<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2022.134015</article-id><article-id pub-id-type="publisher-id">JIS-120004</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Cyclic Lattices, Ideal Lattices and Bounds for the Smoothing Parameter
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Zhiyong</surname><given-names>Zheng</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Fengxia</surname><given-names>Liu</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Yunfan</surname><given-names>Lu</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Kun</surname><given-names>Tian</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Engineering Research Center of Ministry of Education for Financial Computing and Digital Engineering, Renmin University of China, Beijing, China</addr-line></aff><aff id="aff2"><addr-line>Artificial Intelligence Research Institute, Beihang University of China, Beijing, China</addr-line></aff><pub-date pub-type="epub"><day>23</day><month>08</month><year>2022</year></pub-date><volume>13</volume><issue>04</issue><fpage>272</fpage><lpage>293</lpage><history><date date-type="received"><day>10,</day>	<month>July</month>	<year>2022</year></date><date date-type="rev-recd"><day>20,</day>	<month>September</month>	<year>2022</year>	</date><date date-type="accepted"><day>23,</day>	<month>September</month>	<year>2022</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  In this article, we introduce the discrete subgroup in R
  <sup>n</sup>
  
   as preliminaries first. Then we provide some theories of cyclic lattice
  s
   and ideal lattices. By regarding the cyclic lattices and ideal lattices as the correspondences of finitely 
  generated 
  R
  -modules, we prove our main theorem, i.e. the correspondence between cyclic lattices in R<sup>n</sup>
   and finitely generated 
  R
  -modules is one
  -
  to
  -
  one. 
  Finally, we give an explicit and countable upper bound for the smoothing parameter of cyclic lattice
  s
  .
 
</p></abstract><kwd-group><kwd>Cyclic Lattice</kwd><kwd> Ideal Lattice</kwd><kwd> Finitely Generated &lt;i&gt;R&lt;/i&gt;-Module</kwd><kwd> Smoothing Parameter</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Cyclic lattices and ideal lattices were introduced by Micciancio in [<xref ref-type="bibr" rid="scirp.120004-ref1">1</xref>], Lyubashevsky and Micciancio in [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>] respectively, which play an efficient role in Ajtai’s construction of a collision-resistant Hash function (see [<xref ref-type="bibr" rid="scirp.120004-ref3">3</xref>] and [<xref ref-type="bibr" rid="scirp.120004-ref4">4</xref>]) and in Gentry’s construction of fully homomorphic encryption (see [<xref ref-type="bibr" rid="scirp.120004-ref5">5</xref>]). Let R = ℤ [ x ] / 〈 ϕ ( x ) 〉 be a quotient ring of the integer coefficients polynomials ring, Lyubashevsky and Micciancio regarded an ideal lattice as the correspondence of an ideal of R, but they don’t explain how to extend this definition to whole Euclidean space ℝ n . Many researchers have presented some results in their works about cyclic lattices and ideal lattices, however, none of them exhibit the relationship between cyclic lattices and ideal lattices.</p><p>In this paper, we regard the cyclic lattices and ideal lattices as the correspondences of finitely generated R-modules, so that we may show that ideal lattices are actually a special subclass of cyclic lattices, namely, cyclic integer lattices. In fact, there is a one-to-one correspondence between cyclic lattices in ℝ n and finitely generated R-modules (see Theorem 4.9 below). On the other hand, since R is a Noether ring, each ideal of R is a finitely generated R-module, so it is natural and reasonable to regard ideal lattices as a special subclass of cyclic lattices (see Corollary 4.11 below). It is worth noting that we use a more general rotation matrix here, so our definition and results on cyclic lattices and ideal lattices are more general forms. In application, we provide a cyclic lattice with an explicit and countable upper bound for the smoothing parameter (see Theorem 5.5 below). It is an open problem that is the shortest vector problem on cyclic lattice NP-hard (see [<xref ref-type="bibr" rid="scirp.120004-ref1">1</xref>]). Our results may be viewed as substantial progress in this direction.</p></sec><sec id="s2"><title>2. Discrete Subgroup in ℝ n</title><p>Let ℝ be the real numbers field, ℤ be the integers ring and ℝ n be Euclidean space of which is an n-dimensional linear space over ℝ with the Euclidean norm | x | given by</p><p>| x | = ( ∑ i = 1 n x i 2 ) 1 2 , where x ′ = ( x 1 , x 2 , ⋯ , x n ) ∈ ℝ n .</p><p>We use column vector notation for ℝ n throughout this paper, and x ′ = ( x 1 , x 2 , ⋯ , x n ) is transpose of x, which is called row vector of ℝ n .</p><p>Definition 2.1 Let L ⊂ ℝ n be a non-trivial additive subgroup, it is called a discrete subgroup if there is a positive real number λ &gt; 0 such that</p><p>min x ∈ L , x ≠ 0 | x | ≥ λ &gt; 0. (2.1)</p><p>As usual, a ball of center x 0 with radius δ is defined by</p><p>b ( x 0 , δ ) = { x ∈ ℝ n | | x − x 0 | ≤ δ } .</p><p>If L is a discrete subgroup of ℝ n , then there are only finitely many vectors of L lie in every ball b ( 0 , δ ) , thus we always find a vector α ∈ L such that</p><p>| α | = min x ∈ L , x ≠ 0 | x | = λ &gt; 0 , α ∈ L . (2.2)</p><p>α is called one of shortest vector of L and λ is called the minimum distance of L.</p><p>Let B = [ β 1 , β 2 , ⋯ , β m ] ∈ ℝ n &#215; m be a n &#215; m dimensional matrix with rank ( B ) = m ≤ n , it means that β 1 , β 2 , ⋯ , β m are m linearly independent vectors in ℝ n . The lattice L ( B ) generated by B is defined by</p><p>L ( B ) = ∑ i = 1 m x i β i = { B x | x ∈ ℤ m } , ∀ x i ∈ ℤ . (2.3)</p><p>which is all linear combinations of β 1 , β 2 , ⋯ , β m over ℤ . If m = n , L ( B ) is called a full-rank lattice.</p><p>It is a well-known conclusion that a discrete subgroup L in ℝ n is just a lattice L ( B ) . Firstly, we give a detail proof here by making use of the simultaneous Diophantine approximation theory in real number field ℝ (see [<xref ref-type="bibr" rid="scirp.120004-ref6">6</xref>] and [<xref ref-type="bibr" rid="scirp.120004-ref7">7</xref>]).