Recommendations
- LWE with side information: attacks and concrete security estimation
- Revisiting security estimation for LWE with hints from a geometric perspective
- On dual lattice attacks against small-secret LWE and parameter choices in HElib and SEAL
- Faster Dual Lattice Attacks for Solving LWE with Applications to CRYSTALS
- Better key sizes (and attacks) for LWE-based encryption
Cites work
- (Leveled) fully homomorphic encryption without bootstrapping
- A hierarchy of polynomial time lattice basis reduction algorithms
- An Improved Low-Density Subset Sum Algorithm
- Efficient public key encryption based on ideal lattices (extended abstract)
- Factoring polynomials with rational coefficients
- Hardness of computing the most significant bits of secret keys in Diffie-Hellman and related schemes
- scientific article; zbMATH DE number 4213909 (Why is no real title available?)
- scientific article; zbMATH DE number 1186948 (Why is no real title available?)
- scientific article; zbMATH DE number 1256724 (Why is no real title available?)
- scientific article; zbMATH DE number 1559544 (Why is no real title available?)
- scientific article; zbMATH DE number 1859030 (Why is no real title available?)
- Lattice attacks on NTRU and LWE: a history of refinements
- Lattice reduction: a toolbox for the cryptoanalyst
- LWE with side information: attacks and concrete security estimation
- Natural density of rectangular unimodular integer matrices
- On ideal lattices and learning with errors over rings
- On lattices, learning with errors, random linear codes, and cryptography
- Partial key exposure attacks on BIKE, Rainbow and NTRU
- Pseudorandomness of ring-LWE for any ring and modulus
- Small solutions to polynomial equations, and low exponent RSA vulnerabilities
- Worst-case to average-case reductions for module lattices
Cited in
(9)- Revisiting security estimation for LWE with hints from a geometric perspective
- Finding and protecting the weakest link. On side-channel attacks on \(\mathrm{y}\) in masked ML-DSA
- Refined attack on LWE with hints: constructing lattice via Gaussian elimination
- A generic framework for side-channel attacks against LWE-based cryptosystems
- Revisiting the security of approximate FHE with noise-flooding countermeasures
- One bit to rule them all -- imperfect randomness harms lattice signatures
- Fast slicer for Batch-CVP: making lattice hybrid attacks practical
- IND-CPA-D and KR-D security with reduced noise from the HintLWE problem
- One (noisy) bit to rule them all: key recovery from randomness leakage in ML-DSA
This page was built for publication: Too many hints -- when LLL breaks LWE
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q6604869)