Chapter 23 of Trappe & Washington: lattices as both a cryptanalytic tool and a cryptographic foundation. Covers bases and the determinant, exact two-dimensional reduction with the proof that its first vector is shortest, the LLL algorithm and its three guarantees, Coppersmith's attack recovering a stereotyped plaintext from low-exponent RSA without factoring, NTRU over convolution polynomials with a fully worked round trip and its interpretation as a short vector in a 2N-dimensional lattice, the GGH cryptosystem where the trapdoor is a choice of basis, the Closest Vector Problem, and the post-quantum motivation — with every numeric example verified.
Subject: Cryptography · 68 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 23
Short vectors as an attack and as a foundation — and the reason both are the same problem
Objectives
Lattices appear twice in this chapter, in opposite roles. Short vectors are what a cryptanalyst hunts for, and the difficulty of finding them in high dimension is what a lattice cryptosystem is built on.
Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.
Warm-up
The set of all points with integer coordinates in the plane can be described as combinations of (1, 0) and (0, 1) — or of (5, 16) and (6, 19). Both descriptions are complete and correct.
Discussion prompt
Which description would you rather have, and what makes one better?
Hint: Try to find a short point in the set using each description.
Answer:
With (1, 0) and (0, 1) the short points are obvious. They are the basis vectors, and every point's coordinates are read straight off.
With (5, 16) and (6, 19) they are not. Finding a short combination means searching over integer pairs, and the two vectors point in almost the same direction, so most combinations are long.
But the sets are identical, so the difficulty is entirely in the description. That gap — same object, very different usability — is what this chapter is about.
Read one way it is an attack: given a bad basis, find a good one, and short vectors fall out. That breaks low-exponent RSA with predictable plaintext.
Read the other way it is a trapdoor: publish the bad basis, keep the good one. Anyone can describe the lattice; only you can work with it comfortably. That is a public-key cryptosystem, and in high dimension nobody knows how to close the gap.
Section
Section 23.1 · pp. 441-443
Concept
Let v₁, …, v_n be linearly independent vectors in ℝⁿ. The lattice they generate is the set of vectors
\[ m_1 v_1 + \cdots + m_n v_n, \qquad m_i \in \mathbb Z \]
Integer combinations, not real ones — that single restriction is what makes a lattice a discrete grid of points rather than all of space.
The set {v₁, …, v_n} is called a basis, and a lattice has infinitely many. If {v₁, v₂} is a basis then so is {v₁ + kv₂, v₂} for any integer k, since each set of integer combinations contains the other.
More generally, any integer matrix with determinant ±1 turns one basis into another — the determinant condition is exactly what makes the inverse have integer entries too.
Figure (svg): Three different bases generating the same lattice of all integer points in the plane.
Worked example
The book's example, and it repays a moment's checking.
v₁ = (1, 0) and v₂ = (0, 1) generate all pairs (x, y) with x, y integers
Why: The standard integer grid.
{(1, 5), (0, 1)} generates the same lattice
Why: Because (1, 5) = (1,0) + 5(0,1), and conversely (1,0) = (1,5) − 5(0,1). Each basis is an integer combination of the other.
{(5, 16), (6, 19)} does too
Why: The change-of-basis matrix has determinant 5·19 − 16·6 = 95 − 96 = −1.
\[ \det \begin{pmatrix} a & b \\ c & d \end{pmatrix} = \pm 1 \;\Longrightarrow\; \{(a,b), (c,d)\} \text{ is a basis of } \mathbb Z^2 \]
Verify: determinant ±1 is exactly the right condition
Why: If the determinant were 2, the new vectors would generate only half the lattice — an index-2 sublattice. Only ±1 gives an inverse with integer entries, and hence a genuine change of basis.
Figure (svg): Three different bases generating the same lattice of all integer points in the plane.
Concept
The length of v = (x₁, …, x_n) is the usual ‖v‖ = (x₁² + ⋯ + x_n²)^{1/2}.
Shortest vector problem — Find a shortest nonzero vector in a lattice. Hard in general, and especially so when the dimension is large.
Many problems reduce to it, which is why the chapter opens here. In low dimension it is easy, and Section 23.2 gives an algorithm that solves it exactly in two dimensions.
In high dimension nothing is known that works. That gap between dimensions is not a gap in our knowledge of a fixed problem — it is a genuine change in difficulty, and it is the raw material for every construction in the second half of the chapter.
Note the shape of this. A problem that is easy small and hard large is exactly what a cryptosystem needs, and it is the same shape as factoring: trivial for six-digit numbers, infeasible for six-hundred-digit ones.
Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.
Worked example
Take the lattice generated by (31, 59) and (37, 70).
Both basis vectors have length around 70
Why: ‖(31,59)‖ ≈ 66.6 and ‖(37,70)‖ ≈ 79.2.
But (3, −1), of length √10 ≈ 3.16, is in the lattice
Why: Because (3, −1) = −19(31, 59) + 16(37, 70) — check: −589 + 592 = 3 and −1121 + 1120 = −1.
The coefficients are −19 and 16, which no amount of staring would suggest
Why: The short vector is a difference of two large near-parallel multiples, and finding it by search is hopeless even here.
A far better basis is {(3, −1), (1, 4)}
Why: Their dot product is 3 − 4 = −1, so they are nearly orthogonal — against the original pair, which are nearly parallel with a very large dot product.
Verify: the lattice was always the same; only the description improved
Why: And that is the point. Section 23.2 gives an algorithm that produces the good basis from the bad one automatically, in a handful of steps.
Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.
Prediction
Predict first
What does that 13 represent?
Correct: The area of the parallelogram spanned by the basis — the same for every basis of the lattice
Which is why D appears in the LLL bounds. The guarantee ‖b₁‖ ≤ 2^{(n−1)/4} D^{1/n} says the shortest vector found is bounded by the density of the lattice, which is the only intrinsic quantity available.
Check it on the example: D = 13, and the reduced basis {(3,−1), (1,4)} has determinant 3·4 − (−1)·1 = 13 as well. The bad basis and the good one span the same area, which is the invariance in action.
