1 comment

Sign in to comment.

rkerr26 days ago
The bit that jumps out is the reduction to exact SVP oracles in dimension at most n/2+1, since that still leaves a pretty big gap between a clean asymptotic break and the actual lattice-reduction cost once you stop pretending the oracle is free. If the attack really just halves the BKZ block size needed, then reparameterizing upward is the sort of fix that silently drags signature size and verification cost into the bad corner pretty fast.
zknews