Chapter 23: Lattice Methods

Chapter 23 of Trappe & Washington: lattices as both a cryptanalytic tool and a cryptographic foundation. Covers bases and the determinant, exact two-dimensional reduction with the proof that its first vector is shortest, the LLL algorithm and its three guarantees, Coppersmith's attack recovering a stereotyped plaintext from low-exponent RSA without factoring, NTRU over convolution polynomials with a fully worked round trip and its interpretation as a short vector in a 2N-dimensional lattice, the GGH cryptosystem where the trapdoor is a choice of basis, the Closest Vector Problem, and the post-quantum motivation — with every numeric example verified.

Subject: Cryptography · 68 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Lattice Methods

Title

Cryptography · Chapter 23

Short vectors as an attack and as a foundation — and the reason both are the same problem

2. What you will be able to do

Objectives

Lattices appear twice in this chapter, in opposite roles. Short vectors are what a cryptanalyst hunts for, and the difficulty of finding them in high dimension is what a lattice cryptosystem is built on.

Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.

A lattice has infinitely many bases, and reduction is the business of trading a bad one for a good one.

3. What makes a description good?

Warm-up

The set of all points with integer coordinates in the plane can be described as combinations of (1, 0) and (0, 1) — or of (5, 16) and (6, 19). Both descriptions are complete and correct.

Discussion prompt

Which description would you rather have, and what makes one better?

Hint: Try to find a short point in the set using each description.

Answer:

With (1, 0) and (0, 1) the short points are obvious. They are the basis vectors, and every point's coordinates are read straight off.

With (5, 16) and (6, 19) they are not. Finding a short combination means searching over integer pairs, and the two vectors point in almost the same direction, so most combinations are long.

But the sets are identical, so the difficulty is entirely in the description. That gap — same object, very different usability — is what this chapter is about.

Read one way it is an attack: given a bad basis, find a good one, and short vectors fall out. That breaks low-exponent RSA with predictable plaintext.

Read the other way it is a trapdoor: publish the bad basis, keep the good one. Anyone can describe the lattice; only you can work with it comfortably. That is a public-key cryptosystem, and in high dimension nobody knows how to close the gap.

4. Lattices

Section

Section 23.1 · pp. 441-443

5. What a lattice is

Concept

Let v₁, …, v_n be linearly independent vectors in ℝⁿ. The lattice they generate is the set of vectors

\[ m_1 v_1 + \cdots + m_n v_n, \qquad m_i \in \mathbb Z \]

Integer combinations, not real ones — that single restriction is what makes a lattice a discrete grid of points rather than all of space.

The set {v₁, …, v_n} is called a basis, and a lattice has infinitely many. If {v₁, v₂} is a basis then so is {v₁ + kv₂, v₂} for any integer k, since each set of integer combinations contains the other.

More generally, any integer matrix with determinant ±1 turns one basis into another — the determinant condition is exactly what makes the inverse have integer entries too.

Figure (svg): Three different bases generating the same lattice of all integer points in the plane.

Infinitely many descriptions of one object, some of which make its short vectors obvious and some of which hide them.

6. Three bases for the same lattice

Worked example

The book's example, and it repays a moment's checking.

v₁ = (1, 0) and v₂ = (0, 1) generate all pairs (x, y) with x, y integers

Why: The standard integer grid.

{(1, 5), (0, 1)} generates the same lattice

Why: Because (1, 5) = (1,0) + 5(0,1), and conversely (1,0) = (1,5) − 5(0,1). Each basis is an integer combination of the other.

{(5, 16), (6, 19)} does too

Why: The change-of-basis matrix has determinant 5·19 − 16·6 = 95 − 96 = −1.

\[ \det \begin{pmatrix} a & b \\ c & d \end{pmatrix} = \pm 1 \;\Longrightarrow\; \{(a,b), (c,d)\} \text{ is a basis of } \mathbb Z^2 \]

Verify: determinant ±1 is exactly the right condition

Why: If the determinant were 2, the new vectors would generate only half the lattice — an index-2 sublattice. Only ±1 gives an inverse with integer entries, and hence a genuine change of basis.

Figure (svg): Three different bases generating the same lattice of all integer points in the plane.

Infinitely many descriptions of one object, some of which make its short vectors obvious and some of which hide them.

7. The shortest vector problem

Concept

The length of v = (x₁, …, x_n) is the usual ‖v‖ = (x₁² + ⋯ + x_n²)^{1/2}.

Shortest vector problem — Find a shortest nonzero vector in a lattice. Hard in general, and especially so when the dimension is large.

Many problems reduce to it, which is why the chapter opens here. In low dimension it is easy, and Section 23.2 gives an algorithm that solves it exactly in two dimensions.

In high dimension nothing is known that works. That gap between dimensions is not a gap in our knowledge of a fixed problem — it is a genuine change in difficulty, and it is the raw material for every construction in the second half of the chapter.

Note the shape of this. A problem that is easy small and hard large is exactly what a cryptosystem needs, and it is the same shape as factoring: trivial for six-digit numbers, infeasible for six-hundred-digit ones.

Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.

A lattice has infinitely many bases, and reduction is the business of trading a bad one for a good one.

8. A short vector by inspection is not obvious

Worked example

Take the lattice generated by (31, 59) and (37, 70).

Both basis vectors have length around 70

Why: ‖(31,59)‖ ≈ 66.6 and ‖(37,70)‖ ≈ 79.2.

But (3, −1), of length √10 ≈ 3.16, is in the lattice

Why: Because (3, −1) = −19(31, 59) + 16(37, 70) — check: −589 + 592 = 3 and −1121 + 1120 = −1.

The coefficients are −19 and 16, which no amount of staring would suggest

Why: The short vector is a difference of two large near-parallel multiples, and finding it by search is hopeless even here.

A far better basis is {(3, −1), (1, 4)}

Why: Their dot product is 3 − 4 = −1, so they are nearly orthogonal — against the original pair, which are nearly parallel with a very large dot product.

Verify: the lattice was always the same; only the description improved

Why: And that is the point. Section 23.2 gives an algorithm that produces the good basis from the bad one automatically, in a handful of steps.

Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.

A lattice has infinitely many bases, and reduction is the business of trading a bad one for a good one.

9. What does the determinant of a lattice measure?

Prediction

Predict first

What does that 13 represent?

  • The length of the shortest vector
  • The area of the parallelogram spanned by the basis — the same for every basis of the lattice
  • The number of lattice points near the origin
  • The dimension of the lattice

Correct: The area of the parallelogram spanned by the basis — the same for every basis of the lattice

Which is why D appears in the LLL bounds. The guarantee ‖b₁‖ ≤ 2^{(n−1)/4} D^{1/n} says the shortest vector found is bounded by the density of the lattice, which is the only intrinsic quantity available.

Check it on the example: D = 13, and the reduced basis {(3,−1), (1,4)} has determinant 3·4 − (−1)·1 = 13 as well. The bad basis and the good one span the same area, which is the invariance in action.

And the intuition is sound. A denser lattice has shorter vectors, so a bound on the shortest vector has to involve D — nothing else about the lattice is basis-independent.

Why: D is the volume of the parallelepiped spanned by any basis, and it is independent of which basis you use — because change of basis has determinant ±1. It measures how sparse the lattice is: a small D means points are packed closely.

10. Lattice Reduction

Section

Section 23.2 · pp. 443-450

11. Lattice Reduction in two dimensions

Concept

The goal is to replace a basis with one whose vectors are short and nearly orthogonal.

The idea is Gram-Schmidt with rounding. In linear algebra you would replace v₂ by v₂* = v₂ − μv₁ with μ = (v₁·v₂)/(v₁·v₁), which is perpendicular to v₁ — but that vector generally is not in the lattice.