And the intuition is sound. A denser lattice has shorter vectors, so a bound on the shortest vector has to involve D — nothing else about the lattice is basis-independent.
Why: D is the volume of the parallelepiped spanned by any basis, and it is independent of which basis you use — because change of basis has determinant ±1. It measures how sparse the lattice is: a small D means points are packed closely.
Section
Section 23.2 · pp. 443-450
Concept
The goal is to replace a basis with one whose vectors are short and nearly orthogonal.
The idea is Gram-Schmidt with rounding. In linear algebra you would replace v₂ by v₂* = v₂ − μv₁ with μ = (v₁·v₂)/(v₁·v₁), which is perpendicular to v₁ — but that vector generally is not in the lattice.
So round μ to the nearest integer t and subtract that many copies instead:
The result stays in the lattice because t is an integer, and it gets shorter because subtracting the rounded projection moves v₂ closer to perpendicular.
Figure (svg): The two-dimensional reduction algorithm running on the example basis, four steps to a reduced basis.
Concept
A basis {v₁, v₂} is reduced when two conditions hold:
\[ \|v_1\| \le \|v_2\| \qquad \text{and} \qquad -\tfrac12 \le \frac{v_1 \cdot v_2}{v_1 \cdot v_1} \le \tfrac12 \]
The first says v₁ is the shorter. The second says the projection of v₂ onto v₁ is at most half of v₁ — geometrically, that the foot of v₂ lands within half a step of the origin.
And the algorithm stops exactly when the basis is reduced, because t = 0 is precisely the statement that μ lies in [−½, ½].
Which is a satisfying design. The halting condition and the definition of the goal are literally the same condition, so there is no gap between 'the algorithm finished' and 'the answer is correct'.
Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.
Worked example
Four steps, each one subtraction and a swap.
μ = 5277/4442 ≈ 1.19, so t = 1
Why: Replace v₂ by (37,70) − (31,59) = (6, 11), then swap: now v₁ = (6, 11), v₂ = (31, 59).
μ = 835/157 ≈ 5.32, so t = 5
Why: Replace (31,59) by (31,59) − 5(6,11) = (1, 4), then swap: v₁ = (1, 4), v₂ = (6, 11).
μ = 50/17 ≈ 2.94, so t = 3
Why: Replace (6,11) by (6,11) − 3(1,4) = (3, −1), then swap: v₁ = (3, −1), v₂ = (1, 4).
μ = −1/10, which lies in [−½, ½], so t = 0
Why: Stop.
Verify: the reduced basis is {(3, −1), (1, 4)}
Why: Their dot product is −1, so they are nearly orthogonal, and (3, −1) of length √10 is a shortest nonzero vector of the lattice. Four steps from a basis where the shortest vector was completely invisible.
Figure (svg): The two-dimensional reduction algorithm running on the example basis, four steps to a reduced basis.
Worked example
The proof is short and shows exactly what the rounding buys.
Write μ = (v₁·v₂)/(v₁·v₁) and v₂* = v₂ − μv₁, which is perpendicular to v₁
Why: The Gram-Schmidt vector, generally not in the lattice.
Then v₂ − tv₁ = v₂* + (μ − t)v₁, and the two pieces are orthogonal
Why: So Pythagoras applies: ‖v₂ − tv₁‖² = ‖v₂*‖² + (μ − t)²‖v₁‖².
Likewise ‖v₂‖² = ‖v₂*‖² + μ²‖v₁‖²
Why: Same decomposition with t = 0.
If t ≠ 0 then |μ − t| < |μ|, so the first quantity is strictly smaller than the second
Why: Rounding to the nearest integer moves you closer to zero whenever the nearest integer is not zero.
Verify: so every step strictly shortens v₂, and only finitely many lattice vectors are shorter than the original
Why: Hence the process cannot continue forever. Note where discreteness entered: in a continuous space the lengths could decrease forever without ever stopping.
Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.
Worked example
The second half of the theorem, and it is a neat piece of algebra.
Let av₁ + bv₂ be any nonzero lattice vector, a and b integers
Why: Expand the squared length: a²‖v₁‖² + 2ab(v₁·v₂) + b²‖v₂‖².
Reducedness gives |v₁·v₂| ≤ ½‖v₁‖², so 2ab(v₁·v₂) ≥ −|ab|‖v₁‖²
Why: The cross term cannot be very negative.
And ‖v₂‖² ≥ ‖v₁‖², so the whole thing is at least (a² − |ab| + b²)‖v₁‖²
Why: Replacing ‖v₂‖ by the smaller ‖v₁‖.
a² − ab + b² = (a − b/2)² + (3/4)b² is a non-negative integer, zero only when a = b = 0
Why: So for a nonzero vector it is at least 1.
\[ \|a v_1 + b v_2\|^2 \ge \|v_1\|^2 \]
Verify: so v₁ is a shortest nonzero vector — exactly, not approximately
Why: This is the last time in the chapter such a clean statement is available. In three dimensions and up, nothing this strong is known, and LLL settles for 'nearly shortest'.
Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.
Notation
One line does all the work.
Annotate
On: \( v_2 \mapsto v_2 - t v_1, \qquad t = \text{round}\!\left(\frac{v_1 \cdot v_2}{v_1 \cdot v_1}\right) \)
Two dimensions is the case where greedy rounding provably reaches the optimum. Everything above it is a compromise.
Concept
Reduction in dimensions above two is much harder. The most successful algorithm is due to A. Lenstra, H. Lenstra and Lovász.
Its key concession: in most applications a short vector is enough, and it need not be the shortest. LLL looks for vectors that are almost as short as possible, and that relaxation is what makes it run in polynomial time.
Given a lattice L of dimension n with determinant D = |det(v₁, …, v_n)|, and λ the length of a shortest nonzero vector, LLL produces a basis {b₁, …, b_n} with
Statement (3) is worth unpacking. If the vectors were exactly orthogonal the product of their lengths would equal D exactly. The bound says it exceeds D by at most a factor of 2^{n(n−1)/4}, so they are mostly close to orthogonal.
Figure (svg): The three guarantees the LLL algorithm provides, and the example's numbers against each.
