Paper 2026/1962
Compare Before Clearing: Exact Integral-Comparison Frontiers for Lattice Extraction
Abstract
Lattice extraction often produces openings normalized by challenge differences, whereas an inconsistency must ultimately yield a short integral SIS relation. Clearing each extracted branch before comparison removes every denominator obstruction carried by that branch, including factors irrelevant to the mismatch that is eventually tested. We formalize direct integral comparison for generic polynomial block systems. If block \(a\) has width \(r_a\) and the two extraction centers differ on \(J\), the minimum worst-case coefficient degree is \(\max\{\max_a r_a,\sum_{a\in J} r_a\}\). Within a branch-separated polynomial integralize-then-compare architecture, it is \(2\sum_a r_a\). The coordinate case gives \(\max\{1,h\}\) and \(2L\), where \(h=|J|\). Exact conditional resampling obtains the required partially synchronized successful executions without a reciprocal-success loss. The coordinate schedule uses at most \(2L+1\) additional retry invocations in unconditional expectation. Two cases illustrate the bounds. For Cyclo-style coordinate folding, one unsynchronized coordinate has the same certified radius as same-root synchronization. For two independently extracted Esgin-style Vandermonde stars, direct comparison has degree \(\binom{k+1}{2}\) in the anchor-universal polynomial-linear model. The degree is \(k^2\) within the stated branch-separated integralize-then-compare architecture.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Lattice extractionKnowledge extractionModule-SISVandermonde systems
- Contact author(s)
-
ee wangx24 @ gzu edu cn
shihuifu @ sdu edu cn - History
- 2026-09-14: revised
- 2026-09-10: received
- See all versions
- Short URL
- https://ia.cr/2026/1962
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1962,
author = {Xiang Wang and Shihui Fu},
title = {Compare Before Clearing: Exact Integral-Comparison Frontiers for Lattice Extraction},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1962},
year = {2026},
url = {https://eprint.iacr.org/2026/1962}
}