##
**A hybrid lattice basis reduction and quantum search attack on LWE.**
*(English)*
Zbl 1437.94067

Lange, Tanja (ed.) et al., Post-quantum cryptography. 8th international workshop, PQCrypto 2017, Utrecht, The Netherlands, June 26–28, 2017. Proceedings. Cham: Springer. Lect. Notes Comput. Sci. 10346, 184-202 (2017).

Summary: Recently, an increasing amount of papers proposing post-quantum schemes also provide concrete parameter sets aiming for concrete post-quantum security levels. Security evaluations of such schemes need to include all possible attacks, in particular those by quantum adversaries. In the case of lattice-based cryptography, currently existing quantum attacks are mainly classical attacks, carried out with quantum basis reduction as subroutine.{

}In this work, we propose a new quantum attack on the Learning with Errors (LWE) problem, whose hardness is the foundation for many modern lattice-based cryptographic constructions. Our quantum attack is based on Howgrave-Graham’s classical hybrid attack and is suitable for LWE instances in recent cryptographic proposals. We analyze its runtime complexity and optimize it over all possible choices of the attack parameters. In addition, we analyze the concrete post-quantum security levels of the parameter sets proposed for the New Hope and Frodo key exchange schemes, as well as several instances of the Lindner-Peikert encryption scheme. Our results show that – depending on the assumed basis reduction costs – our quantum hybrid attack either significantly outperforms, or is at least comparable to all other attacks covered by Albrecht-Player-Scott in their work “On the concrete hardness of Learning with Errors”. We further show that our quantum hybrid attack improves upon the classical hybrid attack in the case of LWE with binary error.

For the entire collection see [Zbl 1386.94004].

}In this work, we propose a new quantum attack on the Learning with Errors (LWE) problem, whose hardness is the foundation for many modern lattice-based cryptographic constructions. Our quantum attack is based on Howgrave-Graham’s classical hybrid attack and is suitable for LWE instances in recent cryptographic proposals. We analyze its runtime complexity and optimize it over all possible choices of the attack parameters. In addition, we analyze the concrete post-quantum security levels of the parameter sets proposed for the New Hope and Frodo key exchange schemes, as well as several instances of the Lindner-Peikert encryption scheme. Our results show that – depending on the assumed basis reduction costs – our quantum hybrid attack either significantly outperforms, or is at least comparable to all other attacks covered by Albrecht-Player-Scott in their work “On the concrete hardness of Learning with Errors”. We further show that our quantum hybrid attack improves upon the classical hybrid attack in the case of LWE with binary error.

For the entire collection see [Zbl 1386.94004].