Paper 2026/1962

Compare Before Clearing: Exact Integral-Comparison Frontiers for Lattice Extraction

Xiang Wang, Guizhou University
Shihui Fu, Shandong University
Abstract

Lattice extraction often produces openings normalized by challenge differences, whereas an inconsistency must ultimately yield a short integral SIS relation. Clearing each extracted branch before comparison removes every denominator obstruction carried by that branch, including factors irrelevant to the mismatch that is eventually tested. We formalize direct integral comparison for generic polynomial block systems. If block \(a\) has width \(r_a\) and the two extraction centers differ on \(J\), the minimum worst-case coefficient degree is \(\max\{\max_a r_a,\sum_{a\in J} r_a\}\). Within a branch-separated polynomial integralize-then-compare architecture, it is \(2\sum_a r_a\). The coordinate case gives \(\max\{1,h\}\) and \(2L\), where \(h=|J|\). Exact conditional resampling obtains the required partially synchronized successful executions without a reciprocal-success loss. The coordinate schedule uses at most \(2L+1\) additional retry invocations in unconditional expectation. Two cases illustrate the bounds. For Cyclo-style coordinate folding, one unsynchronized coordinate has the same certified radius as same-root synchronization. For two independently extracted Esgin-style Vandermonde stars, direct comparison has degree \(\binom{k+1}{2}\) in the anchor-universal polynomial-linear model. The degree is \(k^2\) within the stated branch-separated integralize-then-compare architecture.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Lattice extractionKnowledge extractionModule-SISVandermonde systems
Contact author(s)
ee wangx24 @ gzu edu cn
shihuifu @ sdu edu cn
History
2026-09-14: revised
2026-09-10: received
See all versions
Short URL
https://ia.cr/2026/1962
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1962,
      author = {Xiang Wang and Shihui Fu},
      title = {Compare Before Clearing: Exact Integral-Comparison Frontiers for Lattice Extraction},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1962},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1962}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.