Principal ideal problem and ideal shortest vector over rational primes in power-of-two cyclotomic fields

📅 2026-01-12
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study investigates the length of the shortest vector in the ideal lattice lying above a rational prime \( p \) in cyclotomic fields of conductor a power of two, with a focus on the cases \( p \equiv 7,9 \pmod{16} \). By reformulating the shortest vector problem as that of finding the shortest generator of a principal ideal, and leveraging ideal factorization, lattice embeddings, and algebraic number theory, the authors introduce a novel approach that avoids reliance on traditional lattice basis reduction. This method yields the first exact characterization of the shortest vector length for these congruence classes and establishes a tight upper bound of \( \sqrt[4]{2^{2n+1}p} \), which improves upon the classical Minkowski bound. Consequently, the shortest vector length problem is now fully resolved for all primes \( p \equiv 3,5,7,9 \pmod{16} \).

Technology Category

Application Category

📝 Abstract
The shortest vector problem (SVP) over ideal lattices is closely related to the Ring-LWE problem, which is widely used to build post-quantum cryptosystems. Power-of-two cyclotomic fields are frequently adopted to instantiate Ring-LWE. Pan et al. (EUROCRYPT~2021) explored the SVP over ideal lattices via the decomposition fields and, in particular determined the length of the shortest vector in prime ideals lying over rational primes $p\equiv3,5\pmod{8}$ in power-of-two cyclotomic fields via explicit construction of reduced lattice bases. In this work, we first provide a new method (different from analyzing lattice bases) to analyze the length of the shortest vector in prime ideals in $\mathbb{Z}[\zeta_{2^{n+1}}]$ when $p\equiv3,5\pmod{8}$. Then we precisely characterize the length of the shortest vector in the cases of $p\equiv7,9\pmod{16}$. Furthermore, we derive a new upper bound $\sqrt[4]{2^{2n+1}p}$ for this length, which is tighter than the bound $2^n\sqrt[4]{p}$ obtained from Minkowski's theorem. Our key technique is to investigate whether a generator of a principal ideal can achieve the shortest length after embedding as a vector. If this holds for the ideal, finding the shortest vector in this ideal can be reduced to finding its shortest generator.
Problem

Research questions and friction points this paper is trying to address.

Shortest Vector Problem
Ideal Lattices
Cyclotomic Fields
Principal Ideal
Ring-LWE
Innovation

Methods, ideas, or system contributions that make the work stand out.

ideal lattices
shortest vector problem
cyclotomic fields
principal ideal
post-quantum cryptography
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
G
Gaohao Cui
School of Cyber Science and Technology, Shandong University, Qingdao 266237, China. Key Laboratory of Cryptologic Technology and Information Security of Ministry of Education, Shandong University, Qingdao, 266237, China State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, 266237, China
J
Jianing Li
Research Center for Mathematics and Interdisciplinary Sciences Shandong University, Qingdao 266237, China Frontiers Science Center for Nonlinear Expectations, Ministry of Education, Qingdao 266237, China State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, 266237, China
Jincheng Zhuang
Jincheng Zhuang
Shandong University
Computational number theorycoding theorycryptography