In this work, we revisit the dual attack and GPV trapdoor sampling, focusing on the lattice Gaussian sampling term, which can be a significant bottleneck in the overall complexity. We show that this sampling step can be quantumly accelerated by combining the lower bound underlying Wang and Ling's analysis of Klein's algorithm with the quantum rejection sampling (QRS) framework proposed by Ozols et al. Specifically, this lower bound gives precisely the pointwise domination condition required for quantum rejection sampling when given coherent oracle access to a truncated Klein proposal distribution, which yields a quantum procedure for preparing the truncated dual $q$-ary lattice Gaussian with a quadratic reduction in the sampling complexity. The truncation radius is chosen so that the truncated distribution is negligibly close to the full lattice Gaussian in total variation distance. Substituting this sampler into the dual attack framework results in reduced overall attack-cost estimates. Compared with Pouly and Shen's modern dual attack under the same parameter choices, our estimates reduce the attack cost by \(9\), \(4\), and \(13\) bits for Kyber-512, Kyber-768, and Kyber-1024, respectively. We also report the corresponding estimates with modulus switching. Finally, by replacing the Markov chain Monte Carlo (MCMC) sampler with the QRS algorithm, we achieve a similar quadratic speedup in the GPV signing process.
翻译:本文重新审视了双重攻击和GPV陷门采样问题,重点关注格高斯采样项——该环节往往是整体复杂度的主要瓶颈。我们证明,通过将Wang和Ling对Klein算法分析中建立的下界与Ozols等人提出的量子拒绝采样框架相结合,该采样步骤可实现量子加速。具体而言,当对截断的Klein提议分布具备相干预言机访问能力时,该下界恰好满足量子拒绝采样所需的逐点支配条件,从而得到一种量子流程,能以采样复杂度的二次方缩减制备截断对偶$q$元格高斯分布。截断半径的选取使得该截断分布与完整格高斯分布的总变差距离可忽略不计。将该采样器代入双重攻击框架后,整体攻击代价估计值降低。在与Pouly和Shen现代双重攻击相同参数设定下,我们的估计显示Kyber-512、Kyber-768和Kyber-1024的攻击代价分别降低9、4和13比特。我们还报告了引入模切换后的相应估计值。最后,通过用量子拒绝采样算法替代马尔可夫链蒙特卡洛采样器,我们在GPV签名过程中实现了类似的二次方加速。