{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,2]],"date-time":"2022-04-02T23:02:37Z","timestamp":1648940557779},"reference-count":64,"publisher":"Walter de Gruyter GmbH","issue":"1","funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["CRC 1119 CROSSING"]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,3,1]]},"abstract":"Abstract<\/jats:title>\n The Learning With Errors (LWE) problem is one of the most important hardness\nassumptions lattice-based constructions base their security on. In 2015,\nAlbrecht, Player and Scott presented the\nsoftware tool LWE-Estimator<\/jats:italic> to estimate the hardness of concrete LWE\ninstances, making the choice of parameters for lattice-based primitives easier\nand better comparable.\nTo give lower bounds on the hardness, it is assumed that\neach algorithm has given the corresponding optimal number of samples. However,\nthis is not the case for many cryptographic applications.\nIn this work\nwe first analyze the hardness of LWE instances given a restricted number of\nsamples. For this, we describe LWE solvers from the literature and estimate
their runtime considering a limited number of samples.
Based on our theoretical results we extend the LWE-Estimator.
Furthermore, we evaluate LWE instances proposed for cryptographic schemes
and show the impact of restricting the number of available samples. 