Abstract
Cryptographic constructions based on the Learning with Errors (LWE) problem have received much attention in recent years for the process of standardizing post-quantum cryptography. The most effective solution against LWE is the BKZ algorithm and the complexity is dominated by block size. Alkim et al . (USENIX 2016) proposed an estimate of the block size which is required to solve LWE via the BKZ algorithm (2016 estimate). In this paper, we verify the fundamental assumption of the 2016 estimate which is applied to some proposed cryptosystems by executing some experiments using the BKZ algorithm. We also show our conjecture of why it is possible to solve LWE with smaller block sizes. Furthermore, we discuss the reason why the LWE solution is recovered earlier than expected by the 2016 estimate.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
References
Albrecht, M.R., Ducas, L., Herold, G., Kirshanova, E., Postlethwaite, E.W., Stevens, M.: The general sieve kernel and new records in lattice reduction. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11477, pp. 717–746. Springer, Cham (2019). https://doi.org/10.1007/978-3-030-17656-3_25
Albrecht, M.R., Göpfert, F., Virdia, F., Wunderer, T.: Revisiting the expected cost of solving uSVP and applications to LWE. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10624, pp. 297–322. Springer, Cham (2017). https://doi.org/10.1007/978-3-319-70694-8_11
Alkim, E., Ducas, L., Pöppelmann, T., Schwabe, P.: Post-quantum key exchange - a new hope. In: Holz, T., Savage, S. (eds.) 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10–12, 2016. pp. 327–343. USENIX Association (2016)
Babai, L.: On Lovász’ lattice reduction and the nearest lattice point problem. In: Mehlhorn, K. (ed.) STACS 1985. LNCS, vol. 182, pp. 13–20. Springer, Heidelberg (1985). https://doi.org/10.1007/BFb0023990
Bai, S., Laarhoven, T., Stehlé, D.: Tuple lattice sieving. IACR Cryptol. ePrint Arch. 2016, 713 (2016)
Chen, Y.: Réduction de réseau et sécurité concrète du chiffrement complètement homomorphe (2013)
Florian, G.F., Yakkundimath, A.: Darmstadt LWE Challenge. https://www.latticechallenge.org/lwe_challenge/challenge.php
Kannan, R.: Minkowski’s convex body theorem and integer programming. Math. Oper. Res. 12(3), 415–440 (1987)
Lenstra, A.K., Lenstra, H.W., Lovász, L.: Factoring polynomials with rational coefficients. Mathematische annalen 261(ARTICLE), 515–534 (1982)
Lyubashevsky, V., Micciancio, D.: On bounded distance decoding, unique shortest vectors, and the minimum distance problem. In: Halevi, S. (ed.) CRYPTO 2009. LNCS, vol. 5677, pp. 577–594. Springer, Heidelberg (2009). https://doi.org/10.1007/978-3-642-03356-8_34
Martin, R., Albrecht, L.D., Herold, G., Kirshanova, E., Postlethwaite, E.W., Stevens, M.: General Sieve Kernel and New Records in Lattice Reduction. https://github.com/fplll/g6k
Micciancio, D., Voulgaris, P.: Faster exponential time algorithms for the shortest vector problem. In: Charikar, M. (ed.) Proceedings of the Twenty-First Annual ACM-SIAM Symposium on Discrete Algorithms, SODA 2010, Austin, Texas, USA, January 17–19, 2010. pp. 1468–1480. SIAM (2010)
Postlethwaite, E.W., Virdia, F.: On the success probability of solving unique SVP via BKZ. In: Garay, J.A. (ed.) PKC 2021. LNCS, vol. 12710, pp. 68–98. Springer, Cham (2021). https://doi.org/10.1007/978-3-030-75245-3_4
Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. J. ACM 56(6), 34:1–34:40 (2009)
Schnorr, C.P.: Lattice reduction by random sampling and birthday methods. In: Alt, H., Habib, M. (eds.) STACS 2003. LNCS, vol. 2607, pp. 145–156. Springer, Heidelberg (2003). https://doi.org/10.1007/3-540-36494-3_14
Schnorr, C., Euchner, M.: Lattice basis reduction: improved practical algorithms and solving subset sum problems. Math. Program. 66, 181–199 (1994)
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2021 Springer Nature Switzerland AG
About this paper
Cite this paper
Takeshige, A., Kosuge, H., Tanaka, H. (2021). Experimental Verification of Estimated Block Size of BKZ Algorithm Against LWE. In: Tripathy, S., Shyamasundar, R.K., Ranjan, R. (eds) Information Systems Security. ICISS 2021. Lecture Notes in Computer Science(), vol 13146. Springer, Cham. https://doi.org/10.1007/978-3-030-92571-0_11
Download citation
DOI: https://doi.org/10.1007/978-3-030-92571-0_11
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-030-92570-3
Online ISBN: 978-3-030-92571-0
eBook Packages: Computer ScienceComputer Science (R0)