{"id":"https://openalex.org/W2007466965","doi":"https://doi.org/10.1145/1568318.1568324","title":"On lattices, learning with errors, random linear codes, and cryptography","display_name":"On lattices, learning with errors, random linear codes, and cryptography","publication_year":2009,"publication_date":"2009-09-01","ids":{"openalex":"https://openalex.org/W2007466965","doi":"https://doi.org/10.1145/1568318.1568324","mag":"2007466965"},"language":"en","primary_location":{"id":"doi:10.1145/1568318.1568324","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1568318.1568324","pdf_url":null,"source":{"id":"https://openalex.org/S118992489","display_name":"Journal of the ACM","issn_l":"0004-5411","issn":["0004-5411","1557-735X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of the ACM","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5049700941","display_name":"Oded Regev","orcid":"https://orcid.org/0000-0002-8616-3163"},"institutions":[{"id":"https://openalex.org/I16391192","display_name":"Tel Aviv University","ror":"https://ror.org/04mhzgx49","country_code":"IL","type":"education","lineage":["https://openalex.org/I16391192"]}],"countries":["IL"],"is_corresponding":true,"raw_author_name":"Oded Regev","raw_affiliation_strings":["Tel Aviv University, Tel Aviv, Israel","Tel Aviv University, Tel Aviv, Israel,"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tel Aviv University, Tel Aviv, Israel","institution_ids":["https://openalex.org/I16391192"]},{"raw_affiliation_string":"Tel Aviv University, Tel Aviv, Israel,","institution_ids":["https://openalex.org/I16391192"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5049700941"],"corresponding_institution_ids":["https://openalex.org/I16391192"],"apc_list":null,"apc_paid":null,"fwci":48.4747,"has_fulltext":false,"cited_by_count":2200,"citation_normalized_percentile":{"value":0.99891848,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"56","issue":"6","first_page":"1","last_page":"40"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10720","display_name":"Complexity and Algorithms in Graphs","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1703","display_name":"Computational Theory and Mathematics"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11130","display_name":"Coding theory and cryptography","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/learning-with-errors","display_name":"Learning with errors","score":0.8167412281036377},{"id":"https://openalex.org/keywords/lattice-problem","display_name":"Lattice problem","score":0.7556922435760498},{"id":"https://openalex.org/keywords/cryptosystem","display_name":"Cryptosystem","score":0.7174376249313354},{"id":"https://openalex.org/keywords/post-quantum-cryptography","display_name":"Post-quantum cryptography","score":0.5892944931983948},{"id":"https://openalex.org/keywords/lattice-based-cryptography","display_name":"Lattice-based cryptography","score":0.5791810154914856},{"id":"https://openalex.org/keywords/key-size","display_name":"Key size","score":0.5697411298751831},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.5645231008529663},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.48742201924324036},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.482060045003891},{"id":"https://openalex.org/keywords/public-key-cryptography","display_name":"Public-key cryptography","score":0.44498682022094727},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.4410548210144043},{"id":"https://openalex.org/keywords/discrete-mathematics","display_name":"Discrete mathematics","score":0.4299500584602356},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.428960919380188},{"id":"https://openalex.org/keywords/low-density-parity-check-code","display_name":"Low-density parity-check code","score":0.41989627480506897},{"id":"https://openalex.org/keywords/reduction","display_name":"Reduction (mathematics)","score":0.4151924252510071},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.4062674045562744},{"id":"https://openalex.org/keywords/quantum-cryptography","display_name":"Quantum cryptography","score":0.356276273727417},{"id":"https://openalex.org/keywords/quantum","display_name":"Quantum","score":0.310981810092926},{"id":"https://openalex.org/keywords/quantum-information","display_name":"Quantum information","score":0.2668335437774658},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.26262181997299194},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.09419649839401245},{"id":"https://openalex.org/keywords/quantum-mechanics","display_name":"Quantum