Trace-based cryptanalysis of cyclotomic -PLWE for the non-split case
arXiv:2209.11962 · doi:10.46298/cm.11153
Abstract
We describe a decisional attack against a version of the PLWE problem in which the samples are taken from a certain proper subring of large dimension of the cyclotomic ring with in the case where but is not totally split over . Our attack uses the fact that the roots of over suitable extensions of have zero-trace and has overwhelming success probability as a function of the number of input samples. An implementation in Maple and some examples of our attack are also provided.
20 pages; 1 figure; Minor updates as per referee's requests; formatted for publication