[Resource Topic] 2023/1125: Finding short integer solutions when the modulus is small

Welcome to the resource topic for 2023/1125

Title:
Finding short integer solutions when the modulus is small

Authors: Léo Ducas, Thomas Espitau, Eamonn W. Postlethwaite

Abstract:

We present cryptanalysis of the inhomogenous short integer solution (ISIS) problem for anomalously small moduli (q) by exploiting the geometry of BKZ reduced bases of q-ary lattices.

We apply this cryptanalysis to examples from the literature where taking such small moduli has been suggested. A recent work [Espitau–Tibouchi–Wallet–Yu, CRYPTO 2022] suggests small (q) versions of the lattice signature scheme FALCON and its variant MITAKA.

For one small (q) parametrisation of FALCON we reduce the estimated security against signature forgery by approximately 26 bits. For one small (q) parametrisation of MITAKA we successfully forge a signature in 15 seconds.

ePrint: https://eprint.iacr.org/2023/1125

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .