AI 中文总结
本文通过调整启发式筛法,在Haar随机格上实现了可证明的SVP和CVP求解,时间$2^{0.292n}$,空间$2^{0.2075n}$,并生成离散高斯样本,显著优于先前结果。
AI 中文摘要
为了缩小硬格问题(如最短向量问题(SVP)和最近向量问题(CVP))的最佳可证明算法与启发式算法之间的差距,我们分析了在Haar随机幺模格上的格筛法。通过对启发式筛法进行精心选择的修改,我们证明了启发式假设不再必要,并且可以在Haar随机格上为各种格问题实现与启发式筛法相同的复杂度。具体而言,在Haar随机格和算法随机性的随机性上以概率 $1 - o(1)$,我们展示了如何:1. 在时间 $2^{0.2924\ldots n + o(n)}$ 和空间 $2^{0.2075\ldots n + o(n)}$ 内求解SVP;2. 以相同复杂度求解随机目标的CVP;3. 以这些复杂度生成 $2^{0.2075\ldots n + o(n)}$ 个任意宽度的离散高斯样本,联合分布误差至多为 $2^{-\Omega(n)}$。这改进了Pouly-Shen [Eurocrypt, 2026] 针对Haar随机格的SVP复杂度(时间 $2^{0.633n + o(n)}$ 和空间 $2^{0.5n + o(n)}$),以及Gao-Feng-Hu和Hhan [Cryptology ePrint Archive, 2026] 最近对最坏情况SVP(和平均情况CVP)的改进(两者时间与空间均为 $2^{0.5n + o(n)}$ 或更高)。与标准筛法类似,我们的方法通过一系列薄球壳进行,从大半径开始,迭代组合向量以获得更小半径球壳中的向量。我们的主要技术贡献是进行一系列调整,以保证在每个球壳生成的每个筛列表中,每个列表向量在该球壳内的所有格点上独立且均匀随机。一旦满足这一不变量,就可以在球壳中平稳航行,直到找到解。
英文摘要
In an attempt to close the gap between the best provable and heuristic algorithms for hard lattice problems, such as the shortest (SVP) and closest vector problem (CVP), we analyze lattice sieving on Haar-random unimodular lattices. With well-chosen modifications to heuristic sieving, we show that the heuristic assumptions are no longer necessary, and we can provably achieve the same complexities as heuristic sieving on Haar-random lattices for various lattice problems. Concretely, with probability $1 - o(1)$ over the randomness of the Haar-random lattice and the algorithmic randomness, we show how to: 1. Solve SVP in time $2^{0.2924\ldots n + o(n)}$ and space $2^{0.2075\ldots n + o(n)}$; 2. Solve CVP for random targets with the same complexities; 3. Produce $2^{0.2075\ldots n + o(n)}$ discrete Gaussian samples at any width with these complexities, up to a $2^{-Ω(n)}$ error in the joint distribution. This improves on the SVP complexities for Haar-random lattices of Pouly-Shen [Eurocrypt, 2026] running in time $2^{0.633n + o(n)}$ and space $2^{0.5n + o(n)}$, as well as the recent worst-case SVP (and average-case CVP) improvements of Gao-Feng-Hu and Hhan [Cryptology ePrint Archive, 2026], both running in time and space $2^{0.5n + o(n)}$ or higher. Similar to standard sieving methods, our approach proceeds through a series of thin spherical shells, starting from a large radius and iteratively combining vectors to obtain vectors from shells with smaller radius. Our main technical contribution is making a series of adjustments to guarantee that for each sieve list generated at each spherical shell, each list vector is independent and uniformly random over all lattice points within this shell. Once this invariant is satisfied, it is a matter of smooth sailing through the spherical shells until we find a solution.
Comments46 pages