Paper 2026/155

Module Learning With Errors and Structured Extrapolated Dihedral Cosets

Weiqiang Wen, Telecom Paris, Institut Polytechnique de Paris
Jinwei Zheng, Telecom Paris, Institut Polytechnique de Paris
Abstract

The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes. Inspired by the equivalence between LWE and Extrapolated Dihedral Cosets Problem (EDCP) in [Brakerski, Kirshanova, Stehlé and Wen, PKC 2018], we show that the MLWE problem is as hard as a structured variant of the EDCP, which we refer to as the Integer Polynomial Module EDCP(IP-M-EDCP). This extension from EDCP to IP-M-EDCP relies crucially on the algebraic structure of the ring underlying MLWE: the extrapolation depends not only on the noise rate, but also on the ring’s degree. In fact, an IP-M-EDCP state forms a superposition over an exponential (in ring degree) number of possibilities. Our equivalence result holds for MLWE defined over power-of-two cyclotomic rings with constant module rank, a setting of particular relevance in cryptographic applications. Moreover, we present a reduction from IP-M-EDCP to EDCP. Therefore, to analyze the quantum hardness of MLWE, it may be advantageous to study IP-M-EDCP, which might be easier than EDCP.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Module Learning with ErrorsExtrapolated Dihedral Cosets
Contact author(s)
weiqiang wen @ telecom-paris fr
jinwei zheng @ telecom-paris fr
History
2026-07-16: last of 2 revisions
2026-01-30: received
See all versions
Short URL
https://ia.cr/2026/155
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/155,
      author = {Weiqiang Wen and Jinwei Zheng},
      title = {Module Learning With Errors and Structured Extrapolated Dihedral Cosets},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/155},
      year = {2026},
      url = {https://eprint.iacr.org/2026/155}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.