Paper 2025/1155

On the Security of Group Ring Learning with Errors

Andrew Mendelsohn, Imperial College London
Charles Grover, Flare Network
Cong Ling, Imperial College London
Abstract

We propose a dimension-reducing transformation on Group Ring Learning with Errors (GRLWE) samples. We exhibit an efficiently computable isomorphism which takes samples defined over the group rings used in the construction of GRLWE to twice as many samples defined over matrix rings, in half the dimension. This is done by composing two maps: the first map is a transformation showing that the group rings used are orders in central simple algebras, and the second map takes the obtained central simple algebra to a matrix ring. When combined with lattice reduction on the resulting matrix samples, this gives an attack on the GRLWE problem. We extend this attack to other groups proposed for cryptographic use by the creators of GRLWE, and display some numerical results quantifying the effects of the transformation, using the `Lattice Estimator'. We then give a family of groups from which GRLWE-style group rings can be constructed which are immune to our attack, namely the generalized quaternion groups. Finally, we discuss the merits and vulnerabilities of a number of different forms of structured LWE.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published by the IACR in CIC 2025
Keywords
learning with errorslatticespost-quantumpublic-key encryptioncryptanalysis
Contact author(s)
andrew mendelsohn18 @ imperial ac uk
c ling @ imperial ac uk
History
2025-06-20: approved
2025-06-18: received
See all versions
Short URL
https://ia.cr/2025/1155
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1155,
      author = {Andrew Mendelsohn and Charles Grover and Cong Ling},
      title = {On the Security of Group Ring Learning with Errors},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1155},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1155}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.