the celebrated Ring Learning with Errors (RLWE) problem (Lyubashevsky...
In this work, we describe an integer version of ring-LWE over the polynomial rings and prove that it...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
Since its proposal by Regev in 2005, the Learning With Errors (LWE) problem was used as the underlyi...
© The Author(s) 2016. Since its introduction in 2010 by Lyubashevsky, Peikert and Regev, the ring le...
In this paper, we propose a new assumption, the Computational Learning With Rounding over rings, whi...
In this paper, we survey the status of attacks on the ring and polynomial learning with errors probl...
In this lecture the LWE and ring-LWE problems were introduced, and it was described how these can be...