Paper 2026/1560
Dimension Reduction for SVP in Hawk: A Trace-Zero Approach
Abstract
Let $E=\mathbb Q(\zeta_m)$ be a power-of-two cyclotomic field, with maximal totally real subfield $K=\mathbb Q(\zeta_m+\zeta_m^{-1})$. In previous work, Chevignard et al. (Eurocrypt'25) gave a reduction from module-LIP for rank-two module lattices over $\mathcal O_E$ to the norm-reduced Principal Ideal Problem (nrdPIP) in a quaternion algebra. We derive two consequences of this reduction. First, we obtain a polynomial time reduction from rank-$2$ module-LIP over $\mathcal O_E$ to rank-$3$ module-LIP over $\mathcal O_K$. Note that rank-$2$ modules over $\mathcal O_E$ are naturally seen as rank-$4$ modules over $\mathcal O_K$, so this is indeed an improvement. Our second result is specific to the module $\mathcal O_E^2$, underlying the Hawk signature scheme. In this setting, we also obtain a reduction to a rank-$3$ module-LIP instance over $\mathcal O_K$, but we can additionally show that these modules have a simple geometric shape: they are isomorphic to $\mathbb Z^{m/2+1} \perp \sqrt{2}\, \mathbb Z^{m/4-1}$. We then adapt Ducas' result (ePrint'23) to this setting. Putting everything together we obtain an algorithm breaking Hawk's key recovery by making polynomially many exact-SVP calls in lattices of dimension at most $3m/8+1$. This improves upon the previous analysis from Ducas (ePrint'23) which required exact-SVP calls in lattices of dimension at most $m/2+1$.
Note: 03/08/2026: added a technical overview section in the introduction
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- HawkModule latticesLattice Isomorphism ProblemCryptanalysis
- Contact author(s)
-
guilhem mureau @ math u-bordeaux fr
alice pellet-mary @ math u-bordeaux fr - History
- 2026-08-03: revised
- 2026-07-30: received
- See all versions
- Short URL
- https://ia.cr/2026/1560
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1560,
author = {Guilhem Mureau and Alice Pellet-Mary},
title = {Dimension Reduction for {SVP} in Hawk: A Trace-Zero Approach},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1560},
year = {2026},
url = {https://eprint.iacr.org/2026/1560}
}