Paper 2026/1022

Thorns in Polynomial Convolution: Correlation, Large Deviations, and Applications

Dongshu Cai, Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Yijian Liu, Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Jiabo Wang, Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Xianhui Lu, Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Abstract

When estimating the decryption failure rate (DFR) of structured lattice-based cryptography, some schemes implicitly assume that the coefficients of the decryption noise are independent. In practice, however, the decryption noise typically contains terms arising from convolutions of small polynomials, which introduce correlations among coefficients. These correlations can create a non-negligible gap between independence-based estimates and empirical failure rates, leading to underestimated DFRs, overestimated security levels, and exploitable attack surfaces. They also obscure the effect of error-correcting mechanisms in structured lattice-based encryption designs. To date, there has been no practical framework for characterizing such correlations. In this paper, we give the first systematic characterization of correlations among the coefficients of convolved polynomials with Gaussian coefficients, using the canonical embedding as the central viewpoint. We establish large-deviation results for the coefficients of the resulting polynomial. Our analysis shows that, as the norm grows, convolutional polynomials asymptotically concentrate near a finite set of fixed two-dimensional planes. This gives rise to directional tail structures in the n-dimensional joint probability density, which we call thorns. As a direct application, we prove that existing decryption-failure attacks succeed precisely by forcing the noise to lie on these thorns. This phenomenon endows the noise with extremely strong correlations, ultimately triggering decryption failures. Furthermore, adopting the canonical embedding perspective allows us to comprehensively illustrate how the independence assumption distorts the true noise distribution. We prove that the independence assumption systematically underestimates the noise norm, and we derive an analytic expression for the probability density function of the Euclidean norm of the decryption noise.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Decryption failure rateConvolutionCanonical embedding
Contact author(s)
caidongshu @ iie ac cn
liuyijian @ iie ac cn
wangjiabo @ iie ac cn
luxianhui @ iie ac cn
History
2026-07-19: revised
2026-05-21: received
See all versions
Short URL
https://ia.cr/2026/1022
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1022,
      author = {Dongshu Cai and Yijian Liu and Jiabo Wang and Xianhui Lu},
      title = {Thorns in Polynomial Convolution: Correlation, Large Deviations, and Applications},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1022},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1022}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.