Comment on Polynomial-Time Quantum Algorithm Proposed for Lattice-Based Cryptography [pdf]parentComments−u1hcw9nx1moExact SVP is NP-hard, but LWE is not. Kyber/ML-KEM and Dilithium/ML-DSA) rely on approximate lattice problems, not exact ones.
Comments
Exact SVP is NP-hard, but LWE is not. Kyber/ML-KEM and Dilithium/ML-DSA) rely on approximate lattice problems, not exact ones.