RLWE and PLWE over cyclotomic fields are not equivalent
Abstract
We prove that the Ring Learning With Errors (RLWE) and the Polynomial Learning With Errors (PLWE) problems over the cyclotomic field Q(ζn) are not equivalent. Precisely, we show that reducing one problem to the other increases the noise by a factor that is more than polynomial in n. We do so by providing a lower bound, holding for infinitely many positive integers n, for the condition number of the Vandermonde matrix of the nth cyclotomic polynomial.
0
Turn this paper into a lesson
ArcXiv compiles a structured reading guide from this paper's metadata: plain-English importance, contributions, prerequisite concepts, which sections to read first, flashcards, and a quiz. Grounded in the abstract, never invented.