Skip to content
Preprint

Key Recovery from Residue-Confined Errors in Pradhan CRT-RLWE

Aug 2026 · 0 citations · 11 references
Computer Science

TL;DR

It is shown that the CRT-FHE scheme of Pradhan et al. is insecure for laws within its assumed error distribution range, and that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE.

Abstract

We show that the CRT-FHE scheme of Pradhan et al.\ is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage $1/2$. We further show that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE. One mechanism underlies both. The Chinese remainder theorem (CRT) function is reduced modulo $p_1p_2$ while its output is used modulo a coprime modulus $q$, so under every zero-preserving section an error in $p_2\R$ encodes to zero. The law $p_2B_1$ is so confined, meets the stated conditions, and decrypts correctly. Confinement is not a weakness of scale: scaling any baseline law by $p_2$ leaves its ordinary Ring-LWE problem exactly equivalent, while the reduced encoder destroys every error it produces. The reduction discrepancy is a multiple of $p_1p_2$ and not of $q$, so the small-error premise of the proof cannot remove it, and at the reported parameters a single error coefficient refutes the identity while satisfying that premise. The centered binomial $B_2$ separates the coefficient laws at total variation distance $3/8$, and at the reported dimension that distance between the induced polynomial laws is exponentially close to one.

View source

Similar papers

Preprint Aug 2026

CRT-Decomposed $\Sigma$-Protocols for CSIDH

We construct a zero-knowledge proof of knowledge for the CSIDH group action that exploits the Chinese Remainder Theorem (CRT) structure of the ideal class group, available whenever the group structure is known exactly, as for CSIDH-512. We prove perfect completeness, perfect special honest-verifier zero-knowledge, and...

I. Dey, I. Cherkaoui · 0 citations
Preprint Aug 2026

Full-Key Recovery and Forgery from One MQOM v2.1 Signature

We give a full-key-recovery attack on MQOM v2.1, a Round-3 candidate in the NIST additional-signature process, that recovers the complete signing key from one accepted signature and uses it to sign a fresh message. If $\delta=\operatorname{FirstBits}_{\lambda}(x)$ is the prefix of the witness $x$, the sibling path dete...

J. L. Delgado · 0 citations
Preprint Sep 2026

Stabilizer-Public-Key Authentication: Long Stabilizer Public Keys Resist Finite-Copy Forgery Attacks

We propose an information-theoretic authentication protocol based on a finite supply of long quadratic-stabilizer public-key states over an odd-prime field, where the effective key length after one signature exposure is the residual dimension $r=n-\ell$. A computationally unbounded adversary observes one valid classica...

Masahito Hayashi, Jing-Tian Zhao, Bai-Chu Yu · 0 citations
Preprint Sep 2026

Compressed Permutation Oracles Revisited

The compressed permutation oracle has been used to analyze the quantum security of a number of cryptographic constructions which resisted prior techniques. However, these analyses were fundamentally limited by the poor soundness of the method: the technique was proven sound only up to $O(N^{1/12})$ queries to permutati...

Joseph Carolan, Christian Majenz · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.