So round μ to the nearest integer t and subtract that many copies instead:

  1. If ‖v₁‖ > ‖v₂‖, swap so that v₁ is the shorter
  2. Let t be the closest integer to μ = (v₁·v₂)/(v₁·v₁)
  3. If t = 0, stop. Otherwise replace v₂ by v₂ − t v₁ and repeat

The result stays in the lattice because t is an integer, and it gets shorter because subtracting the rounded projection moves v₂ closer to perpendicular.

Figure (svg): The two-dimensional reduction algorithm running on the example basis, four steps to a reduced basis.

Gram-Schmidt with the projections rounded to integers, so the result stays inside the lattice.

12. What 'reduced' means

Concept

A basis {v₁, v₂} is reduced when two conditions hold:

\[ \|v_1\| \le \|v_2\| \qquad \text{and} \qquad -\tfrac12 \le \frac{v_1 \cdot v_2}{v_1 \cdot v_1} \le \tfrac12 \]

The first says v₁ is the shorter. The second says the projection of v₂ onto v₁ is at most half of v₁ — geometrically, that the foot of v₂ lands within half a step of the origin.

And the algorithm stops exactly when the basis is reduced, because t = 0 is precisely the statement that μ lies in [−½, ½].

Which is a satisfying design. The halting condition and the definition of the goal are literally the same condition, so there is no gap between 'the algorithm finished' and 'the answer is correct'.

Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.

Two inequalities that are cheap to test and that between them pin down the shortest vector in the plane.

13. Reducing (31, 59) and (37, 70)

Worked example

Four steps, each one subtraction and a swap.

μ = 5277/4442 ≈ 1.19, so t = 1

Why: Replace v₂ by (37,70) − (31,59) = (6, 11), then swap: now v₁ = (6, 11), v₂ = (31, 59).

μ = 835/157 ≈ 5.32, so t = 5

Why: Replace (31,59) by (31,59) − 5(6,11) = (1, 4), then swap: v₁ = (1, 4), v₂ = (6, 11).

μ = 50/17 ≈ 2.94, so t = 3

Why: Replace (6,11) by (6,11) − 3(1,4) = (3, −1), then swap: v₁ = (3, −1), v₂ = (1, 4).

μ = −1/10, which lies in [−½, ½], so t = 0

Why: Stop.

Verify: the reduced basis is {(3, −1), (1, 4)}

Why: Their dot product is −1, so they are nearly orthogonal, and (3, −1) of length √10 is a shortest nonzero vector of the lattice. Four steps from a basis where the shortest vector was completely invisible.

Figure (svg): The two-dimensional reduction algorithm running on the example basis, four steps to a reduced basis.

Gram-Schmidt with the projections rounded to integers, so the result stays inside the lattice.

14. Why the algorithm terminates

Worked example

The proof is short and shows exactly what the rounding buys.

Write μ = (v₁·v₂)/(v₁·v₁) and v₂* = v₂ − μv₁, which is perpendicular to v₁

Why: The Gram-Schmidt vector, generally not in the lattice.

Then v₂ − tv₁ = v₂* + (μ − t)v₁, and the two pieces are orthogonal

Why: So Pythagoras applies: ‖v₂ − tv₁‖² = ‖v₂*‖² + (μ − t)²‖v₁‖².

Likewise ‖v₂‖² = ‖v₂*‖² + μ²‖v₁‖²

Why: Same decomposition with t = 0.

If t ≠ 0 then |μ − t| < |μ|, so the first quantity is strictly smaller than the second

Why: Rounding to the nearest integer moves you closer to zero whenever the nearest integer is not zero.

Verify: so every step strictly shortens v₂, and only finitely many lattice vectors are shorter than the original

Why: Hence the process cannot continue forever. Note where discreteness entered: in a continuous space the lengths could decrease forever without ever stopping.

Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.

Two inequalities that are cheap to test and that between them pin down the shortest vector in the plane.

15. Why the first vector is shortest

Worked example

The second half of the theorem, and it is a neat piece of algebra.

Let av₁ + bv₂ be any nonzero lattice vector, a and b integers

Why: Expand the squared length: a²‖v₁‖² + 2ab(v₁·v₂) + b²‖v₂‖².

Reducedness gives |v₁·v₂| ≤ ½‖v₁‖², so 2ab(v₁·v₂) ≥ −|ab|‖v₁‖²

Why: The cross term cannot be very negative.

And ‖v₂‖² ≥ ‖v₁‖², so the whole thing is at least (a² − |ab| + b²)‖v₁‖²

Why: Replacing ‖v₂‖ by the smaller ‖v₁‖.

a² − ab + b² = (a − b/2)² + (3/4)b² is a non-negative integer, zero only when a = b = 0

Why: So for a nonzero vector it is at least 1.

\[ \|a v_1 + b v_2\|^2 \ge \|v_1\|^2 \]

Verify: so v₁ is a shortest nonzero vector — exactly, not approximately

Why: This is the last time in the chapter such a clean statement is available. In three dimensions and up, nothing this strong is known, and LLL settles for 'nearly shortest'.

Figure (svg): The two conditions defining a reduced basis, shown as a length test and a projection test.

Two inequalities that are cheap to test and that between them pin down the shortest vector in the plane.

16. Reading the reduction step

Notation

One line does all the work.

Annotate

On: \( v_2 \mapsto v_2 - t v_1, \qquad t = \text{round}\!\left(\frac{v_1 \cdot v_2}{v_1 \cdot v_1}\right) \)

  • The projection coefficient from Gram-Schmidt: how many copies of v₁ fit inside v₂ along v₁'s direction.
  • The only difference from ordinary Gram-Schmidt, and the entire reason the result stays in the lattice. Subtracting a non-integer multiple would leave it.
  • Rounding to the nearest integer makes |μ − t| ≤ ½ < |μ| whenever t ≠ 0, and Pythagoras converts that into a strictly shorter vector.
  • Keeps v₁ the shorter vector, which is needed for the shortest-vector proof and keeps the projection coefficients small.
  • With n vectors there are n(n−1)/2 pairs to reduce and reducing one pair can un-reduce another. LLL adds a condition controlling the order in which this is done, and settles for an approximate answer.

Two dimensions is the case where greedy rounding provably reaches the optimum. Everything above it is a compromise.

17. LLL Algorithm

Concept

Reduction in dimensions above two is much harder. The most successful algorithm is due to A. Lenstra, H. Lenstra and Lovász.

Its key concession: in most applications a short vector is enough, and it need not be the shortest. LLL looks for vectors that are almost as short as possible, and that relaxation is what makes it run in polynomial time.

Given a lattice L of dimension n with determinant D = |det(v₁, …, v_n)|, and λ the length of a shortest nonzero vector, LLL produces a basis {b₁, …, b_n} with

  1. ‖b₁‖ ≤ 2^{(n−1)/4} D^{1/n} — an absolute bound in terms of the lattice's density
  2. ‖b₁‖ ≤ 2^{(n−1)/2} λ — b₁ is close to shortest, when n is small
  3. ‖b₁‖‖b₂‖⋯‖b_n‖ ≤ 2^{n(n−1)/4} D — the basis is close to orthogonal

Statement (3) is worth unpacking. If the vectors were exactly orthogonal the product of their lengths would equal D exactly. The bound says it exceeds D by at most a factor of 2^{n(n−1)/4}, so they are mostly close to orthogonal.

Figure (svg): The three guarantees the LLL algorithm provides, and the example's numbers against each.

Not the shortest vector, but a short one, quickly — and the gap between those two is where lattice cryptography lives.

18. Checking the bounds on the example

Worked example

For the two-dimensional lattice generated by (31, 59) and (37, 70), LLL gives the same answer as the exact algorithm: b₁ = (3, −1), b₂ = (1, 4).

D = 13 and λ = ‖(3, −1)‖ = √10

Why: The determinant computed from either basis.

(1): √10 = 3.162 ≤ 2^{1/4}√13 = 4.288 ✓

Why: With n = 2 the exponent is (n−1)/4 = 1/4.

