分圆陪集:素数幂模数的隐藏子群与量子筛算法
Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli
浏览论文内容
中文总结 AI 辅助
本文提出分圆陪集问题(CCP),保留隐藏子群结构,并利用π-adic理想链构造量子筛,在素数幂模数下以拟多项式时间解决CCP、均匀EDCP及高斯S|LWE>,但不直接适用于标准LWE。
中文摘要 AI 辅助
带误差学习(LWE)问题是后量子密码学中的一个基本假设。Regev建立了从LWE到二面体陪集问题(DCP)的量子归约。后来,Brakerski等人引入了外推二面体陪集问题(EDCP),并证明了其与LWE的等价性。然而,与DCP不同,EDCP不再具有陪集结构,这限制了隐藏子群问题技术的直接应用。在本工作中,我们引入了分圆陪集问题(CCP),它是DCP的一种分圆推广,保留了精确的隐藏子群结构。设ζ_p为p次本原单位根,令π=ζ_p-1,并记q=p^t和L=t(p-1)。我们在R_q=Z_q[ζ_p]≅Z[ζ_p]/(π^L)上工作,其中该同构由完全分歧恒等式(p)=(π)^{p-1}得出。我们利用由此产生的π-adic理想链构造了一个量子筛,该筛逐步将相位态模π^L,π^{L-1},…,π进行约简。对于每个固定的素数p和模数q=p^t,我们的算法在时间和样本复杂度2^{O_p(log n log q)}内解决CCP,并使用多项式量子空间。该筛也适用于均匀EDCP和高斯S|LWE>,当q=poly(n)时,为上述所有问题提供拟多项式时间算法。这将Bai等人(CRYPTO 2025)的二的幂次EDCP筛扩展到分圆设置。然而,我们强调,我们的结果本身并不产生标准LWE的拟多项式时间算法,因为目前已知的归约仅产生有限数量的近似CCP态。
英文摘要
The Learning With Errors (LWE) problem is a fundamental assumption in post-quantum cryptography. Regev established a quantum reduction from LWE to the Dihedral Coset Problem (DCP). Later, Brakerski et al. introduced the Extrapolated Dihedral Coset Problem (EDCP), proving its equivalence to LWE. However, unlike DCP, EDCP no longer admits a coset structure. This limits the direct application of techniques for hidden subgroup problems. In this work, we introduce the Cyclotomic Coset Problem (CCP), a cyclotomic generalization of DCP that preserves an exact hidden-subgroup structure. Let $ζ_p$ be a primitive $p$-th root of unity, let $π=ζ_p-1$, and write $q=p^t$ and $L=t(p-1)$. We work over $R_q=\mathbb Z_q[ζ_p] \cong \mathbb Z[ζ_p]/(π^L)$, where the isomorphism follows from the total ramification identity $(p)=(π)^{p-1}$. We exploit the resulting $π$-adic ideal chain to construct a quantum sieve that successively reduces phase states modulo $π^{L},π^{L-1},\ldots,π$. For every fixed prime $p$ and modulus $q=p^t$, our algorithm solves the CCP in time and sample complexity $2^{O_p(\log n\log q)}$, using polynomial quantum space. The sieve also applies to uniform EDCP and Gaussian S|LWE>, yielding quasi-polynomial time algorithms for all the above problems when $q=\text{poly}(n)$. This extends the power-of-two EDCP sieve of Bai et al. (CRYPTO 2025) to a cyclotomic setting. However, we emphasize that our result does not, by itself, yield a quasi-polynomial-time algorithm for standard LWE, because the currently known reduction produces only a limited number of approximate CCP states.
发表机构
- Univ Rennes, Inria, CNRS, IRISA(雷恩大学、Inria、法国国家信息与自动化研究所、IRISA)
机构由 AI 辅助整理,请以论文原文为准。