Events Add an event Speakers Talks Collections
 
Crypto 2020
August 20, 2021, Online, USA
Crypto 2020
Request Q&A
Crypto 2020
From the conference
Crypto 2020
Request Q&A
Video
s-124: Lattices and Related Problems
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Add to favorites
266
I like 0
I dislike 0
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
  • Description
  • Transcript
  • Discussion

About the talk

About speaker

Weiqiang Wen
Cryptanalyst
Share

Okay, feel free to start whenever. Welcome to the session of lattice's and related problems. In the first talk will be on faster. Numeration, based out of production. In time to take the cable rate, the papers by Marshall. Don't think you're going to a wedding for the introduction. So, how about a new fast? OU Motel. So I compared to the power 10. Same type, we can reach the send Corey teen. Why would a small time complexity Tampico? And when the time is now we can

prove this improvement improvement over inaccurate and next to get a few notation. So, so flustered. As you can see, the Penguins me back to have moms are closer to each other than before I will call you g mean on Tinder later and buy the car is here, but they see if one, can you do? So call me back and also the inspector and he knows he has to hand in practice by Emily interested in the beach. And the beat a jaguar and the ink machine base. 101 can consider the best with the three process mode of

you on fire. And in this rock, I will make the southeast portion of single connector the time complexity requires tomorrow. So, it's Caitlin. Our idea is to stand from an SUV Surah of smaller sizes. And you know ti-30xa ship. Can you order me cigarettes? So you start tomorrow so far is it to run after you stop a caesar salad? And caught the country katwe. And this post out together introduced a new summer of the new Sorel is Rock Lee's wife and family and I can prove that's a station for approaching outside.

So this required to be roughly at. This is not responsible for keeping your sister or assistant. My goodness candidate. Where is required. Okay. So, instead of running International with the trade originally proposed, a practical Baron and now the interchange on also, the last block, where we assumed to be educated, and they also did you send for the religion and the 75%, which has the lowest cost at 11 p.m. A simulation. You can see It'll seem right. The cost of the Petco guy runs did well with the cage, which one? And the culture

shaped like rock music to buy the Petticoat. It's good as the one stand up and share can see, that's the best line here even below want to wake up. So just, you know, the cost of an reconsider. And you also leave the Sarah correction for future work and I will call them here so far. Is it to remove this here is because I'm trying to use in our end of the season. And second is to extend our spacing on stb cater to other registry that cantankerous. And further. If you can see the other people

searching for free because can be below or so. Is it possible to have the oral Carter still be below. These kids? We can't wait. Am I missing this encouraging? And last is about the cat water. Evans office work? So in this work, we only have a situation analysis, sport is more time, efficient. So it will be very interesting to have a form for this reason. And then you'll be interesting to study the new crossover point between a new base and see Paisley, a letter to addiction.

And this computer, thank you for the tension equation. Text very much. Are there any questions Michael so far? I don't see any. You don't want to. Okay, so we can get the next speaker to start preparing the toxic own. But if anyone has any questions about this, we can Circle back at the end of the session. I think no ask the question. What's special about hate? Yeso y, a to the k / 8. Like what? Where does it come from? Play tongue. I didn't open the Minecraft story.

Last broker will be completely over this because Is this the best? Okay, we can Richard. English video spaces. This original, you can be even better than the way that you've been through something like this. Thank you. Okay, so we can move on to the second Talk of the session. So this one is on random, sulfur disability of Ideal svpb, Iraq of the random, walks by, and Alex going to marry and Benjamin wrestler. Go ahead,. Thank you for the introduction for him. Wanting. Could you, maybe raise your volume cause I can. So if you're going to ask questions at

public can tell you if it's your fault. Okay, so high, I'm going to blow this joint work with Alice play Maria about a worst-case to Everett skate with Dakshin or they have meat, that's creepy. Problem on audio lattices and we do this by considering the space, all audio latisys over fixed number field that is called the arcade of class group. I'm okay, and we travel from a worst-case to Annapolis case, lattice or lattice by means of a random walk on this, Raquel of