(2): √10 ≤ 2^{1/2}√10 = 4.472 ✓

Why: Here b₁ actually is the shortest, so the bound has room to spare.

(3): √10·√17 = 13.04 ≤ 2^{1/2}·13 = 18.38 ✓

Why: The basis is nearly orthogonal, and the product only slightly exceeds D.

Verify: all three hold, with room

Why: In two dimensions LLL is doing better than its guarantee. The point of the bounds is what happens when n grows — and there the factors 2^{(n−1)/2} and 2^{n(n−1)/4} become astronomically weak.

Figure (svg): The three guarantees the LLL algorithm provides, and the example's numbers against each.

Not the shortest vector, but a short one, quickly — and the gap between those two is where lattice cryptography lives.

19. How does LLL scale?

Prediction

Predict first

What does that mean for its use in cryptanalysis?

  • It is efficient for all dimensions
  • Efficient in the size of the numbers, but the guarantee degrades exponentially in n — so it works in low dimension and fails in high
  • It is exponential in the number size
  • It never terminates for n above 100

Correct: Efficient in the size of the numbers, but the guarantee degrades exponentially in n — so it works in low dimension and fails in high

Which is precisely the gap the second half of the chapter exploits. NTRU's lattice has dimension 2N = 1006 for the high-security parameters, and no reduction algorithm gets near the short vector there.

And it is why the RSA attack works at all. That lattice has dimension 4 — for a cubic polynomial, d + 1 — where LLL is close to exact.

Better algorithms exist, notably BKZ, which trades running time for approximation quality by reducing blocks of the basis exactly. Choosing lattice parameters means estimating what BKZ with a given block size can achieve, and those estimates are the ongoing research the security of post-quantum schemes depends on.

Why: The running time is polynomial in both n and the bit lengths, so LLL always finishes. What degrades is the quality: the approximation factor 2^{(n−1)/2} means that for n around 300 the returned vector may be astronomically longer than the shortest. It runs, and the answer stops being useful.

20. Sort by whether LLL will help

Definition probe

Four lattice problems.

Sort into buckets

Sort each by whether LLL is likely to find what is wanted.

LLL succeeds
A 4-dimensional lattice from a cubic RSA polynomial; A 2-dimensional lattice from two integer vectors
LLL is useless
The 1006-dimensional lattice from NTRU with N = 503; The 600-dimensional lattice from GGH with n = 300
yes
In dimension 2 the reduction is exact, and in dimension 4 the approximation factor 2^{3/2} is small enough that the vector found is short enough to use. Both attacks in this chapter live here.
no
The approximation factor grows as 2^{(n−1)/2}, which for n in the hundreds is beyond astronomical. The parameters of both cryptosystems were chosen precisely to put their lattices in this regime.

21. An Attack on RSA

Section

Section 23.3 · pp. 450-454

22. Coppersmith's Attack: stereotyped messages

Concept

Alice sends Bob messages of a predictable form:

  1. The answer is ∗∗
  2. The password for your new account is ∗∗∗∗∗∗∗∗

So the message is m = B + x where B is known and |x| ≤ Y for a small bound Y. Suppose Bob's public exponent is e = 3.

\[ c \equiv (B + x)^3 \pmod n \]

Eve knows B, Y, n and c, and wants x. She forms

\[ f(T) = (B+T)^3 - c \equiv T^3 + a_2 T^2 + a_1 T + a_0 \pmod n \]

and is looking for a small root of f(T) ≡ 0 (mod n). Solving a congruence mod n usually needs the factorisation; the lattice will remove that need.

Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.

The trick of the whole chapter: turn a congruence mod n, which needs the factorisation, into an exact equation, which does not.

23. Building the lattice

Concept

Eve applies LLL to the lattice generated by four vectors:

\[ v_1 = (n, 0, 0, 0), \; v_2 = (0, Yn, 0, 0), \; v_3 = (0, 0, Y^2 n, 0), \; v_4 = (a_0, a_1 Y, a_2 Y^2, Y^3) \]

The powers of Y are a scaling trick. A coefficient eᵢ multiplies xⁱ, and |x| ≤ Y, so the term contributes at most |eᵢ|Yⁱ. Weighting the i-th coordinate by Yⁱ makes the vector's length control the polynomial's value at x.

The multiples of n encode the congruence. Adding any of v₁, v₂, v₃ changes the coefficients by multiples of n, which does not change the polynomial mod n. So every lattice vector is a polynomial congruent to a multiple of f mod n.

LLL returns b₁, short. Writing b₁ = (e₀, Ye₁, Y²e₂, Y³e₃), the polynomial g(T) = e₃T³ + e₂T² + e₁T + e₀ satisfies g(x) ≡ 0 (mod n) — and being short, it is also small at x.

Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.

The trick of the whole chapter: turn a congruence mod n, which needs the factorisation, into an exact equation, which does not.

24. Why g(x) is exactly zero

Worked example

The step that turns a congruence into an equation.

The determinant of the four vectors is n³Y⁶, so LLL gives ‖b₁‖ ≤ 2^{3/4}(n³Y⁶)^{1/4} = 2^{3/4}n^{3/4}Y^{3/2}

Why: The first LLL bound with n = 4.

And |g(x)| ≤ |e₀| + |e₁|Y + |e₂|Y² + |e₃|Y³, since |x| ≤ Y

Why: Bounding each term by its worst case.

That sum is (1,1,1,1)·(|e₀|, |e₁|Y, |e₂|Y², |e₃|Y³) ≤ ‖(1,1,1,1)‖·‖b₁‖ = 2‖b₁‖

Why: Cauchy-Schwarz, and ‖(1,1,1,1)‖ = 2.

Now assume Y < 2^{−7/6} n^{1/6}. Then 2‖b₁‖ ≤ 2^{7/4}n^{3/4}Y^{3/2} < n

Why: Substituting the bound on Y makes the whole expression less than n.

Verify: so |g(x)| < n and g(x) ≡ 0 (mod n), which forces g(x) = 0

Why: An integer that is divisible by n and smaller than n in absolute value is zero. Now g is an ordinary cubic: find its roots numerically by Newton's method, test the at most three candidates, and read off x.

Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.

The trick of the whole chapter: turn a congruence mod n, which needs the factorisation, into an exact equation, which does not.

25. The answer is 42

Worked example

The book's worked example, verified.

n = 1927841055428697487157594258917, secretly 757285757575769 × 2545724696579693

Why: Eve does not know the factorisation and does not need it.

The message is “The answer is ∗∗” with B = 200805000114192305180009190000 and 0 ≤ x < 100

Why: So Y = 100 and the unknown is two digits.

Alice sends c ≡ (B + x)³ ≡ 30326308498619648559464058932 (mod n)

Why: Which is exactly what (B + 42)³ mod n gives.

Eve forms f with a₂ = 602415000342576915540027570000, a₁ = 1123549124004247469362171467964, a₀ = 587324114445679876954457927616

Why: Where a₀ ≡ B³ − c (mod n).

LLL on the four vectors gives b₁, hence g(T), whose roots are 42.000000000 and −0.9496 ± 76.0796 i

Why: One real root, and it is an integer.

Verify: g(42) = 0, so the plaintext is “The answer is 42”

Why: Here brute force over 100 values would also have worked. But for a 200-digit n the bound allows Y with about 33 digits — a search space of 10³³, which no brute force touches. The attack is real; the example is small only for legibility.

Figure (svg): The worked attack recovering a two-digit number from a stereotyped RSA message.

A cute example with a serious point: stereotyped plaintext plus a small exponent is a complete break, not a weakness.

26. Coppersmith's general result

Concept

The same construction handles a polynomial congruence of degree d using a lattice of dimension d + 1 — provided d is small enough for LLL to run comfortably.

