• No results found

[PDF] Top 20 Provably weak instances of Ring-LWE

Has 10000 "Provably weak instances of Ring-LWE" found on our website. Below are the top 20 most common "Provably weak instances of Ring-LWE".

Provably  weak  instances  of  Ring-LWE

Provably weak instances of Ring-LWE

... of Ring-LWE to these attacks, we state and examine the Ring-LWE problem for general number rings and demonstrate provably weak instances of ...that Ring-LWE ... See full document

26

LP  Solutions  of  Vectorial  Integer  Subset  Sums -  Cryptanalysis  of  Galbraith's  Binary  Matrix  LWE

LP Solutions of Vectorial Integer Subset Sums - Cryptanalysis of Galbraith's Binary Matrix LWE

... indeed weak – based on an estimation of the volume of the search space that comes from the LP ...identifying weak instances I is a quite remarkable prop- erty of Linear ... See full document

13

Partial  Key  Exposure  in  Ring-LWE-Based  Cryptosystems:  Attacks   and  Resilience

Partial Key Exposure in Ring-LWE-Based Cryptosystems: Attacks and Resilience

... Thus far we focused only on guessing sets of variables from the error terms of the RLWE instances; we extend our attack to guess sets of variables from the RLWE secret as well. Specifically, if a candidate ... See full document

28

Practical  CCA2-Secure   and  Masked  Ring-LWE  Implementation

Practical CCA2-Secure and Masked Ring-LWE Implementation

... of ring-LWE PKE schemes that need to be considered before any wide-spread deployment of lattice- based cryptography can be ...instantiate ring-LWE public-key encryption ( n = 1024, q = 12289, ... See full document

33

A  masked  ring-LWE  implementation

A masked ring-LWE implementation

... There are plenty of countermeasures against DPA. Most notably, masking [6,12] is both a provably sound and popular in industry. Masking effectively randomizes the computation of the cryptographic algorithm by ... See full document

21

Cold  Boot  Attacks  on  Ring   and  Module  LWE  Keys  Under  the  NTT

Cold Boot Attacks on Ring and Module LWE Keys Under the NTT

... boot instances, each one corresponding to an individual polynomial in the secret key; this leads to multiple instances of relatively low dimension for ... See full document

53

Ring-LWE  Cryptography  for  the  Number  Theorist

Ring-LWE Cryptography for the Number Theorist

... In [ELOS], the attack on PLWE was extended by weakening the condi- tions on f (x) and the reduction from RLWE to PLWE was extended by weakening condition (4). A large class of fields were constructed where the attack on ... See full document

20

Indistinguishability  Obfuscation  Without  Multilinear  Maps:  iO  from   LWE,  Bilinear  Maps,   and  Weak  Pseudorandomness

Indistinguishability Obfuscation Without Multilinear Maps: iO from LWE, Bilinear Maps, and Weak Pseudorandomness

... The correctness of our scheme follows immediately from the correctness properties of the TFHE scheme. Intuitively, security seems to hold because of the following argument. Upon combining λ 2 independent, random ... See full document

108

On  the  Ring-LWE   and  Polynomial-LWE  problems

On the Ring-LWE and Polynomial-LWE problems

... identify weak generating polynomials f of a number field K, but they only work for error distributions with small width relative to the geom- etry of the corresponding ring ... See full document

39

Weak  Instances  of  PLWE

Weak Instances of PLWE

... When selecting secure parameters for cryptographic applications of the hardness of RLWE, the following known attacks are currently taken into account. The distinguishing attack considered in [MR09,RS10] for LWE ... See full document

12

CHIMERA:  Combining  Ring-LWE-based  Fully  Homomorphic  Encryption  Schemes

CHIMERA: Combining Ring-LWE-based Fully Homomorphic Encryption Schemes

... As a byproduct of our analysis of the three above schemes from the perspec- tive of TFHE, we propose the general definition of a FHE module structure, that is, an external product allowing to homomorphically evaluate the ... See full document

29

Weak incidence algebra and maximal ring of quotients

Weak incidence algebra and maximal ring of quotients

... 3. Isomorphism. Let X be any preordered set (i.e., X is a set with a relation that is reflexive and transitive). For any x, y ∈ X, set x y, if x y x. Then is an equivalence relation. A preordered set X is said to be a ... See full document

11

NEON  PQCryto:  Fast   and  Parallel  Ring-LWE  Encryption  on  ARM  NEON  Architecture

NEON PQCryto: Fast and Parallel Ring-LWE Encryption on ARM NEON Architecture

... (e.g., Ring-LWE) on different ...of LWE and ring-LWE based encryp- tion schemes were presented by G¨ottert et ...the ring-LWE based encryption scheme is faster by at least ... See full document

8

The  impact  of  error  dependencies  on  Ring/Mod-LWE/LWR  based  schemes

The impact of error dependencies on Ring/Mod-LWE/LWR based schemes

... in Ring-LWE or Mod-LWE schemes such as New Hope [1], LAC [14], LIMA [16], ...in Ring-LWR and Mod-LWR schemes as in Round2 [8] and Saber [3] ... See full document

13

On  the  Leakage  Resilience  of  Ring-LWE  Based  Public  Key  Encryption

On the Leakage Resilience of Ring-LWE Based Public Key Encryption

... We show that in each of Leakage Scenarios I, II and III, the R-Dual-Regev encryption scheme can be proven secure, as long as the parameter s—corresponding to the standard deviation of the Gaussian from which the secret ... See full document

32

Faster  AVX2  optimized  NTT  multiplication  for  Ring-LWE  lattice  cryptography

Faster AVX2 optimized NTT multiplication for Ring-LWE lattice cryptography

... of Ring-LWE in power-of-two cyclotomic fields with completely splitting primes, the AVX2 optimized implementation of the Number-Theoretic Transform (NTT) from the NewHope key-exchange scheme is the state of ... See full document

14

High-speed  Polynomial  Multiplication  Architecture  for  Ring-LWE   and  SHE  Cryptosystems

High-speed Polynomial Multiplication Architecture for Ring-LWE and SHE Cryptosystems

... in ring-Learning With Er- rors (ring-LWE) encryption and “Somewhat” Homomorphic Encryption (SHE) ...for ring-LWE encryption and SHE are ...the ring-LWE scheme (n = 256, p ... See full document

10

Adding  Distributed  Decryption   and  Key  Generation  to  a  Ring-LWE  Based  CCA  Encryption  Scheme

Adding Distributed Decryption and Key Generation to a Ring-LWE Based CCA Encryption Scheme

... on Ring-LWE, and Fully/Somewhat Homormorphic Encryption (FHE/SHE) schemes derived from Ring-LWE being relatively new, applications of distributed decryption have found numerous applications ... See full document

18

Efficient  Evaluation  of  Low  Degree  Multivariate  Polynomials  in  Ring-LWE  Homomorphic  Encryption  Schemes

Efficient Evaluation of Low Degree Multivariate Polynomials in Ring-LWE Homomorphic Encryption Schemes

... One of the first approaches aiming to efficiently encode the messages for HE schemes is the packing method proposed by Smart and Vercauteren in [24, 14]. By using CRT (Chinese Remainder Theorem) on polynomials, one can ... See full document

17

XPIR:  Private  Information  Retrieval  for  Everyone

XPIR: Private Information Retrieval for Everyone

... 5Gbits/s. After importation, the database is pro- cessed during the reply generation phase at roughly 20Gbits/s. If data is quickly obsolete (e.g. IPTV streams) the main bottleneck is getting the data into NTT-CRT form ... See full document

24

Show all 10000 documents...