Costco on this space, of all audio lattices. Okay. So, you know, how early should we consider that have meat? A strip, a problem problem, that actually just yes, people and bacteria can lay the store the tractor with the phone volume, then with the shortest factor of that lad has, so and we are stream for Simplicity that. H a d like to switch over half volume one. We just reschedule them so that they have Volume One. Ok, and I will actually be applied to any number field but it is particularly nice for the stomach and a circle tonic field. In that

case, it it reads as follows. So if you can solve the EP of a random audio lattices You can also solve, Prime have any idea of the rank. How does it relate to previous work about Westgate to Africa to Jackson? Is already be done by country that we improve on this result in many ways. And important thing. I would like to stay this that actually already used in the recent state that like, hey, this is an avocado cost of combination of unit club and Costco or back to the stress, the importance of the arcade of Costco.

And the last point is what I want to chase. That we post something about. About the random walk, the end of the random walk should give you a uniform distribution. And the way we proved that is actually supposed to see a single cell production of the logo with a problem on elliptic curves. So, let's go to the actual in the full video. I actually, I explained that it's paid for by a circle or well, buy a torch, but in, in two Dimensions, which is activity a circle.

And I'm moving on this circle to this truck was the arcade of class, go to space, moving on, the circle, facts on the largest ocean. But if you want to reduce, if you want to use like the S could be on a guy's life is too short for SVP on the west coast, it won't work because the geometry of the extra people in them is also changed. So Disturbed. As you can see, the circle is, is an ellipse right now. So this is not. We should also have another way of random working and that's not

by just to let you know by moving continuously What It Is by specifications, just taking an ideal shape lattice. So you remove points You remove points from the lattice just that the remaining points. Also form a Nadia l. I d like to search with fixed for him. So he asked to scale the ideal life is, so that's a test, like the volume one. And imma try to to apply as could be with try to do an SP Oracle. But better to use this shortest tractor for the origin over Skies lettuce, we need to to scale back to also here. We have a sort of

operation of this sort of attack, the problem of fear. It's just a scaling, nice are Disturbed now, it's bad. If you, if you apply this those two ways of special case, those two guys and walking, if you combine those then you hope that the Fallen happened. So you have actually the specifications state champs. Those are qualities randomly. Discrete jumps to also have the way the continuous the blurring idea. So you hope that if you have enough points, you have enough blowing that you read something that that that is close to uniform on on the circle or on the toilet on the arcade of

classical space of all, I would like to see that. The ant point, the endpoint of the animal is actually uniform and the intervention is that it actually is because of this picture. Well, I think that's wrong. Thank you for your attention. And if you have questions, I would like to answer them with all pleasure. Thank you, very much,. So there's no questions of right now. They're so short discussion. We just talk but people have pointed out that they read like your your visualization of the message going on. So

I wanted to also say that it's Thanks. Thank you very much. 69. Income tax. Yeah, go ahead discussion of the previous. Talk to you when I do it now, or Maybe stuck back at the end. So you guys can see my slides and they're like in presentation mode. That's annoying. Now, it looks good. Presentation mode, I sent you. Okay, good. Now. Look up. Okay. So the next talk and no one's getting the next to Tops and he asked us to flip them around cuz one seems to depend on the other event. That's okay. So

this talk is going to be a slight reduction Revisited filling the gaps in sap approximation by division. And Jen when I leave on Grand and I think the team and also, I just want to thank Danielle and Tom, for organizing a really excellent conference to you today about a joint work with the best. John Wayne song about slide reduction. If you don't talk to me, so let me start out with the basics on me. Just tell you what a lot of things. So, a lot of factors in 10 dimensional space. Looks like this in two dimensions.

