<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Paper Reading on As it was</title>
    <link>https://galoishlee.github.io/categories/paper-reading/</link>
    <description>Recent content in Paper Reading on As it was</description>
    <generator>Hugo</generator>
    <language>zh-CN</language>
    <managingEditor>maocred@gmail.com (Halois)</managingEditor>
    <webMaster>maocred@gmail.com (Halois)</webMaster>
    <copyright>This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.</copyright>
    <lastBuildDate>Sat, 30 May 2026 20:37:52 +0800</lastBuildDate>
    <atom:link href="https://galoishlee.github.io/categories/paper-reading/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Solving LWE with Independent Hints about Secret and Errors — Lu, Feng, Pan (2025)</title>
      <link>https://galoishlee.github.io/lattice-hints-lu2025/</link>
      <pubDate>Wed, 27 May 2026 12:00:00 +0800</pubDate><author>maocred@gmail.com (Halois)</author>
      <guid>https://galoishlee.github.io/lattice-hints-lu2025/</guid>
      <description>&lt;p&gt;Reading: Lu, Feng, Pan (2025). &lt;em&gt;Solving LWE with Independent Hints about Secret and Errors.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;问题设定：&lt;/strong&gt; 给定 LWE 实例 \((A, \mathbf{b} = \mathbf{s}A + \mathbf{e} \bmod q)\) 和一组精确的侧信道 hint（关于 \(\mathbf{s}\) 或 \(\mathbf{e}\) 的内积值），构造 primal attack 格基进行密钥恢复。&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;本文的改进：&lt;/strong&gt; 将 Nowakowski-May (ASIACRYPT 2023) 嵌入 hint 时使用的 LLL 约简替换为 Hermite 标准型（HNF）——一个多项式次数更低的整数线性代数操作。Kyber512 上 234 个完美 hint 的基构造从 2.16 小时降至 0.35 小时。格基维度与行列式与 MN23 等价，对完美 hint 行列式略有增大。&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;本笔记关注：&lt;/strong&gt; (1) 构造链——hint 转为 lattice hint 后如何通过矩阵乘法嵌入 primal attack 格基；(2) HNF 比 LLL 快在哪——多项式次数的差距及其工程含义；(3) 论文未说但值得追问的部分——带噪 hint、联合 hint、attack pipeline 完整评测的缺失。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
