An Efficient and Parallel Gaussian Sampler for Lattices

نویسنده

  • Chris Peikert
چکیده

At the heart of many recent lattice-based cryptographic schemes is a polynomial-time algorithm that, given a ‘high-quality’ basis, generates a lattice point according to a Gaussian-like distribution. Unlike most other operations in lattice-based cryptography, however, the known algorithm for this task (due to Gentry, Peikert, and Vaikuntanathan; STOC 2008) is rather inefficient, and is inherently sequential. We present a new Gaussian sampling algorithm for lattices that is efficient and highly parallelizable. We also show that in most cryptographic applications, the algorithm’s efficiency comes at almost no cost in asymptotic security. At a high level, our algorithm resembles the “perturbation” heuristic proposed as part of NTRUSign (Hoffstein et al., CT-RSA 2003), though the details are quite different. To our knowledge, this is the first algorithm and rigorous analysis demonstrating the security of a perturbation-like technique.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Hybrid Gaussian Sampler for Lattices over Rings

Gaussian sampling over lattices is a cornerstone of latticebased cryptography as it allows to build numerous cryptographic primitives. There are two main algorithms performing this task. The rst one is due to Klein (SODA 2000) and Gentry, Peikert and Vaikuntanathan (STOC 2008), and outputs vectors of good quality but runs rather slowly, in quadratic time. The second one is due to Peikert (CRYPT...

متن کامل

Parallel sampling of GMRFs and geostatistical GMRF models

In this report the main focuses are geostatistical Gaussian Markov random field (GMRF) models and parallel exact sampling of GMRFs. There are also brief overviews of parallel computing and Markov chain Monte Carlo (MCMC) methods, and a literature review of parallel MCMC. The geostatistical GMRF models are constructed by discretising the domain region using a lattice. Instead of giving this latt...

متن کامل

Sampling Gaussian Distributions in Krylov Spaces with Conjugate Gradients

This paper introduces a conjugate gradient sampler that is a simple extension of the method of conjugate gradients (CG) for solving linear systems. The CG sampler iteratively generates samples from a Gaussian probability density, using either a symmetric positive definite covariance or precision matrix, whichever is more convenient to model. Similar to how the Lanczos method solves an eigenvalu...

متن کامل

Gaussian Z Channel with Intersymbol Interference

In this paper, we derive a capacity inner bound for a synchronous Gaussian Z channel with intersymbol interference (ISI) under input power constraints. This is done by converting the original channel model into an n-block memoryless circular Gaussian Z channel (n-CGZC) and successively decomposing the n-block memoryless channel into a series of independent parallel channels in the frequency dom...

متن کامل

GLITCH: A Discrete Gaussian Testing Suite for Lattice-based Cryptography

Lattice-based cryptography is one of the most promising areas within post-quantum cryptography, and offers versatile, efficient, and high performance security services. The aim of this paper is to verify the correctness of the discrete Gaussian sampling component, one of the most important modules within lattice-based cryptography. In this paper, the GLITCH software test suite is proposed, whic...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2010  شماره 

صفحات  -

تاریخ انتشار 2010