Worked example
For the two-dimensional lattice generated by (31, 59) and (37, 70), LLL gives the same answer as the exact algorithm: b₁ = (3, −1), b₂ = (1, 4).
D = 13 and λ = ‖(3, −1)‖ = √10
Why: The determinant computed from either basis.
(1): √10 = 3.162 ≤ 2^{1/4}√13 = 4.288 ✓
Why: With n = 2 the exponent is (n−1)/4 = 1/4.
(2): √10 ≤ 2^{1/2}√10 = 4.472 ✓
Why: Here b₁ actually is the shortest, so the bound has room to spare.
(3): √10·√17 = 13.04 ≤ 2^{1/2}·13 = 18.38 ✓
Why: The basis is nearly orthogonal, and the product only slightly exceeds D.
Verify: all three hold, with room
Why: In two dimensions LLL is doing better than its guarantee. The point of the bounds is what happens when n grows — and there the factors 2^{(n−1)/2} and 2^{n(n−1)/4} become astronomically weak.
Figure (svg): The three guarantees the LLL algorithm provides, and the example's numbers against each.
Prediction
Predict first
What does that mean for its use in cryptanalysis?
Correct: Efficient in the size of the numbers, but the guarantee degrades exponentially in n — so it works in low dimension and fails in high
Which is precisely the gap the second half of the chapter exploits. NTRU's lattice has dimension 2N = 1006 for the high-security parameters, and no reduction algorithm gets near the short vector there.
And it is why the RSA attack works at all. That lattice has dimension 4 — for a cubic polynomial, d + 1 — where LLL is close to exact.
Better algorithms exist, notably BKZ, which trades running time for approximation quality by reducing blocks of the basis exactly. Choosing lattice parameters means estimating what BKZ with a given block size can achieve, and those estimates are the ongoing research the security of post-quantum schemes depends on.
Why: The running time is polynomial in both n and the bit lengths, so LLL always finishes. What degrades is the quality: the approximation factor 2^{(n−1)/2} means that for n around 300 the returned vector may be astronomically longer than the shortest. It runs, and the answer stops being useful.
Definition probe
Four lattice problems.
Sort into buckets
Sort each by whether LLL is likely to find what is wanted.
Section
Section 23.3 · pp. 450-454
Concept
Alice sends Bob messages of a predictable form:
So the message is m = B + x where B is known and |x| ≤ Y for a small bound Y. Suppose Bob's public exponent is e = 3.
\[ c \equiv (B + x)^3 \pmod n \]
Eve knows B, Y, n and c, and wants x. She forms
\[ f(T) = (B+T)^3 - c \equiv T^3 + a_2 T^2 + a_1 T + a_0 \pmod n \]
and is looking for a small root of f(T) ≡ 0 (mod n). Solving a congruence mod n usually needs the factorisation; the lattice will remove that need.
Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.
Concept
Eve applies LLL to the lattice generated by four vectors:
\[ v_1 = (n, 0, 0, 0), \; v_2 = (0, Yn, 0, 0), \; v_3 = (0, 0, Y^2 n, 0), \; v_4 = (a_0, a_1 Y, a_2 Y^2, Y^3) \]
The powers of Y are a scaling trick. A coefficient eᵢ multiplies xⁱ, and |x| ≤ Y, so the term contributes at most |eᵢ|Yⁱ. Weighting the i-th coordinate by Yⁱ makes the vector's length control the polynomial's value at x.
The multiples of n encode the congruence. Adding any of v₁, v₂, v₃ changes the coefficients by multiples of n, which does not change the polynomial mod n. So every lattice vector is a polynomial congruent to a multiple of f mod n.
LLL returns b₁, short. Writing b₁ = (e₀, Ye₁, Y²e₂, Y³e₃), the polynomial g(T) = e₃T³ + e₂T² + e₁T + e₀ satisfies g(x) ≡ 0 (mod n) — and being short, it is also small at x.
Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.
Worked example
The step that turns a congruence into an equation.
The determinant of the four vectors is n³Y⁶, so LLL gives ‖b₁‖ ≤ 2^{3/4}(n³Y⁶)^{1/4} = 2^{3/4}n^{3/4}Y^{3/2}
Why: The first LLL bound with n = 4.
And |g(x)| ≤ |e₀| + |e₁|Y + |e₂|Y² + |e₃|Y³, since |x| ≤ Y
Why: Bounding each term by its worst case.
That sum is (1,1,1,1)·(|e₀|, |e₁|Y, |e₂|Y², |e₃|Y³) ≤ ‖(1,1,1,1)‖·‖b₁‖ = 2‖b₁‖
Why: Cauchy-Schwarz, and ‖(1,1,1,1)‖ = 2.
Now assume Y < 2^{−7/6} n^{1/6}. Then 2‖b₁‖ ≤ 2^{7/4}n^{3/4}Y^{3/2} < n
Why: Substituting the bound on Y makes the whole expression less than n.
Verify: so |g(x)| < n and g(x) ≡ 0 (mod n), which forces g(x) = 0
Why: An integer that is divisible by n and smaller than n in absolute value is zero. Now g is an ordinary cubic: find its roots numerically by Newton's method, test the at most three candidates, and read off x.
Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.
Worked example
The book's worked example, verified.
n = 1927841055428697487157594258917, secretly 757285757575769 × 2545724696579693
Why: Eve does not know the factorisation and does not need it.
The message is “The answer is ∗∗” with B = 200805000114192305180009190000 and 0 ≤ x < 100
Why: So Y = 100 and the unknown is two digits.
Alice sends c ≡ (B + x)³ ≡ 30326308498619648559464058932 (mod n)
Why: Which is exactly what (B + 42)³ mod n gives.
Eve forms f with a₂ = 602415000342576915540027570000, a₁ = 1123549124004247469362171467964, a₀ = 587324114445679876954457927616
Why: Where a₀ ≡ B³ − c (mod n).
LLL on the four vectors gives b₁, hence g(T), whose roots are 42.000000000 and −0.9496 ± 76.0796 i
Why: One real root, and it is an integer.
