---
res:
  bibo_abstract:
  - The (decisional) learning with errors problem (LWE) asks to distinguish &quot;noisy&quot;
    inner products of a secret vector with random vectors from uniform. The learning
    parities with noise problem (LPN) is the special case where the elements of the
    vectors are bits. In recent years, the LWE and LPN problems have found many applications
    in cryptography. In this paper we introduce a (seemingly) much stronger adaptive
    assumption, called &quot;subspace LWE&quot; (SLWE), where the adversary can learn
    the inner product of the secret and random vectors after they were projected into
    an adaptively and adversarially chosen subspace. We prove that, surprisingly,
    the SLWE problem mapping into subspaces of dimension d is almost as hard as LWE
    using secrets of length d (the other direction is trivial.) This result immediately
    implies that several existing cryptosystems whose security is based on the hardness
    of the LWE/LPN problems are provably secure in a much stronger sense than anticipated.
    As an illustrative example we show that the standard way of using LPN for symmetric
    CPA secure encryption is even secure against a very powerful class of related
    key attacks. @eng
  bibo_authorlist:
  - foaf_Person:
      foaf_givenName: Krzysztof Z
      foaf_name: Pietrzak, Krzysztof Z
      foaf_surname: Pietrzak
      foaf_workInfoHomepage: http://www.librecat.org/personId=3E04A7AA-F248-11E8-B48F-1D18A9856A87
    orcid: 0000-0002-9139-1654
  bibo_doi: 10.1007/978-3-642-28914-9_31
  bibo_volume: 7194
  dct_date: 2012^xs_gYear
  dct_language: eng
  dct_publisher: Springer@
  dct_title: Subspace LWE@
...
