| Literature DB >> 32226228 |
Thijs Laarhoven1, Michele Mosca2,3,4, Joop van de Pol5.
Abstract
By applying a quantum search algorithm to various heuristic and provable sieve algorithms from the literature, we obtain improved asymptotic quantum results for solving the shortest vector problem on lattices. With quantum computers we can provably find a shortest vector in time 2 1.799 n + o ( n ) , improving upon the classical time complexities of 2 2.465 n + o ( n ) of Pujol and Stehlé and the 2 2 n + o ( n ) of Micciancio and Voulgaris, while heuristically we expect to find a shortest vector in time 2 0.268 n + o ( n ) , improving upon the classical time complexity of 2 0.298 n + o ( n ) of Laarhoven and De Weger. These quantum complexities will be an important guide for the selection of parameters for post-quantum cryptosystems based on the hardness of the shortest vector problem.Entities:
Keywords: Lattices; Quantum search; Shortest vector problem; Sieving
Year: 2015 PMID: 32226228 PMCID: PMC7089694 DOI: 10.1007/s10623-015-0067-5
Source DB: PubMed Journal: Des Codes Cryptogr ISSN: 0925-1022 Impact factor: 1.492