Verify: g(42) = 0, so the plaintext is “The answer is 42”
Why: Here brute force over 100 values would also have worked. But for a 200-digit n the bound allows Y with about 33 digits — a search space of 10³³, which no brute force touches. The attack is real; the example is small only for legibility.
Figure (svg): The worked attack recovering a two-digit number from a stereotyped RSA message.
Concept
The same construction handles a polynomial congruence of degree d using a lattice of dimension d + 1 — provided d is small enough for LLL to run comfortably.
Coppersmith improved it considerably. His algorithm uses higher-dimensional lattices to find small roots x of a monic polynomial congruence f(T) ≡ 0 (mod n) of degree d, and it succeeds whenever
\[ |x| \le n^{1/d} \]
in time polynomial in log n and d — a much better bound than the 2^{−7/6}n^{1/6} the elementary version gives for d = 3.
The practical consequences are large. Coppersmith's method underlies the attack on RSA with partially known plaintext, the recovery of a private key from half its bits, Håstad's broadcast attack, and the factorisation of n given half the bits of p — all of Chapter 9's warnings about small exponents, in one technique.
And the fix has been standard for decades: randomised padding. OAEP destroys the stereotyped structure, so no low-degree polynomial relation exists to exploit.
Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.
Socratic
The attack converts f(x) ≡ 0 (mod n) into g(x) = 0 over the integers.
Discussion prompt
Why is the second so much easier than the first?
Hint: What would you need to solve each?
Answer:
Solving a polynomial congruence mod n generally requires the factorisation. The standard route is to solve mod p and mod q separately and recombine by CRT — and if you had p and q you would not be attacking RSA in the first place.
Solving an exact polynomial equation needs no factorisation at all. Newton's method, or any numerical root finder, locates the real roots of a cubic in microseconds.
So the lattice has traded a number-theoretic problem for an analytic one, and the analytic one is trivial. That exchange is the whole content of the attack.
The mechanism is a size argument, and it is worth naming. If an integer is divisible by n and strictly smaller than n, it is zero. The lattice's job is entirely to produce a polynomial small enough for that argument to fire.
This pattern recurs across the subject. Whenever you can force a quantity to be simultaneously divisible by something large and bounded by it, congruence collapses to equality — the same move appears in Wiener's continued-fraction attack on small RSA decryption exponents.
Anomaly
Bob uses the standard public exponent e = 65537 rather than 3.
Predict first
Does the attack still work?
Correct: No — the polynomial has degree 65537, so the lattice has 65538 dimensions and LLL is hopeless
Which is exactly why e = 65537 is the standard choice. It is large enough to defeat low-degree attacks and has only two bits set, so exponentiation is cheap — 16 squarings and one multiplication.
Coppersmith's bound |x| ≤ n^{1/d} says the same thing quantitatively. At d = 3 the unknown can be a third the bit length of n; at d = 65537 it can be a fraction of a bit, which is no attack at all.
But do not read this as 'large e makes RSA safe'. Padding is the real defence: it removes the algebraic structure that any such attack needs, and it protects against attacks that do not depend on the exponent at all.
Why: The polynomial degree equals the encryption exponent, and the lattice dimension is d + 1. At degree 3 the lattice has 4 dimensions and LLL is near-exact; at degree 65537 it has 65538, where LLL's approximation factor is beyond meaningless — and the algorithm would not finish in any case.
Faded example
Four blanks.
Fill in the blanks
Eve knows the message is B + x with |x| ≤ Y, and forms the polynomial f(T) = (B+T)³ − c, which is ≡ 0 mod n at T = x. She builds a lattice whose coordinates are weighted by powers of Y, runs LLL to find a short vector, and reads off a polynomial g. Because g is short, |g(x)| < n; because g ≡ c₄f mod n, g(x) ≡ 0 mod n. Therefore g(x) = 0 exactly, and x is found by a numerical root finder.
Why: The last step is the whole attack: an integer divisible by n and smaller than n must be zero, and the lattice exists solely to make g small enough for that to apply.
Section
Section 23.4 · pp. 454-459
Concept
If the dimension is large, say n ≥ 100, LLL cannot find short vectors — and that is what allows lattices to be used constructively. NTRU is the most successful such system.
The arithmetic is on polynomials of degree less than N, with a product defined by
\[ h = f * g, \qquad c_i = \sum_{j + k \equiv i \, (\mathrm{mod}\, N)} a_j b_k \]
Which is ordinary polynomial multiplication modulo Xᴺ − 1 — the exponents wrap around, hence 'convolution'.
L(j, k) — The set of polynomials of degree less than N with j coefficients equal to +1, k coefficients equal to −1, and the rest 0. NTRU works with these small polynomials throughout.
Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.
Worked example
The book's small example, with N = 3.
f = X² + 7X + 9 and g = 3X² + 2X + 5
Why: So the coefficient lists, constant first, are (9, 7, 1) and (5, 2, 3).
The coefficient of X is c₁ = a₀b₁ + a₁b₀ + a₂b₂
Why: The pairs (j, k) with j + k ≡ 1 (mod 3): (0,1), (1,0) and (2,2).
= 9·2 + 7·5 + 1·3 = 18 + 35 + 3 = 56
Why: Note the (2,2) term, which is the wrap-around: X²·X² = X⁴ = X modulo X³ − 1.
Verify: f ∗ g = 46X² + 56X + 68
Why: The wrap-around is the only difference from ordinary polynomial multiplication, and it is what keeps every product inside the same fixed-size space — which is what makes the arithmetic uniform and fast.
Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.
Concept
Bob chooses integers N, p, q with gcd(p, q) = 1 and p much smaller than q. The book's recommended parameters:
He picks two secret small polynomials f and g, with f invertible both mod p and mod q — that is, there are F_p and F_q with F_p ∗ f ≡ 1 (mod p) and F_q ∗ f ≡ 1 (mod q). He computes
\[ h \equiv F_q * g \pmod q \]
Public key: (N, p, q, h). Private key: f, with F_p stored secretly since decryption needs it. He need not keep g, since g ≡ f ∗ h (mod q) recovers it.
