SearcharxivSearch

arXiv · 2506.23438

Some Mathematical Problems Behind Lattice-Based Cryptography

Abstract

In 1994, P. Shor discovered quantum algorithms which can break both the RSA cryptosystem and the ElGamal cryptosystem. In 2007, D-Wave demonstrated the first quantum computer. These events and further developments have brought a crisis to secret communication. In 2016, the National Institute of Standards and Technology (NIST) launched a global project to solicit and select a handful of encryption algorithms with the ability to resist quantum computer attacks. In 2022, it announced four candidates, CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon and Sphincs$+$ for post-quantum cryptography standards. The first three are based on lattice theory and the last on the Hash function. It is well known that the security of the lattice-based cryptosystems relies on the computational complexity of the shortest vector problem (SVP), the closest vector problem (CVP) and their generalizations. In fact, the SVP is a ball packing problem and the CVP is a ball covering problem. Furthermore, both SVP and CVP are equivalent to arithmetic problems for positive definite quadratic forms. Therefore, post-quantum cryptography provides unprecedented opportunities for mathematicians to make contributions in modern technology. This paper will briefly review the mathematical problems on which the lattice-based cryptography is built up, so that mathematicians can see that they are indeed in the game.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Chuanming Zong. 2025-06-30. Some Mathematical Problems Behind Lattice-Based Cryptography. https://arxiv.org/abs/2506.23438

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Tile sets consisting of two types of concave polygons derived from periodic tilings corresponding to non-periodic tilings with hat and turtle tiles

Using a convex pentagonal monotile belonging to the Type 5 family, we investigate the relationships among the hat tile, turtle tile, and Tile$(1, 1)$. By applying Sugimoto's Perspective and Amfirifma's Perspective, we obtain four types of concave polygons, AH-tile, BH-tile, AT-tile, and BT-tile, each having Heesch number 1 under the conditions considered. We show that these polygons correspond to clusters used to generate the non-periodic tilings $\mathscr{T}_h$ and $\mathscr{T}_s$. We further discuss the possibility that tile sets consisting of pairs selected from these polygons may correspond to $\textit{ASPmr}\{\text{A-tile}, \text{B-tile}\}$.

math.MG

The mean distance to a simple closed curve on the sphere

Kimberling's Problem 10 asks for a simple closed curve of prescribed length $L$ (in particular, $L=4\pi$) on the unit sphere minimizing the mean geodesic distance $\mathcal{J}$ from a point of the sphere to the curve. For a positive integer $n$, put $\vartheta_{n}=\pi/(2n)$ and $L_{n}=2\pi/\sin\vartheta_{n}$. We show that the minimum of $\mathcal{J}$ over rectifiable simple closed curves of length at most $L_{n}$ equals $\vartheta_{n}-\tan(\vartheta_{n}/2)$, that it is attained only by curves of length exactly $L_{n}$, and that the sphere-filling ropes $\beta^{n,k}$ of Gerlach and von der Mosel attain it. Kimberling's case is $n=3$: at $L=4\pi$ the minimum is $\pi/6+\sqrt{3}-2=0.255649\ldots$, attained by an explicit six-arc curve and by its mirror image. For $L\le2\pi$ we determine $J(L)$, the infimum of $\mathcal{J}$ over curves of length $L$, exactly: it equals $\pi/2-L/(2\pi)$, attained precisely by the circles of length $L$. At the lengths $L_{n}$ we do not classify all minimizers, but show that every one of them bisects the sphere into two disks of area $2\pi$ and inradius $\vartheta_{n}$ whose inward collars have the largest possible area at every depth. The great circle is the only minimizer for $n=1$, and the $\beta^{n,k}$ are, up to congruence, the only ones of thickness at least $\sin\vartheta_{n}$. For arbitrary $L$ the function $J$ is nonincreasing, and together with the above this brackets it between two explicit values.

math.MG

The topology of Gromov--Hausdorff space

We prove that the Gromov--Hausdorff space is homeomorphic to the Hilbert space. This paper is divided into four parts. In Part I, we construct an assignment of a full-support probability measure to every nonempty compact metric space that respects isometries and is continuous for simultaneous Hausdorff convergence of the spaces and weak convergence of the measures. In Part II, we use these measures to construct finite-dimensional local models whose induced pseudometrics approximate the original distances uniformly and whose norms and point maps vary continuously up to orthogonal changes of coordinates. In Part III, we use the local models to prove that the Gromov--Hausdorff space is an absolute retract for all metrizable spaces. In Part IV, we establish a discrete approximation property and conclude that the space of isometry classes of nonempty compact metric spaces is homeomorphic to the real separable infinite-dimensional Hilbert space.

math.MG