</p><p>Lemma 2.1 Let L ⊂ ℝ n be a discrete subgroup, α 1 , α 2 , ⋯ , α m ∈ L be m vectors of L. Then α 1 , α 2 , ⋯ , α m are linearly independent over ℝ , if and only if which are linearly independent over ℤ .</p><p>Proof: If α 1 , α 2 , ⋯ , α m are linearly independent over ℝ , trivially which are linearly independent over ℤ . Suppose that α 1 , α 2 , ⋯ , α m are linearly independent over ℤ , we consider arbitrary linear combination over ℝ . Let</p><p>a 1 α 1 + a 2 α 2 + ⋯ + a m α m = 0 , ∀ a i ∈ ℝ . (2.4)</p><p>We should prove (2.4) is equivalent to a 1 = a 2 = ⋯ = a m = 0 , which implies that α 1 , α 2 , ⋯ , α m are linearly independent over ℝ .</p><p>By Minkowski’s Third Theorem (see Theorem VII of [<xref ref-type="bibr" rid="scirp.120004-ref7">7</xref>]), for any sufficiently large N &gt; 1 , there are a positive integer q ≥ 1 and integers p 1 , p 2 , ⋯ , p m ∈ ℤ such that</p><p>max 1 ≤ i ≤ m | q a i − p i | &lt; N − 1 m , and 1 ≤ q ≤ N . (2.5)</p><p>By (2.4), we have</p><p>| p 1 α 1 + p 2 α 2 + ⋯ + p m α m | = | ( q a 1 − p 1 ) α 1 + ( q a 2 − p 2 ) α 2 + ⋯ + ( q a m − p m ) α m | ≤ m N − 1 m max 1 ≤ i ≤ m | α i | . (2.6)</p><p>Let λ be the minimum distance of L, ε &gt; 0 be any positive real number. We select N such that</p><p>N &gt; max { ( m ε ) m , ( m λ ) m max 1 ≤ i ≤ m | α i | m } .</p><p>It follows that m N − 1 m &lt; ε and</p><p>m N − 1 m max 1 ≤ i ≤ m | α i | &lt; λ .</p><p>By (2.6) we have</p><p>| p 1 α 1 + p 2 α 2 + ⋯ + p m α m | &lt; λ .</p><p>Since p 1 α 1 + p 2 α 2 + ⋯ + p m α m ∈ L , thus we have p 1 α 1 + p 2 α 2 + ⋯ + p m α m = 0 ,</p><p>and p 1 = p 2 = ⋯ = p m = 0 . By (2.5) we have q | a i | &lt; 1 m ε for all i, 1 ≤ i ≤ m .</p><p>Since ε is sufficiently small positive number, we must have a 1 = a 2 = ⋯ = a m = 0 . We complete the proof of lemma.</p><p>口</p><p>Suppose that B ∈ ℝ n &#215; m is an n &#215; m -dimensional matrix and rank ( B ) = m , B ′ is the transpose of B. It is easy to verify</p><p>rank ( B ′ B ) = rank ( B ) = m ⇒ det ( B ′ B ) ≠ 0 ,</p><p>which implies that B ′ B is an invertible square matrix of m &#215; m dimension, here det ( B ′ B ) is the determinant of the matrix B ′ B . Since B ′ B is a positive defined symmetric matrix, then there is an orthogonal matrix P ∈ ℝ m &#215; m such that</p><p>P ′ B ′ B P = diag { δ 1 , δ 2 , ⋯ , δ m } , (2.7)</p><p>where δ i &gt; 0 are the characteristic value of B ′ B , and diag { δ 1 , δ 2 , ⋯ , δ m } is the diagonal matrix of m &#215; m dimension.</p><p>Lemma 2.2 Suppose that B ∈ ℝ n &#215; m with rank ( B ) = m , δ 1 , δ 2 , ⋯ , δ m are m characteristic values of B ′ B , and λ ( L ( B ) ) is the minimum distance of lattice L ( B ) , then we have</p><p>λ ( L ( B ) ) = min x ∈ ℤ m , x ≠ 0 | B x | ≥ δ , (2.8)</p><p>where δ = min { δ 1 , δ 2 , ⋯ , δ m } .</p><p>Proof: Let A = B ′ B , by (2.7), there exists an orthogonal matrix P ∈ ℝ m &#215; m such that</p><p>P ′ A P = diag { δ 1 , δ 2 , ⋯ , δ m } .</p><p>If x ∈ ℤ m , x ≠ 0 , we have</p><p>| B x | 2 = x ′ A x = x ′ P ( P ′ A P ) P ′ x = ( P ′ x ) ′ diag { δ 1 , δ 2 , ⋯ , δ m } P ′ x ≥ δ | P ′ x | 2 = δ | x | 2 .</p><p>Since x ∈ ℤ m and x ≠ 0 , we have | x | 2 ≥ 1 , it follows that</p><p>min x ∈ ℤ m , x ≠ 0 | B x | ≥ δ | x | ≥ δ .</p><p>We have Lemma 2.2 immediately.</p><p>口</p><p>Another application of Lemma 2.2 is to give a countable upper bound for smoothing parameter (see Theorem 5.5 below). Combining Lemma 2.1 and Lemma 2.2, we show that the following assertion.</p><p>Theorem 2.3 Let L ⊂ ℝ n be a subset, then L is a discrete subgroup if and only if there is an n &#215; m dimensional matrix B ∈ ℝ n &#215; m with rank ( B ) = m such that</p><p>L = L ( B ) = { B x | x ∈ ℤ m } . (2.9)</p><p>Proof: If L ⊂ ℝ n is a discrete subgroup, then L is a free ℤ -module. By Lemma 2.1, we have rank ℤ ( L ) = m ≤ n . Let β 1 , β 2 , ⋯ , β m be a ℤ -basis of L, then</p><p>L = { ∑ i = 1 m a i β i | a i ∈ ℤ } .</p><p>Writing B = [ β 1 , β 2 , ⋯ , β m ] n &#215; m , then the rank of matrix B is m, and</p><p>L = { B x | x ∈ ℤ m } = L ( B ) .</p><p>Conversely, let L ( B ) be arbitrary lattice generated by B, obviously, L ( B ) is an additive subgroup of ℝ n , by Lemma 2.2, L ( B ) is also a discrete subgroup, we have Theorem 2.3 at once.</p><p>口</p><p>Corollary 2.4 Let L ⊂ ℝ n be a lattice and G ⊂ L be an additive subgroup of L, then G is a lattice of ℝ n .</p><p>Corollary 2.5 Let L ⊂ ℤ n be an additive subgroup, then L is a lattice of ℝ n . These lattices are called integer lattices.</p><p>According to above Theorem 2.3, a lattice L ( B ) is equivalent to a discrete subgroup of ℝ n . Suppose L = L ( B ) is a lattice with generated matrix B ∈ ℝ n &#215; m , and rank ( B ) = m , we write rank ( L ) = rank ( B ) , and</p><p>d ( L ) = det ( B ′ B ) . (2.10)</p><p>In particular, if rank ( L ) = n is a full-rank lattice, then d ( L ) = | det ( B ) | as usual. A sublattice N of L means a discrete additive subgroup of L, the quotient group is written by L/N and the cardinality of L/N is denoted by |L/N|.</p><p>Lemma 2.6 Let L ⊂ ℝ n be a lattice and N ⊂ L be a sublattice. If rank ( N ) = rank ( L ) , then the quotient group L/N is a finite group.</p><p>Proof: Let rank ( L ) = m , and L = L ( B ) , where B ∈ ℝ n &#215; m with rank ( B ) = m . We define a mapping σ from L to ℤ m by σ ( B x ) = x . Clearly, σ is an additive group isomorphism, σ ( N ) ⊂ ℤ m is a full-rank lattice of ℤ m , and L / N ≅ ℤ m / σ ( N ) . It is a well-known result that</p><p>| ℤ m / σ ( N ) | = d ( σ ( N ) ) .</p><p>It follows that</p><p>| L / N | = | ℤ m / σ ( N ) | = d ( σ ( N ) ) .</p><p>Lemma 2.6 follows.</p><p>口</p><p>Suppose that L 1 ⊂ ℝ n , L 2 ⊂ ℝ n are two lattices of ℝ n , we define L 1 + L 2 = { a + b | a ∈ L 1 , b ∈ L 2 } . Obviously, L 1 + L 2 is an additive subgroup of ℝ n , but generally speaking, L 1 + L 2 is not a lattice of ℝ n again.</p><p>Lemma 2.7 Let L 1 ⊂ ℝ n , L 2 ⊂ ℝ n be two lattices of ℝ n . If rank ( L 1 ∩ L 2 ) = rank ( L 1 ) or rank ( L 1 ∩ L 2 ) = rank ( L 2 ) , then L 1 + L 2 is again a lattice of ℝ n .</p><p>Proof: To prove L 1 + L 2 is a lattice of ℝ n , by Theorem 2.3, it is sufficient to prove L 1 + L 2 is a discrete subgroup of ℝ n . Suppose that rank ( L 1 ∩ L 2 ) = rank ( L 1 ) , for any x ∈ L 1 , we define a distance function ρ ( x ) by</p><p>ρ ( x ) = inf { | x − y | | y ≠ x , y ∈ L 2 } .