A time-distance trade-off for GDD with preprocessing---Instantiating the DLW heuristic

02/22/2019
by   Noah Stephens-Davidowitz, et al.
0

For 0 ≤α≤ 1/2, we show an algorithm that does the following. Given appropriate preprocessing P(L) consisting of N_α := 2^O(n^1-2α + n) vectors in some lattice L⊂R^n and a target vector t∈R^n, the algorithm finds y∈L such that y- t≤ n^1/2 + αη(L) in time poly(n) · N_α, where η(L) is the smoothing parameter of the lattice. The algorithm itself is very simple and was originally studied by Doulgerakis, Laarhoven, and de Weger (to appear in PQCrypto, 2019), who proved its correctness under certain reasonable heuristic assumptions on the preprocessing P(L) and target t. Our primary contribution is a choice of preprocessing that allows us to prove correctness without any heuristic assumptions. Our main motivation for studying this is the recent breakthrough algorithm for IdealSVP due to Hanrot, Pellet--Mary, and Stehlé (to appear in Eurocrypt, 2019), which uses the DLW algorithm as a key subprocedure. In particular, our result implies that the HPS IdealSVP algorithm can be made to work with fewer heuristic assumptions. Our only technical tool is the discrete Gaussian distribution over L, and in particular, a lemma showing that the one-dimensional projections of this distribution behave very similarly to the continuous Gaussian. This lemma might be of independent interest.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/07/2018

Maximum Distance Sub-Lattice Problem

In this paper, we define a problem on lattices called the Maximum Distan...
research
06/10/2020

The nearest-colattice algorithm

In this work, we exhibit a hierarchy of polynomial time algorithms solvi...
research
07/22/2020

Improved Distance Sensitivity Oracles with Subcubic Preprocessing Time

We consider the problem of building Distance Sensitivity Oracles (DSOs)....
research
11/06/2019

Fine-grained hardness of CVP(P)— Everything that we can prove (and nothing else)

We show that the Closest Vector Problem in the ℓ_p norm (CVP_p) cannot b...
research
12/16/2021

Non-Gaussian Component Analysis via Lattice Basis Reduction

Non-Gaussian Component Analysis (NGCA) is the following distribution lea...
research
10/09/2020

Lattice (List) Decoding Near Minkowski's Inequality

Minkowski proved that any n-dimensional lattice of unit determinant has ...

Please sign up or login with your details

Forgot password? Click here to reset