Skip to main navigation Skip to search Skip to main content

Solving Small LWE Instances with the Dropping Meet-in-the-Middle Algorithm

  • Xiaofei Tong
  • , Jingguo Bi*
  • , Shuwen Luo
  • , Licheng Wang
  • , Lixiang Li
  • , Lin Wang*
  • *Corresponding author for this work
  • Beijing University of Posts and Telecommunications
  • Beijing Institute of Technology
  • National Key Laboratory of Security Communication

Research output: Contribution to journalConference articlepeer-review

Abstract

The Learning With Errors (LWE) problem serves as the security foundation for many post-quantum cryptographic schemes. Its various variants, including the sparse and small LWE problem, also play a key role in post-quantum cryptography. Accurately evaluating the computational complexity of solving LWE and its variants is important for understanding the security of related cryptographic schemes. In this paper, we propose an improved Dropping Meet-in-the-Middle (MitM) algorithm for LWE instances with sparse and small secrets. The core idea is to reduce the dimension of the MitM phase by pre-guessing τ components of the secret vector s, and to balance the additional guessing overhead against the reduction in the MitM phase, thereby achieving an overall optimization of computational cost. Experimental results show that our proposed method exhibits better performance compared with other attacks.

Original languageEnglish
Pages (from-to)730-737
Number of pages8
JournalProceedings of the IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom
Issue number2025
DOIs
Publication statusPublished - 2025
Externally publishedYes
Event24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2025 - Guiyang, China
Duration: 14 Nov 202517 Nov 2025

Keywords

  • Dropping technique
  • LWE
  • Meet-in-the-Middle

Fingerprint

Dive into the research topics of 'Solving Small LWE Instances with the Dropping Meet-in-the-Middle Algorithm'. Together they form a unique fingerprint.

Cite this