Coppersmith improved it considerably. His algorithm uses higher-dimensional lattices to find small roots x of a monic polynomial congruence f(T) ≡ 0 (mod n) of degree d, and it succeeds whenever

\[ |x| \le n^{1/d} \]

in time polynomial in log n and d — a much better bound than the 2^{−7/6}n^{1/6} the elementary version gives for d = 3.

The practical consequences are large. Coppersmith's method underlies the attack on RSA with partially known plaintext, the recovery of a private key from half its bits, Håstad's broadcast attack, and the factorisation of n given half the bits of p — all of Chapter 9's warnings about small exponents, in one technique.

And the fix has been standard for decades: randomised padding. OAEP destroys the stereotyped structure, so no low-degree polynomial relation exists to exploit.

Figure (svg): The lattice built for the low-exponent RSA attack, with the short vector giving a polynomial that vanishes exactly.

The trick of the whole chapter: turn a congruence mod n, which needs the factorisation, into an exact equation, which does not.

27. Why is turning a congruence into an equation such a gain?

Socratic

The attack converts f(x) ≡ 0 (mod n) into g(x) = 0 over the integers.

Discussion prompt

Why is the second so much easier than the first?

Hint: What would you need to solve each?

Answer:

Solving a polynomial congruence mod n generally requires the factorisation. The standard route is to solve mod p and mod q separately and recombine by CRT — and if you had p and q you would not be attacking RSA in the first place.

Solving an exact polynomial equation needs no factorisation at all. Newton's method, or any numerical root finder, locates the real roots of a cubic in microseconds.

So the lattice has traded a number-theoretic problem for an analytic one, and the analytic one is trivial. That exchange is the whole content of the attack.

The mechanism is a size argument, and it is worth naming. If an integer is divisible by n and strictly smaller than n, it is zero. The lattice's job is entirely to produce a polynomial small enough for that argument to fire.

This pattern recurs across the subject. Whenever you can force a quantity to be simultaneously divisible by something large and bounded by it, congruence collapses to equality — the same move appears in Wiener's continued-fraction attack on small RSA decryption exponents.

28. The exponent is 65537 instead of 3

Anomaly

Bob uses the standard public exponent e = 65537 rather than 3.

Predict first

Does the attack still work?

  • Yes, unchanged
  • No — the polynomial has degree 65537, so the lattice has 65538 dimensions and LLL is hopeless
  • Yes, but it needs the factorisation
  • Only if the message is shorter

Correct: No — the polynomial has degree 65537, so the lattice has 65538 dimensions and LLL is hopeless

Which is exactly why e = 65537 is the standard choice. It is large enough to defeat low-degree attacks and has only two bits set, so exponentiation is cheap — 16 squarings and one multiplication.

Coppersmith's bound |x| ≤ n^{1/d} says the same thing quantitatively. At d = 3 the unknown can be a third the bit length of n; at d = 65537 it can be a fraction of a bit, which is no attack at all.

But do not read this as 'large e makes RSA safe'. Padding is the real defence: it removes the algebraic structure that any such attack needs, and it protects against attacks that do not depend on the exponent at all.

Why: The polynomial degree equals the encryption exponent, and the lattice dimension is d + 1. At degree 3 the lattice has 4 dimensions and LLL is near-exact; at degree 65537 it has 65538, where LLL's approximation factor is beyond meaningless — and the algorithm would not finish in any case.

29. Complete the RSA attack

Faded example

Four blanks.

Fill in the blanks

Eve knows the message is B + x with |x| ≤ Y, and forms the polynomial f(T) = (B+T)³ − c, which is ≡ 0 mod n at T = x. She builds a lattice whose coordinates are weighted by powers of Y, runs LLL to find a short vector, and reads off a polynomial g. Because g is short, |g(x)| < n; because g ≡ c₄f mod n, g(x) ≡ 0 mod n. Therefore g(x) = 0 exactly, and x is found by a numerical root finder.

Why: The last step is the whole attack: an integer divisible by n and smaller than n must be zero, and the lattice exists solely to make g small enough for that to apply.

30. NTRU

Section

Section 23.4 · pp. 454-459

31. NTRU: convolution polynomials

Concept

If the dimension is large, say n ≥ 100, LLL cannot find short vectors — and that is what allows lattices to be used constructively. NTRU is the most successful such system.

The arithmetic is on polynomials of degree less than N, with a product defined by

\[ h = f * g, \qquad c_i = \sum_{j + k \equiv i \, (\mathrm{mod}\, N)} a_j b_k \]

Which is ordinary polynomial multiplication modulo Xᴺ − 1 — the exponents wrap around, hence 'convolution'.

L(j, k) — The set of polynomials of degree less than N with j coefficients equal to +1, k coefficients equal to −1, and the rest 0. NTRU works with these small polynomials throughout.

Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.

Two moduli doing different jobs: q carries the arithmetic and p extracts the message from it.

32. A convolution product

Worked example

The book's small example, with N = 3.

f = X² + 7X + 9 and g = 3X² + 2X + 5

Why: So the coefficient lists, constant first, are (9, 7, 1) and (5, 2, 3).

The coefficient of X is c₁ = a₀b₁ + a₁b₀ + a₂b₂

Why: The pairs (j, k) with j + k ≡ 1 (mod 3): (0,1), (1,0) and (2,2).

= 9·2 + 7·5 + 1·3 = 18 + 35 + 3 = 56

Why: Note the (2,2) term, which is the wrap-around: X²·X² = X⁴ = X modulo X³ − 1.

Verify: f ∗ g = 46X² + 56X + 68

Why: The wrap-around is the only difference from ordinary polynomial multiplication, and it is what keeps every product inside the same fixed-size space — which is what makes the arithmetic uniform and fast.

Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.

Two moduli doing different jobs: q carries the arithmetic and p extracts the message from it.

33. Key generation

Concept

Bob chooses integers N, p, q with gcd(p, q) = 1 and p much smaller than q. The book's recommended parameters:

  1. (N, p, q) = (107, 3, 64) for moderate security
  2. (N, p, q) = (503, 3, 256) for very high security

He picks two secret small polynomials f and g, with f invertible both mod p and mod q — that is, there are F_p and F_q with F_p ∗ f ≡ 1 (mod p) and F_q ∗ f ≡ 1 (mod q). He computes

\[ h \equiv F_q * g \pmod q \]

Public key: (N, p, q, h). Private key: f, with F_p stored secretly since decryption needs it. He need not keep g, since g ≡ f ∗ h (mod q) recovers it.

A detail with a reason: f has a different number of +1s and −1s so that f(1) ≠ 0 — because f(1) = 0 makes f non-invertible.

Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.

Two moduli doing different jobs: q carries the arithmetic and p extracts the message from it.

34. Encrypting and decrypting

Concept

Alice represents her message as a polynomial m of degree less than N with coefficients of absolute value at most (p−1)/2 — so for p = 3, coefficients in {−1, 0, 1}.

She chooses a small random φ and sends

\[ c \equiv p\phi * h + m \pmod q \]

Bob decrypts in two steps. First a ≡ f ∗ c (mod q), with every coefficient of a taken in (−q/2, q/2]. Then

\[ m \equiv F_p * a \pmod p \]

Sometimes it fails. With the recommended parameters the probability of a decryption error is under 5 × 10⁻⁵ — small, but not zero, which is unusual among the systems in this course and something a protocol using NTRU must handle.

Figure (svg): The NTRU key generation, encryption and decryption pipeline over convolution polynomials.

Two moduli doing different jobs: q carries the arithmetic and p extracts the message from it.

35. Why decryption works

Worked example

The argument turns on the coefficients staying small.

a ≡ f ∗ c ≡ f ∗ (pφ ∗ h + m) (mod q)

Why: Substituting the ciphertext.

Since h ≡ F_q ∗ g, this is f ∗ pφ ∗ F_q ∗ g + f ∗ m

Why: And F_q ∗ f ≡ 1 (mod q), so the f and F_q cancel.

a ≡ pφ ∗ g + f ∗ m (mod q)

Why: The private key has done its job: the mask is stripped.