A detail with a reason: f has a different number of +1s and −1s so that f(1) ≠ 0 — because f(1) = 0 makes f non-invertible.
Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.
Concept
Alice represents her message as a polynomial m of degree less than N with coefficients of absolute value at most (p−1)/2 — so for p = 3, coefficients in {−1, 0, 1}.
She chooses a small random φ and sends
\[ c \equiv p\phi * h + m \pmod q \]
Bob decrypts in two steps. First a ≡ f ∗ c (mod q), with every coefficient of a taken in (−q/2, q/2]. Then
\[ m \equiv F_p * a \pmod p \]
Sometimes it fails. With the recommended parameters the probability of a decryption error is under 5 × 10⁻⁵ — small, but not zero, which is unusual among the systems in this course and something a protocol using NTRU must handle.
Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.
Worked example
The argument turns on the coefficients staying small.
a ≡ f ∗ c ≡ f ∗ (pφ ∗ h + m) (mod q)
Why: Substituting the ciphertext.
Since h ≡ F_q ∗ g, this is f ∗ pφ ∗ F_q ∗ g + f ∗ m
Why: And F_q ∗ f ≡ 1 (mod q), so the f and F_q cancel.
a ≡ pφ ∗ g + f ∗ m (mod q)
Why: The private key has done its job: the mask is stripped.
Now the crucial step: φ, g, f and m all have small coefficients, and p is much smaller than q
Why: So with very high probability the polynomial pφ ∗ g + f ∗ m has every coefficient below q/2 in absolute value — meaning the congruence is an equality.
Reduce mod p: F_p ∗ a = pF_p ∗ φ ∗ g + F_p ∗ f ∗ m
Why: The first term vanishes because of the factor p, and F_p ∗ f ≡ 1 (mod p).
Verify: F_p ∗ a ≡ m (mod p)
Why: And note where the failure probability comes from: if any coefficient of pφ ∗ g + f ∗ m does exceed q/2, the congruence is not an equality and the decryption is wrong. It is the same 'small enough to be exact' argument as the RSA attack, used constructively.
Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.
Worked example
Too small for any security, and small enough to check every step. (N, p, q) = (5, 3, 16).
Bob takes f = X⁴ + X − 1 and g = X³ − X
Why: And computes the inverses: F_p = F_q = X³ + X² − 1, since (X³+X²−1) ∗ (X⁴+X−1) ≡ 1 both mod 3 and mod 16.
h ≡ F_q ∗ g ≡ −X⁴ − 2X³ + 2X + 1 (mod 16)
Why: The public key is (5, 3, 16, h).
Alice's message is m = X² − X + 1 and she picks φ = X − 1
Why: Coefficients in {−1, 0, 1}, as required for p = 3.
c ≡ 3φ ∗ h + m ≡ −3X⁴ + 6X³ + 7X² − 4X − 5 (mod 16)
Why: The ciphertext.
Bob computes a ≡ f ∗ c ≡ 4X⁴ − 2X³ − 5X² + 6X − 2 (mod 16)
Why: Centred in (−8, 8], and every coefficient is comfortably inside.
Verify: F_p ∗ a ≡ X² − X + 1 (mod 3) — the message
Why: Every step verified. Notice how much smaller the coefficients of a are than q = 16: that margin is the decryption-failure budget, and the recommended parameters are chosen to keep it comfortable.
Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.
Concept
NTRU is not described using lattices, but it has a lattice interpretation — and it is the main line of attack.
Build the N × N circulant matrix H whose rows are the cyclic shifts of the coefficients of h. Representing f and g as row vectors, f H ≡ g (mod q).
Now form the 2N × 2N matrix
\[ M = \begin{pmatrix} I & H \\ 0 & qI \end{pmatrix} \]
Since g = f ∗ h + qy for some y, the vector (f, y) times M equals (f, g). So (f, g) lies in the lattice generated by the rows of M — and since f and g have small coefficients, it is a short vector.
The private key is therefore a short lattice vector, and the security of NTRU is exactly the difficulty of finding it. That is why N must be large: it makes the lattice 2N-dimensional, and lattice reduction ineffective.
Figure (svg): The NTRU lattice: the private key appears as a short vector in a 2N-dimensional lattice built from the public key.
Concept
Two refinements from the book, and both are instructive about how lattice parameters are chosen.
Reduction works best when the shortest vector is small relative to the 2N-th root of the determinant. So the attacker wants the target vector to stand out, and the designer wants it to blend in.
The attacker's improvement: replace I in the upper-left block by αI for a well-chosen real α. This makes the target vector (αf, g) comparatively shorter and therefore easier to find — a rescaling exactly like the powers of Y in the RSA attack.
The designer's response: choose the sizes of f and g to limit the effect. NTRU's recommended L(j, k) parameters are set with this attack in mind, which is why they look so specific — f ∈ L(216, 215) for N = 503, not some round number.
And the tension is permanent. Larger N gives security and slower encryption; the suggested values are the compromise. The book's own verdict is measured: NTRU appears strong, its security is still being studied, and if it holds it offers RSA-comparable security with smaller keys and faster operations.
Figure (svg): The NTRU lattice: the private key appears as a short vector in a 2N-dimensional lattice built from the public key.
Definition probe
Several polynomials appear in the scheme.
Sort into buckets
Sort each by whether it is public.
Section
Section 23.5 · pp. 459-460
Concept
Goldreich, Goldwasser and Halevi's 1997 system makes the trapdoor completely explicit: it is a choice of basis.
Let L be a 300-dimensional lattice of integer points. The private key is a good basis G — good meaning the entries are small. The public key is a bad basis B = GU, where U is a secret integer matrix with determinant 1, so that U⁻¹ is integral too. Bad means many large entries.
A message is an integer vector m, encrypted as
\[ c = B m + e \]
where e is a small random error vector with entries from {0, ±1, ±2, ±3}.
Decryption is B⁻¹G ⌊G⁻¹c⌉, where ⌊·⌉ rounds each entry to the nearest integer.
Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.
Worked example
Two lines of algebra, and the rounding does the work.
