Revisiting the Sparsification Technique in Kannan’s Embedding Attack on LWE

  • Yuntao WangEmail author
  • Thomas Wunderer
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 11125)


The Learning with Errors (LWE) problem is one of the most important computational problems in modern lattice-based cryptography. It can be viewed as a Bounded Distance Decoding (BDD) problem, which can be reduced to the unique Shortest Vector Problem (uSVP). The standard way to reduce BDD to uSVP is via Kannan’s embedding. At ICALP 2016, Bai, Stehlé, and Wen presented an improved theoretical reduction from BDD to uSVP which uses sparsification techniques. So far, the implications of this improved reduction and the use of sparsification to the hardness of LWE have not been studied. In this work, we consider a sparsified embedding attack on LWE which is deduced from the Bai–Stehlé–Wen reduction. In particular, we analyze its performance under the so-called 2016 estimate introduced at USENIX 2016 by Alkim, Ducas, Pöppelmann, and Schwabe and analyzed at ASIACRYPT 2017 by Albrecht, Göpfert, Virdia, and Wunderer. Our results suggest that in general the sparsified embedding attack does not yield a better attack on LWE in practice than Kannan’s embedding. However, for certain parameter sets and scenarios with a reasonable amount of computing clusters, the use of sparsification may be beneficial.


Lattice-based cryptography Sparsification Cryptanalysis BDD SVP LWE 



This work has been supported by JSPS KAKENHI Grant Number JP17J01987 and by the DFG as part of project P1 within the CRC 1119 CROSSING.