Now the crucial step: φ, g, f and m all have small coefficients, and p is much smaller than q

Why: So with very high probability the polynomial pφ ∗ g + f ∗ m has every coefficient below q/2 in absolute value — meaning the congruence is an equality.

Reduce mod p: F_p ∗ a = pF_p ∗ φ ∗ g + F_p ∗ f ∗ m

Why: The first term vanishes because of the factor p, and F_p ∗ f ≡ 1 (mod p).

Verify: F_p ∗ a ≡ m (mod p)

Why: And note where the failure probability comes from: if any coefficient of pφ ∗ g + f ∗ m does exceed q/2, the congruence is not an equality and the decryption is wrong. It is the same 'small enough to be exact' argument as the RSA attack, used constructively.

Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.

The whole scheme rests on smallness: coefficients that stay under q/2 turn a congruence into an equation.

36. A full NTRU round trip with N = 5

Worked example

Too small for any security, and small enough to check every step. (N, p, q) = (5, 3, 16).

Bob takes f = X⁴ + X − 1 and g = X³ − X

Why: And computes the inverses: F_p = F_q = X³ + X² − 1, since (X³+X²−1) ∗ (X⁴+X−1) ≡ 1 both mod 3 and mod 16.

h ≡ F_q ∗ g ≡ −X⁴ − 2X³ + 2X + 1 (mod 16)

Why: The public key is (5, 3, 16, h).

Alice's message is m = X² − X + 1 and she picks φ = X − 1

Why: Coefficients in {−1, 0, 1}, as required for p = 3.

c ≡ 3φ ∗ h + m ≡ −3X⁴ + 6X³ + 7X² − 4X − 5 (mod 16)

Why: The ciphertext.

Bob computes a ≡ f ∗ c ≡ 4X⁴ − 2X³ − 5X² + 6X − 2 (mod 16)

Why: Centred in (−8, 8], and every coefficient is comfortably inside.

Verify: F_p ∗ a ≡ X² − X + 1 (mod 3) — the message

Why: Every step verified. Notice how much smaller the coefficients of a are than q = 16: that margin is the decryption-failure budget, and the recommended parameters are chosen to keep it comfortable.

Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.

The whole scheme rests on smallness: coefficients that stay under q/2 turn a congruence into an equation.

37. The lattice attack on NTRU

Concept

NTRU is not described using lattices, but it has a lattice interpretation — and it is the main line of attack.

Build the N × N circulant matrix H whose rows are the cyclic shifts of the coefficients of h. Representing f and g as row vectors, f H ≡ g (mod q).

Now form the 2N × 2N matrix

\[ M = \begin{pmatrix} I & H \\ 0 & qI \end{pmatrix} \]

Since g = f ∗ h + qy for some y, the vector (f, y) times M equals (f, g). So (f, g) lies in the lattice generated by the rows of M — and since f and g have small coefficients, it is a short vector.

The private key is therefore a short lattice vector, and the security of NTRU is exactly the difficulty of finding it. That is why N must be large: it makes the lattice 2N-dimensional, and lattice reduction ineffective.

Figure (svg): The NTRU lattice: the private key appears as a short vector in a 2N-dimensional lattice built from the public key.

The private key is not merely related to a short vector — it is one, and N is chosen so that nobody can find it.

38. Tuning against the attack

Concept

Two refinements from the book, and both are instructive about how lattice parameters are chosen.

Reduction works best when the shortest vector is small relative to the 2N-th root of the determinant. So the attacker wants the target vector to stand out, and the designer wants it to blend in.

The attacker's improvement: replace I in the upper-left block by αI for a well-chosen real α. This makes the target vector (αf, g) comparatively shorter and therefore easier to find — a rescaling exactly like the powers of Y in the RSA attack.

The designer's response: choose the sizes of f and g to limit the effect. NTRU's recommended L(j, k) parameters are set with this attack in mind, which is why they look so specific — f ∈ L(216, 215) for N = 503, not some round number.

And the tension is permanent. Larger N gives security and slower encryption; the suggested values are the compromise. The book's own verdict is measured: NTRU appears strong, its security is still being studied, and if it holds it offers RSA-comparable security with smaller keys and faster operations.

Figure (svg): The NTRU lattice: the private key appears as a short vector in a 2N-dimensional lattice built from the public key.

The private key is not merely related to a short vector — it is one, and N is chosen so that nobody can find it.

39. Sort the NTRU quantities

Definition probe

Several polynomials appear in the scheme.

Sort into buckets

Sort each by whether it is public.

Public
h; the ciphertext c
Secret
f and F_p; the random φ
pub
h is the public key and c travels over the wire. Both are large-coefficient polynomials mod q, which is what hides the small ones behind them.
sec
f is the private key and F_p is needed for decryption. φ is Alice's per-message randomness — reusing it across two messages would let their difference be analysed, exactly as with any randomised encryption.

40. Another Lattice-Based Cryptosystem

Section

Section 23.5 · pp. 459-460

41. GGH Cryptosystem: good and bad bases

Concept

Goldreich, Goldwasser and Halevi's 1997 system makes the trapdoor completely explicit: it is a choice of basis.

Let L be a 300-dimensional lattice of integer points. The private key is a good basis G — good meaning the entries are small. The public key is a bad basis B = GU, where U is a secret integer matrix with determinant 1, so that U⁻¹ is integral too. Bad means many large entries.

A message is an integer vector m, encrypted as

\[ c = B m + e \]

where e is a small random error vector with entries from {0, ±1, ±2, ±3}.

Decryption is B⁻¹G ⌊G⁻¹c⌉, where ⌊·⌉ rounds each entry to the nearest integer.

Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.

The cleanest illustration of a trapdoor in the course: two descriptions of one object, one of which makes a hard problem easy.

42. Why the good basis decrypts

Worked example

Two lines of algebra, and the rounding does the work.

Since U = G⁻¹B, we have G⁻¹c = G⁻¹Bm + G⁻¹e = Um + G⁻¹e

Why: Splitting the ciphertext into a lattice part and an error part.

U and m have integer entries, so Um is an integer vector

Why: It survives the rounding untouched.

G is good, so the entries of G⁻¹ are small — and G⁻¹e is therefore a vector of small fractions

Why: Which vanish in the rounding.

So ⌊G⁻¹c⌉ = Um, probably

Why: 'Probably' because a large enough e could push an entry past a half-integer. The error bound {0, ±1, ±2, ±3} is chosen to make that unlikely.

Verify: B⁻¹G · Um = B⁻¹GG⁻¹B m = m

Why: The message. Note that the decryption formula B⁻¹G⌊G⁻¹c⌉ simplifies to U⁻¹⌊G⁻¹c⌉, since B⁻¹G = (GU)⁻¹G = U⁻¹G⁻¹G = U⁻¹ — which is how the worked example computes it.

Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.

The cleanest illustration of a trapdoor in the course: two descriptions of one object, one of which makes a hard problem easy.

43. The two-dimensional example, both ways

Worked example

The book's illustration, scaled to two dimensions and verified throughout.

G = [[5, 2], [1, 4]] and U = [[17, 18], [16, 17]], so B = GU = [[117, 124], [81, 86]]

Why: det U = 289 − 288 = 1, as required. G has small entries; B does not.

Message m = (59, 37) and error e = (1, −1) give c = Bm + e = (11492, 7960)

Why: Since Bm = (11491, 7961).

G⁻¹c = (1669.33, 1572.67), which rounds to (1669, 1573)

Why: The fractional parts came from G⁻¹e, and they are small.

U⁻¹ = [[17, −18], [−16, 17]], and U⁻¹(1669, 1573) = (59, 37)

Why: The message, recovered exactly.

Now try the bad basis: B⁻¹c = (212/3, 26) ≈ (70.67, 26)

Why: Which rounds to (71, 26).

