[LS15] Worst-case to average-case reductions for module lattices
Authors: Adeline Langlois, Damien Stehlé | Venue: Designs, Codes and Cryptography | Source
Introduced Module LWE (MLWE), which generalizes Ring LWE by considering rank- modules over a polynomial ring . When this recovers Ring LWE; when this recovers plain LWE. The module structure interpolates between the two extremes, yielding a flexible parameter trade-off between efficiency and security assumptions. Kyber (ML-KEM) and Dilithium (ML-DSA), the NIST post-quantum standards, are based on Module LWE.
BibTeX
@Article{DCC:LanSte15,
author = {Adeline Langlois and Damien Stehl{\'e}},
title = {Worst-case to average-case reductions for module lattices},
pages = {565--599},
journal = {Designs, Codes and Cryptography},
volume = {75},
number = {3},
publisher = {Springer},
year = {2015},
doi = {10.1007/s10623-014-9938-4},
}