It's best. If I buy a basis, B ones are Beyond of linearly independent vectors figures a basis for this lattice. And the lattice itself is the set of all integer, linear combinations of the basis vectors. We all know this, but I'm getting used to my notation. And of course, like sort of one of the fundamental geometric properties that we care about on the lattice is, is this land of one quantity. So this is the length of the shortest nonzero in the computational problem that I'm interested in this SVP. So I want to find a short

in the first and exact problem so much. I'm more interested in the approximate problem. So I'm the one will will accept silver. Gampel offer. Gammy was about 2 or something that this point will be fine. And of course, has promised a hard. I'm not going to show you a polynomial time at this. Problem is that is interesting for ridiculous range of a proclamation from 12, to the end for crypto were typically interested in in Italian. I'm going to talk about. Algorithms are better than others are the best-known but they're only the best known.

If you want to prove their correctness. Approximate SVP is actually kind of funny on what we do is we reduce approximate Step2 itself, but in lower Dimensions, so we are reduced and dimensions to Grandma. S d. I c p NK Dimensions, where pay is less than. And that's what makes So you'll probably know the hell out of them. LOL is a special case of cables to a prayer. All gamma rays are usually what happens with relatively small. So K is called the block size, is what happens with relatively small block size. What you can see here is the

running time or the Consul in the exponent of the running time. And the x-axis is the log base, 10 of the approximation Factor. So you can see a dysfunction is essentially gamma to the Andover Cay with these weird jumps from around and around an issue. And I've drunk two lines here. Because they're sort of two different depending on which SBP Oracle you plug in and you get different results. So the formal, the formal result that was written down. As far as I know, only had

registered has a cat video. We made this formal in our paper. So now it's written down. But more importantly an issue with this is that there are jobs, which is quite obvious. Traits of this is like a piecewise function because of this rounding and I need Trump's happen because the block size Kay has to divide. The dimension had another issue is that there was nothing non-trivial known for less than or equal to a less than or equal. To as far as we know, the problem is just as far as we knew, the problem was just as hard as the exact prob.

Approximate. This is kind of a bummer cuz, like, photography, really cares about this regime, we care about like small polynomial factors. So are we need to graph look like this? That's what we did. So in particular, is there are no jump anymore so we can handle any block size. Are they block site doesn't need to divide and we got the exact same process works in the regime where there are sort of fewer than two blocks on the Block sizes larger than an over 20 minutes. Let us get non-trivial results below an

end to the end and this seems kind of natural cuz there's a real sort of natural barrier that comes with square, root in which is, which is the best that we can do at Sky. because the gas prices, because we have So let me just show you in pictures. How are algorithm works. I'm not going to explain what these pictures mean, but you can pretend your face has a triangular and you can break your base blocks side reduction breaks your bases up into two different kinds of black blue and red. That

are that are represented here. There. It's lighted thing we did this. So we added a green and orange block to the front and I are green and orange blocks, rhs thing to the first block. Would you make a little bit bigger to account for the fact that we have some sort of extra Dimensions? Because Katie doesn't divide that, that's what we do for small block size, for very large, block size. We do something else. So that's that's what I want to say. Thank you. Thank you, Noah, I guess you can get your next slides, ready.

Oh again so far no questions yet. I maybe maybe I have one. So you mention says that this with the -1 things like minor at First Sight, but you mentioned that, you know, that corresponds to a point in the fact that we really care about in crypto. Does this work have any like vacation or purely for understanding or I mean, yeah, so only has direct application for crypto. If you require your adversary to prove. If everything doesn't have to prove that his algorithm work, you can just throw in bkz

Shira Stickley sheaves roughly the same Proclamation. I know, but I mean, part of that, just because it's not implemented, right? It's it's possible that actually performs, I guess you guys has been performing. Not too bad. I'm not as bad as was expected. I remember if I am getting a better understanding. I guess. My thought is just like one understand. I got. Okay, thanks. So here's no. Again, giving a talk on lattice reduction for models or how to reduce modulus weepy to modulus.