Verify: (71, 26) is nowhere near (59, 37)

Why: The entries of B⁻¹ are much larger than those of G⁻¹, so the small error e is amplified rather than rounded away. Same lattice, same ciphertext, and the only difference is which basis you hold — which is as clean a picture of a trapdoor as the course provides.

Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.

The cleanest illustration of a trapdoor in the course: two descriptions of one object, one of which makes a hard problem easy.

44. The Closest Vector Problem

Concept

Attacking GGH means solving a specific lattice problem.

Closest Vector Problem — Given a point P in ℝⁿ, find the lattice point closest to P. Hard for general lattices.

Bm is a lattice point, and c is close to it — moved off the lattice by the small vector e. So decrypting without the good basis means solving CVP.

But the book flags an important caveat. CVP is very hard for general lattices, and it seems to be easier when the point is very close to a lattice point — which is exactly the situation here. So the actual security level is not clear.

That caution was well placed. GGH was broken by Nguyen in 1999 for the proposed parameters, using precisely this observation: the error was small enough and structured enough to exploit. The system as specified is not used.

The idea survived, though. Modern lattice cryptography adds a crucial ingredient — errors drawn from a carefully chosen distribution, with security proved by reduction to worst-case lattice problems. Learning With Errors is that idea, and it is what the deployed post-quantum schemes are built on.

Figure (svg): The closest vector problem: a ciphertext sits just off a lattice point, and decryption is finding which one.

The security assumption is not that CVP is hard in general, but that it is hard in the particular regime the scheme uses.

45. Post-Quantum Cryptography?

Section

Section 23.6 · p. 460

46. Why lattices, and what they cost

Concept

If a quantum computer is built, Chapter 25 will show that systems based on factoring or discrete logs become much less secure.

Lattice-based systems are among the most promising candidates, because their security does not depend on factoring or discrete logs, and no quantum attack on them has been found. The McEliece system, based on error-correcting codes and structurally similar to GGH, is another.

The difficulty is key size. GGH's public key is a 300 × 300 matrix — 90 000 integer entries, many of them large. At 100 bits each that is about 9 million bits, vastly more than any conventional public key.

NTRU is the exception, and that is why it stands out: its public key is a single polynomial with N coefficients, so a few kilobits rather than megabits. Structure buys compactness, at the price of a lattice with structure an attacker might exploit.

The chapter ends with a question mark in its title, written before the migration it anticipated began. It has since begun: NIST's standardisation selected lattice schemes — ML-KEM and ML-DSA, descended from these ideas — and NTRU itself was a finalist.

Figure (svg): Why lattices are a post-quantum candidate, and the key-size cost they carry.

The chapter's forward-looking section, written before the migration it anticipated actually began.

47. Where lattice cryptography stands now

Real world

The chapter's closing section asked a question that has since been answered.

Discussion prompt

What happened to lattice-based cryptography after this chapter was written?

Hint: Standardisation, deployment, and one notable casualty.

Answer:

NIST ran a post-quantum standardisation process from 2016 to 2024, and the primary selections are lattice-based: ML-KEM for key encapsulation and ML-DSA for signatures, derived from Kyber and Dilithium.

They use Learning With Errors over rings, which is a direct descendant of the ideas here — a small error hiding a lattice point, with the crucial addition that the error distribution is chosen so that security reduces to worst-case lattice problems.

Deployment has already started. Chrome and Cloudflare run hybrid X25519+ML-KEM key exchange on a large fraction of TLS connections, and Signal added a post-quantum layer to its ratchet. This is live traffic, not a pilot.

The motivation is store-now-decrypt-later. Traffic captured today can be decrypted when a quantum computer arrives, so anything requiring long-term confidentiality needs migrating before the machine exists — which is why the urgency is real despite no such machine existing.

And a cautionary note the chapter would have appreciated. SIKE, an isogeny-based finalist and not lattice-based, was broken in 2022 by a classical attack that ran in about an hour on one laptop — after years of scrutiny. New assumptions can fail suddenly, which is why the deployments are hybrids rather than replacements.

48. Find the flaws in this lattice deployment

Error analysis

From a design document.

Annotate

  • Far too small. LLL and BKZ are effective well past 60 dimensions, so an attacker recovers a good basis directly from the public one. GGH was proposed at 300 and even that was broken.
  • It destroys the scheme. If e is known, the attacker computes c − e = Bm exactly and solves an ordinary linear system — no lattice problem remains at all. The error must be random and secret.
  • Then every user shares the same trapdoor, so whoever generated B can read all traffic, and compromising one user's good basis compromises all of them.
  • Structured plaintexts give an attacker known linear relations among the message coordinates, narrowing the search — the lattice analogue of the stereotyped-message attack earlier in this chapter.

The second is the fatal one and the most instructive: the error is not noise added for safety, it is the thing that makes the problem hard. Remove it and there is no cryptography left.

49. Attack or foundation

Trade off

The same problem in two roles. Fill the blanks.

Comparison matrix

Lattices as an attackLattices as a foundation
Dimensionsmall — 4 for cubic RSAlarge — 1006 for NTRU at N = 503
What you wantLLL to succeedLLL to fail
The short vector isa polynomial that vanishes at the secretthe private key itself
Design leverreformulate in fewer dimensionsraise N until reduction is useless
What breaks itpadding, or a large exponentbetter reduction algorithms, or structure in the lattice

One algorithm, two opposite goals, and the same parameter — dimension — decides which side wins. That is unusually direct as design tensions go.

50. Match each scheme to its hard problem

Matching

Five constructions from this chapter and earlier ones.

Match the pairs

  • m1. NTRU
  • m2. GGH
  • m3. Coppersmith's attack
  • m4. RSA
  • m5. Elliptic curve Diffie-Hellman
  • r1. Finding a short vector in a 2N-dimensional lattice
  • r2. The closest vector problem
  • r3. Solved by lattice reduction in low dimension
  • r4. Factoring
  • r5. The elliptic curve discrete logarithm

Why: The first three are all lattice problems, and the difference between them is dimension and which vector is wanted. The last two are the classical assumptions that a quantum computer would break — which is exactly why the first two are interesting.

51. Which are broken by a quantum computer?

Discrimination

Six systems from the course.

Sort into buckets

Sort each by whether Shor's algorithm applies.

Broken by Shor
RSA; Elliptic curve Diffie-Hellman; ElGamal mod p
Not broken by Shor
NTRU; AES-256; GGH
broken
All three reduce to factoring or discrete logarithms, and Shor's algorithm solves both in polynomial time. The curve version falls fastest, since its smaller keys need fewer qubits.
not
Lattice problems have no known quantum algorithm that does better than classical, and AES faces only Grover's algorithm, which halves the effective key length — so AES-256 retains 128 bits of security against a quantum attacker.

52. How much confidence should lattice assumptions get?

Edge cases

Post-quantum standards are now built on lattice problems.

Discussion prompt

What is the evidence for them, and where are the soft spots?

Hint: Consider worst-case reductions, structure, and parameter estimation.

Answer:

The strongest evidence is worst-case to average-case reductions. For Learning With Errors, breaking a random instance implies solving lattice problems in the worst case — a guarantee that RSA and discrete logs have never had, since a random RSA modulus might be easy while some are hard.

The soft spot is structure. Efficient schemes use ring or module variants, whose lattices have extra algebraic structure. The reductions are weaker there, and structure has repeatedly turned out to be exploitable elsewhere in this course.

Parameter estimation is genuinely uncertain. Security rests on predicting what BKZ with a given block size achieves, and those estimates have been revised more than once. It is a much less settled science than estimating factoring effort.

And the field is young. Lattice cryptography is thirty years old against RSA's fifty and discrete logs' longer history, with far fewer person-years of attack behind it.

Which is why deployments are hybrids. Chrome's TLS combines X25519 with ML-KEM so that breaking the connection requires breaking both. Given SIKE's sudden collapse in 2022, that caution looks well judged rather than excessive.

