摘要 本综述中,我们描述了带错误的学习 (LWE) 问题,讨论了它的性质、困难性及其密码应用。 关键词:错误学习;格密码 一、引言 近年来,[Reg05] 中引入的带错误学习 (LWE) 问题,已被证明是密码构造的通用基础。 它主要名声来自于与最坏情况的格问题一样困难,因此在最坏情况的格问题困难性的假设下,使所有基于它的密码构造都是安全的。 本次综述的
假设我们可以访问使用模数 q 和误差参数 α 解决 LWE 问题的预言机,那么给定任何格 Λ 作为输入,来自离散高斯分布DΛ∗,r 的足够大的多项式样本数,对于某些(不是太小)r,以及离 Λ 的距离 αq/2r 内的点 x,我们可以在多项式时间内得到(唯一)最接近 x 的格点。 r不能太小的要求是很温和的;精确的条件...
Learning-With-ErrorsWorst-Case ReductionUniform Interval Error-DistributionThe hardness of the Learning-With-Errors (LWE) Problem has become one of the most useful assumptions in cryptography. It exhibits a worst-to-average-case reduction making the LWE assumption very plausible. This worst-to-...
TheLearningWithErrorsProblem The Learning With Errors Problem;Overview;A secret vector s in ?174 We are given an arbitrary number of equations, each correct up to ?1 Can you find s? ;LWE’s Claim to Fame;LWE’s Origins;LWE – More Precisely;LWE – Parameters: n, q, ?;Algorithms;...
Several recent proposals of efficient public-key encryption are based on variants of the polynomial learning with errors problem (PLWE $$^f$$
We introduce a new class of intractability problems, called Learning with Errors in the Exponent (LWEE). We give a tight reduction from Learning with Errors (LWE) and the Representation Problem (RP) in finite groups, two seemingly unrelated problem, to LWEE. The argument holds in the ...
1.1 Our Results and Techniques The learning with error (LWE) problem, introduced by Regev [27] is a generalization of the well-known "learning parity with noise" problem. For a security parameter n, and a prime number q, the LWE prob- lem with secret s ∈ ℤnq is defined as follows...
台湾大学林轩田机器学习基石课程学习笔记1 -- The Learning Problem 一、What is Machine Learning 什么是“学习”?学习就是人类通过观察、积累经验,掌握某项技能或能力。就好像我们从小学习识别字母、认识汉字,就是学习的过程。而机器学习(Machine Learning),顾名思义,就是让机器(计算机)也能向人类一样,通过观察...
This C library implementsFrodoKEM, an IND-CCA secure key encapsulation (KEM) protocol based on the well-studied Learning with Errors (LWE) problem [1,3], which in turn has close connections to conjectured-hard problems on generic, "algebraically unstructured" lattices. This package also includes...
Our main result is that the hardness of the learning with error (LWE) problem implies its hardness with leaky secrets. More generally, we show that the standard LWE assumption implies that LWE is secure even if the secret is taken from an arbitrary distribution with sufficient entropy, and ...