BP. Don't work with how many can look at you. Yeah, so as we can decide this is, this is trying to work. With,, she told nobody finds our title to be funny anyway, so I'm going to repeat what I did in the last. I'm going to do some minor changes, which I hope you'll start a big nor. But a lioness is the integer span of finally many vectors rational actors in. It's the integers fans or some integer X Y 1 + of integer X. And again, like the sort of geometric properties that were interested in is the length of the shortest vector or the

short doctors in the latter. Again, were interested in solving us but not interested in solving SVP, a very specific Pacific lines of latitude with a rather dense definition to the formal definition of modulus emerges with polynomial. You take a ring or order, which is a ring of integers of of your number field. And then this is the arm span of finally many factors. In case. So before we had the Z's fan of rational vectors, now, we have czars fan of doctors that live over this number field and Bellefontaine dimensional Vector space over

Q. So if we've UK has acute and yes, I'm embedding. This is actually a lot has closed under addition, which is all you need. Which is fine. And the number K, which is sort of the dimension of this. Number. Feel like I'm lying slightly here is, is the rank of the module and ask her about the formal definition of definition. Have some linear symmetries so you can apply oil in your back and the set of symmetry is exactly. This ring are fortunate. This definition has a lot of problems. That's how you stink of it. They're just started very pretty lattices

that are closed under a particular scent, module, Addison's, our license we can ask about solving sdp on them. So we can Define gamma module a TV as a problem. And of course, like this only makes sense. If you like specify which ring or you're talkin about him with your wedding. And there's all this mess. Why does crypto that use during practices devices to solve gamma Model? S T P? If you want to break all remaining candidates for the When is competition modular CPS and

observe with their ranking module is he is an instance of gam ask if he mentions that's just because this is the way we normally would, which is to reduce it to a lower dimensional problem. Like And if we could do significantly better than this, then a lot of crypto will be broken and practice module. Oh and asterisk year, which is like hiding a tremendous amount and read the paper in the vacation is there in 2 to learn the car? So that's scary as we think it is.

And you might previously have conjectured that. It's just as hard to solve SVP on modules, as it is to solve it and has a generic classes, but that's actually not true. In the rank. 1. Modules are called ideals and there is now a long line of work. But recent work showing that there are faster algorithms for ideal. Spp with even more asterisk. And this just doesn't directly bake crypto because for crypto actually care about higher-ranked modules. It also doesn't break it for other reasons, which is why there are many asterisk. But morally there's sort of this boundary. If we want to break

crypto. We need to go from rank 1 to the higher rank. A severe some sort of natural approach to try to solve module, s t p. Instead of reducing module Step2 itself. So why don't you do some model smt with rent a, it's a model smt with rank data for a Betta lesson K. And this would be something like that. And of course, this this diagram sort of commune. So this would be like a strict Improvement. If we could do this, at least, if all the number for the same. And of course if we could use it for bait equals one, we more or less break a lot of crypto

up too many asterisks and in recent beautiful werkley pellet Mary Stella and showed that this does work for beta equals two and b equals one brake brakes crypto. They pulled off her baby equals to leave you in a little bit of food stamps. I can say all, what are we going to do? Are we going to get the answers? We get beta greater than or equal to 20, show that you can serve trade-off ranking, if you want. As long as you stay above rank one, you can think of this is

our work as sort of generalizing l. L p. S w in the same way that generates generalized, LOL. So this is the current picture. And the moral is that a module STP Oracle is just as good as a nasty Oracle for solving Model. S, u p. And of course, the big question here is, does this mean? So there two ways to interpret a reduction. I think of this as meaning, that high rank model SUV, is that low rank model? Smt is hard 4 beta greater than one. In particular, is a huge gap between

