logo IMB
Retour

Séminaire de Théorie Algorithmique des Nombres

A unified reduction from RLWE to MP-LWE

Wenwen Xia

( UB )

Salle 2

29 septembre 2026 à 11:00

Ring Learning With Errors (RLWE) is a central assumption in lattice-based cryptography, but its hardness depends on the underlying number field. Middle-Product Learning With Errors (MP-LWE) offers a structured alternative whose definition is independent of any particular number field. Previous reductions from RLWE to MP-LWE cover different families of fields, and neither of the two main approaches subsumes the other.

In this talk, I will present a unified reduction framework for both primal and dual RLWE, parameterized by a pair of field elements, which recovers both previous approaches. Using geometry of numbers, we prove the existence of parameters giving polynomial noise growth for every monic irreducible defining polynomial whose coefficients are polynomially bounded in its degree. The result holds for sufficiently large prime moduli coprime to the polynomial discriminant, extending the families covered by previous reductions. I will explain the algebraic mechanism and the geometry behind the noise bound. The reduction is non-uniform: suitable parameters are proved to exist, while finding them in polynomial time cost in general remains open.