Paper 2026/1208

Preimage sampleable function families without discrete Gaussians

Eamonn W. Postlethwaite, King's College London
Filip Trenkić, King's College London
Abstract

We construct preimage sampleable function families on $q$-ary lattices [Gentry–Peikert–Vaikuntanathan, STOC'08] for which preimage sampling reduces to sampling uniform points of unitriangular lattices from simple polytopes: affine linear transforms on the $\ell_1$ and $\ell_\infty$ balls, and a scaled intersection thereof. We build the necessary samplers by adapting an algorithm of [Kannan–Vempala, STOC'97] and improving its analysis. This sampling requires only uniform bits and affine linear transforms on the uniform distribution on $[0,1]$. The collision resistance of these families relies on the short integer solutions problem [Ajtai, STOC'96] in various $\ell_p$ norms. Considering the Lee metric as the $\ell_1$ norm in $q$-ary lattices, we answer an open question to construct such families for the Lee metric [Hörmann–van Woerden, CRYPTO'24]. We also answer an open question of [Plançon--Prest, PKC'21] by sampling from polytopes with inradius smaller by a factor almost square root in the lattice rank. We provide a generic framework for constructing preimage sampleable function families from polytopes with sufficient conditions for realising it. While our parameters are worse than prior discrete Gaussian based constructions, such distributions are challenging from a physical security perspective.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published by the IACR in CRYPTO 2026
Keywords
latticespolytopestrapdoor samplingSIS
Contact author(s)
eamonn postlethwaite @ kcl ac uk
filip trenkic @ kcl ac uk
History
2026-06-10: approved
2026-06-08: received
See all versions
Short URL
https://ia.cr/2026/1208
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1208,
      author = {Eamonn W. Postlethwaite and Filip Trenkić},
      title = {Preimage sampleable function families without discrete Gaussians},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1208},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1208}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.