2019/02/21 by Noah Stephens-Davidowitz, Stephens-Davidowitz, Noah
Computer Science · #Coding theory and cryptography #Complexity and Algorithms in Graphs #Cryptography and Data Security #Data Structures and Algorithms (cs.DS) #FOS: Computer and information sciences #cs.DS
paper · pdf · doi:10.48550/arxiv.1902.08340
openalex publication_date 2019/02/21 · arxiv created 2019/02/25 · arxiv updated 2019/02/26 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
For 0 ≤ α≤ 1/2, we show an algorithm that does the following. Given appropriate preprocessing P(L) consisting of Nα:= 2^O(n1-2α + log n) vectors in some lattice L ⊂ ℝn and a target vector \boldsymbolt∈ ℝn, the algorithm finds \boldsymboly ∈ L such that ‖\boldsymboly- \boldsymbolt‖ ≤ n1/2 + α η(L) in time poly(n) ⋅ Nα, where η(L) is the smoothing parameter of the lattice. The algorithm itself is very simple and was originally studied by Doulgerakis, Laarhoven, and de Weger (to appear in PQCrypto, 2019), who proved its correctness under certain reasonable heuristic assumptions on the preprocessing P(L) and target \boldsymbolt. Our primary contribution is a choice of preprocessing that allows us to prove correctness without any heuristic assumptions. Our main motivation for studying this is the recent breakthrough algorithm for IdealSVP due to Hanrot, Pellet--Mary, and Stehlé (to appear in Eurocrypt, 2019), which uses the DLW algorithm as a key subprocedure. In particular, our result implies that the HPS IdealSVP algorithm can be made to work with fewer heuristic assumptions. Our only technical tool is the discrete Gaussian distribution over L, and in particular, a lemma showing that the one-dimensional projections of this distribution behave very similarly to the continuous Gaussian. This lemma might be of independent interest.