</p><p>Here the function inf(A) is the infimum of a set A. Since there are only finitely many vectors in L 2 ∩ b ( x , δ ) , where b ( x , δ ) is any a ball of center x with radius δ . Therefore, we have</p><p>ρ ( x ) = min { | x − y | | y ≠ x , y ∈ L 2 } = λ x &gt; 0. (2.11)</p><p>On the other hand, if x 1 ∈ L 1 , x 2 ∈ L 1 and x 1 − x 2 ∈ L 2 , then there is y 0 ∈ L 2 such that x 1 = x 2 + y 0 , and we have ρ ( x 1 ) = ρ ( x 2 ) . It means that ρ ( x ) is defined over the quotient group L 1 + L 2 / L 2 . Because we have the following group isomorphic theorem</p><p>L 1 + L 2 / L 2 ≅ L 1 / L 1 ∩ L 2 .</p><p>By Lemma 2.6, it follows that</p><p>| L 1 + L 2 / L 2 | = | L 1 / L 1 ∩ L 2 | &lt; ∞ .</p><p>In other words, L 1 + L 2 / L 2 is also a finite group. Let x 1 , x 2 , ⋯ , x k be the representative elements of L 1 + L 2 / L 2 , we have</p><p>min x ∈ L 1 , y ∈ L 2 , x ≠ y | x − y | = min 1 ≤ i ≤ k ρ ( x i ) ≥ min { λ x 1 , λ x 2 , ⋯ , λ x k } &gt; 0.</p><p>Therefore, L 1 + L 2 is a discrete subgroup of ℝ n , thus it is a lattice of ℝ n by Theorem 2.3.</p><p>口</p><p>Remark 2.8 The condition rank ( L 1 ∩ L 2 ) = rank ( L 1 ) or rank ( L 1 ∩ L 2 ) = rank ( L 2 ) in Lemma 2.7 seems to be necessary. As a counterexample, we see the real line ℝ , let L 1 = ℤ and L 2 = 2 ℤ , then L 1 + L 2 is not a discrete subgroup of ℝ , thus L 1 + L 2 is not a lattice in ℝ . Because L 1 + L 2 = { n + 2 m | n ∈ ℤ , m ∈ ℤ } is dense in ℝ by Dirichlet’s Theorem (see Theorem I of [<xref ref-type="bibr" rid="scirp.120004-ref7">7</xref>]).</p><p>As a direct consequence, we have the following generalized form of Lemma 2.7.</p><p>Corollary 2.9 Let L 1 , L 2 , ⋯ , L m be m lattices of ℝ n and</p><p>rank ( L 1 ∩ L 2 ∩ ⋯ ∩ L m ) = rank ( L j ) forsome 1 ≤ j ≤ m .</p><p>Then L 1 + L 2 + ⋯ + L m is a lattice of ℝ n .</p><p>Proof: Without loss of generality, we assume that</p><p>rank ( L 1 ∩ L 2 ∩ ⋯ ∩ L m ) = rank ( L m ) .</p><p>Let L 1 + L 2 + ⋯ + L m − 1 = L ′ , then</p><p>L ′ + L m / L ′ ≅ L m / L ′ ∩ L m .</p><p>Since rank ( L ′ ∩ L m ) = rank ( L m ) , by Lemma 2.7, we have L ′ + L m = L 1 + L 2 + ⋯ + L m is a lattice of ℝ n and the corollary follows.</p><p>口</p></sec><sec id="s3"><title>3. Ideal Matrices</title><p>Let ℝ [ x ] and ℤ [ x ] be the polynomials rings over ℝ and ℤ with variable x respectively. Suppose that</p><p>ϕ ( x ) = x n − ϕ n − 1 x n − 1 − ⋯ − ϕ 1 x − ϕ 0 ∈ ℤ [ x ] , ϕ 0 ≠ 0 , (3.1)</p><p>is a polynomial with integer coefficients of which has no multiple roots in complex numbers field ℂ . Let w 1 , w 2 , ⋯ , w n be the n different roots of ϕ ( x ) in ℂ , the Vandermonde matrix V ϕ is defined by</p><p>V ϕ = ( 1 1 ⋯ 1 w 1 w 2 ⋯ w n ⋮ ⋮ ⋮ w 1 n − 1 w 2 n − 1 ⋯ w n n − 1 ) , anddet ( V ϕ ) ≠ 0. (3.2)</p><p>According to the given polynomial ϕ ( x ) , we define a rotation matrix H = H ϕ by</p><p>H = H ϕ = ( 0 ⋯ 0 ϕ 0 ϕ 1 I n − 1 ⋮ ϕ n − 1 ) n &#215; n ∈ ℤ n &#215; n , (3.3)</p><p>where I n − 1 is the ( n − 1 ) &#215; ( n − 1 ) unit matrix. Obviously, the characteristic polynomial of H is just ϕ ( x ) .</p><p>We use column notation for vectors in ℝ n , for any f = ( f 0 f 1 ⋮ f n − 1 ) ∈ ℝ n , the ideal matrix generated by vector f is defined by</p><p>H * ( f ) = [ f , H f , H 2 f , ⋯ , H n − 1 f ] n &#215; n ∈ ℝ n &#215; n , (3.4)</p><p>which is a block matrix in terms of each column H k f ( 0 ≤ k ≤ n − 1 ) . Sometimes, f is called an input vector. It is easily seen that H * ( f ) is a more general form of the classical circulant matrix (see [<xref ref-type="bibr" rid="scirp.120004-ref8">8</xref>]) and r-circulant matrix (see [<xref ref-type="bibr" rid="scirp.120004-ref9">9</xref>] and [<xref ref-type="bibr" rid="scirp.120004-ref10">10</xref>]). In fact, if ϕ ( x ) = x n − 1 , then H * ( f ) is the ordinary circulant matrix generated by f. If ϕ ( x ) = x n − r , then H * ( f ) is the r-circulant matrix.</p><p>By (3.4), it follows immediately that</p><p>H * ( f + g ) = H * ( f ) + H * ( g ) , and H * ( λ f ) = λ H * ( f ) , ∀ λ ∈ ℝ . (3.5)</p><p>Moreover, H * ( f ) = 0 is a zero matrix if and only if f = 0 is a zero vector, thus one has H * ( f ) = H * ( g ) if and only if f = g . Let M * be the set of all ideal matrices, namely</p><p>M * = { H * ( f ) | f ∈ ℝ n } . (3.6)</p><p>We may regard H * as a mapping from ℝ n to M * of which is a one to one correspondence.</p><p>In [<xref ref-type="bibr" rid="scirp.120004-ref11">11</xref>], we have shown that some basic properties for ideal matrix, most of them may be summarized as the following theorem.</p><p>Theorem 3.1 Suppose that ϕ ( x ) ∈ ℤ [ x ] is a fixed polynomial with no multiple roots in ℂ , then for any two column vectors f and g in ℝ n , we have</p><p>1) H * ( f ) = f 0 I n + f 1 H + ⋯ + f n − 1 H n − 1 ;</p><p>2) H * ( f ) H * ( g ) = H * ( H * ( f ) g ) and H * ( f ) H * ( g ) = H * ( g ) H * ( f ) ;</p><p>3) H * ( f ) = V ϕ − 1 diag { f ( w 1 ) , f ( w 2 ) , ⋯ , f ( w n ) } V ϕ ;</p><p>4) det ( H * ( f ) ) = ∏ i = 1 n f ( w i ) ;</p><p>5) H * ( f ) is an invertible matrix if and only if ( ϕ ( x ) , f ( x ) ) = 1 in ℝ [ x ] .</p><p>where V ϕ is the Vandermonde matrix given by (2.2), w i ( 1 ≤ i ≤ n ) are all roots of ϕ ( x ) in ℂ , and diag { f ( w 1 ) , f ( w 2 ) , ⋯ , f ( w n ) } is the diagonal matrix.</p><p>Proof: See Theorem 2 of [<xref ref-type="bibr" rid="scirp.120004-ref11">11</xref>].</p><p>口</p><p>Let e 1 , e 2 , ⋯ , e n be unit vectors of ℝ n , that is</p><p>e 1 = ( 1 0 ⋮ 0 ) , e 2 = ( 0 1 ⋮ 0 ) , ⋯ , e n = ( 0 0 ⋮ 1 ) .</p><p>It is easy to verify that</p><p>H * ( e 1 ) = I n , and H * ( e k ) = H k − 1 , 1 ≤ k ≤ n . (3.7)</p><p>This means that the unit matrix I n and rotation matrices H k ( 1 ≤ k ≤ n − 1 ) are all the ideal matrices.</p><p>Let ϕ ( x ) ℝ [ x ] and ϕ ( x ) ℤ [ x ] be the principal ideals generated by ϕ ( x ) in ℝ [ x ] and ℤ [ x ] respectively, we denote the quotient rings R and R &#175; by</p><p>R = ℤ [ x ] / ϕ ( x ) ℤ [ x ] , and R &#175; = ℝ [ x ] / ϕ ( x ) ℝ [ x ] . (3.8)</p><p>There is a one to one correspondence between R &#175; and ℝ n given by</p><p>f ( x ) = f 0 + f 1 x + ⋯ + f n − 1 x n − 1 ∈ R &#175; → t f = ( f 0 f 1 ⋮ f n − 1 ) ∈ ℝ n .</p><p>We denote this correspondence by t, that is</p><p>t ( f ( x ) ) = f and t − 1 ( f ) = f ( x ) , ∀ f ( x ) ∈ R &#175; , and f ∈ ℝ n . (3.9)</p><p>If we restrict t in the quotient ring R, then which gives a one to one correspondence between R and ℤ n . First, we show that t is also a ring isomorphism.