paper

Module Lattice Security (Part III): Structured CVP Distance on the Log-Unit Lattice

arXiv:2605.17404

Abstract

We prove that the CVP distance from a random short ring element to the log-unit lattice of $\Q(ζ_{2^k})$ converges to as . We then show that this target lies inside the Voronoi cell of the origin for . For the norm, the maximum over sub-Gaussian coordinates yields which translates into a sub-polynomial approximation factor for the Short Generator Problem. We show a Coarse Lattice Theorem that Babai's algorithm returns zero for all structured targets, yet exactly recovers unit perturbations of arbitrary size. For module determinant ideals, we further prove the Trigamma Theorem that proves an intrinsic imbalance independent of the modulus . Finally, combined with Parts I and II, we reduce the CDPR factor for ML-KEM from $\exp(\tO(\sqrt{n}))$ to a sub-polynomial value.

26 pages (simplied version). Most important part in this series

Module Lattice Security (Part III): Structured CVP Distance on the Log-Unit Lattice · wovepaper