2

I am interested in what the state of the art results on the hardness of the Short Integer Solution (SIS) instances are. The one I am the most familiar with (and the most discussed) is to use lattice reduction, which can be ignored. I have also found the Blum-Kalai-Wasserman (BKW) algorithm, which seems to be applicable to SIS, though I have not looked too deeply into it. Apart from these, are there other attacks specifically for SIS, or that can be adapted to it, e.g., from attacks on LWE?

It seems that hardness of LWE is widely discussed, hence this question.


Related

ketsi
  • 375
  • 1
  • 13

0 Answers0