3

Does module-LWE remains hard for an even modulus $q$, or a power of two?

This is true for Ring-LWE (pseudorandomness) and Module-LWR (SABER).

I can't find any reference to it!

C.S.
  • 515
  • 3
  • 10

1 Answers1

1

Yes. Learning with Rounding (LWR) is a special case of LWE, where the errors are introduced deterministically by scaling and rounding operations. If you had an algorithm that could solve LWE, the same could be used to solve LWR.

Thus, Module-LWE is at least as secure as Module-LWR.

Andrea
  • 166
  • 5