Skip to main content
QUICK REVIEW

[Paper Review] On the RLWE/PLWE equivalence for cyclotomic number fields

Iván Blanco Chacón|arXiv (Cornell University)|Jan 29, 2020
Cryptography and Data Security16 references4 citations
TL;DR

This paper establishes the equivalence between the Ring Learning With Errors (RLWE) and Polynomial Learning With Errors (PLWE) problems in cyclotomic number fields, showing that the two problems are equivalent via a polynomial noise increase when the number of distinct prime factors of the conductor is constant. The key contribution is a general asymptotic subexponential bound on the condition number of the Vandermonde matrix associated with cyclotomic polynomials, which implies that RLWE and PLWE remain equivalent under polynomial noise growth for such fields.

ABSTRACT

We study the equivalence between the Ring Learning With Errors and Polynomial Learning With Errors problems for cyclotomic number fields,namely: we prove that both problems are equivalent via a polynomial noise increase as long as the number of distinct primes dividing the conductor is kept constant. We refine our bound in the case where the conductor is divisible by at most three primes and we give an asymptotic subexponential formula for the condition number of the attached Vandermonde matrix valid for arbitrary degree.

Motivation & Objective

  • To establish the equivalence between RLWE and PLWE problems in cyclotomic number fields, particularly under conditions where the number of distinct prime factors of the conductor is fixed.
  • To refine bounds on the condition number of the Vandermonde matrix associated with cyclotomic polynomials for fields with up to three prime factors in the conductor.
  • To derive an asymptotic subexponential upper bound on the condition number of the Vandermonde matrix for arbitrary cyclotomic fields, using known estimates on cyclotomic polynomial coefficients.
  • To show that the general case of RLWE/PLWE equivalence can be reduced to the square-free case up to a square factor in the degree, with only the radical of the conductor affecting noise growth.
  • To strengthen the theoretical foundation for using polynomial ring models in post-quantum cryptography by quantifying the distortion between canonical and coordinate embeddings in cyclotomic fields.

Proposed method

  • Uses algebraic number theory to analyze the isomorphism between the ring of integers of a cyclotomic number field and the polynomial ring modulo a cyclotomic polynomial.
  • Applies Vieta’s formulas to analyze the coefficients of cyclotomic polynomials in terms of their roots, enabling precise control over the norm of the Vandermonde matrix.
  • Employs arithmetic estimates for the divisor function and bounds on the maximal coefficient of cyclotomic polynomials, particularly leveraging Bateman’s asymptotic bound on the maximal coefficient $ A(n) $.
  • Applies results from Bang (2001) and Bloom (1997) to refine bounds on the condition number for fields with conductor divisible by at most three primes.
  • Derives a general upper bound on the condition number of the Vandermonde matrix $ V_{ ilde{ ho}} $ via the inverse of the derivative of the cyclotomic polynomial evaluated at roots of unity.
  • Combines the bound on the maximal coefficient $ A(n) $ with the prime divisor function $ ho(n) = ext{rad}(n) $ to derive a subexponential asymptotic estimate for the condition number.

Experimental results

Research questions

  • RQ1Under what conditions is the RLWE problem equivalent to the PLWE problem in cyclotomic number fields?
  • RQ2How does the condition number of the Vandermonde matrix associated with a cyclotomic polynomial grow with respect to the degree of the field?
  • RQ3Can the RLWE/PLWE equivalence be extended beyond the power-of-two cyclotomic case, and what is the noise increase factor in such cases?
  • RQ4What is the asymptotic growth rate of the maximal coefficient of cyclotomic polynomials, and how does it affect the condition number of the associated Vandermonde matrix?
  • RQ5To what extent can the general case of RLWE/PLWE equivalence be reduced to the square-free case in terms of noise growth?

Key findings

  • For cyclotomic number fields where the number of distinct prime factors of the conductor is bounded, RLWE and PLWE are equivalent with a polynomial noise increase.
  • When the conductor is divisible by at most three distinct primes, the condition number of the Vandermonde matrix is bounded by $ 2m^4 $, where $ m $ is the maximum absolute value of the coefficients of the cyclotomic polynomial.
  • For general $ n $, the condition number $ ext{Cond}(V_{ ilde{ ho}}) $ is bounded by $ ext{O}(n^{n^{ rac{1}{ ext{log log } n}} + rac{ ext{log } n}{ ext{log log } n} + 3} e^{n^{ rac{1}{ ext{log log } n}}}) $, showing subexponential growth.
  • The maximal coefficient $ A(n) $ of the cyclotomic polynomial $ ilde{ ho}_n $ satisfies $ A(n) o e^{n^{(1+ ho) ext{log }2/ ext{log log }n}} $ for any $ \rho > 0 $, which underpins the subexponential bound.
  • The general case of RLWE/PLWE equivalence can be reduced to the square-free case up to a square factor in the degree, with only the radical of $ n $ affecting the noise increase.
  • The bound on the condition number is polynomial in the degree when the number of prime factors is constant, confirming that RLWE and PLWE remain equivalent under polynomial noise growth in such settings.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.