Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge in post-quantum cryptography that the Extended Dihedral Coset Problem (EDCP) lacks a hidden subgroup structure, rendering existing techniques inapplicable. To overcome this, it proposes the Cyclic Cyclotomic Coset Problem (CCP). Methodologically, this work introduces CCP for the first time to preserve an exact hidden subgroup structure, generalizing the binary-power EDCP sieving method of Bai et al. to cyclic cyclotomic fields. Furthermore, by constructing π-adic ideal chains, a quantum sieving algorithm is developed to efficiently solve CCP and uniform EDCP modulo prime powers through iterative phase-state reduction. This approach achieves quasi-polynomial time complexity with polynomial quantum space consumption, significantly improving the solving efficiency for specific Learning With Errors (LWE) variants.
📝 Abstract
The Learning With Errors (LWE) problem is a fundamental assumption in post-quantum cryptography. Regev established a quantum reduction from LWE to the Dihedral Coset Problem (DCP). Later, Brakerski et al. introduced the Extrapolated Dihedral Coset Problem (EDCP), proving its equivalence to LWE. However, unlike DCP, EDCP no longer admits a coset structure. This limits the direct application of techniques for hidden subgroup problems. In this work, we introduce the Cyclotomic Coset Problem (CCP), a cyclotomic generalization of DCP that preserves an exact hidden-subgroup structure. Let $\zeta_p$ be a primitive $p$-th root of unity, let $\pi=\zeta_p-1$, and write $q=p^t$ and $L=t(p-1)$. We work over $R_q=\mathbb Z_q[\zeta_p] \cong \mathbb Z[\zeta_p]/(\pi^L)$, where the isomorphism follows from the total ramification identity $(p)=(\pi)^{p-1}$. We exploit the resulting $\pi$-adic ideal chain to construct a quantum sieve that successively reduces phase states modulo $\pi^{L},\pi^{L-1},\ldots,\pi$. For every fixed prime $p$ and modulus $q=p^t$, our algorithm solves the CCP in time and sample complexity $2^{O_p(\log n\log q)}$, using polynomial quantum space. The sieve also applies to uniform EDCP and Gaussian S|LWE>, yielding quasi-polynomial time algorithms for all the above problems when $q=\text{poly}(n)$. This extends the power-of-two EDCP sieve of Bai et al. (CRYPTO 2025) to a cyclotomic setting. However, we emphasize that our result does not, by itself, yield a quasi-polynomial-time algorithm for standard LWE, because the currently known reduction produces only a limited number of approximate CCP states.
Problem

Research questions and friction points this paper is trying to address.

Learning With Errors
Extrapolated Dihedral Coset Problem
Cyclotomic Coset Problem
Hidden Subgroup Problem
Post-Quantum Cryptography
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cyclotomic Coset Problem
Hidden Subgroup Structure
Quantum Sieve Algorithm
Learning With Errors
Extrapolated Dihedral Coset Problem
🔎 Similar Papers
💼 Related Jobs
No related jobs found.