Since U = G⁻¹B, we have G⁻¹c = G⁻¹Bm + G⁻¹e = Um + G⁻¹e
Why: Splitting the ciphertext into a lattice part and an error part.
U and m have integer entries, so Um is an integer vector
Why: It survives the rounding untouched.
G is good, so the entries of G⁻¹ are small — and G⁻¹e is therefore a vector of small fractions
Why: Which vanish in the rounding.
So ⌊G⁻¹c⌉ = Um, probably
Why: 'Probably' because a large enough e could push an entry past a half-integer. The error bound {0, ±1, ±2, ±3} is chosen to make that unlikely.
Verify: B⁻¹G · Um = B⁻¹GG⁻¹B m = m
Why: The message. Note that the decryption formula B⁻¹G⌊G⁻¹c⌉ simplifies to U⁻¹⌊G⁻¹c⌉, since B⁻¹G = (GU)⁻¹G = U⁻¹G⁻¹G = U⁻¹ — which is how the worked example computes it.
Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.
Worked example
The book's illustration, scaled to two dimensions and verified throughout.
G = [[5, 2], [1, 4]] and U = [[17, 18], [16, 17]], so B = GU = [[117, 124], [81, 86]]
Why: det U = 289 − 288 = 1, as required. G has small entries; B does not.
Message m = (59, 37) and error e = (1, −1) give c = Bm + e = (11492, 7960)
Why: Since Bm = (11491, 7961).
G⁻¹c = (1669.33, 1572.67), which rounds to (1669, 1573)
Why: The fractional parts came from G⁻¹e, and they are small.
U⁻¹ = [[17, −18], [−16, 17]], and U⁻¹(1669, 1573) = (59, 37)
Why: The message, recovered exactly.
Now try the bad basis: B⁻¹c = (212/3, 26) ≈ (70.67, 26)
Why: Which rounds to (71, 26).
Verify: (71, 26) is nowhere near (59, 37)
Why: The entries of B⁻¹ are much larger than those of G⁻¹, so the small error e is amplified rather than rounded away. Same lattice, same ciphertext, and the only difference is which basis you hold — which is as clean a picture of a trapdoor as the course provides.
Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.
Concept
Attacking GGH means solving a specific lattice problem.
Closest Vector Problem — Given a point P in ℝⁿ, find the lattice point closest to P. Hard for general lattices.
Bm is a lattice point, and c is close to it — moved off the lattice by the small vector e. So decrypting without the good basis means solving CVP.
But the book flags an important caveat. CVP is very hard for general lattices, and it seems to be easier when the point is very close to a lattice point — which is exactly the situation here. So the actual security level is not clear.
That caution was well placed. GGH was broken by Nguyen in 1999 for the proposed parameters, using precisely this observation: the error was small enough and structured enough to exploit. The system as specified is not used.
The idea survived, though. Modern lattice cryptography adds a crucial ingredient — errors drawn from a carefully chosen distribution, with security proved by reduction to worst-case lattice problems. Learning With Errors is that idea, and it is what the deployed post-quantum schemes are built on.
Figure (svg): The closest vector problem: a ciphertext sits just off a lattice point, and decryption is finding which one.
Section
Section 23.6 · p. 460
Concept
If a quantum computer is built, Chapter 25 will show that systems based on factoring or discrete logs become much less secure.
Lattice-based systems are among the most promising candidates, because their security does not depend on factoring or discrete logs, and no quantum attack on them has been found. The McEliece system, based on error-correcting codes and structurally similar to GGH, is another.
The difficulty is key size. GGH's public key is a 300 × 300 matrix — 90 000 integer entries, many of them large. At 100 bits each that is about 9 million bits, vastly more than any conventional public key.
NTRU is the exception, and that is why it stands out: its public key is a single polynomial with N coefficients, so a few kilobits rather than megabits. Structure buys compactness, at the price of a lattice with structure an attacker might exploit.
The chapter ends with a question mark in its title, written before the migration it anticipated began. It has since begun: NIST's standardisation selected lattice schemes — ML-KEM and ML-DSA, descended from these ideas — and NTRU itself was a finalist.
Figure (svg): Why lattices are a post-quantum candidate, and the key-size cost they carry.
Real world
The chapter's closing section asked a question that has since been answered.
Discussion prompt
What happened to lattice-based cryptography after this chapter was written?
Hint: Standardisation, deployment, and one notable casualty.
Answer:
NIST ran a post-quantum standardisation process from 2016 to 2024, and the primary selections are lattice-based: ML-KEM for key encapsulation and ML-DSA for signatures, derived from Kyber and Dilithium.
They use Learning With Errors over rings, which is a direct descendant of the ideas here — a small error hiding a lattice point, with the crucial addition that the error distribution is chosen so that security reduces to worst-case lattice problems.
Deployment has already started. Chrome and Cloudflare run hybrid X25519+ML-KEM key exchange on a large fraction of TLS connections, and Signal added a post-quantum layer to its ratchet. This is live traffic, not a pilot.
The motivation is store-now-decrypt-later. Traffic captured today can be decrypted when a quantum computer arrives, so anything requiring long-term confidentiality needs migrating before the machine exists — which is why the urgency is real despite no such machine existing.
And a cautionary note the chapter would have appreciated. SIKE, an isogeny-based finalist and not lattice-based, was broken in 2022 by a classical attack that ran in about an hour on one laptop — after years of scrutiny. New assumptions can fail suddenly, which is why the deployments are hybrids rather than replacements.
Error analysis
From a design document.
Annotate
The second is the fatal one and the most instructive: the error is not noise added for safety, it is the thing that makes the problem hard. Remove it and there is no cryptography left.
Trade off
The same problem in two roles. Fill the blanks.
Comparison matrix
| Lattices as an attack | Lattices as a foundation | |
|---|---|---|
| Dimension | small — 4 for cubic RSA | large — 1006 for NTRU at N = 503 |
| What you want | LLL to succeed | LLL to fail |
| The short vector is | a polynomial that vanishes at the secret | the private key itself |
| Design lever | reformulate in fewer dimensions | raise N until reduction is useless |
| What breaks it | padding, or a large exponent | better reduction algorithms, or structure in the lattice |
One algorithm, two opposite goals, and the same parameter — dimension — decides which side wins. That is unusually direct as design tensions go.