I thinks I think I want. Thank you. Noah. Are there any questions you put a lot of asterisks? Will you put almost in Forever? Is it is it looks pretty stronger than the atomy. How almost is a small panel meal Factor Wilfork Ramen, natural parameters. Use a small town back there and Polynomial in the rank of polynomial. In the dimension, in the dimension like square root on the a I can't question to come up until it by Rohit, Saturday. And I'm going to cite this. Can you briefly, explain the

reductions dependent dependent on the underlying ring? Yeah, so we worked really really hard to actually just updated the paper. Said it works for the geometry of the Ring, affects the approximation factor, and I think sort of the the high order effect of the geometry of the ring is, so it's like well known that murkowski's. The arm is the factor square root in, for example, and cycle atomics. And that factor of square root name for this. Not thinking of it right now,

but how loose make house keys near me? So if you take like a really really wonky ring, then look at it. And another question by the same technique. Also imply something non-trivial, if translated, to the letter setting. So I think the answer is yes, so you can think of what we're doing as started instead of working with the vectors. We work, with sub lattices and, you know, we work really hard to make the sub Linus's modules. But if you don't care about that, I

think it's still make sense to think about a more general form of lattice reduction in which instead of looking for short vectors. You're looking for dentist of lattice's. I think this is this is what the questions getting at and I think our techniques just started immediately work for that. I'm not kind of mentioned that paper, but I'm not sure. Maybe I can answer the question. I got to, we have time for more questions, spring. Do the word assumption in the number field.

Owawa work with a case of our. And if you do that and if you do that properly. Okay. and then, There's another question by Daniel, that look until you show up in the spirit of. Is there an interesting way to define a reasonable form of noodle Ellerbe that somehow in between rank 1 and rank to where you could get lunch with a text meaning? A text that look more like the rank wanted to extend the range hood plus a text. I mean, I think that falls into the general category of trying

to figure out how to Port these ideal ICP algorithms to Model S, E T for rank to which like we're all kind of thinking about it at least a little bit if I had no idea there, I'd be very happy or sad. I got cool. I think this covers. Oh, yeah. Can you set my screen? I don't know. They can see you. Maybe Walter my setting up Noah. What is the Singapore? Leo? What is the CM assumption? Complex multiplication. Yeah, it's it's it's that the number feel it is a compass. Multiplication field.

So, what's what's, what's going on, but not for them. So, like cube root of 2. So she wax mod x q, -2 is not right. Okay, to be there all real. No. No. Thanks. Okay, I think so. I already know everything on Fast production of algebra classes and her mom will give the talk. So yeah, just I'm not proof that you received the results on the reduction of and Rebecca and as a difference, which just wish we were having Services results relying on, you can get your records unconditional

employment in Comanche. So, yeah, so just very quickly because like everyone has done them just before So we called is a toll SEC. So, just be so rude, before you get in space, and it's rank, which is endowed with some, in a product on the engine specs and body of a song of a short note of the dimension, close to the normal high school. Okay. So this kind of tropical rayz, a heart problem, and we're only interested in this set of a strawberry. Turn off prescription and basic building blocks of

any algorithm in algebraic number Theory because it has some out, you control the size of your demands. And now we're getting interested, more and more into a broader class of a legend. And we can realize this this extension cord in a quotient of 2x over over some interesting ring, which is the ring of integers, which is the set of elements which vanished under a reaction of some money, putting them in the act. So over two weeks and you could think of some of those is ring of protection of

80, as I said, we could sort of lettuce is a 3D module with Sammy. And Alexis is to say that another break,, no product on Jim Justice. Okay, so you can find some way of defining, get your things and be sure and other experts will translate metrically into symmetries. I know why we do not use for their son's. I asked you to set up a bit of context of the Sentra brake and like And we would like to reuse them. If a cyst on your trip to Africa. They could just wait. I get to security of this. So I will be to find a way to

church to give Buster Atalanta prediction is that suitable fields of study and we show that we could explore this regressive strategy, which is that will disable use as a single phase to do blood work, and some bunk of the unit group and use them in a specific way to control the size of the elements with your children's are somehow related to the condition number of the Chris is appearing during competition. So if you are able to use any group to control the side of the country member of the mattresses use it,

so just to show you how they are ready. Shane is working on a very high-level if she wants to reduce a wrong and you will do basically the same as you were doing. So well. I don't remember ever seeing him to try to get on mattresses bikes, rather composition and then you will see that to your size reduction, some procedures, which is a simple procedure used to shrink that they do not touch things. You're older. And this is where we need and it's just working condition twice because we're watching his mother.

