Lecture 14 – Short Integer Solutions, lattice

Published  . 0 views
↓ Download
Lecture 14 – Short Integer Solutions, lattice
1 / 1
Lecture 14 – Short Integer Solutions, lattice - slide 1 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 2 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 3 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 4 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 5 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 6 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 7 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 8 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 9 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 10 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 11 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 12 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 13 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 14 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 15 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 16 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 17 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 18 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 19 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 20 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 21 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 22 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 23 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 24 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 25 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 26 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 27 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 28 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 29 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 30 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 31 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 32 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 33 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 34 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 35 of 36 Lecture 14 – Short Integer Solutions, lattice - slide 36 of 36
Description: Lecture 14 Short Integer Solutions, lattice signatures, ML-DSA TEK4500 19.11.2025 Håkon Jacobsen hakon.jacobsenits.uio.no Recap: notation 2 Recap: linear algebra basics Matrix-vector multiplication 3 Recap: Learning With Errors (LWE) 4

Related Topics

Download Presentation

"Lecture 14 – Short Integer Solutions, lattice" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Lecture 14 – Short Integer Solutions, lattice signatures, ML-DSA TEK4500
19.11.2025
Håkon Jacobsen
hakon.jacobsen@its.uio.no<br>
slide2. Recap: notation 2<br>
slide3. Recap: linear algebra basics Matrix-vector multiplication 3<br>
slide4. Recap: Learning With Errors (LWE) 4 random in random in random in<br>
slide5. Recap: LWE-KEM Correctness: public 5<br>
slide6. Recap: computational aspects 6<br>
slide7. Recap: computational aspects 7<br>
slide8. Recap: computational aspects 8<br>
slide9. Making LWE more efficient – Ring-LWE only one LWE sample! 9 The dream: Solution: polynomials<br>
slide10. Plain-LWE vs. Module-LWE vs. Ring-LWE Each row is the cyclic shift of the row above; lots of structure 10 Completely random matrix;
no structure Plain-LWE Ring-LWE<br>
slide11. Plain-LWE vs. Module-LWE vs. Ring-LWE Plain-LWE Ring-LWE Module-LWE 11 "Hybrid" between plain LWE and Ring-LWE Each row is the cyclic shift of the row above; lots of structure Completely random matrix;
no structure Can extra structure be exploited? Ring-LWE assumption: no More structure than plain-LWE, less structure than Ring-LWE Can extra structure be exploited? Module-LWE assumption: no<br>
slide12. ML-KEM (Kyber) 12<br>
slide13. Signatures from lattices<br>
slide14. Linear algebra basics Matrix-matrix multiplication 14<br>
slide15. Short Integer Solutions (SIS) problem 15 Theorem: The SIS and ISIS problems are computationally equivalent<br>
slide16. SIS as a lattice problem 16 SIS solutions<br>
slide17. Recap: DLOG proof of knowledge    17<br>
slide18. Recap: DLOG proof of knowledge    18<br>
slide19. Recap: DLOG proof of knowledge    19<br>
slide20. Recap: Interactive signature scheme    20<br>
slide21. Recap: Non-interactive signature scheme   21  <br>
slide22. Recap: Non-interactive signature scheme    22 (Schnorr)<br>
slide23. Lattice-based proof of knowledge 23 accept if   difficult to find by the LWE assumption …or is it?<br>
slide24. Lattice-based proof of knowledge 24 accept if  no guarantee that these are small<br>
slide25. Lattice-based proof of knowledge 25 accept if<br>
slide26. Lattice-based proof of knowledge 26 accept if  <br>
slide27. Lattice-based proof of knowledge 27 accept if  else abort <br>
slide28. Lattice-based proof of knowledge 28 accept if else abort    (assuming no abort)<br>
slide29. Lattice-based signatures 29   (assuming no abort)  accept if<br>
slide30. Lattice-based signatures 30   (assuming no abort)  accept if<br>
slide31. ML-DSA (Dilithium) Standardized Lattice-based signature scheme
Selected as the winner of NIST-led competition that began in in 2017
Based on Module-LWE/SIS

Many optimizations over the previous signature scheme
Closer to Ring-LWE than Plain-LWE
Number Theoretic Transform (NTT) for faster (polynomial) multiplication
Compresses signing key, verification key, and signature 31<br>
slide32. End of Part II
(Asymmetric crypto)<br>
slide33. Summary of asymmetric cryptography 33<br>
slide34. Summary of asymmetric cryptography 34<br>
slide35. Summary of asymmetric cryptography 35<br>
slide36. Next week Guest lecture by Hagen Echzell
Topic: end-to-end encryption in group messaging protocols

Course recap
Mini-lecture summarizing the main topics covered this year

Going through old exams 36<br>