</p><p>Definition 3.2 For any two column vectors f and g in ℝ n , we define the ϕ -convolutional product f * g by f * g = H * ( f ) g .</p><p>By Theorem 3.1, it is easy to see that</p><p>f * g = g * f , and H * ( f * g ) = H * ( f ) H * ( g ) . (3.10)</p><p>Lemma 3.3 For any two polynomials f ( x ) and g ( x ) in R &#175; , we have</p><p>t ( f ( x ) g ( x ) ) = H * ( f ) g = f * g .</p><p>Proof: Let g ( x ) = g 0 + g 1 x + ⋯ + g n − 1 x n − 1 ∈ R &#175; , then</p><p>x g ( x ) = ϕ 0 g n − 1 + ( g 0 + ϕ 1 g n − 1 ) x + ⋯ + ( g n − 2 + ϕ n − 1 g n − 1 ) x n − 1 .</p><p>It follows that</p><p>t ( x g ( x ) ) = H t ( g ( x ) ) = H g . (3.11)</p><p>Hence, for any 0 ≤ k ≤ n − 1 , we have</p><p>t ( x k g ( x ) ) = H k t ( g ( x ) ) = H k g , 0 ≤ k ≤ n − 1. (3.12)</p><p>Let f ( x ) = f 0 + f 1 x + ⋯ + f n − 1 x n − 1 ∈ R &#175; , by (i) of Theorem 3.1, we have</p><p>t ( f ( x ) g ( x ) ) = ∑ i = 0 n − 1 f i t ( x i g ( x ) ) = ∑ i = 0 n − 1 f i H i g = H * ( f ) g .</p><p>The lemma follows.</p><p>口</p><p>Theorem 3.4 Under ϕ -convolutional product, ℝ n is a commutative ring with identity element e 1 and ℤ n ⊂ ℝ n is its subring. Moreover, we have the following ring isomorphisms</p><p>R &#175; ≅ ℝ n ≅ M * , and R ≅ ℤ n ≅ M ℤ * ,</p><p>where M * is the set of all ideal matrices given by (3.6), and M ℤ * is the set of all integer ideal matrices.</p><p>Proof: Let f ( x ) ∈ R &#175; and g ( x ) ∈ R &#175; , then</p><p>t ( f ( x ) + g ( x ) ) = f + g = t ( f ( x ) ) + t ( g ( x ) ) ,</p><p>and</p><p>t ( f ( x ) g ( x ) ) = H * ( f ) g = f * g = t ( f ( x ) ) * t ( g ( x ) ) .</p><p>This means that t is a ring isomorphism. Since f * g = g * f and e 1 * g = H * ( e 1 ) g = I n g = g , then ℝ n is a commutative ring with e 1 as the identity elements. Noting H * ( f ) is an integer matrix if and only if f ∈ ℤ n is an integer vector, the isomorphism of subrings follows immediately.</p><p>口</p><p>According to property (v) of Theorem 3.1, H * ( f ) is an invertible matrix whenever ( f ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] , we show that the inverse of an ideal matrix is again an ideal matrix.</p><p>Lemma 3.5 Let f ( x ) ∈ R &#175; and ( f ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] , then</p><p>( H * ( f ) ) − 1 = H * ( u ) ，</p><p>where u ( x ) ∈ R &#175; is the unique polynomial such that u ( x ) f ( x ) ≡ 1 (mod ( ϕ ( x ) )).</p><p>Proof: By Lemma 3.3, we have u * f = e 1 , it follows that</p><p>H * ( u ) H * ( f ) = H * ( e 1 ) = I n .</p><p>Thus we have ( H * ( f ) ) − 1 = H * ( u ) . It is worth to note that if H * ( f ) is an invertible integer matrix, then ( H * ( f ) ) − 1 is not an integer matrix in general.</p><p>口</p><p>Sometimes, the following lemma may be useful, especially, when we consider an integer matrix.</p><p>Lemma 3.6 Let f ( x ) ∈ ℤ [ x ] and ( f ( x ) , ϕ ( x ) ) = 1 in ℤ [ x ] , then we have ( f ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] .</p><p>Proof: Let ℚ be the rational number field. Since ( f ( x ) , ϕ ( x ) ) = 1 in ℤ [ x ] , then ( f ( x ) , ϕ ( x ) ) = 1 in ℚ [ x ] . We know that ℚ [ x ] is a principal ideal domain, thus there are two polynomials a ( x ) and b ( x ) in ℚ [ x ] such that</p><p>a ( x ) f ( x ) + b ( x ) ϕ ( x ) = 1.</p><p>This means that ( f ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] .</p><p>口</p></sec><sec id="s4"><title>4. Cyclic Lattices and Ideal Lattices</title><p>As we know that cyclic code play a central role in algebraic coding theorem (see Chapter 6 of [<xref ref-type="bibr" rid="scirp.120004-ref12">12</xref>]). In [<xref ref-type="bibr" rid="scirp.120004-ref11">11</xref>], we extended ordinary cyclic code to more general forms, namely ϕ -cyclic codes. To obtain an analogous concept of ϕ -cyclic code in ℝ n , we note that every rotation matrix H defines a linear transformation of ℝ n by x → H x .</p><p>Definition 4.1 A linear subspace C ⊂ ℝ n is called a ϕ -cyclic subspace if ∀ α ∈ C ⇒ H α ∈ C . A lattice L ⊂ ℝ n is called a ϕ -cyclic lattice if ∀ α ∈ L ⇒ H α ∈ L .</p><p>In other words, a ϕ -cyclic subspace C is a linear subspace of ℝ n , of which is closed under linear transformation H. A ϕ -cyclic lattice L is a lattice of ℝ n of which is closed under H. If ϕ ( x ) = x n − 1 , then H is the classical circulant matrix and the corresponding cyclic lattice was first appeared in Micciancio [<xref ref-type="bibr" rid="scirp.120004-ref1">1</xref>], but he do not discuss the further property for these lattices. To obtain the explicit algebraic construction of ϕ -cyclic lattice, we first show that there is a one to one correspondence between ϕ -cyclic subspaces of ℝ n and the ideals of R &#175; .</p><p>Lemma 4.2 Let t be the correspondence between R &#175; and ℝ n given by (3.9), then a subset C ⊂ ℝ n is a ϕ -cyclic subspace of ℝ n , if and only if t − 1 ( C ) ⊂ R &#175; is an ideal.</p><p>Proof: We extend the correspondence t to subsets of R &#175; and ℝ n by</p><p>C ( x ) ⊂ R &#175; → t C = { c | c ( x ) ∈ C ( x ) } ⊂ ℝ n . (4.1)</p><p>Let C ( x ) ⊂ R &#175; be an ideal, it is clear that C ⊂ t ( C ( x ) ) is a linear subspace of ℝ n . To prove C is a ϕ -cyclic subspace, we note that if c ( x ) ∈ C ( x ) , then by (3.11)</p><p>x c ( x ) ∈ C ( x ) ⇔ H t ( c ( x ) ) = H c ∈ C .</p><p>Therefore, if C ( x ) is an ideal of R &#175; , then t ( C ( x ) ) = C is a ϕ -cyclic subspace of ℝ n . Conversely, if C ⊂ ℝ n is a ϕ -cyclic subspace, then for any k ≥ 1 , we have H k c ∈ C whenever c ∈ C , it implies</p><p>∀ c ( x ) ∈ C ( x ) ⇒ x k c ( x ) ∈ C ( x ) , 0 ≤ k ≤ n − 1 ,</p><p>which means that C ( x ) is an ideal of R &#175; . We complete the proof.</p><p>口</p><p>By above lemma, to find a ϕ -cyclic subspace in ℝ n , it is enough to find an ideal of R &#175; . There are two trivial ideals C ( x ) = 0 and C ( x ) = R &#175; , the corresponding ϕ -cyclic subspace are C = 0 and C = ℝ n . To find non-trivial ϕ -cyclic subspaces, we make use of the homomorphism theorems, which is a standard technique in algebra. Let π be the natural homomorphism from ℝ [ x ] to R &#175; , ker π = ϕ ( x ) ℝ [ x ] . We write ϕ ( x ) ℝ [ x ] by 〈 ϕ ( x ) 〉 . Let N be an ideal of ℝ [ x ] satisfying</p><p>〈 ϕ ( x ) 〉 ⊂ N ⊂ ℝ [ x ] → π R &#175; = ℝ [ x ] / 〈 ϕ ( x ) 〉 . (4.2)</p><p>Since ℝ [ x ] is a principal ideal domain, then N = 〈 g ( x ) 〉 is a principal ideal generated by a monic polynomial g ( x ) ∈ ℝ [ x ] . It is easy to see that</p><p>〈 ϕ ( x ) 〉 ⊂ 〈 g ( x ) 〉 ⇔ g ( x ) | ϕ ( x ) in ℝ [ x ] .