Who predicted substances? So if we're working over Q example, receive basically we can just use Dallas cigar. And what we're going to do is send these wrongs to let you choose something, Justin Bieber where the Icarus is the rank of the new sublet of the eulogies bigger, but then we can reach the word prostitute. And once a resume say, okay, my run to sublet, it should reduce. What I need to do is to lift. The result is your personal and this is not in the same generation

as generalized to work in numbers. Okay, and we can eat and all of this can be using some additional structure, which comes from Zar simplistic, symmetries that we can construct a just say what is that as an aristocrat? Because they're relying on some music on the size of German Zeppelin everywhere signs of self-defense, perler bead ring the size of the size of the info. So you gay So, it's way faster, but it's a bigger. And they said that you could do this is kind of a General Session of the World Cup for Garmin in Glen in 06. So

basically results if you take a wrong, so that means that you have some action of the same picture on it and pictures of Thrones two swords. Are you can find a natural way and we can way of having additional signatures. What we proved is that we can do that at each of the recursive level, so we can trade symplectic symmetries at each of the three of the notes of the temperature. In time at north of the richest, country in the world, in the dimension. You can get to put them. So

if you look at the improved from visiting the schedule, for example of a week and we can be so we can do. So we can fight, we can reduce electricity in Time, Square minus or eat or something, which depends on which is slightly worse than before. And in practice tonight, let you see him for days where our submission for state of job would be for forty thousand years and we were able to rent for the first time in 1024, in 100 hours where I chatted with extenders. Search for Christian, please. Don't ask me. We were happy to answer.

He was asking if you can set up your your slides while arresting questions, so we can have more time questions for you as well. Are you all ready for the questions? I was asking if you know, not to answer because it's whatever is a book Mission factor, which turn on Yoshi's with paper. so, I can't wait to see if you can do stuff before weiwei. Okay. Thanks. The next session is Rowdy by. Thank you. And as you're done one, and the shutdown will give the tuck.

Okay. Alright, so he'll are 100 on our talk about rugby injuries. This is joy and just work. Okay, so let me with the star with the definition of learning was wrong over when is a, which was the first leap proposal by Banner, to Pike & Rose in Internet. Hell, if I know he's probably just pick you and is having a problem in 25 secret secret as from giving somebody a sap. Where is an abacus to the wrong of a x s. T p and Q is the finest around a few times. That amount of heat. Okay. So the decision

problem is to distinguish she'd of hell of a view from unicorn you and a Publications such as well. Strap the functions and more. So it is important to determine the hardness of this problem. I summarize the prior harness results of any other player in the ringer by the following figures or more precisely. We consider the case of this problems in two cases. We just you properly modulus in the rispoli modulus. Fall planner for playing the harness results are more, dates. However, in the ring said, results are limited besides a basic reduction.

I'll bring the other week from power. We also show options of which Super Pollo Mario's by the workout p p o r t o n. We can also show a reduction from searching out of you to search anything up there by the work of Bountiful Gomez Leah Richardson and Wilson in 2016. Are there any Honda or we don't know the other enemies of ring Abra, who is Polly Madras? On the other hand, the harness of a ring of brawl Mojo, a table with leaky secret is to be determined and the weaker security,.

