Source author record

Kristin E. Lauter

Kristin E. Lauter appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

8works
3topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

8 published item(s)

preprint2015arXiv

Provably weak instances of Ring-LWE

The ring and polynomial learning with errors problems (Ring-LWE and Poly-LWE) have been proposed as hard problems to form the basis for cryptosystems, and various security reductions to hard lattice problems have been presented. So far these problems have been stated for general (number) rings but have only been closely examined for cyclotomic number rings. In this paper, we state and examine the Ring-LWE problem for general number rings and demonstrate provably weak instances of Ring-LWE. We construct an explicit family of number fields for which we have an efficient attack. We demonstrate the attack in both theory and practice, providing code and running times for the attack. The attack runs in time linear in q, where q is the modulus. Our attack is based on the attack on Poly-LWE which was presented in [Eisenträger-Hallgren-Lauter]. We extend the EHL-attack to apply to a larger class of number fields, and show how it applies to attack Ring-LWE for a heuristically large class of fields. Certain Ring-LWE instances can be transformed into Poly-LWE instances without distorting the error too much, and thus provide the first weak instances of the Ring-LWE problem. We also provide additional examples of fields which are vulnerable to our attacks on Poly-LWE, including power-of-$2$ cyclotomic fields, presented using the minimal polynomial of $ζ_{2^n} \pm 1$.

preprint2015arXiv

Ring-LWE Cryptography for the Number Theorist

In this paper, we survey the status of attacks on the ring and polynomial learning with errors problems (RLWE and PLWE). Recent work on the security of these problems [Eisenträger-Hallgren-Lauter, Elias-Lauter-Ozman-Stange] gives rise to interesting questions about number fields. We extend these attacks and survey related open problems in number theory, including spectral distortion of an algebraic number and its relationship to Mahler measure, the monogenic property for the ring of integers of a number field, and the size of elements of small order modulo q.

preprint2012arXiv

New methods for bounding the number of points on curves over finite fields

We provide new upper bounds on N_q(g), the maximum number of rational points on a smooth absolutely irreducible genus-g curve over F_q, for many values of q and g. Among other results, we find that N_4(7) = 21 and N_8(5) = 29, and we show that a genus-12 curve over F_2 having 15 rational points must have characteristic polynomial of Frobenius equal to one of three explicitly given possibilities. We also provide sharp upper bounds for the lengths of the shortest vectors in Hermitian lattices of small rank and determinant over the maximal orders of small imaginary quadratic fields of class number 1. Some of our intermediate results can be interpreted in terms of Mordell-Weil lattices of constant elliptic curves over one-dimensional function fields over finite fields. Using the Birch and Swinnerton-Dyer conjecture for such elliptic curves, we deduce lower bounds on the orders of certain Shafarevich-Tate groups.

preprint2011arXiv

A Gross-Zagier formula for quaternion algebras over totally real fields

We prove a higher dimensional generalization of Gross and Zagier's theorem on the factorization of differences of singular moduli. Their result is proved by giving a counting formula for the number of isomorphisms between elliptic curves with complex multiplication by two different imaginary quadratic fields $K$ and $K^\prime$, when the curves are reduced modulo a supersingular prime and its powers. Equivalently, the Gross-Zagier formula counts optimal embeddings of the ring of integers of an imaginary quadratic field into particular maximal orders in $B_{p, \infty}$, the definite quaternion algebra over $\QQ$ ramified only at $p$ and infinity. Our work gives an analogous counting formula for the number of simultaneous embeddings of the rings of integers of primitive CM fields into superspecial orders in definite quaternion algebras over totally real fields of strict class number 1. Our results can also be viewed as a counting formula for the number of isomorphisms modulo $\frak{p} | p$ between abelian varieties with CM by different fields. Our counting formula can also be used to determine which superspecial primes appear in the factorizations of differences of values of Siegel modular functions at CM points associated to two different CM fields, and to give a bound on those supersingular primes which can appear. In the special case of Jacobians of genus 2 curves, this provides information about the factorizations of numerators of Igusa invariants, and so is also relevant to the problem of constructing genus 2 curves for use in cryptography.

preprint2010arXiv

Genus 2 Curves with Complex Multiplication

Genus 2 curves are useful in cryptography for both discrete-log based and pairing-based systems, but a method is required to compute genus 2 curves such that the Jacobian has a given number of points. Currently, all known methods involve constructing genus 2 curves with complex multiplication via computing their three Igusa class polynomials. These polynomials have rational coefficients and require extensive computation and precision to compute. Both the computation and the complexity analysis of these algorithms can be improved by a more precise understanding of the denominators of the coefficients of the polynomials. The main goal of this paper is to give a bound on the denominators of Igusa class polynomials of genus 2 curves with CM by a primitive quartic CM field. We give an overview of Igusa's results on the moduli space of genus two curves and the method to construct genus 2 curves via their Igusa invariants. We also give a complete characterization of the reduction type of a CM abelian surface, for biquadratic, cyclic, and non-Galois quartic CM fields, and for any type of prime decomposition of the prime, including ramified primes. The methods of the proof of the main result involve studying the embedding problem of the quartic CM field into certain matrix algebras over quaternions and invoking techniques from crystalline deformation theory.

preprint2008arXiv

The elliptic curve discrete logarithm problem and equivalent hard problems for elliptic divisibility sequences

We define three hard problems in the theory of elliptic divisibility sequences (EDS Association, EDS Residue and EDS Discrete Log), each of which is solvable in sub-exponential time if and only if the elliptic curve discrete logarithm problem is solvable in sub-exponential time. We also relate the problem of EDS Association to the Tate pairing and the MOV, Frey-Rück and Shipsey EDS attacks on the elliptic curve discrete logarithm problem in the cases where these apply.

preprint2007arXiv

Improved upper bounds for the number of points on curves over finite fields

We give new arguments that improve the known upper bounds on the maximal number N_q(g) of rational points of a curve of genus g over a finite field F_q for a number of pairs (q,g). Given a pair (q,g) and an integer N, we determine the possible zeta functions of genus-g curves over F_q with N points, and then deduce properties of the curves from their zeta functions. In many cases we can show that a genus-g curve over F_q with N points must have a low-degree map to another curve over F_q, and often this is enough to give us a contradiction. In particular, we able to provide eight previously unknown values of N_q(g), namely: N_4(5) = 17, N_4(10) = 27, N_8(9) = 45, N_{16}(4) = 45, N_{128}(4) = 215, N_3(6) = 14, N_9(10) = 54, and N_{27}(4) = 64. Our arguments also allow us to give a non-computer-intensive proof of the recent result of Savitt that there are no genus-4 curves over F_8 having exactly 27 rational points. Furthermore, we show that there is an infinite sequence of q's such that for every g with 0 < g < log_2 q, the difference between the Weil-Serre bound on N_q(g) and the actual value of N_q(g) is at least g/2.