</p><p>It follows that all ideals N satisfying (4.2) are given by</p><p>{ 〈 ϕ ( x ) 〉 | g ( x ) ∈ ℝ [ x ] ismonicand g ( x ) | ϕ ( x ) } .</p><p>We write by 〈 g ( x ) 〉 mod ϕ ( x ) , the image of 〈 g ( x ) 〉 under π , i.e.</p><p>〈 g ( x ) 〉 mod ϕ ( x ) = π ( 〈 g ( x ) 〉 ) .</p><p>It is easy to check</p><p>〈 g ( x ) 〉 mod ϕ ( x ) = { a ( x ) g ( x ) | a ( x ) ∈ ℝ [ x ]   and   deg a ( x ) + deg g ( x ) &lt; n } , (4.3)</p><p>more precisely, which is a representative elements set of 〈 g ( x ) 〉 mod ϕ ( x ) . By homomorphism theorem in ring theory, all ideals of R &#175; given by</p><p>{ 〈 g ( x ) 〉 mod ϕ ( x ) | g ( x ) ∈ ℝ [ x ] ismonicand g ( x ) | ϕ ( x ) } . (4.4)</p><p>Let d be the number of monic divisors of ϕ ( x ) in ℝ [ x ] , we have the following corollary.</p><p>Corollary 4.3 The number of ϕ -cyclic subspace of ℝ n is d.</p><p>Next, we discuss ϕ -cyclic lattice, which is the geometric analogy of cyclic code. The ϕ -cyclic subspace of ℝ n maybe regarded as the algebraic analogy of cyclic code. Let the quotient rings R and R &#175; given by (3.8). A R-module is an Abel group Λ such that there is an operator λ α ∈ Λ for all λ ∈ R and α ∈ Λ , satisfying 1 ⋅ α = α and ( λ 1 λ 2 ) α = λ 1 ( λ 2 α ) . It is easy to see that R &#175; is a R-module, if Λ ⊂ R &#175; and Λ is a R-module, then Λ is called a R-submodule of R &#175; . All R-modules we discuss here are R-submodule of R &#175; . On the other hand, if I ⊂ R , then I is an ideal of R, if and only if I is a R-module. Let α ∈ R &#175; , the cyclic R-module generated by α be defined by</p><p>R α = { λ α | λ ∈ R } . (4.5)</p><p>If there are finitely many polynomials α 1 , α 2 , ⋯ , α k in R &#175; such that Λ = R α 1 + R α 2 + ⋯ + R α k , then Λ is called a finitely generated R-module, which is a R-submodule of R &#175; .</p><p>Now, if L ⊂ ℝ n is a ϕ -cyclic lattice, g ∈ ℝ n , H * ( g ) is the ideal matrix generated by vector g, and L ( H * ( g ) ) is the lattice generated by H * ( g ) . It is easy to show that any L ( H * ( g ) ) is a ϕ -cyclic lattice and</p><p>L ( H * ( g ) ) ⊂ L , whenever g ∈ L , (4.6)</p><p>which implies that L ( H * ( g ) ) is the smallest ϕ -cyclic lattice of which contains vector g. Therefore, we call L ( H * ( g ) ) is a minimal ϕ -cyclic lattice in ℝ n .</p><p>Lemma 4.4 There is a one to one correspondence between the minimal ϕ -cyclic lattice in ℝ n and the cyclic R-submodule in R &#175; , namely,</p><p>t ( R g ( x ) ) = L ( H * ( g ) ) , forall g ( x ) ∈ R &#175;</p><p>and</p><p>t − 1 ( L ( H * ( g ) ) ) = R g ( x ) , forall g ∈ ℝ n .</p><p>Proof: Let b ( x ) ∈ R , by Lemma 3.3, we have</p><p>t ( b ( x ) g ( x ) ) = H * ( b ) g = H * ( g ) b ∈ L ( H * ( g ) ) ,</p><p>and t ( R g ( x ) ) ⊂ L ( H * ( g ) ) . Conversely, if α ∈ L ( H * ( g ) ) , and α = H * ( g ) b for some integer vector b, by Lemma 3.3 again, we have b ( x ) g ( x ) ∈ R g ( x ) , and t ( b ( x ) g ( x ) ) = α . This implies that L ( H * ( g ) ) ⊂ t ( R g ( x ) ) , and</p><p>t ( R g ( x ) ) = L ( H * ( g ) ) .</p><p>The lemma follows immediately.</p><p>口</p><p>Suppose L = L ( β 1 , β 2 , ⋯ , β m ) is arbitrary ϕ -cyclic lattice, where B = [ β 1 , β 2 , ⋯ , β m ] n &#215; m is the generated matrix of L. L may be expressed as the sum of finitely many minimal ϕ -cyclic lattices, in fact, we have</p><p>L = L ( H * ( β 1 ) ) + L ( H * ( β 2 ) ) + ⋯ + L ( H * ( β m ) ) . (4.7)</p><p>To state and prove our main results, first, we give a definition of prime spot in ℝ n .</p><p>Definition 4.5 Let g ∈ ℝ n , and g ( x ) = t − 1 ( g ) ∈ R &#175; . If ( g ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] , we call g is a prime spot of ℝ n .</p><p>By (v) of Theorem 3.1, g ∈ ℝ n is a prime spot if and only if H * ( g ) is an invertible matrix, thus the minimal ϕ -cyclic lattice L ( H * ( g ) ) generated by a prime spot is a full-rank lattice.</p><p>Lemma 4.6 Let g and f be two prime spots of ℝ n , then L ( H * ( g ) ) + L ( H * ( f ) ) is a full-rank ϕ -cyclic lattice.</p><p>Proof: According to Lemma 2.7, it is sufficient to show that</p><p>rank ( L ( H * ( g ) ) ∩ L ( H * ( f ) ) ) = rank ( L ( H * ( g ) ) ) = n . (4.8)</p><p>In fact, we should prove in general</p><p>L ( H * ( g ) ⋅ H * ( f ) ) ⊂ L ( H * ( g ) ) ∩ L ( H * ( f ) ) . (4.9)</p><p>Since H * ( g ) ⋅ H * ( f ) is an invertible matrix, then rank ( L ( H * ( g ) ⋅ H * ( f ) ) ) = n , and (4.8) follows immediately.</p><p>To prove (4.9), we note that</p><p>L ( H * ( g ) ⋅ H * ( f ) ) = L ( H * ( g * f ) ) .</p><p>It follows that</p><p>t − 1 ( L ( H * ( g ) ⋅ H * ( f ) ) ) = R g ( x ) f ( x ) .</p><p>It is easy to see that</p><p>R f ( x ) g ( x ) ⊂ R g ( x ) ∩ R f ( x ) .</p><p>Therefore, we have</p><p>L ( H * ( g ) ⋅ H * ( f ) ) = t ( R g ( x ) f ( x ) ) ⊂ L ( H * ( g ) ) ∩ L ( H * ( f ) ) .</p><p>This is the proof of Lemma 4.6.</p><p>口</p><p>It is worth to note that (4.9) is true for more general case, do not need the condition of prime spot.</p><p>Corollary 4.7 Let β 1 , β 2 , ⋯ , β m be arbitrary m vectors in ℝ n , then we have</p><p>L ( H * ( β 1 ) H * ( β 2 ) ⋯ H * ( β m ) ) ⊂ L ( H * ( β 1 ) ) ∩ L ( H * ( β 2 ) ) ∩ ⋯ ∩ L ( H * ( β m ) ) . (4.10)</p><p>Proof: If β 1 , β 2 , ⋯ , β m are integer vectors, then (4.10) is trivial. For the general case, we write</p><p>L ( H * ( β 1 ) H * ( β 2 ) ⋯ H * ( β m ) ) = L ( H * ( β 1 * β 2 * ⋯ * β m ) ) ,</p><p>where β 1 * β 2 * ⋯ * β m is the ϕ -convolutional product, then</p><p>t − 1 ( L ( H * ( β 1 ) H * ( β 2 ) ⋯ H * ( β m ) ) ) = R β 1 ( x ) β 2 ( x ) ⋯ β m ( x ) .</p><p>Since</p><p>R β 1 ( x ) β 2 ( x ) ⋯ β m ( x ) ⊂ R β 1 ( x ) ∩ R β 2 ( x ) ∩ ⋯ ∩ R β m ( x ) .</p><p>It follows that</p><p>L ( H * ( β 1 ) H * ( β 2 ) ⋯ H * ( β m ) ) ⊂ L ( H * ( β 1 ) ) ∩ L ( H * ( β 2 ) ) ∩ ⋯ ∩ L ( H * ( β m ) ) .</p><p>We have this corollary.</p><p>口</p><p>By Lemma 4.6, we also have the following assertion.</p><p>Corollary 4.8 Let β 1 , β 2 , ⋯ , β m be m prime spots of ℝ n , then L ( H * ( β 1 ) ) + L ( H * ( β 2 ) ) + ⋯ + L ( H * ( β m ) ) is a full-rank ϕ -cyclic lattice.</p><p>Proof: It follows immediately from Corollary 2.9.