  1. [ADPS16]
    Alkim, E., Ducas, L., Pöppelmann, T., Schwabe, P.: Post-quantum key exchange - a new hope. In: Holz, T., Savage, S. (eds.) 25th USENIX Security Symposium, USENIX Security 16, pp. 327–343. USENIX Association (2016)Google Scholar
  2. [AFG14]
    Albrecht, M.R., Fitzpatrick, R., Göpfert, F.: On the efficacy of solving LWE by reduction to unique-SVP. In: Lee, H.-S., Han, D.-G. (eds.) ICISC 2013. LNCS, vol. 8565, pp. 293–310. Springer, Cham (2014). Scholar
  3. [AGVW17]
    Albrecht, M.R., Göpfert, F., Virdia, F., Wunderer, T.: Revisiting the expected cost of solving uSVP and applications to LWE. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10624, pp. 297–322. Springer, Cham (2017). Scholar
  4. [APS15]
    Albrecht, M.R., Player, R., Scott, S.: On the concrete hardness of Learning with Errors. J. Math. Cryptol. 9(3), 169–203 (2015)MathSciNetCrossRefGoogle Scholar
  5. [AWHT16]
    Aono, Y., Wang, Y., Hayashi, T., Takagi, T.: Improved progressive BKZ algorithms and their precise cost estimation by sharp simulator. In: Fischlin, M., Coron, J.-S. (eds.) EUROCRYPT 2016. LNCS, vol. 9665, pp. 789–819. Springer, Heidelberg (2016). Scholar
  6. [BG14]
    Bai, S., Galbraith, S.D.: An improved compression technique for signatures based on learning with errors. In: Benaloh, J. (ed.) CT-RSA 2014. LNCS, vol. 8366, pp. 28–47. Springer, Cham (2014). Scholar
  7. [BSW16]
    Bai, S., Stehlé, D., Wen, W.: Improved reduction from the bounded distance decoding problem to the unique shortest vector problem in lattices. In: Chatzigiannakis, I., Mitzenmacher, M., Rabani, Y., Sangiorgi, D. (eds.) ICALP 2016, Volume 55 of LIPIcs, pp. 76:1–76:12. Schloss Dagstuhl, July 2016Google Scholar
  8. [Che13]
    Chen, Y.: Réduction de réseau et sécurité concrete du chiffrement completement homomorphe. Ph.D. thesis, ENS-Lyon, France (2013)Google Scholar
  9. [CN11]
    Chen, Y., Nguyen, P.Q.: BKZ 2.0: better lattice security estimates. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 1–20. Springer, Heidelberg (2011). Scholar
  10. [DK13]
    Dadush, D., Kun, G.: Lattice sparsification and the approximate closest vector problem. In: Khanna, S. (ed.) 24th SODA, pp. 1088–1102. ACM-SIAM, January 2013CrossRefGoogle Scholar
  11. [DRS14]
    Dadush, D., Regev, O., Stephens-Davidowitz, N.: On the closest vector problem with a distance guarantee. In: IEEE 29th Conference on Computational Complexity, CCC 2014, Vancouver, BC, Canada, June 11–13, 2014, pp. 98–109. IEEE Computer Society (2014)Google Scholar
  12. [GSW13]
    Gentry, C., Sahai, A., Waters, B.: homomorphic encryption from learning with errors: conceptually-simpler, asymptotically-faster, attribute-based. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013. LNCS, vol. 8042, pp. 75–92. Springer, Heidelberg (2013). Scholar
  13. [Kan87]
    Kannan, R.: Minkowski’s convex body theorem and integer programming. Math. Oper. Res. 12(3), 415–440 (1987)MathSciNetCrossRefGoogle Scholar
  14. [Kho03]
    Khot, S.: Hardness of approximating the shortest vector problem in high Lp norms. In: 44th FOCS, pp. 290–297. IEEE Computer Society Press, October 2003Google Scholar
  15. [Kho04]
    Khot, S.: Hardness of approximating the shortest vector problem in lattices. In: 45th FOCS, pp. 126–135. IEEE Computer Society Press, October 2004Google Scholar
  16. [LLM06]
    Liu, Y.-K., Lyubashevsky, V., Micciancio, D.: On bounded distance decoding for general lattices. In: Díaz, J., Jansen, K., Rolim, J.D.P., Zwick, U. (eds.) APPROX/RANDOM-2006. LNCS, vol. 4110, pp. 450–461. Springer, Heidelberg (2006). Scholar
  17. [LM09]
    Lyubashevsky, V., Micciancio, D.: On bounded distance decoding, unique shortest vectors, and the minimum distance problem. In: Halevi, S. (ed.) CRYPTO 2009. LNCS, vol. 5677, pp. 577–594. Springer, Heidelberg (2009). Scholar
  18. [LP10]
    Lindner, R., Peikert, C.: Better key sizes (and attacks) for LWE-based encryption. Cryptology ePrint Archive, Report 2010/613 (2010).
  19. [LP11]
    Lindner, R., Peikert, C.: Better key sizes (and attacks) for LWE-based encryption. In: Kiayias, A. (ed.) CT-RSA 2011. LNCS, vol. 6558, pp. 319–339. Springer, Heidelberg (2011). Scholar
  20. [LWXZ14]
    Liu, M., Wang, X., Guangwu, X., Zheng, X.: A note on BDD problems with \(\lambda \)\({}_{\text{2 }}\)-gap. Inf. Process. Lett. 114(1–2), 9–12 (2014)MathSciNetCrossRefGoogle Scholar
  21. [Reg09]
    Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. J. ACM 56(6), 140 (2009)MathSciNetCrossRefGoogle Scholar
  22. [SD16]
    Stephens-Davidowitz, N.: Discrete Gaussian sampling reduces to CVP and SVP. In: Krauthgamer, R. (ed.) 27th SODA, pp. 1748–1764. ACM-SIAM, January 2016Google Scholar
  23. [SE94]
    Schnorr, C.-P., Euchner, M.: Lattice basis reduction: improved practical algorithms and solving subset sum problems. Math. Program. 66, 181–199 (1994)MathSciNetCrossRefGoogle Scholar
  24. [Var97]
    Vardy, A.: Algorithmic complexity in coding theory and the minimum distance problem (invited session). In: 29th ACM STOC, pp. 92–109. ACM Press, May 1997Google Scholar
  25. [WAT18]
    Wang, Y., Aono, Y., Takagi, T.: An experimental study of kannan’s embedding technique for the search LWE problem. In: Qing, S., Mitchell, C., Chen, L., Liu, D. (eds.) ICICS 2017. LNCS, vol. 10631, pp. 541–553. Springer, Cham (2018). Scholar

Copyright information

© Springer Nature Switzerland AG 2018

Authors and Affiliations

  1. 1.Kyushu UniversityFukuokaJapan
  2. 2.The University of TokyoTokyoJapan
  3. 3.Technische Universität DarmstadtDarmstadtGermany

Personalised recommendations