Classical hardness of the Learning with Errors problem
Adeline Langlois
Aric Team, LIP, ENS Lyon Joint work with
- Z. Brakerski, C. Peikert, O. Regev and D. Stehlé
August 12, 2013
Adeline Langlois Hardness of LWE August 12, 2013 1/ 18
Classical hardness of the Learning with Errors problem Adeline - - PowerPoint PPT Presentation
Classical hardness of the Learning with Errors problem Adeline Langlois Aric Team, LIP, ENS Lyon Joint work with Z. Brakerski, C. Peikert, O. Regev and D. Stehl August 12, 2013 Adeline Langlois Hardness of LWE August 12, 2013 1/ 18 Our
Adeline Langlois Hardness of LWE August 12, 2013 1/ 18
Adeline Langlois Hardness of LWE August 12, 2013 2/ 18
Adeline Langlois Hardness of LWE August 12, 2013 3/ 18
Adeline Langlois Hardness of LWE August 12, 2013 4/ 18
Adeline Langlois Hardness of LWE August 12, 2013 4/ 18
Adeline Langlois Hardness of LWE August 12, 2013 4/ 18
Adeline Langlois Hardness of LWE August 12, 2013 4/ 18
Adeline Langlois Hardness of LWE August 12, 2013 4/ 18
log n
Adeline Langlois Hardness of LWE August 12, 2013 5/ 18
log n
Adeline Langlois Hardness of LWE August 12, 2013 5/ 18
log n
Adeline Langlois Hardness of LWE August 12, 2013 5/ 18
Adeline Langlois Hardness of LWE August 12, 2013 6/ 18
Adeline Langlois Hardness of LWE August 12, 2013 7/ 18
Adeline Langlois Hardness of LWE August 12, 2013 8/ 18
◮ one public pkA ◮ one secret skA
Adeline Langlois Hardness of LWE August 12, 2013 9/ 18
q ), A ←
q
r
r b
Adeline Langlois Hardness of LWE August 12, 2013 10/ 18
q ), A ←
q
r
r b
r
s
e + ⌊q/2⌉ . M−
r
s
small + ⌊q/2⌉ . M
Adeline Langlois Hardness of LWE August 12, 2013 10/ 18
q ), A ←
q
r
r b
r
s
e + ⌊q/2⌉ . M−
r
s
small + ⌊q/2⌉ . M
Adeline Langlois Hardness of LWE August 12, 2013 10/ 18
Adeline Langlois Hardness of LWE August 12, 2013 11/ 18
◮ A quantum reduction; ◮ with q polynomial.
◮ A classical reduction; ◮ with q exponential,
◮ A classical reduction; ◮ based on a non-standard
◮ with q polynomial.
Adeline Langlois Hardness of LWE August 12, 2013 12/ 18
◮ A quantum reduction; ◮ with q polynomial.
◮ A classical reduction; ◮ with q exponential,
◮ A classical reduction; ◮ based on a non-standard
◮ with q polynomial.
Adeline Langlois Hardness of LWE August 12, 2013 12/ 18
Adeline Langlois Hardness of LWE August 12, 2013 13/ 18
Adeline Langlois Hardness of LWE August 12, 2013 13/ 18
Adeline Langlois Hardness of LWE August 12, 2013 14/ 18
q A + R.
q ).
Adeline Langlois Hardness of LWE August 12, 2013 14/ 18
Adeline Langlois Hardness of LWE August 12, 2013 15/ 18
Adeline Langlois Hardness of LWE August 12, 2013 16/ 18
Adeline Langlois Hardness of LWE August 12, 2013 17/ 18
Adeline Langlois Hardness of LWE August 12, 2013 18/ 18
Adeline Langlois Hardness of LWE August 12, 2013 18/ 18
Adeline Langlois Hardness of LWE August 12, 2013 18/ 18