Paper 2025/1852

A Gaussian Leftover Hash Lemma for Modules over Number Fields

Martin R. Albrecht, King's College London, SandboxAQ
Joël Felderhoff, King's College London
Russell W. F. Lai, Aalto University
Oleksandra Lapiha, Royal Holloway University of London
Ivy K. Y. Woo, Aalto University
Abstract

Leftover Hash Lemma (LHL) states that \(\mathbf{X} \cdot \mathbf{v}\) for a Gaussian \(\mathbf{v}\) is an essentially independent Gaussian sample. It has seen numerous applications in cryptography for hiding sensitive distributions of \(\mathbf{v}\). We generalise the Gaussian LHL initially stated over \(\mathbb{Z}\) by Agrawal, Gentry, Halevi, and Sahai (2013) to modules over number fields. Our results have a sub-linear dependency on the degree of the number field and require only polynomial norm growth: \(\lVert\mathbf{v}\rVert/\lVert\mathbf{X}\rVert\). To this end, we also prove when \(\mathbf{X}\) is surjective (assuming the Generalised Riemann Hypothesis) and give bounds on the smoothing parameter of the kernel of \(\mathbf{X}\). We also establish when the resulting distribution is independent of the geometry of \(\mathbf{X}\) and establish the hardness of the \(k\)-SIS and \(k\)-LWE problems over modules (\(k\)-MSIS/\(k\)-MLWE) based on the hardness of SIS and LWE over modules (MSIS/MLWE) respectively, which was assumed without proof in prior works.

Note: Changelog 24/02/2026 Fixed typos and included reviewers remarks

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
A major revision of an IACR publication in EUROCRYPT 2026
Keywords
Leftover Hash LemmaModule LatticesDiscrete GaussianPost-QuantumSIS With Hints
Contact author(s)
martinralbrecht @ googlemail com
joel felderhoff @ kcl ac uk
russell lai @ aalto fi
sasha lapiha 2021 @ live rhul ac uk
ivy woo @ aalto fi
History
2026-02-24: revised
2025-10-07: received
See all versions
Short URL
https://ia.cr/2025/1852
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1852,
      author = {Martin R. Albrecht and Joël Felderhoff and Russell W. F. Lai and Oleksandra Lapiha and Ivy K. Y. Woo},
      title = {A Gaussian Leftover Hash Lemma for Modules over Number Fields},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1852},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1852}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.