Hypercubic Lattice Reduction and Analysis of GGH and NTRU Signatures

  • Michael Szydlo
Conference paper
In this paper, we introduce a new lattice reduction technique applicable to the narrow, but important class of Hypercubic lattices, (L ≅ ℤN). Hypercubic lattices arise during transcript analysis of certain GGH, and NTRUSign signature schemes. After a few thousand signatures, key recovery amounts to discovering a hidden unitary matrix U, from its Gram matrix G = UU T . This case of the Gram Matrix Factorization Problem is equivalent to finding the shortest vectors in the hypercubic lattice, L G , defined by the quadratic form G. Our main result is a polynomial-time reduction to a conjecturally easier problem: the Lattice Distinguishing Problem. Additionally, we propose a heuristic solution to this distinguishing problem with a distributed computation of many “relatively short” vectors.


Lattice Isomorphism Lattice Distinguishing Oracle Distributed Lattice Reduction Decisional Lattice Problem Gram Matrix Factorization Integral Lattice Embedding Orthogonal Lattice GGH Cryptanalysis NTRUSign 


Authors and Affiliations

  • Michael Szydlo
    • 1
  1. 1.RSA LaboratoriesBedfordUSA