</p><p>口</p><p>Our main result in this paper is to establish the following one to one correspondence between ϕ -cyclic lattices in ℝ n and finitely generated R-modules in R &#175; .</p><p>Theorem 4.9 Let Λ = R α 1 ( x ) + R α 2 ( x ) + ⋯ + R α m ( x ) be a finitely generated R-module in R &#175; , then t ( Λ ) is a ϕ -cyclic lattice in ℝ n . Conversely, if L ⊂ ℝ n is a ϕ -cyclic lattice in ℝ n , then t − 1 ( L ) is a finitely generated R-module in R &#175; , that is a one to one correspondence.</p><p>Proof: If Λ is a finitely generated R-module, by Lemma 4.4, we have</p><p>t ( Λ ) = t ( R α 1 ( x ) + ⋯ + R α m ( x ) ) = L ( H * ( α 1 ) ) + L ( H * ( α 2 ) ) + ⋯ + L ( H * ( α m ) ) .</p><p>The main difficult is to show that t ( Λ ) is a lattice of ℝ n , we require a surgery to embed t ( Λ ) into a full-rank lattice. To do this, let ( α i ( x ) , ϕ ( x ) ) = d i ( x ) , d i ( x ) ∈ ℤ [ x ] , and β i ( x ) = α i ( x ) / d i ( x ) , 1 ≤ i ≤ m . Since ϕ ( x ) has no multiple roots by assumption, then ( β i ( x ) , ϕ ( x ) ) = 1 in ℝ [ x ] . In other words, each t ( β i ( x ) ) = β i is a prime spot. It is easy to verify R α i ( x ) ⊂ R β i ( x )   ( 1 ≤ i ≤ m ) , thus we have</p><p>t ( Λ ) ⊂ L ( H * ( β 1 ) ) + L ( H * ( β 2 ) ) + ⋯ + L ( H * ( β m ) ) .</p><p>By Corollary 4.8 and Corollary 2.4, we have t ( Λ ) is ϕ -cyclic lattice. Conversely, if L ⊂ ℝ n is a ϕ -cyclic lattice of ℝ n , and L = L ( β 1 , β 2 , ⋯ , β m ) , by (4.7), we have</p><p>t − 1 ( L ) = R β 1 ( x ) + R β 2 ( x ) + ⋯ + R β m ( x ) ,</p><p>which is a finitely generated R-module in R &#175; . We complete the proof of Theorem 4.9.</p><p>口</p><p>As we introduced in abstract, since R is a Noether ring, then I ⊂ R is an ideal if and only if I is a finitely generated R-module. On the other hand, if I ⊂ R is an ideal, then t ( I ) ⊂ ℤ n is a discrete subgroup of ℤ n , thus t ( I ) is a lattice.</p><p>Definition 4.10 Let I ⊂ R be an ideal, t ( I ) is called the ϕ -ideal lattice.</p><p>Ideal lattice was first appeared in [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>] (see Definition 3.1 of [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>]). As a direct consequences of Theorem 4.9, we have the following corollary.</p><p>Corollary 4.11 Let L ⊂ ℝ n be a subset, then L is a ϕ -cyclic lattice if and only if</p><p>L = L ( H * ( β 1 ) ) + L ( H * ( β 2 ) ) + ⋯ + L ( H * ( β m ) ) ,</p><p>where β i ∈ ℝ n and m ≤ n . Furthermore, L is a ϕ -ideal lattice if and only if every β i ∈ ℤ n , 1 ≤ i ≤ m .</p><p>Corollary 4.12 Suppose that ϕ ( x ) is an irreducible polynomial in ℤ [ x ] , then any non-zero ideal I of R defines a full-rank ϕ -ideal lattice t ( I ) ⊂ ℤ n .</p><p>Proof: Let I ⊂ R be a non-zero ideal, then we have I = R α 1 ( x ) + ⋯ + R α m ( x ) , where α i ( x ) ∈ R and ( α i ( x ) , ϕ ( x ) ) = 1 . It follows that</p><p>t ( I ) = L ( H * ( α 1 ) ) + L ( H * ( α 2 ) ) + ⋯ + L ( H * ( α m ) ) .</p><p>Since each α i is a prime spot, we have rank ( t ( I ) ) = n by Corollary 4.8, and the corollary follows at once.</p><p>口</p><p>According to Definition 3.1 of [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>], we have proved that any an ideal of R corresponding to a ϕ -ideal lattice, which just is a ϕ -cyclic integer lattice under the more general rotation matrix H = H ϕ . Cyclic lattice and ideal lattice were introduced in [<xref ref-type="bibr" rid="scirp.120004-ref1">1</xref>] and [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>] respectively to improve the space complexity of lattice based cryptosystems. Ideal lattices allow to represent a lattice using only two polynomials. Using such lattices, class lattice based cryptosystems can diminish their space complexity from O ( n 2 ) to O ( n ) . Ideal lattices also allow to accelerate computations using the polynomial structure. The original structure of Micciancio’s matrices uses the ordinary circulant matrices and allows for an interpretation in terms of arithmetic in polynomial ring ℤ [ x ] / 〈 x n − 1 〉 . Lyubashevsky and Micciancio [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>] latter suggested to change the ring to ℤ [ x ] / 〈 ϕ ( x ) 〉 with an irreducible ϕ ( x ) over ℤ [ x ] . Our results here suggest to change the ring to ℤ [ x ] / 〈 ϕ ( x ) 〉 with any a polynomial ϕ ( x ) . There are many works are subsequent to Micciancio [<xref ref-type="bibr" rid="scirp.120004-ref1">1</xref>] and Lyubashevsky and Micciancio [<xref ref-type="bibr" rid="scirp.120004-ref2">2</xref>], such as [<xref ref-type="bibr" rid="scirp.120004-ref13">13</xref>] - [<xref ref-type="bibr" rid="scirp.120004-ref19">19</xref>].</p><p>Example 4.13 It is interesting to find some examples of ϕ -cyclic lattices in an algebraic number field K. Let ℚ be rational number field, without loss of generality, an algebraic number field K of degree n is just K = ℚ ( w ) , where w = w i is a root of ϕ ( x ) . If all ℚ ( w i ) ⊂ ℝ ( 1 ≤ i ≤ n ), then K is called a totally real algebraic number field. Let O K be the ring of algebraic integers of K, and I ⊂ O K be an ideal, I ≠ 0 . Since there is an integral basis { α 1 , α 2 , ⋯ , α n } ⊂ I such that</p><p>I = ℤ α 1 + ℤ α 2 + ⋯ + ℤ α n .</p><p>We may regard every ideal of O K as a lattice in ℚ n , our assertion is that every nonzero ideal of O K is corresponding to a full-rank ϕ -cyclic lattice of ℚ n . To see this example, let</p><p>ℚ [ w ] = { ∑ i = 0 n − 1 a i w i | a i ∈ ℚ } .</p><p>It is known that K = ℚ [ w ] , thus every α ∈ K corresponds to a vector α &#175; ∈ ℚ n by</p><p>α = ∑ i = 0 n − 1 a i w i → τ α &#175; = ( a 0 a 1 ⋮ a n − 1 ) ∈ ℚ n .</p><p>If I ⊂ O K is an ideal of O K and I = ℤ α 1 + ℤ α 2 + ⋯ + ℤ α n , let B = [ α 1 &#175; , α 2 &#175; , ⋯ , α n &#175; ] ∈ ℚ n &#215; n , which is full-rank matrix. We have τ ( I ) = L ( B ) is a full-rank lattice. It remains to show that τ ( I ) is a ϕ -cyclic lattice, we only prove that if α ∈ I ⇒ H α &#175; ∈ τ ( I ) . Suppose that α ∈ I , then w α ∈ I . It is easy to verify that τ ( w ) = e 2 (see (3.7)) and</p><p>τ ( w α ) = τ ( w ) * τ ( α ) = H α &#175; ∈ τ ( I ) .</p><p>This means that τ ( I ) is a ϕ -cyclic lattice of ℚ n , which is a full-rank lattice.</p></sec><sec id="s5"><title>5. Smoothing Parameter</title><p>As application of the algebraic structure of ϕ -cyclic lattice, we show that an explicit upper bound of the smoothing parameter for the ϕ -cyclic lattices. Firstly, we introduce some basic notations.