Paper 2026/1734
Key Recovery from Residue-Confined Errors in the Pradhan CRT-RLWE Construction
Abstract
We show that the CRT-FHE scheme of Pradhan et al. is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage $1/2$. We further show that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE. One mechanism underlies both. The Chinese remainder theorem (CRT) function is reduced modulo $p_1p_2$ while its output is used modulo a coprime modulus $q$, so under every zero-preserving section an error in $p_2\mathcal{R}$ encodes to zero. The law $p_2B_1$ is so confined, meets the stated conditions, and decrypts correctly. Confinement is not a weakness of scale: scaling any baseline law by $p_2$ leaves its ordinary Ring-LWE problem exactly equivalent, while the reduced encoder destroys every error it produces. The reduction discrepancy is a multiple of $p_1p_2$ and not of $q$, so the small-error premise of the proof cannot remove it, and at the reported parameters a single error coefficient refutes the identity while satisfying that premise. The centered binomial $B_2$ separates the coefficient laws at total variation distance $3/8$, and at the reported dimension that distance between the induced polynomial laws is exponentially close to one.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Chinese remainder theoremring learning with errorshomomorphic encryption
- Contact author(s)
-
me @ lukaszolejnik com
bartnas @ amu edu pl - History
- 2026-08-22: approved
- 2026-08-19: received
- See all versions
- Short URL
- https://ia.cr/2026/1734
- License
-
CC BY-NC-ND
BibTeX
@misc{cryptoeprint:2026/1734,
author = {Lukasz Olejnik and Bartosz Naskrecki},
title = {Key Recovery from Residue-Confined Errors in the Pradhan {CRT}-{RLWE} Construction},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1734},
year = {2026},
url = {https://eprint.iacr.org/2026/1734}
}