Matching
Five constructions from this chapter and earlier ones.
Match the pairs
Why: The first three are all lattice problems, and the difference between them is dimension and which vector is wanted. The last two are the classical assumptions that a quantum computer would break — which is exactly why the first two are interesting.
Discrimination
Six systems from the course.
Sort into buckets
Sort each by whether Shor's algorithm applies.
Edge cases
Post-quantum standards are now built on lattice problems.
Discussion prompt
What is the evidence for them, and where are the soft spots?
Hint: Consider worst-case reductions, structure, and parameter estimation.
Answer:
The strongest evidence is worst-case to average-case reductions. For Learning With Errors, breaking a random instance implies solving lattice problems in the worst case — a guarantee that RSA and discrete logs have never had, since a random RSA modulus might be easy while some are hard.
The soft spot is structure. Efficient schemes use ring or module variants, whose lattices have extra algebraic structure. The reductions are weaker there, and structure has repeatedly turned out to be exploitable elsewhere in this course.
Parameter estimation is genuinely uncertain. Security rests on predicting what BKZ with a given block size achieves, and those estimates have been revised more than once. It is a much less settled science than estimating factoring effort.
And the field is young. Lattice cryptography is thirty years old against RSA's fifty and discrete logs' longer history, with far fewer person-years of attack behind it.
Which is why deployments are hybrids. Chrome's TLS combines X25519 with ML-KEM so that breaking the connection requires breaking both. Given SIKE's sudden collapse in 2022, that caution looks well judged rather than excessive.
Ranking
Five problems.
Put in order
Why: A large key is an efficiency problem. Decryption failures are a correctness problem — though in some schemes a failure oracle leaks key information, so it is not entirely benign. Reused randomness lets two ciphertexts be differenced, exposing the relation between the messages. Too small a dimension means reduction recovers the private key. And a predictable error removes the lattice problem entirely, leaving ordinary linear algebra.
Constraint
An organisation stores medical records that must stay confidential for fifty years, and asks what to do about quantum computers.
Discussion prompt
What is the advice, and what is the reasoning?
Hint: Start from the threat timeline, not the technology.
Answer:
The threat is store-now-decrypt-later, and it is active today. An adversary recording encrypted traffic now can decrypt it whenever a quantum computer arrives. For a fifty-year confidentiality requirement, that risk is already live regardless of when the machine appears.
So migrate key exchange first, because that is what protects recorded traffic. Signatures matter less urgently — a forged signature requires a quantum computer at the time of forgery, so it cannot be done retroactively.
Deploy hybrids, not replacements. X25519 combined with ML-KEM means an attacker must break both, which protects against a classical break of the new scheme as much as against a quantum break of the old one — and SIKE showed that is not a theoretical concern.
Plan for larger keys and ciphertexts. ML-KEM's public keys are around 1.2 KB against 32 bytes for X25519, which affects handshake sizes, embedded devices and anything with tight packet budgets.
And build in crypto-agility. The single most valuable property is being able to change algorithm without changing the protocol, because these parameters will be revised. The organisations that struggled with SHA-1 and RSA-1024 deprecation are the ones that hard-coded them.
Cost model
One exponent governs when lattice attacks work.
Annotate
On: \( \|b_1\| \le 2^{(n-1)/2} \, \lambda \)
A rare case where one exponent separates 'attack' from 'cryptosystem', and where the design decision is simply which side of it to sit on.
Missing information
A scheme is described as lattice-based and therefore quantum-resistant.
Discussion prompt
What still needs checking?
Hint: Which lattice problem, which lattices, and which parameters.
Answer:
Which problem it reduces to. Shortest vector, closest vector, LWE, SIS and NTRU-style problems are related but not equivalent, and their reductions to each other are partial.
Whether the lattices are structured. Ring-LWE lattices carry algebraic structure that plain LWE does not. It buys efficiency and weakens the reduction, and structure has been a repeated source of attacks throughout this course.
Whether the parameters are current. Estimates for lattice attack cost have been revised, and a scheme quoting a security level from an older analysis may not deliver it.
Whether decryption failures leak. Several lattice schemes have a small failure probability, and an attacker who can trigger and observe failures can extract key information — a chosen-ciphertext attack that has broken real proposals.
And whether the implementation is constant-time. Lattice arithmetic involves sampling from discrete Gaussians and rejection sampling, both of which leak through timing if done naively. GGH aside, this is where practical lattice deployments actually go wrong.
Two truths and a lie
Two of these overstate it.
Eliminate the wrong options
Which statement is correct?
Survives elimination: a
Why: The precise claim has three conditions and each is necessary. What makes the attack instructive is that it breaks the message without touching the underlying hard problem — a reminder that a cryptosystem's security is not identical to its hard problem's difficulty.
Commit first
An organisation deploys ML-KEM using a well-regarded library at standardised parameters.
Predict first
What is the realistic failure?
Correct: An implementation issue — non-constant-time sampling, or a decryption-failure oracle
This is the same conclusion as Chapters 21 and 22. The mathematics is the studied part; the implementation is where the failures actually occur.
Lattice schemes add two hazards the older systems did not have. Sampling from a discrete Gaussian is subtle and easy to make data-dependent, and a nonzero decryption failure rate is an attack surface with no analogue in RSA or ECC.
Which is why the standardised versions use Fujisaki-Okamoto transforms to achieve chosen-ciphertext security, and why deterministic re-encryption checks are part of the specification rather than an optional hardening.
Why: Lattice schemes sample from carefully shaped distributions and have a small decryption failure probability, and both are exploitable if handled naively. Timing leaks in samplers and chosen-ciphertext attacks driven by failure oracles have broken real implementations, while the underlying assumptions have held.
Explain it
A colleague asks how a public key can describe the same thing as a private key and still be safe.
Discussion prompt
Explain the GGH idea without matrices.
Hint: Two descriptions of the same grid.
Answer:
Start with the grid. Imagine an infinite regular grid of points in space. You can describe it by giving a few arrows: every grid point is a whole number of steps along each arrow.