mechanics","score":0.08123353123664856}],"concepts":[{"id":"https://openalex.org/C2779014939","wikidata":"https://www.wikidata.org/wiki/Q6510239","display_name":"Learning with errors","level":3,"score":0.8167412281036377},{"id":"https://openalex.org/C168482242","wikidata":"https://www.wikidata.org/wiki/Q6497128","display_name":"Lattice problem","level":3,"score":0.7556922435760498},{"id":"https://openalex.org/C6295992","wikidata":"https://www.wikidata.org/wiki/Q976521","display_name":"Cryptosystem","level":3,"score":0.7174376249313354},{"id":"https://openalex.org/C108277079","wikidata":"https://www.wikidata.org/wiki/Q7233576","display_name":"Post-quantum cryptography","level":4,"score":0.5892944931983948},{"id":"https://openalex.org/C137660015","wikidata":"https://www.wikidata.org/wiki/Q6497083","display_name":"Lattice-based cryptography","level":5,"score":0.5791810154914856},{"id":"https://openalex.org/C47750902","wikidata":"https://www.wikidata.org/wiki/Q1557574","display_name":"Key size","level":4,"score":0.5697411298751831},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.5645231008529663},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.48742201924324036},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.482060045003891},{"id":"https://openalex.org/C203062551","wikidata":"https://www.wikidata.org/wiki/Q201339","display_name":"Public-key cryptography","level":3,"score":0.44498682022094727},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.4410548210144043},{"id":"https://openalex.org/C118615104","wikidata":"https://www.wikidata.org/wiki/Q121416","display_name":"Discrete mathematics","level":1,"score":0.4299500584602356},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.428960919380188},{"id":"https://openalex.org/C67692717","wikidata":"https://www.wikidata.org/wiki/Q187444","display_name":"Low-density parity-check code","level":3,"score":0.41989627480506897},{"id":"https://openalex.org/C111335779","wikidata":"https://www.wikidata.org/wiki/Q3454686","display_name":"Reduction (mathematics)","level":2,"score":0.4151924252510071},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4062674045562744},{"id":"https://openalex.org/C144901912","wikidata":"https://www.wikidata.org/wiki/Q471906","display_name":"Quantum cryptography","level":4,"score":0.356276273727417},{"id":"https://openalex.org/C84114770","wikidata":"https://www.wikidata.org/wiki/Q46344","display_name":"Quantum","level":2,"score":0.310981810092926},{"id":"https://openalex.org/C169699857","wikidata":"https://www.wikidata.org/wiki/Q2122243","display_name":"Quantum information","level":3,"score":0.2668335437774658},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.26262181997299194},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.09419649839401245},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.08123353123664856},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/1568318.1568324","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1568318.1568324","pdf_url":null,"source":{"id":"https://openalex.org/S118992489","display_name":"Journal of the ACM","issn_l":"0004-5411","issn":["0004-5411","1557-735X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of the ACM","raw_type":"journal-article"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.106.5202","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.106.5202","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.tau.ac.il/~odedr/papers/qcrypto.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.215.3543","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.215.3543","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.tau.ac.il/~odedr/papers/qcrypto.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.863.6537","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.863.6537","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.au.dk/%7Estm/local-cache/regev-on-lattices.pdf","raw_type":"text"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2712623667","display_name":null,"funder_award_id":"15848","funder_id":"https://openalex.org/F4320334962","funder_display_name":"Sixth Framework Programme"},{"id":"https://openalex.org/G768557654","display_name":null,"funder_award_id":"DAAD19-03-1-0082","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"}],"funders":[{"id":"https://openalex.org/F4320334962","display_name":"Sixth Framework