</p><p>A Gauss function ρ s , c ( x ) in ℝ n is given by</p><p>ρ s , c ( x ) = e − π | x − c | 2 / s 2 , (5.1)</p><p>where x ∈ ℝ n , c ∈ ℝ n and s &gt; 0 is a positive real number. ρ s , c ( x ) is called the Gauss function around original point c with parameter s. It is easy to see that</p><p>∫ ℝ n ρ s , c ( x ) d x = s n .</p><p>Thus we may define a probability density function D s , c ( x ) by</p><p>D s , c ( x ) = ρ s , c ( x ) / ∫ ℝ n ρ s , c ( x ) d x = ρ s , c ( x ) / s n . (5.2)</p><p>Suppose L ⊂ ℝ n is a lattice, let</p><p>D s , c ( L ) = ∑ x ∈ L D s , c ( x ) , ρ s , c ( L ) = ∑ x ∈ L ρ s , c ( x ) . (5.3)</p><p>The discrete Gauss distribution over L is a probability distribution D L , s , c over L given by</p><p>D L , s , c ( x ) = D s , c ( x ) D s , c ( L ) = ρ s , c ( x ) ρ s , c ( L ) . (5.4)</p><p>If c = 0 is the zero vector of ℝ n , we write ρ s , 0 ( x ) = ρ s ( x ) , ρ s , 0 ( L ) = ρ s ( L ) , D s , 0 ( x ) = D s ( x ) and D s , 0 ( L ) = D s ( L ) . Suppose that L is a full-rank lattice and L * is its dual lattice, we define the smoothing parameter η ε ( L ) of L to be the smallest s such that ρ 1 / s ( L * ) ≤ 1 + ε , more precisely,</p><p>η ε ( L ) = min { s : s &gt; 0 and ρ 1 / s ( L * ) ≤ 1 + ε } , (5.5)</p><p>where ε &gt; 0 is a positive number. Notice that ρ 1 / s ( L * ) is a continuous and strictly decreasing function of s, thus the smoothing parameter η ε ( L ) is a continuous and strictly decreasing function of ε .</p><p>Let L = L ( β 1 , β 2 , ⋯ , β n ) ⊂ ℝ n be a full-rank lattice with a basis β 1 , β 2 , ⋯ , β n , the fundamental region P ( L ) is given by</p><p>P ( L ) = { ∑ i = 1 n a i β i | 0 ≤ a i &lt; 1 , 1 ≤ i ≤ n } . (5.6)</p><p>Suppose that X and Y are two discrete random variables on ℝ n , the statistical distance between X and Y over L is defined by</p><p>Δ ( X , Y ) = 1 2 ∑ a ∈ L | P { X = a } − P { Y = a } |     . (5.7)</p><p>If X and Y are continuous random variables with probability density function T 1 and T 2 respectively, then Δ ( X , Y ) is defined by</p><p>Δ ( X , Y ) = 1 2 ∫ ℝ n | T 1 ( z ) − T 2 ( z ) | d z . (5.8)</p><p>The smoothing parameter was introduced by Micciancio and Regev in [<xref ref-type="bibr" rid="scirp.120004-ref20">20</xref>], which plays an important role in the statistical information of lattices. An important property of smoothing parameter is for any lattice L = L ( B ) and any ε &gt; 0 , the statistical distance between D s mod L and the uniform distribution over the fundamental region P ( L ) is at most ρ 1 / s ( L ( B ) * ) / 2 . More precisely, for any ε &gt; 0 and any s ≥ η ε ( L ( B ) ) , the statistical distance is at most ε / 2 , namely</p><p>Δ ( D s , c mod L , U ( P ( L ) ) ) ≤ ε 2 . (5.9)</p><p>Lemma 5.1 Let L ⊂ ℝ n be a full-rank lattice, we have</p><p>η 2 − n ( L ) ≤ n / λ 1 ( L * ) , (5.10)</p><p>where L * is the dual lattice of L, and λ 1 ( L * ) is the minimum distance of L * .</p><p>Proof: See Lemma 3.2 of [<xref ref-type="bibr" rid="scirp.120004-ref20">20</xref>] [<xref ref-type="bibr" rid="scirp.120004-ref21">21</xref>].</p><disp-formula id="scirp.120004-formula23"><graphic  xlink:href="//html.scirp.org/file/5-7800829x718.png?20220922164355621"  xlink:type="simple"/></disp-formula><p>Lemma 5.2 Suppose that L 1 and L 2 are two full-rank lattices in ℝ n , and L 1 ⊂ L 2 , then for any ε &gt; 0 , we have</p><p>η ε ( L 2 ) ≤ η ε ( L 1 ) . (5.11)</p><p>Proof: Let η ε ( L 1 ) = s , we are to show that η ε ( L 2 ) ≤ s . Since</p><p>ρ 1 / s ( L 1 * ) = 1 + ε , and ∑ x ∈ L 1 * e − π s 2 | x | 2 = 1 + ε .</p><p>It is easy to check that L 2 * ⊂ L 1 * , it follows that</p><p>1 + ε = ∑ x ∈ L 1 * e − π s 2 | x | 2 ≥ ∑ x ∈ L 2 * e − π s 2 | x | 2 ,</p><p>which implies</p><p>ρ 1 / s ( L 2 * ) ≤ 1 + ε ,</p><p>and η ε ( L 2 ) ≤ s = η ε ( L 1 ) , thus we have Lemma 5.2.</p><disp-formula id="scirp.120004-formula24"><graphic  xlink:href="//html.scirp.org/file/5-7800829x732.png?20220922164355621"  xlink:type="simple"/></disp-formula><p>According to (3.4), the ideal matrix H * ( f ) with input vector f ∈ ℝ n is just the ordinary circulant matrix when ϕ ( x ) = x n − 1 . Next lemma shows that the transpose of a circulant matrix is still a circulant matrix. For any</p><p>g = ( g 0 g 1 ⋮ g n − 1 ) ∈ ℝ n , we denote g &#175; = ( g n − 1 g n − 2 ⋮ g 0 ) , which is called the conjugation of g.</p><p>Lemma 5.3 Let ϕ ( x ) = x n − 1 , then for any g = ( g 0 g 1 ⋮ g n − 1 ) ∈ ℝ n , we have</p><p>( H * ( g ) ) ′ = H * ( H   g &#175; ) . (5.12)</p><p>Proof: Since ϕ ( x ) = x n − 1 , then H = H ϕ (see(3.3)) is an orthogonal matrix, and we have H − 1 = H n − 1 = H ′ . We write H 1 = H ′ = H − 1 . The following identity is easy to verify</p><p>H * ( g ) = ( g &#175; ′ H 1 g &#175; ′ H 1 2 ⋮ g &#175; ′ H 1 n ) .</p><p>It follows that</p><p>( H * ( g ) ) ′ = [ H   g &#175; , H ( H   g &#175; ) , ⋯ , H n − 1 ( H   g &#175; ) ] = H * ( H   g &#175; ) ,</p><p>and we have the lemma.</p><disp-formula id="scirp.120004-formula25"><graphic  xlink:href="//html.scirp.org/file/5-7800829x747.png?20220922164355621"  xlink:type="simple"/></disp-formula><p>Lemma 5.4 Suppose that g ∈ ℝ n and the circulant matrix H * ( g ) is invertible. Let A = ( H * ( g ) ) ′ H * ( g ) , then all characteristic values of A are given by</p><p>{ | g ( θ 1 ) | 2 , | g ( θ 2 ) | 2 , ⋯ , | g ( θ n ) | 2 } ,</p><p>where θ i n = 1   ( 1 ≤ i ≤ n ) are the n-th roots of unity.</p><p>Proof: By Lemma 5.3 and (ii) of Theorem 3.1, we have</p><p>A = H * ( H   g &#175; ) H * g = H * ( H * ( H   g &#175; ) g ) = H * ( g ″ ) ,</p><p>where g ″ = H * ( H   g &#175; ) g . Let g ″ ( x ) = t − 1 ( g ″ ) is the corresponding polynomial of g ″ . By (iii) of Theorem 3.1 all characteristic values of A are given by</p><p>{ g ″ ( θ 1 ) , g ″ ( θ 2 ) , ⋯ , g ″ ( θ n ) } , θ i n = 1 , 1 ≤ i ≤ n . (5.13)</p><p>Let g = ( g 0 g 1 ⋮ g n − 1 ) ∈ ℝ n . It is easy to see that</p><p>g ″ ( x ) = ∑ i = 0 n − 1 g i 2 + ( ∑ i = 0 n − 1 g i g 1 − i ) x + ⋯ + ( ∑ i = 0 n − 1 g i g ( n − 1 ) − i ) x n − 1 = | g ( x ) | 2 ,</p><p>where g − i = g n − i for all 1 ≤ i ≤ n − 1 , then the lemma follows at once.