A Refined Hardness Estimation of LWE in Two-Step Mode

被引:0
|
作者
Xia, Wenwen [1 ,2 ,5 ]
Wang, Leizhang [3 ]
Wang, Geng [4 ,5 ]
Gu, Dawu [1 ,4 ]
Wang, Baocang [3 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
[2] Shanghai Jiao Tong Univ, Lab Cryptol & Comp Secur, Shanghai 200240, Peoples R China
[3] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710071, Peoples R China
[4] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai 200240, Peoples R China
[5] State Key Lab Cryptol, POB 5159, Beijing 100878, Peoples R China
来源
关键词
Lattice-based Cryptanalysis; Security Strength; LWE estimator; Two-step mode;
D O I
10.1007/978-3-031-57725-3_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, researchers have proposed many LWE estimators, such as lattice-estimator (Albrecht et al, Asiacrypt 2017) and leaky-LWE-Estimator (Dachman-Soled et al, Crypto 2020), while the latter has already been used in estimating the security level of Kyber and Dilithium using only BKZ. However, we prove in this paper that solving LWE by combining a lattice reduction step (by LLL or BKZ) and a target vector searching step (by enumeration or sieving), which we call a Two-step mode, is more efficient than using only BKZ. Moreover, we give a refined LWE estimator in Two-step mode by analyzing the relationship between the probability distribution of the target vector and the solving success rate in a Two-step mode LWE solving algorithm. While the latest Two-step estimator for LWE, which is the "primal-bdd" mode in lattice-estimator (https://github.com/malb/lattice-estimator), does not take into account some up-to-date results and lacks a thorough theoretical analysis. Under the same gate-count model, our estimation for NIST PQC standards drops by 2.1-3.4 bits (2.2-4.6 bits while considering more flexible blocksize and jump strategy) compared with leaky-LWE-Estimator. Furthermore, we also give a conservative estimation for LWE from the Two-step solving algorithm. Compared with the Core-SVP model, which is used in previous conservative estimations, our estimation relies on weaker assumptions and outputs higher evaluation results than the Core-SVP model. For NIST PQC standards, our conservative estimation is 4.17-8.11 bits higher than the Core-SVP estimation. Hence our estimator can give a closer estimation for both upper bound and lower bound of LWE hardness.
引用
收藏
页码:3 / 35
页数:33
相关论文
共 50 条
  • [41] An Improved Two-step Regularization Scheme for Spot Volatility Estimation
    Ogawa, Shigeyoshi
    Sanfelici, Simona
    ECONOMIC NOTES, 2011, 40 (03) : 107 - 134
  • [42] Relative sensor registration with two-step method for state estimation
    Ge, Quanbo
    Chen, Tianxiang
    Duan, Zhansheng
    Liu, Mingxin
    Niu, Zhuyun
    COGNITIVE COMPUTATION AND SYSTEMS, 2019, 1 (02) : 45 - 54
  • [43] Two-Step Windowing Technique for Wide Range Motion Estimation
    Lin, Meng-Chun
    Dung, Lan-Rong
    2008 IEEE ASIA PACIFIC CONFERENCE ON CIRCUITS AND SYSTEMS (APCCAS 2008), VOLS 1-4, 2008, : 1478 - +
  • [44] Two-Step Estimation and Inference with Possibly Many Included Covariates
    Cattaneo, Matias D.
    Jansson, Michael
    Ma, Xinwei
    REVIEW OF ECONOMIC STUDIES, 2019, 86 (03): : 1095 - 1122
  • [45] Two-step procedure decreases variance in tone frequency estimation
    Toma, Liviu
    De Sabata, Aldo
    Vasiu, Gabriel
    REVUE ROUMAINE DES SCIENCES TECHNIQUES-SERIE ELECTROTECHNIQUE ET ENERGETIQUE, 2007, 52 (04): : 463 - 474
  • [46] A two-step estimation of diffusion processes using noisy observations
    Ye, Xu-Guo
    Lin, Jin-Guan
    Zhao, Yan-Yong
    JOURNAL OF NONPARAMETRIC STATISTICS, 2018, 30 (01) : 145 - 181
  • [47] Estimation of the covariance matrix with two-step monotone missing data
    Hyodo, Masashi
    Shutoh, Nobumichi
    Seo, Takashi
    Pavlenko, Tatjana
    COMMUNICATIONS IN STATISTICS-THEORY AND METHODS, 2016, 45 (07) : 1910 - 1922
  • [48] Variance factor estimation for two-step analysis of deformation networks
    Even-Tzur, G
    JOURNAL OF SURVEYING ENGINEERING-ASCE, 2004, 130 (03): : 113 - 118
  • [49] Two-Step Noise Variation Estimation Based on Image Segmentation
    Wang, Zhiming
    2013 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND APPLICATIONS (CSA), 2013, : 631 - 634
  • [50] TWO-STEP ESTIMATION OF A MULTI-VARIATE LEVY PROCESS
    Esmaeili, Habib
    Klueppelberg, Claudia
    JOURNAL OF TIME SERIES ANALYSIS, 2013, 34 (06) : 668 - 690