On Ideal Lattices and Learning With Errors Over Rings
Vadim Lyubashevsky1 Chris Peikert 2 Oded Regev1
1Tel Aviv University 2Georgia Institute of Technology
Eurocrypt 2010
1 / 12
On Ideal Lattices and Learning With Errors Over Rings Vadim - - PowerPoint PPT Presentation
On Ideal Lattices and Learning With Errors Over Rings Vadim Lyubashevsky 1 Chris Peikert 2 Oded Regev 1 1 Tel Aviv University 2 Georgia Institute of Technology Eurocrypt 2010 1 / 12 The Learning With Errors Problem [Regev05]
1Tel Aviv University 2Georgia Institute of Technology
1 / 12
2 / 12
2 / 12
2 / 12
2 / 12
2 / 12
2 / 12
2 / 12
2 / 12
3 / 12
3 / 12
3 / 12
3 / 12
4 / 12
4 / 12
4 / 12
4 / 12
5 / 12
5 / 12
⋆ Careful: w/ small error, coordinate-wise multiplication is not secure! 5 / 12
⋆ Careful: w/ small error, coordinate-wise multiplication is not secure!
5 / 12
⋆ Careful: w/ small error, coordinate-wise multiplication is not secure!
5 / 12
6 / 12
6 / 12
⋆ Concurrently & using different techniques, [SSTX’09] proved a
6 / 12
⋆ Concurrently & using different techniques, [SSTX’09] proved a
⋆ Pseudorandomness is new, and important for crypto & efficiency.
6 / 12
⋆ Concurrently & using different techniques, [SSTX’09] proved a
⋆ Pseudorandomness is new, and important for crypto & efficiency.
6 / 12
7 / 12
⋆ Elements may be viewed as dim < n polynomials with Zq coeffs. . . ⋆ . . . or as vectors in Zn
q.
7 / 12
⋆ Elements may be viewed as dim < n polynomials with Zq coeffs. . . ⋆ . . . or as vectors in Zn
q.
7 / 12
⋆ Elements may be viewed as dim < n polynomials with Zq coeffs. . . ⋆ . . . or as vectors in Zn
q.
7 / 12
⋆ Elements may be viewed as dim < n polynomials with Zq coeffs. . . ⋆ . . . or as vectors in Zn
q.
7 / 12
8 / 12
8 / 12
8 / 12
8 / 12
8 / 12
8 / 12
9 / 12
9 / 12
9 / 12
10 / 12
10 / 12
10 / 12
10 / 12
10 / 12
10 / 12
10 / 12
11 / 12
11 / 12
11 / 12
11 / 12
11 / 12
11 / 12
11 / 12
12 / 12
12 / 12
12 / 12
12 / 12