So it is important to determine the highest result of a ring-tailed lemur. In our world exactly, answer. You questions. So let me just stayed all results. Are we first introduced a new framework of our friend? We consider around him procedure. Romney according business, which is more flexible than Original London, recording koi fish in your body. We also Define framework. I'll call the last day of their, which is inspired by the fire and Penny in 2019. And I didn't come past is very sad breakup, ring up the Order of Police Mojo, album and more and shoes

harness. I'll bring already employs hundreds of others. So from this weekend folks, on the horns of ring out where I don't, we show a reduction from search to decision really bad with the Holy mother's assigning. You a show that we should? Zohar is a ring and the Mojo after I'm done. Looking for another job. We proposed under certainly nearer to the Emoji. I wish you a reduction from decision tree have to be to decision. Mojo ring out the back even really

cheap. Okay, that's how are you? I just saw me texting. So let me sketch does to the render me. So I'll bring out the route. The target is to show the relaxing from search bring about to decision. And high-level fighting the secret as is equal in a two fighting coefficients of ass under a basis of similar to that of wishes to their enemies of a ring at the beach. And all relaxing pass you that that follows us that when she was in search ring other bright are the immediate. And search

problem. Also hard is the prime idea. And the step to buy shoes are relaxing for a another route. You and me the worstest, you seem problem. I buy in the Steph Curry shoes. The reduction from to stop by to die. Out of his problem is he's your ring at their step two and three are similar to him. Somehow, we strongly suspect two other so-called. I love my new car basis. When we need the widely used as power of 2, Rick is with no longer are we can secure device running procedure to achieve this? Anyway, also remarked on YouTube. So provide some insight for comments for

choosing basis. So, it is very interesting to determine more pieces, satisfying, or requirements of a motor out of a secretor. We generally work off to the recession, which shoes are reduction for playing at the bar with leakage a similar to a cave. We can defy the law system in the competition distinguish, if you'll step on each others nerves, What is the member has a low arrendador for General ring of integers? Hey, we finally get rid of this Berry by showing or another exam. I hear the statement of our lamb is a little

from our limo. We know that the four Jello ring of Engineers. Just so you know who our enemies are in a bungalow by baps no pass gym. B u b s. I d o r. I g. I d affect her work. You can be smarter. Thank you. Are there any questions? Where is a few? So, About time you think that some of the earlier questions are worth going back to 21 by Yang, Yu asking to search the way you are and which Q is not a multiple of P. Yes, exactly. Okay, that's it should be straightforward. Rachel

players such as p and Q both powers of 2. Tiene que be powerful to have to. We can also, do you find the wrong thing? We do not know if we consider these the power of a Hog BBQ in Low, Places by The Weeknd weekend, Define the wrong year to This Kiss. We need some tricky. We, we, we need to Define surrounded with respect to the absolute value. Any more questions and clerk's office to head over to do that. And if they want to do for the other question, on the first target has been addressed envelope. I want to see office. So I think be Can go today.

Thanks everybody that he's another session.

Cackle comments for the website

Buy this talk

Access to the talk “s-124: Lattices and Related Problems”
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free

Ticket

Get access to all videos “Crypto 2020”
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Ticket

Interested in topic “Cryptocurrency”?

You might be interested in videos from this event

September 15 - 17, 2021
Denver, CO
16
61.1 K
dao , governance, investing, nft, token

Similar talks

Matthew Jagielski
Google at Northeastern University
+ 1 speaker
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Omri Shmueli
Tel Aviv University
+ 1 speaker
Zvika Brakerski
Weizmann Institute of Science
+ 1 speaker
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Mohammad Mahmoody
associate professor in the Computer Science Department at University of Virginia (UVA)
+ 1 speaker
Kay McKelly
Freelance Software Developer & Virtual Event Organizer at The International Association for Cryptologic Research (IACR)
+ 1 speaker
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free

Buy this video

Video
Access to the talk “s-124: Lattices and Related Problems”
Available
In cart
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free
Free

Conference Cast

With ConferenceCast.tv, you get access to our library of the world's best conference talks.

Conference Cast
904 conferences
36106 speakers
13698 hours of content