53. Order these by how badly they break a lattice scheme

Ranking

Five problems.

Put in order

  1. The public key is larger than expected
  2. Occasional decryption failures
  3. The same randomness φ is reused across messages
  4. The dimension is chosen too small
  5. The error vector is predictable

Why: A large key is an efficiency problem. Decryption failures are a correctness problem — though in some schemes a failure oracle leaks key information, so it is not entirely benign. Reused randomness lets two ciphertexts be differenced, exposing the relation between the messages. Too small a dimension means reduction recovers the private key. And a predictable error removes the lattice problem entirely, leaving ordinary linear algebra.

54. Advise on post-quantum migration

Constraint

An organisation stores medical records that must stay confidential for fifty years, and asks what to do about quantum computers.

Discussion prompt

What is the advice, and what is the reasoning?

Hint: Start from the threat timeline, not the technology.

Answer:

The threat is store-now-decrypt-later, and it is active today. An adversary recording encrypted traffic now can decrypt it whenever a quantum computer arrives. For a fifty-year confidentiality requirement, that risk is already live regardless of when the machine appears.

So migrate key exchange first, because that is what protects recorded traffic. Signatures matter less urgently — a forged signature requires a quantum computer at the time of forgery, so it cannot be done retroactively.

Deploy hybrids, not replacements. X25519 combined with ML-KEM means an attacker must break both, which protects against a classical break of the new scheme as much as against a quantum break of the old one — and SIKE showed that is not a theoretical concern.

Plan for larger keys and ciphertexts. ML-KEM's public keys are around 1.2 KB against 32 bytes for X25519, which affects handshake sizes, embedded devices and anything with tight packet budgets.

And build in crypto-agility. The single most valuable property is being able to change algorithm without changing the protocol, because these parameters will be revised. The organisations that struggled with SHA-1 and RSA-1024 deprecation are the ones that hard-coded them.

55. Reading the LLL approximation factor

Cost model

One exponent governs when lattice attacks work.

Annotate

On: \( \|b_1\| \le 2^{(n-1)/2} \, \lambda \)

  • Factor 2^{1/2} ≈ 1.41, and in fact the two-dimensional algorithm is exact. Reduction fully solves the problem.
  • Factor 2^{3/2} ≈ 2.83. Small enough that the RSA attack's polynomial is short enough for the size argument to fire.
  • Factor about 2^{150} ≈ 10^{45}. The guarantee is worthless, though LLL in practice does considerably better than its worst case.
  • NTRU at N = 503. Nothing known comes close, which is the security argument.
  • BKZ with block size β interpolates between LLL and exact reduction, and parameter choices are made against estimates of BKZ's behaviour rather than LLL's bound. Those estimates are where the real uncertainty lives.

A rare case where one exponent separates 'attack' from 'cryptosystem', and where the design decision is simply which side of it to sit on.

56. What does 'lattice-based' not tell you?

Missing information

A scheme is described as lattice-based and therefore quantum-resistant.

Discussion prompt

What still needs checking?

Hint: Which lattice problem, which lattices, and which parameters.

Answer:

Which problem it reduces to. Shortest vector, closest vector, LWE, SIS and NTRU-style problems are related but not equivalent, and their reductions to each other are partial.

Whether the lattices are structured. Ring-LWE lattices carry algebraic structure that plain LWE does not. It buys efficiency and weakens the reduction, and structure has been a repeated source of attacks throughout this course.

Whether the parameters are current. Estimates for lattice attack cost have been revised, and a scheme quoting a security level from an older analysis may not deliver it.

Whether decryption failures leak. Several lattice schemes have a small failure probability, and an attacker who can trigger and observe failures can extract key information — a chosen-ciphertext attack that has broken real proposals.

And whether the implementation is constant-time. Lattice arithmetic involves sampling from discrete Gaussians and rejection sampling, both of which leak through timing if done naively. GGH aside, this is where practical lattice deployments actually go wrong.

57. What the lattice attack on RSA shows

Two truths and a lie

Two of these overstate it.

Eliminate the wrong options

Which statement is correct?

  • a. RSA with a small exponent and predictable plaintext structure can be broken without factoring n
  • b. RSA is broken by lattice reduction
  • c. The attack recovers the factorisation of n

Survives elimination: a

Why: The precise claim has three conditions and each is necessary. What makes the attack instructive is that it breaks the message without touching the underlying hard problem — a reminder that a cryptosystem's security is not identical to its hard problem's difficulty.

58. Where would a lattice deployment fail first?

Commit first

An organisation deploys ML-KEM using a well-regarded library at standardised parameters.

Predict first

What is the realistic failure?

  • Someone finds a polynomial-time algorithm for lattice problems
  • An implementation issue — non-constant-time sampling, or a decryption-failure oracle
  • A quantum computer is built
  • The public keys are too large to transmit

Correct: An implementation issue — non-constant-time sampling, or a decryption-failure oracle

This is the same conclusion as Chapters 21 and 22. The mathematics is the studied part; the implementation is where the failures actually occur.

Lattice schemes add two hazards the older systems did not have. Sampling from a discrete Gaussian is subtle and easy to make data-dependent, and a nonzero decryption failure rate is an attack surface with no analogue in RSA or ECC.

Which is why the standardised versions use Fujisaki-Okamoto transforms to achieve chosen-ciphertext security, and why deterministic re-encryption checks are part of the specification rather than an optional hardening.

Why: Lattice schemes sample from carefully shaped distributions and have a small decryption failure probability, and both are exploitable if handled naively. Timing leaks in samplers and chosen-ciphertext attacks driven by failure oracles have broken real implementations, while the underlying assumptions have held.

59. Explain the trapdoor to someone who has not seen lattices

Explain it

A colleague asks how a public key can describe the same thing as a private key and still be safe.

Discussion prompt

Explain the GGH idea without matrices.

Hint: Two descriptions of the same grid.

Answer:

Start with the grid. Imagine an infinite regular grid of points in space. You can describe it by giving a few arrows: every grid point is a whole number of steps along each arrow.

Some sets of arrows are pleasant — short and pointing in very different directions. Given a location, you can immediately say which grid point is nearest.

Others are horrible — enormously long and nearly parallel. They describe the same grid, but working out which point is nearest to a location becomes a nightmare of near-cancelling large numbers.

Publish the horrible arrows and keep the pleasant ones. To send you a message, someone picks a grid point and nudges it slightly off. Anyone can verify the arithmetic; only you can round back to the grid point reliably.

And the reason it is hard to cheat is that recovering pleasant arrows from horrible ones is the shortest vector problem — solvable in two or three dimensions and, as far as anyone knows, hopeless in three hundred.

Figure (svg): The GGH cryptosystem: a good basis rounds away the error, a bad basis amplifies it.

The cleanest illustration of a trapdoor in the course: two descriptions of one object, one of which makes a hard problem easy.

60. Why do both attacks turn on 'small enough'?

Explain it to yourself

The RSA attack argues |g(x)| < n; NTRU's decryption argues that coefficients stay below q/2.

Discussion prompt

Explain what these two arguments have in common.

Hint: In both, a congruence becomes an equality.

Answer:

Both convert a statement mod something into a statement over the integers. g(x) ≡ 0 (mod n) plus |g(x)| < n forces g(x) = 0 exactly. And a ≡ pφ∗g + f∗m (mod q) plus all coefficients under q/2 forces equality.

A congruence loses information; an equality does not. Knowing a value mod n leaves n possibilities; knowing it exactly leaves one. The size bound is what recovers the lost information.

In the RSA attack this is used offensively. The lattice's entire job is to produce a polynomial whose coefficients are small enough for the argument to fire — nothing else about b₁ matters.

In NTRU it is used constructively, and the failure probability is exactly the chance that the size bound fails. The parameters exist to make that chance about 5 in 100 000.

