[论文解读] On Ideal Lattices over the Tensor Product of Number Fields and Ring Learning with Errors over Multivariate Rings.
本文将多变量学习错误问题(m-RLWE)引入为RLWE在多变量多项式环上的推广,通过将理想格约化到数域张量积上,建立了其困难性。研究表明,m-RLWE具有密码学安全性,且相较于其单变量对应物,更适用于多维密码学应用。
The with Errors (RLWE) problem was formulated as a variant of the Learning with Errors (LWE) problem, with the purpose of taking advantage of an additional algebraic structure in the underlying considered lattices; this enables improvements on the efficiency and cipher expansion on those cryptographic applications which were previously based on the LWE problem. In Eurocrypt 2010, Lyubashevsky et al. introduced this hardness problem and showed its relation to some known hardness problems over lattices with a special structure. In this work, we generalize the results and the hardness problems presented by Lyubashevsky et al. to the more general case of multivariate rings, highlighting the main differences with respect to the security proof for the RLWE counterpart. We denote this hardness problem as Multivariate Ring with Errors (m-RLWE or multivariate RLWE) and we show its relation to hardness problems over the tensor product of ideal lattices. Additionally, the m-RLWE problem is more adequate than its univariate version for cryptographic applications dealing with multidimensional structures.
研究动机与目标
- 将RLWE问题从单变量多项式环推广至多变量多项式环,以实现更高效且可扩展的密码学构造。
- 通过将m-RLWE与数域张量积上的理想格相关联,形式化其困难性。
- 证明m-RLWE相较于单变量RLWE,更适合用于涉及多维代数结构的密码学应用。
- 提供一种m-RLWE的安全性约化,该约化推广了已知的RLWE约化方法,同时考虑了多变量设置中的结构性差异。
提出的方法
- 通过考虑数域张量积的环结构,将RLWE框架推广至多变量多项式环。
- 将m-RLWE问题定义为在具有小误差项的多变量多项式环上的困难性假设。
- 利用代数数论和理想格结构,从最坏情况下的理想格问题到m-RLWE问题建立约化。
- 通过将m-RLWE与数域张量积上理想格的最短向量问题求解困难性相关联,分析其安全性。
- 利用代数数论刻画多变量设置下的环结构与理想性质,确保约化过程的正确性。
- 证明m-RLWE问题继承了底层理想格问题的困难性,从而确保其密码学安全性。
实验结果
研究问题
- RQ1如何在保持其困难性和密码学实用性的同时,将RLWE问题推广至多变量多项式环?
- RQ2m-RLWE问题与数域张量积上的理想格之间存在何种关系?
- RQ3在约化和底层困难性假设方面,m-RLWE的安全性相较于单变量RLWE有何差异?
- RQ4在涉及多维代数结构的密码学应用中,m-RLWE相较于RLWE在哪些方面更具适用性?
主要发现
- m-RLWE问题被正式定义为多变量多项式环上的困难性假设,扩展了单变量RLWE框架。
- m-RLWE的安全性被约化为数域张量积上理想格问题的最坏情况困难性。
- 与单变量RLWE相比,m-RLWE在多维密码学应用中表现出更强的结构性优势。
- 从最坏情况理想格问题到m-RLWE的约化,推广了已知的RLWE约化方法,同时考虑了多变量环的更高复杂性。
- 使用数域的张量积可提供更丰富的代数结构,支持更高效且可扩展的密码学方案。
- 结果表明,m-RLWE保持了后量子密码学所需的理想困难性特性,并在多维设置中具有潜在的效率优势。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。