Approximating Shortest Lattice Vectors is not Harder than Approximating Closest Lattice Vectors

نویسندگان

  • Oded Goldreich
  • Daniele Micciancio
  • Shmuel Safra
  • Jean-Pierre Seifert
چکیده

We show that given oracle access to a subroutine which returns approximate closest vectors in a lattice, one may find in polynomial time approximate shortest vectors in a lattice. The level of approximation is maintained; that is, for any function f , the following holds: Suppose that the subroutine, on input a lattice L and a target vector w (not necessarily in the lattice), outputs v ∈ L such that ‖v−w‖ ≤ f(n) ·‖u−w‖ for any u ∈ L. Then, our algorithm, on input a lattice L, outputs a non-zero vector v ∈ L such that ‖v‖ ≤ f(n) · ‖u‖ for any non-zero vector u ∈ L. The result holds for any norm, and preserves the dimension of the lattice, i.e. the closest vector oracle is called on lattices of exactly the same dimension as the original shortest vector problem. This result establishes the widely believed conjecture by which the shortest vector problem is not harder than the closest vector problem. The proof can be easily adapted to establish an analogous result for the corresponding computational problems for linear codes.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

SVP is no harder than CVP

We write A ≤T B to denote that A is Turing-reducible to B; A is Turing-reducible to a problem B if given an oracle for B, one can compute answers to A. In this case we will show taht if we can compute correct answers for CV Pγ , we can use this to compute the γ-shortest vector of some fixed lattice. Note that the decision formulation of CV P is NP-hard while (the natural decision version of) SV...

متن کامل

Shortest Vector Problem ( 1982 ; Lenstra , Lenstra , Lovasz )

of n linearly independent vectors b1, . . . ,bn ∈ Rm in m-dimensional Euclidean space. For computational purposes, the lattice vectors b1, . . . ,bn are often assumed to have integer (or rational) entries, so that the lattice can be represented by an integer matrix B = [b1, . . . ,bn] ∈ Zm×n (called basis) having the generating vectors as columns. Using matrix notation, lattice points in L(B) c...

متن کامل

Lattices with Many Cycles Are Dense

We give a method for approximating any n-dimensional lattice with a lattice Λ whose factor group Z/Λ has n− 1 cycles of equal length with arbitrary precision. We also show that a direct consequence of this is that the Shortest Vector Problem and the Closest Vector Problem cannot be easier for this type of lattices than for general lattices.

متن کامل

Improved Short Lattice Signatures in the Standard Model

We present a signature scheme provably secure in the standard model (no random oracles) based on the worst-case complexity of approximating the Shortest Vector Problem in ideal lattices within polynomial factors. The distinguishing feature of our scheme is that it achieves short signatures (consisting of a single lattice vector), and relatively short public keys (consisting of O(logn) vectors.)...

متن کامل

Sampling Short Lattice Vectors and the Closest Lattice Vector Problem

We present a 2 O(n) time Turing reduction from the closest lattice vector problem to the shortest lattice vector problem. Our reduction assumes access to a subroutine that solves SVP exactly and a subroutine to sample short vectors from a lattice, and computes a (1+)-approximation to CVP. As a consequence, using the SVP algorithm from 1], we obtain a randomized 2 O(1+ ?1)n algorithm to obtain a...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Inf. Process. Lett.

دوره 71  شماره 

صفحات  -

تاریخ انتشار 1999