Paper 2026/1924

Decryption-Failure Rate with Multidimensional Lattice Decoders: Unified Framework, Theory Refinement, and More Accurate Evaluation

Boyue Fang, Fudan University
Songlin Li, Fudan University
Yunlei Zhao, Fudan University
Abstract

Using a multidimensional lattice block code complicates decryption-failure analysis in two distinct ways. A norm or BDD certificate need not equal the implemented message-failure event, and structured polynomial products can make the residual coordinates dependent. We record every estimate by its decoder event, residual law, tail engine, and ciphertext/key aggregation. This event-aligned framework yields finite directional bounds for arbitrary residual laws and a finite Gaussian reference calculation for the gap between a radial certificate and a polyhedral decoding cell. ML-KEM is included only as a scalar consistency check; the main analysis concerns non-scalar lattice-coded block decoders. For BW-KEM, whose deployed algorithm is a BDD for the 32-dimensional Barnes--Wall lattice $BW_{32}$, we keep the published radius event fixed. We extend its Gaussian product limit to bounded centered coefficient laws and prove joint convergence for every fixed decoder block. A noncentral chi-squared mixture then retains the terminal discrete noise exactly under the Gaussian product reference. The original Chernoff calculation has the same large-deviation exponent but may lose a polynomial prefactor. Across five measurable diagnostic points, the mixture exponent and the empirical exponent of the exact any-block BDD event differ by at most 1.116 bits; the original reference-law log probabilities lie 3.131--3.585 bits above the simulated values. For prime-degree CTRU and DTRU, we derive the adjacent coefficient covariance, prove a joint normal limit for nonadjacent coordinates of bounded-coefficient products, and introduce a parity-separated public block assignment. It removes the identified adjacent covariance from every decoder block in the second-order product model. Under the Gaussian BDD reference, the single CTRU-Prime row decreases by 137.116 bits; the single DTRU-Prime row gives a conditional, scalar-anchored decrease of 73.299 bits. Paired complete-map experiments separately quantify the certificate-to-decoder gap for CTRU and DTRU. Each numerical claim is labeled as a rigorous bound, a reference-law calculation, or a diagnostic measurement; none of the Prime reference values is presented as an exact DFR.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
decryption failure ratelattice-based cryptographycorrectness analysisE8 lattice codingevent alignment
Contact author(s)
byfang16 @ fudan edu cn
slli22 @ m fudan edu cn
ylzhao @ fudan edu cn
History
2026-09-12: approved
2026-09-08: received
See all versions
Short URL
https://ia.cr/2026/1924
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/1924,
      author = {Boyue Fang and Songlin Li and Yunlei Zhao},
      title = {Decryption-Failure Rate with Multidimensional Lattice Decoders: Unified Framework, Theory Refinement, and More Accurate Evaluation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1924},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1924}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.