Paper 2025/1382

Using Learning with Rounding to Instantiate Post-Quantum Cryptographic Algorithms

Andrea Basso, IBM Zurich
Joppe W. Bos, NXP Semiconductors
Jan-Pieter D'Anvers, KU Leuven
Angshuman Karmakar, Indian Institute of Technology Kanpur
Jose Maria Bermudo Mera, PQShield
Joost Renes, NXP Semiconductors
Sujoy Sinha Roy, Graz University of Technology
Frederik Vercauteren, KU Leuven
Peng Wang, University of Chinese Academy of Sciences
Yuewu Wang, University of Chinese Academy of Sciences
Shicong Zhang, University of Chinese Academy of Sciences
Chenxin Zhong, University of Chinese Academy of Sciences
Abstract

The Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) paper presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This paper systematically reviews existing LWR-based schemes --- including Saber, Lizard, Florete, Espada, Sable, and SMAUG --- analyzing their design choices, parameter sets, and performance trade-offs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims to guide future cryptographic design and standardization efforts leveraging LWR.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-Quantum CryptographyLearning with RoundingLattice-Based CryptographyCryptographic Survey
Contact author(s)
joppe bos @ nxp com
History
2025-07-31: approved
2025-07-29: received
See all versions
Short URL
https://ia.cr/2025/1382
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1382,
      author = {Andrea Basso and Joppe W. Bos and Jan-Pieter D'Anvers and Angshuman Karmakar and Jose Maria Bermudo Mera and Joost Renes and Sujoy Sinha Roy and Frederik Vercauteren and Peng Wang and Yuewu Wang and Shicong Zhang and Chenxin Zhong},
      title = {Using Learning with Rounding to Instantiate Post-Quantum Cryptographic Algorithms},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1382},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1382}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.