Shortest vector from lattice sieving: a few dimensions for free

From MaRDI portal
Publication:1648783

DOI10.1007/978-3-319-78381-9_5zbMath1423.94069OpenAlexW2795008797MaRDI QIDQ1648783

Léo Ducas

Publication date: 9 July 2018

Full work available at URL: https://ir.cwi.nl/pub/27649




Related Items (30)

Dual lattice attacks for closest vector problems (with preprocessing)Improved Discrete Gaussian and Subgaussian Analysis for Lattice CryptographyLower bounds on lattice sieving and information set decodingSieve, Enumerate, Slice, and Lift:Solving the search-LWE problem over projected latticesPredicting the concrete security of LWE against the dual attack using binary searchFaster Dual Lattice Attacks for Solving LWE with Applications to CRYSTALSSieve algorithms for some orthogonal integer latticesGeneralized attack on ECDSA: known bits in arbitrary positionsA thorough treatment of highly-efficient NTRU instantiationsEHNP strikes back: analyzing SM2 implementationsHandle the traces: revisiting the attack on ECDSA with EHNPA non-heuristic approach to time-space tradeoffs and optimizations for BKWDevelopment and analysis of massive parallelization of a lattice basis reduction algorithmDoes the dual-sieve attack on learning with errors even work?Finding short integer solutions when the modulus is smallEstimating the hidden overheads in the BDGL lattice sieving algorithmEstimating quantum speedups for lattice sievesA lattice reduction algorithm based on sublattice BKZDynamic self-dual DeepBKZ lattice reduction with free dimensions and its implementationAnalysis of DeepBKZ reduction for finding short lattice vectorsApproximate Voronoi cells for lattices, revisitedLearning strikes again: the case of the DRS signature schemeA Survey of Solving SVP Algorithms and Recent Strategies for Solving the SVP ChallengeA \(2^{n/2}\)-time algorithm for \(\sqrt{n} \)-SVP and \(\sqrt{n} \)-Hermite SVP, and an improved time-approximation tradeoff for (H)SVPOn bounded distance decoding with predicate: breaking the ``lattice barrier for the hidden number problemAdvanced lattice sieving on GPUs, with tensor coresWorst case short lattice vector enumeration on block reduced bases of arbitrary blocksizesA new polynomial-time variant of LLL with deep insertions for decreasing the squared-sum of Gram-Schmidt lengthsFaster enumeration-based lattice reduction: root Hermite factor \(k^{1/(2k)}\) time \(k^{k/8+o(k)}\)



Cites Work


This page was built for publication: Shortest vector from lattice sieving: a few dimensions for free