Some sets of arrows are pleasant — short and pointing in very different directions. Given a location, you can immediately say which grid point is nearest.
Others are horrible — enormously long and nearly parallel. They describe the same grid, but working out which point is nearest to a location becomes a nightmare of near-cancelling large numbers.
Publish the horrible arrows and keep the pleasant ones. To send you a message, someone picks a grid point and nudges it slightly off. Anyone can verify the arithmetic; only you can round back to the grid point reliably.
And the reason it is hard to cheat is that recovering pleasant arrows from horrible ones is the shortest vector problem — solvable in two or three dimensions and, as far as anyone knows, hopeless in three hundred.
Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.
Explain it to yourself
The RSA attack argues |g(x)| < n; NTRU's decryption argues that coefficients stay below q/2.
Discussion prompt
Explain what these two arguments have in common.
Hint: In both, a congruence becomes an equality.
Answer:
Both convert a statement mod something into a statement over the integers. g(x) ≡ 0 (mod n) plus |g(x)| < n forces g(x) = 0 exactly. And a ≡ pφ∗g + f∗m (mod q) plus all coefficients under q/2 forces equality.
A congruence loses information; an equality does not. Knowing a value mod n leaves n possibilities; knowing it exactly leaves one. The size bound is what recovers the lost information.
In the RSA attack this is used offensively. The lattice's entire job is to produce a polynomial whose coefficients are small enough for the argument to fire — nothing else about b₁ matters.
In NTRU it is used constructively, and the failure probability is exactly the chance that the size bound fails. The parameters exist to make that chance about 5 in 100 000.
So the same technique appears as attack and as design, which is the chapter's recurring shape. And it explains the obsession with smallness throughout: 'small' is not an efficiency concern here, it is the mechanism by which modular arithmetic is escaped.
Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.
Pattern
One object, used twice, and the parameter that decides which role it plays is dimension.
The design tension is unusually direct. Every improvement in lattice reduction simultaneously strengthens the attacks and forces the cryptosystems' parameters upward — which is why estimating BKZ's behaviour is now a load-bearing part of post-quantum security.
Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.
Trap
The trap. Shor's algorithm breaks factoring and discrete logarithms, so RSA and elliptic curves fall to a quantum computer. Lattice problems are not affected by Shor. Therefore lattice-based cryptography is quantum-proof and the migration problem is solved by switching.
The first two sentences are correct. The conclusion carries much more than they support.
'No known quantum algorithm' is not 'no quantum algorithm'. It is the same kind of claim as the classical assumptions in this course — evidence from failed attempts, not a proof. Quantum algorithms for lattice problems are an active research area.
Classical attacks remain the immediate risk. GGH was broken classically in 1999, and SIKE — a post-quantum finalist — was broken classically in 2022 by an attack that ran in about an hour. New assumptions can fail suddenly and for ordinary reasons.
Efficient variants weaken the guarantees. The worst-case reductions that make lattices attractive are strongest for unstructured problems, and the schemes fast enough to deploy use ring or module structure where the reduction is weaker — the familiar trade of structure for speed.
Parameter estimates are unsettled. Security rests on predictions about BKZ that have been revised, and this is a much younger science than estimating factoring cost.
The accurate claim is narrow and still worth acting on: lattice problems have no known efficient quantum algorithm, so they are the best available candidate for post-quantum key exchange — deployed alongside a classical scheme, not instead of one. The hybrid is not timidity; it is the correct response to a young assumption.
Check
Work it out before clicking.
Check your understanding
After running the two-dimensional reduction algorithm, what is true of v₁?
Answer: B
Why: The theorem proves it exactly: for any nonzero lattice vector av₁ + bv₂, the reducedness conditions give ‖av₁ + bv₂‖² ≥ (a² − ab + b²)‖v₁‖², and a² − ab + b² is a positive integer for nonzero (a, b). Two dimensions is the one case where a greedy algorithm provably reaches the optimum.
Check
Consider the final step of Coppersmith's attack.
Check your understanding
The attack concludes that g(x) = 0 exactly. What justifies that?
Answer: B
Why: The lattice's whole purpose is to produce a short vector, hence a polynomial with small coefficients, hence a small value at x. Divisible by n and smaller than n in absolute value leaves only zero — and the congruence has become an equation solvable without any factorisation.
Check
Consider the lattice interpretation.
Check your understanding
In the lattice attack on NTRU, what is the short vector an attacker seeks?
Answer: B
Why: Since g = f ∗ h + qy, the vector (f, y) times M gives (f, g), so (f, g) lies in the 2N-dimensional lattice generated by M's rows — and f and g are small by construction. Finding it breaks the system, which is why N must be large enough that reduction fails.
Connect it up
The chapter is one problem used in opposite directions.
Draw it
Draw two columns, 'attack' and 'foundation'. In each, write: the lattice's dimension, what the short vector represents, whether LLL succeeds, and what a designer changes to move the outcome. Then write the two size arguments — |g(x)| < n and coefficients under q/2 — and say in one line what they have in common. Finish with the post-quantum position: which assumptions fall to Shor, which do not, and why deployments are hybrids.
The two size arguments are the thing to be able to state cleanly. They are the same observation used offensively and defensively, and recognising it makes both halves of the chapter one idea.
Exit ticket
One question, about the parameter that decides everything.
Predict first
What separates a lattice attack from a lattice cryptosystem?
Correct: The dimension — LLL is effective in low dimensions and useless in high ones
Why: Both use short vectors in a lattice. In the RSA attack the lattice has 4 dimensions and reduction is near-exact; in NTRU it has 1006 and no known algorithm gets close. LLL's approximation factor 2^{(n−1)/2} is the dividing line, and the design decision is simply which side of it to sit on.
Recap
Short vectors, hunted and hidden.
Chapter 24 next. Error-correcting codes: Hamming codes, linear codes and the McEliece cryptosystem — the other post-quantum family, and the one this chapter named as the alternative to lattices.
Figure (svg): Why lattices are a post-quantum candidate, and the key-size cost they carry.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.