Paper 2026/155

Module Learning With Errors and Structured Extrapolated Dihedral Cosets

Weiqiang Wen, Telecom Paris, Institut Polytechnique de Paris
Jinwei Zheng, Telecom Paris, Institut Polytechnique de Paris
Abstract

The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes. Inspired by the equivalence between LWE and Extrapolated Dihedral Cosets Problem (EDCP) in [Brakerski, Kirshanova, Stehlé and Wen, PKC 2018], we show that the MLWE problem is as hard as a variant of the EDCP, which we refer to as the structured EDCP (stEDCP). This extension from EDCP to stEDCP relies crucially on the algebraic structure of the ring underlying MLWE: the extrapolation depends not only on the noise rate, but also on the ring’s degree. In fact, an stEDCP state forms a superposition over an exponential (in ring degree) number of possibilities. Our equivalence result holds for MLWE defined over power-of-two cyclotomic rings with constant module rank, a setting of particular relevance in cryptographic applications. Moreover, we present a reduction from stEDCP to EDCP. Therefore, to analyze the quantum hardness of MLWE, it may be advantageous to study stEDCP, which might be easier than EDCP.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
Module Learning with ErrorsExtrapolated Dihedral Cosets
Contact author(s)
weiqiang wen @ telecom-paris fr
jinwei zheng @ telecom-paris fr
History
2026-02-28: revised
2026-01-30: received
See all versions
Short URL
https://ia.cr/2026/155
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/155,
      author = {Weiqiang Wen and Jinwei Zheng},
      title = {Module Learning With Errors and Structured Extrapolated Dihedral Cosets},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/155},
      year = {2026},
      url = {https://eprint.iacr.org/2026/155}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.