Paper 2025/1997

Provable decryption failure security for practical lattice-based PKE

Christian Majenz, Technical University of Denmark
Fabrizio Sisinni, Technical University of Denmark
Abstract

Recently, Hövelmanns, Hülsing, and Majenz introduced a security notion called Find Failing Plaintext – Non Generic (FFP-NG), which captures the ability of an adversary to find decryption failures by making non-trivial use of the public key. A first analysis of this property for lattice-based schemes was presented by Majenz and Sisinni, who showed that the Learning With Errors (LWE) problem reduces to breaking the FFP-NG security of the PVW scheme with discrete Gaussian noise. In this work, we generalize their result by analysing the FFP-NG security of widely used schemes based on Ring-LWE and Module-LWE. To keep our analysis as general as possible, we consider a family of subgaussian distributions that includes, among others, discrete Gaussians and centered binomials.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
LWEML-KEMFFP-NGsubgaussian
Contact author(s)
chmaj @ dtu dk
fasi @ dtu dk
History
2025-10-30: approved
2025-10-25: received
See all versions
Short URL
https://ia.cr/2025/1997
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1997,
      author = {Christian Majenz and Fabrizio Sisinni},
      title = {Provable decryption failure security for practical lattice-based {PKE}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1997},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1997}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.