paper

Module Lattice Security (Part II): Module Lattice Reduction via Optimal Sign Selection

arXiv:2604.22900

Abstract

We extend the CDPR's quantum attack from ideal lattices to module lattices over -th cyclotomic rings. Using trace orthogonality of the power basis, we decompose a rank- module into mutually orthogonal rank- submodules, and apply CDPR's analysis to each independently and return the shortest candidate. The Hermite factor matches the ideal case, with a module reduction factor independent of the rank, under a balance hypothesis (proved for Gaussian distribution) automatic for MLWE-distributed bases. To enable a bounded-precision implementation, we replace coordinate-wise rounding with Chinese Remainder Theorem-scaled rounding at totally split primes, reducing the Gram-Schmidt rounding radius from to at cost . Finally, we reformulate the CDPR's sign-selection step as a mixed-integer linear program and prove its optimum is no more than 1/2 for all ( for all tested , conjecturally universal). This replaces the previous heuristic discrepancy . All results build on the class number condition established in Part I of this series.

30 pages, add new results and proofs of previous simulations and examples. The key change is alpha_d=sqrt C which is changed into 1.3346.This does not affect all the polynomical algorithms in Part IV. For simulation video see the comment of Part IV in this series

Module Lattice Security (Part II): Module Lattice Reduction via Optimal Sign Selection · wovepaper