Programme","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W119362848","https://openalex.org/W149470655","https://openalex.org/W1485280854","https://openalex.org/W1490468194","https://openalex.org/W1499237070","https://openalex.org/W1527730705","https://openalex.org/W1536683582","https://openalex.org/W1606729219","https://openalex.org/W1624621931","https://openalex.org/W1631356911","https://openalex.org/W1678240491","https://openalex.org/W1788833175","https://openalex.org/W1856342626","https://openalex.org/W1972050218","https://openalex.org/W1989510734","https://openalex.org/W1994790157","https://openalex.org/W2001093624","https://openalex.org/W2013794527","https://openalex.org/W2024697209","https://openalex.org/W2037426925","https://openalex.org/W2038761522","https://openalex.org/W2050689197","https://openalex.org/W2051176401","https://openalex.org/W2058785578","https://openalex.org/W2061949491","https://openalex.org/W2065151783","https://openalex.org/W2072802070","https://openalex.org/W2076146713","https://openalex.org/W2077244027","https://openalex.org/W2110824700","https://openalex.org/W2111416661","https://openalex.org/W2113333997","https://openalex.org/W2119877753","https://openalex.org/W2141040012","https://openalex.org/W2142048307","https://openalex.org/W2152783950","https://openalex.org/W2167236842","https://openalex.org/W2171001107","https://openalex.org/W2181114408","https://openalex.org/W2561675875"],"related_works":["https://openalex.org/W3165155389","https://openalex.org/W4298094689","https://openalex.org/W2895855268","https://openalex.org/W2883034031","https://openalex.org/W3172324685","https://openalex.org/W3127629500","https://openalex.org/W2061949491","https://openalex.org/W2951286680","https://openalex.org/W2315723423","https://openalex.org/W2007466965"],"abstract_inverted_index":{"Our":[0,65],"main":[1,87,120],"result":[2],"is":[3,23,68,90,109,124,139,150],"a":[4,16,24,49,57,79,103,159,165,196],"reduction":[5,93],"from":[6,30,48],"worst-case":[7,129],"lattice":[8],"problems":[9,62],"such":[10],"as":[11,43],"GapSVP":[12,83,133],"and":[13,84,134,157,181],"SIVP":[14],"to":[15,35,74,215],"certain":[17],"learning":[18,21,76,116],"problem.":[19,117],"This":[20],"problem":[22,34,45,77],"natural":[25],"extension":[26],"of":[27,46,114,132,151,167,200,208],"the":[28,44,75,112,115,119,128,147,190,206,209],"\u201clearning":[29],"parity":[31],"with":[32],"error\u201d":[33],"higher":[36],"moduli.":[37],"It":[38],"can":[39,94,212],"also":[40,101,125],"be":[41,95,213],"viewed":[42],"decoding":[47],"random":[50,197],"linear":[51],"code.":[52],"This,":[53],"we":[54],"believe,":[55],"gives":[56],"strong":[58],"indication":[59],"that":[60,192],"these":[61,174],"are":[63,176],"hard.":[64],"reduction,":[66],"however,":[67],"quantum.":[69],"Hence,":[70],"an":[71],"efficient":[72,142],"solution":[73],"implies":[78],"quantum":[80,130],"algorithm":[81],"for":[82],"SIVP.":[85,135],"A":[86],"open":[88],"question":[89],"whether":[91],"this":[92],"made":[96],"classical":[97],"(i.e.,":[98],"nonquantum).":[99],"We":[100],"present":[102],"(classical)":[104],"public-key":[105],"cryptosystem":[106,138],"whose":[107],"security":[108,123],"based":[110,126],"on":[111,127],"hardness":[113,131],"By":[118],"result,":[121],"its":[122,162],"The":[136],"new":[137],"much":[140],"more":[141],"than":[143],"previous":[144,172],"lattice-based":[145],"cryptosystems:":[146],"public":[148,210],"key":[149,211],"size":[152,163,207],"\u00d5(":[153,168,177,182,202,216],"n":[154,169,178,183,203,217],"2":[155,184,204],")":[156,170,180],"encrypting":[158],"message":[160],"increases":[161],"by":[164],"factor":[166],"(in":[171],"cryptosystems":[173],"values":[175],"4":[179],"),":[185,205],"respectively).":[186],"In":[187],"fact,":[188],"under":[189],"assumption":[191],"all":[193],"parties":[194],"share":[195],"bit":[198],"string":[199],"length":[201],"reduced":[214],").":[218]},"counts_by_year":[{"year":2026,"cited_by_count":125},{"year":2025,"cited_by_count":298},{"year":2024,"cited_by_count":246},{"year":2023,"cited_by_count":238},{"year":2022,"cited_by_count":229},{"year":2021,"cited_by_count":188},{"year":2020,"cited_by_count":161},{"year":2019,"cited_by_count":136},{"year":2018,"cited_by_count":102},{"year":2017,"cited_by_count":89},{"year":2016,"cited_by_count":73},{"year":2015,"cited_by_count":80},{"year":2014,"cited_by_count":70},{"year":2013,"cited_by_count":55},{"year":2012,"cited_by_count":39}],"updated_date":"2026-06-25T08:15:23.626066","created_date":"2025-10-10T00:00:00"}
