Lecture 14 – Short Integer Solutions, lattice
Description: Lecture 14 Short Integer Solutions, lattice signatures, ML-DSA TEK4500 19.11.2025 Håkon Jacobsen hakon.jacobsenits.uio.no Recap: notation 2 Recap: linear algebra basics Matrix-vector multiplication 3 Recap: Learning With Errors (LWE) 4
Related Topics
Download Presentation
"Lecture 14 – Short Integer Solutions, lattice" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Lecture 14 – Short Integer Solutions,lattice signatures, ML-DSA TEK4500
19.11.2025
Håkon Jacobsen
hakon.jacobsen@its.uio.no<br>
slide2. Recap: notation 2<br>
slide3. Recap: linear algebra basics Matrix-vector multiplication 3<br>
slide4. Recap: Learning With Errors (LWE) 4 random in random in random in<br>
slide5. Recap: LWE-KEM Correctness: public 5<br>
slide6. Recap: computational aspects 6<br>
slide7. Recap: computational aspects 7<br>
slide8. Recap: computational aspects 8<br>
slide9. Making LWE more efficient – Ring-LWE only one LWE sample! 9 The dream: Solution: polynomials<br>
slide10. Plain-LWE vs. Module-LWE vs. Ring-LWE Each row is the cyclic shift of the row above; lots of structure 10 Completely random matrix;
no structure Plain-LWE Ring-LWE<br>
slide11. Plain-LWE vs. Module-LWE vs. Ring-LWE Plain-LWE Ring-LWE Module-LWE 11 "Hybrid" between plain LWE and Ring-LWE Each row is the cyclic shift of the row above; lots of structure Completely random matrix;
no structure Can extra structure be exploited?Ring-LWE assumption: no More structure than plain-LWE, less structure than Ring-LWE Can extra structure be exploited?Module-LWE assumption: no<br>
slide12. ML-KEM (Kyber) 12<br>
slide13. Signatures from lattices<br>
slide14. Linear algebra basics Matrix-matrix multiplication 14<br>
slide15. Short Integer Solutions (SIS) problem 15 Theorem: The SIS and ISIS problems are computationally equivalent<br>
slide16. SIS as a lattice problem 16 SIS solutions<br>
slide17. Recap: DLOG proof of knowledge 17<br>
slide18. Recap: DLOG proof of knowledge 18<br>
slide19. Recap: DLOG proof of knowledge 19<br>
slide20. Recap: Interactive signature scheme 20<br>
slide21. Recap: Non-interactive signature scheme 21 <br>
slide22. Recap: Non-interactive signature scheme 22 (Schnorr)<br>
slide23. Lattice-based proof of knowledge 23 accept if difficult to find by the LWE assumption …or is it?<br>
slide24. Lattice-based proof of knowledge 24 accept if no guarantee that these are small<br>
slide25. Lattice-based proof of knowledge 25 accept if<br>
slide26. Lattice-based proof of knowledge 26 accept if <br>
slide27. Lattice-based proof of knowledge 27 accept if else abort <br>
slide28. Lattice-based proof of knowledge 28 accept if else abort (assuming no abort)<br>
slide29. Lattice-based signatures 29 (assuming no abort) accept if<br>
slide30. Lattice-based signatures 30 (assuming no abort) accept if<br>
slide31. ML-DSA (Dilithium) Standardized Lattice-based signature scheme
Selected as the winner of NIST-led competitionthat began in in 2017
Based on Module-LWE/SIS
Many optimizations over the previous signature scheme
Closer to Ring-LWE than Plain-LWE
Number Theoretic Transform (NTT) for faster (polynomial) multiplication
Compresses signing key, verification key, and signature 31<br>
slide32. End of Part II
(Asymmetric crypto)<br>
slide33. Summary of asymmetric cryptography 33<br>
slide34. Summary of asymmetric cryptography 34<br>
slide35. Summary of asymmetric cryptography 35<br>
slide36. Next week Guest lecture by Hagen Echzell
Topic: end-to-end encryption in group messaging protocols
Course recap
Mini-lecture summarizing the main topics covered this year
Going through old exams 36<br>
19.11.2025
Håkon Jacobsen
hakon.jacobsen@its.uio.no<br>
slide2. Recap: notation 2<br>
slide3. Recap: linear algebra basics Matrix-vector multiplication 3<br>
slide4. Recap: Learning With Errors (LWE) 4 random in random in random in<br>
slide5. Recap: LWE-KEM Correctness: public 5<br>
slide6. Recap: computational aspects 6<br>
slide7. Recap: computational aspects 7<br>
slide8. Recap: computational aspects 8<br>
slide9. Making LWE more efficient – Ring-LWE only one LWE sample! 9 The dream: Solution: polynomials<br>
slide10. Plain-LWE vs. Module-LWE vs. Ring-LWE Each row is the cyclic shift of the row above; lots of structure 10 Completely random matrix;
no structure Plain-LWE Ring-LWE<br>
slide11. Plain-LWE vs. Module-LWE vs. Ring-LWE Plain-LWE Ring-LWE Module-LWE 11 "Hybrid" between plain LWE and Ring-LWE Each row is the cyclic shift of the row above; lots of structure Completely random matrix;
no structure Can extra structure be exploited?Ring-LWE assumption: no More structure than plain-LWE, less structure than Ring-LWE Can extra structure be exploited?Module-LWE assumption: no<br>
slide12. ML-KEM (Kyber) 12<br>
slide13. Signatures from lattices<br>
slide14. Linear algebra basics Matrix-matrix multiplication 14<br>
slide15. Short Integer Solutions (SIS) problem 15 Theorem: The SIS and ISIS problems are computationally equivalent<br>
slide16. SIS as a lattice problem 16 SIS solutions<br>
slide17. Recap: DLOG proof of knowledge 17<br>
slide18. Recap: DLOG proof of knowledge 18<br>
slide19. Recap: DLOG proof of knowledge 19<br>
slide20. Recap: Interactive signature scheme 20<br>
slide21. Recap: Non-interactive signature scheme 21 <br>
slide22. Recap: Non-interactive signature scheme 22 (Schnorr)<br>
slide23. Lattice-based proof of knowledge 23 accept if difficult to find by the LWE assumption …or is it?<br>
slide24. Lattice-based proof of knowledge 24 accept if no guarantee that these are small<br>
slide25. Lattice-based proof of knowledge 25 accept if<br>
slide26. Lattice-based proof of knowledge 26 accept if <br>
slide27. Lattice-based proof of knowledge 27 accept if else abort <br>
slide28. Lattice-based proof of knowledge 28 accept if else abort (assuming no abort)<br>
slide29. Lattice-based signatures 29 (assuming no abort) accept if<br>
slide30. Lattice-based signatures 30 (assuming no abort) accept if<br>
slide31. ML-DSA (Dilithium) Standardized Lattice-based signature scheme
Selected as the winner of NIST-led competitionthat began in in 2017
Based on Module-LWE/SIS
Many optimizations over the previous signature scheme
Closer to Ring-LWE than Plain-LWE
Number Theoretic Transform (NTT) for faster (polynomial) multiplication
Compresses signing key, verification key, and signature 31<br>
slide32. End of Part II
(Asymmetric crypto)<br>
slide33. Summary of asymmetric cryptography 33<br>
slide34. Summary of asymmetric cryptography 34<br>
slide35. Summary of asymmetric cryptography 35<br>
slide36. Next week Guest lecture by Hagen Echzell
Topic: end-to-end encryption in group messaging protocols
Course recap
Mini-lecture summarizing the main topics covered this year
Going through old exams 36<br>