On Ideal Lattices and Learning With Errors Over Rings
Summary and Conclusions I In any cyclotomic ring, Ring-LWE is pseudorandom if ideal lattice problems are (quantumly) hard in the worst case. I Ring-LWE allows for much more compact and efficient encryption schemes than standard LWE. E.g., PKE in O~(1) work per message bit. I Main open directio