On the probability of generating a lattice

From MaRDI portal
Publication:2437315



Abstract: We study the problem of determining the probability that m vectors selected uniformly at random from the intersection of the full-rank lattice L in R^n and the window [0,B)^n generate Lambda when B is chosen to be appropriately large. This problem plays an important role in the analysis of the success probability of quantum algorithms for solving the Discrete Logarithm Problem in infrastructures obtained from number fields and also for computing fundamental units of number fields. We provide the first complete and rigorous proof that 2n+1 vectors suffice to generate L with constant probability (provided that B is chosen to be sufficiently large in terms of n and the covering radius of L and the last n+1 vectors are sampled from a slightly larger window). Based on extensive computer simulations, we conjecture that only n+1 vectors sampled from one window suffice to generate L with constant success probability. If this conjecture is true, then a significantly better success probability of the above quantum algorithms can be guaranteed.


Motivated by an analysis of the success probability of quantum algorithms for solving the discrete logarithm problem in infrastructures obtained from number fields, the paper under review studies the problem of determining the probability that \(m\) vectors selected uniformly at random from \({\mathcal L} \cap [0,B)^n\) generate the (full-rank) lattice \({\mathcal L} \subset {\mathbb R^n}\), when \(B\) is chosen appropriately large. To state the main theorem precisely, assume that \(B \geq 8 n^{ n \over 2 } \nu({\mathcal L})\) and \(B_1 \geq 8 n^2 (n+1) B\), where \(\nu({\mathcal L})\) is the covering radius of \(\mathcal L\) (i.e., the smallest \(r\) such that translates by \(\mathcal L\) of a ball of radius \(r\) covers \({\mathbb R}^n\)), and that \(n\) vectors are selected uniformly at random from \({\mathcal L} \cap [0,B)^n\) and \(n+1\) vectors from \({\mathcal L} \cap [0,B)^n\). If the vectors are sampled independently then the probability that they generate \(\mathcal L\) is at least \[ \left( \prod_{ j=2 }^{ n+1 } \zeta(j)^{ -1 } - {1 \over 4} \right) \prod_{ k=0 }^{ n-1 } \left( 1 - n^{ k \over 2 } {{ \left( 4 n^{ n \over 2 } + 1 \right)^k } \over { \left( 4 n^{ n \over 2 } - 1 \right)^n }} \right) . \] This means that \(2n+1\) vectors suffice to generate \(\mathcal L\) with constant probability, provided that \(B\) is chosen sufficiently large. The authors conjecture that the quantity \(2n+1\) in this statement can be replaced by \(n+1\).





Describes a project that uses

Uses Software






This page was built for publication: On the probability of generating a lattice

Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q2437315)