So the same technique appears as attack and as design, which is the chapter's recurring shape. And it explains the obsession with smallness throughout: 'small' is not an efficiency concern here, it is the mechanism by which modular arithmetic is escaped.

Figure (svg): Why NTRU decrypts: the f times c product reduces to a small polynomial that survives the mod-q reduction intact.

The whole scheme rests on smallness: coefficients that stay under q/2 turn a congruence into an equation.

61. Short vectors, in both directions

Pattern

One object, used twice, and the parameter that decides which role it plays is dimension.

  1. A lattice has infinitely many bases, and only a change of basis with determinant ±1 preserves it. So 'the basis' is a description, not a property.
  2. Reduction trades a bad basis for a good one, exactly in two dimensions and approximately above — LLL guarantees ‖b₁‖ ≤ 2^{(n−1)/2}λ, which is tight when n is small and worthless when n is large.
  3. As an attack: encode a problem so that its solution is a short vector in a low-dimensional lattice. Coppersmith's method does this for small roots of polynomial congruences, breaking low-exponent RSA with stereotyped plaintext.
  4. As a foundation: make the lattice high-dimensional and hide the private key as a short vector in it. NTRU and GGH do this, and their parameters are chosen so that reduction fails.
  5. And both turn on the same move: a quantity divisible by the modulus and smaller than it must be zero, so a congruence becomes an equality.

The design tension is unusually direct. Every improvement in lattice reduction simultaneously strengthens the attacks and forces the cryptosystems' parameters upward — which is why estimating BKZ's behaviour is now a load-bearing part of post-quantum security.

Figure (svg): A two-dimensional lattice with a nearly-parallel bad basis and a short, nearly-orthogonal good basis.

A lattice has infinitely many bases, and reduction is the business of trading a bad one for a good one.

62. Lattice-based means quantum-proof

Trap

The trap

The trap. Shor's algorithm breaks factoring and discrete logarithms, so RSA and elliptic curves fall to a quantum computer. Lattice problems are not affected by Shor. Therefore lattice-based cryptography is quantum-proof and the migration problem is solved by switching.

The first two sentences are correct. The conclusion carries much more than they support.

The fix

'No known quantum algorithm' is not 'no quantum algorithm'. It is the same kind of claim as the classical assumptions in this course — evidence from failed attempts, not a proof. Quantum algorithms for lattice problems are an active research area.

Classical attacks remain the immediate risk. GGH was broken classically in 1999, and SIKE — a post-quantum finalist — was broken classically in 2022 by an attack that ran in about an hour. New assumptions can fail suddenly and for ordinary reasons.

Efficient variants weaken the guarantees. The worst-case reductions that make lattices attractive are strongest for unstructured problems, and the schemes fast enough to deploy use ring or module structure where the reduction is weaker — the familiar trade of structure for speed.

Parameter estimates are unsettled. Security rests on predictions about BKZ that have been revised, and this is a much younger science than estimating factoring cost.

The accurate claim is narrow and still worth acting on: lattice problems have no known efficient quantum algorithm, so they are the best available candidate for post-quantum key exchange — deployed alongside a classical scheme, not instead of one. The hybrid is not timidity; it is the correct response to a young assumption.

63. Check: what reduction achieves

Check

Work it out before clicking.

Check your understanding

After running the two-dimensional reduction algorithm, what is true of v₁?

  • A. It is shorter than it was
  • B. It is a shortest nonzero vector in the lattice — exactly, not approximately (correct)
  • C. It is orthogonal to v₂
  • D. It is within a factor of 2 of the shortest

Answer: B

Why: The theorem proves it exactly: for any nonzero lattice vector av₁ + bv₂, the reducedness conditions give ‖av₁ + bv₂‖² ≥ (a² − ab + b²)‖v₁‖², and a² − ab + b² is a positive integer for nonzero (a, b). Two dimensions is the one case where a greedy algorithm provably reaches the optimum.

Why A tempts people
True but far weaker than what is proved, and it would not be enough for the attacks that follow.
Why C tempts people
Nearly orthogonal, not orthogonal — the dot product of the example's reduced basis is −1, not 0. Exact orthogonality is generally impossible within a lattice.
Why D tempts people
That is the shape of LLL's guarantee in higher dimensions. In two dimensions the answer is exact.

64. Check: why the RSA attack works

Check

Consider the final step of Coppersmith's attack.

Check your understanding

The attack concludes that g(x) = 0 exactly. What justifies that?

  • A. LLL solves the congruence directly
  • B. g(x) ≡ 0 (mod n) and |g(x)| < n, and the only such integer is 0 (correct)
  • C. The factorisation of n was recovered
  • D. g has degree 3, so it has a real root

Answer: B

Why: The lattice's whole purpose is to produce a short vector, hence a polynomial with small coefficients, hence a small value at x. Divisible by n and smaller than n in absolute value leaves only zero — and the congruence has become an equation solvable without any factorisation.

Why A tempts people
LLL only finds a short vector. Turning that into a solution needs the size argument.
Why C tempts people
n is never factored. That is what makes the attack notable — it sidesteps the hard problem rather than solving it.
Why D tempts people
Every real cubic has a real root; that says nothing about it being the plaintext, or an integer.

65. Check: where NTRU's security lives

Check

Consider the lattice interpretation.

Check your understanding

In the lattice attack on NTRU, what is the short vector an attacker seeks?

  • A. The ciphertext c
  • B. (f, g) — the private key, which is short because f and g have small coefficients (correct)
  • C. The public key h
  • D. The random polynomial φ

Answer: B

Why: Since g = f ∗ h + qy, the vector (f, y) times M gives (f, g), so (f, g) lies in the 2N-dimensional lattice generated by M's rows — and f and g are small by construction. Finding it breaks the system, which is why N must be large enough that reduction fails.

Why A tempts people
The ciphertext is public and has large coefficients mod q; it is not a short lattice vector.
Why C tempts people
h is the public key, also with large coefficients — it is what builds the lattice, not what is hidden in it.
Why D tempts people
φ is per-message randomness. Recovering it would expose one message; recovering f exposes all of them.

66. Write the two roles side by side

Connect it up

The chapter is one problem used in opposite directions.

Draw it

Draw two columns, 'attack' and 'foundation'. In each, write: the lattice's dimension, what the short vector represents, whether LLL succeeds, and what a designer changes to move the outcome. Then write the two size arguments — |g(x)| < n and coefficients under q/2 — and say in one line what they have in common. Finish with the post-quantum position: which assumptions fall to Shor, which do not, and why deployments are hybrids.

The two size arguments are the thing to be able to state cleanly. They are the same observation used offensively and defensively, and recognising it makes both halves of the chapter one idea.

67. Exit ticket

Exit ticket

One question, about the parameter that decides everything.

Predict first

What separates a lattice attack from a lattice cryptosystem?

  • The choice of hard problem
  • The dimension — LLL is effective in low dimensions and useless in high ones
  • Whether the lattice has integer coordinates
  • The size of the modulus

Correct: The dimension — LLL is effective in low dimensions and useless in high ones

Why: Both use short vectors in a lattice. In the RSA attack the lattice has 4 dimensions and reduction is near-exact; in NTRU it has 1006 and no known algorithm gets close. LLL's approximation factor 2^{(n−1)/2} is the dividing line, and the design decision is simply which side of it to sit on.

68. What to carry into Chapter 24

Recap

Short vectors, hunted and hidden.

Chapter 24 next. Error-correcting codes: Hamming codes, linear codes and the McEliece cryptosystem — the other post-quantum family, and the one this chapter named as the alternative to lattices.

Figure (svg): Why lattices are a post-quantum candidate, and the key-size cost they carry.

The chapter's forward-looking section, written before the migration it anticipated actually began.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 23 — Lattice Methods (sections 23.1-23.7) — Trappe & Washington, 3rd edition, pp. 441-460

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108