</p><disp-formula id="scirp.120004-formula26"><graphic  xlink:href="//html.scirp.org/file/5-7800829x762.png?20220922164355621"  xlink:type="simple"/></disp-formula><p>By definition 4.5, if g ∈ ℝ n is a prime spot, then there is a unique polynomial u ( x ) ∈ R &#175; such that u ( x ) g ( x ) ≡ 1 (mod ϕ ( x ) ). We define a new vector T g and its corresponding polynomial T g ( x ) by</p><p>T g = H u &#175; , and T g ( x ) = t − 1 ( H u &#175; ) . (5.14)</p><p>If g ∈ ℤ n is an integer vector, then T g ∈ ℤ n is also an integer vector, and T g ( x ) ∈ ℤ [ x ] is a polynomial with integer coefficients. Our main result on smoothing parameter is the following theorem.</p><p>Theorem 5.5 Let ϕ ( x ) = x n − 1 , L ⊂ ℝ n be a full-rank ϕ -cyclic lattice, then for any prime spots g ∈ L , we have</p><p>η 2 − n ( L ) ≤ n ( min { | T g ( θ 1 ) | , | T g ( θ 2 ) | , ⋯ , | T g ( θ n ) | } ) − 1 , (5.15)</p><p>where θ i n = 1 , 1 ≤ i ≤ n , and T g ( x ) is given by (5.14).</p><p>Proof: Let g ∈ L be a prime spot, by Lemma 5.2, we have</p><p>L ( H * ( g ) ) ⊂ L ⇒ η ε ( L ) ≤ η ε ( L ( H * ( g ) ) ) , ∀ ε &gt; 0. (5.16)</p><p>To estimate the smoothing parameter of L ( H * ( g ) ) , the dual lattice of L ( H * ( g ) ) is given by</p><p>L ( H * ( g ) ) * = L ( ( H * ( u ) ) ′ ) = L ( H * ( H u &#175; ) ) = L ( H * ( T g ) ) ,</p><p>where u ( x ) ∈ R &#175; and u ( x ) g ( x ) ≡ 1 (mod x n − 1 ), and T g is given by (5.14). Let A = ( H * ( T g ) ) ′ H * ( T g ) , by Lemma 5.4, all characteristic values of A are</p><p>{ | T g ( θ 1 ) | 2 , | T g ( θ 2 ) | 2 , ⋯ , | T g ( θ n ) | 2 } .</p><p>By Lemma 2.2, the minimum distance λ 1 ( L ( H * ( g ) ) * ) is bounded by</p><p>λ 1 ( L ( H * ( g ) ) * ) ≥ min { | T g ( θ 1 ) | , | T g ( θ 2 ) | , ⋯ , | T g ( θ n ) | } . (5.17)</p><p>Now, Theorem 5.5 follows from Lemma 5.1 immediately.</p><disp-formula id="scirp.120004-formula27"><graphic  xlink:href="//html.scirp.org/file/5-7800829x793.png?20220922164355621"  xlink:type="simple"/></disp-formula><p>Let L = L ( B ) be a full-rank lattice and B = [ β 1 , β 2 , ⋯ , β n ] . We denote by B * = [ β 1 * , β 2 * , ⋯ , β n * ] the Gram-Schmidt orthogonal vectors { β i * } of the ordered basis B = { β i } . It is a well-known conclusion that</p><p>λ 1 ( L ) ≥ | B * | = min 1 ≤ i ≤ n | β i * | ,</p><p>which yields by Lemma 5.1 the following upper bound</p><p>η 2 − n ( L ) ≤ n | B 0 * | − 1 , (5.18)</p><p>where B 0 * is the orthogonal basis of dual lattice L * of L.</p><p>For a ϕ -cyclic lattice L, we observe that the upper bound (5.17) is always better than (5.18) by numerical testing, we give two examples here.</p><p>Example 5.6 Let n = 3 and ϕ ( x ) = x 3 − 1 , the rotation matrix H is</p><p>H = ( 0 0 1 1 0 0 0 1 0 ) .</p><p>We select a ϕ -cyclic lattice L = L ( B ) , where</p><p>B = ( 1 1 1 0 1 1 0 0 1 ) .</p><p>Since L = ℤ 3 , thus L is a ϕ -cyclic lattice. It is easy to check</p><p>| B 0 * | = min 1 ≤ i ≤ 3 | β i * | = 3 3 .</p><p>On the other hand, we randomly find a prime spot g = ( 0 0 1 ) ∈ L and g ( x ) = x 2 . Since x g ( x ) ≡ 1 (mod x 3 − 1 ), we have T g ( x ) = x 2 , it follows that | T g ( θ 1 ) | = | T g ( θ 2 ) | = | T g ( θ 3 ) | = 1 , and</p><p>min 1 ≤ i ≤ 3 | T g ( θ i ) | − 1 ≤ | B 0 * | − 1 = 3 .</p><p>Example 5.7 Let n = 4 and ϕ ( x ) = x 4 − 1 , the rotation matrix H is</p><p>H = ( 0 0 0 1 1 0 0 0 0 1 0 0 0 0 1 0 ) .</p><p>We select a ϕ -cyclic lattice L = L ( B ) , where</p><p>B = ( 1 1 1 1 0 1 1 1 0 0 1 1 0 0 0 1 ) .</p><p>Since L = ℤ 4 , thus L is a ϕ -cyclic lattice. It is easy to check</p><p>| B 0 * | = min 1 ≤ i ≤ 4 | β i * | = 1 2 .</p><p>On the other hand, we randomly find a prime spot g = ( − 2 1 0 0 ) ∈ L and g ( x ) = x − 2 . Since</p><p>( 1 7 x 3 − 1 7 x 2 − 2 7 x − 5 7 ) g ( x ) ≡ 1 mod x 4 − 1 ,</p><p>we have</p><p>T g ( x ) = − 2 7 x 3 − 1 7 x 2 + 1 7 x − 5 7 .</p><p>It follows that | T g ( θ 1 ) | = 1 , | T g ( θ 2 ) | = | T g ( θ 3 ) | = | T g ( θ 4 ) | = 5 7 , and</p><p>min 1 ≤ i ≤ 4 | T g ( θ i ) | − 1 = 7 5 ≤ | B 0 * | − 1 = 2.</p></sec><sec id="s6"><title>6. Conclusion</title><p>In this study, we show that ideal lattices are actually a special subclass of cyclic lattices, and prove that there is a one-to-one correspondence between cyclic lattices in ℝ n and finitely generated R-modules. Here, we use a more general rotation matrix so that our definition and results on cyclic lattices and ideal lattices are more general forms. Finally, we give a more explicit and countable upper bound for the smoothing parameter of cyclic lattices.</p></sec><sec id="s7"><title>Conflicts of Interest</title><p>The authors declare no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s8"><title>Cite this paper</title><p>Zheng, Z.Y., Liu, F.X., Lu, Y.F. and Tian, K. (2022) Cyclic Lattices, Ideal Lattices and Bounds for the Smoothing Parameter. Journal of Information Security, 13, 272-293. https://doi.org/10.4236/jis.2022.134015</p></sec></body><back><ref-list><title>References</title><ref id="scirp.120004-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Micciancio, D. (2002) Generalized Compact Knapsacks, Cyclic Lattices, and Efficient One-Way Functions from Worst-Case Complexity Assumptions: (Extended Abstract). The 43rd Annual IEEE Symposium on Foundations of Computer Science, Vancouver, 19 November 2002, 356-365. https://doi.org/10.1109/SFCS.2002.1181960</mixed-citation></ref><ref id="scirp.120004-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Lyubashevsky, V. and Micciancio, D. (2006) Generalized Compact Knapsacks are Collision Resistant. International Colloquium on Automata, Languages, and Programming 2006, Venice, 10-14 July 2006, 144-155. https://doi.org/10.1007/11787006_13</mixed-citation></ref><ref id="scirp.120004-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Ajtai, M. (1996) Generating Hard Instances of the Short Basis Problem. Proceedings of 28th Symposium on the Theory of Computing, Philadephia, 22-24 May 1996, 99-108.</mixed-citation></ref><ref id="scirp.120004-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Ajtai, M. and Dwork, C. (1997) A Public-key Cryptosystem with Worst-Case/Average-Case Equivalence. Proceedings of 29th Symposium on the Theory of Computing, El Paso, 4-6 May 1997, 284-293. https://doi.org/10.1145/258533.258604</mixed-citation></ref><ref id="scirp.120004-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Gentry, C. (2009) Fully Homomorphic Encryption Using Ideal Lattices. Proceedings of 41st Symposium on the Theory of Computing, Bethesda, 31 May-2 June 2009, 169-178. https://doi.org/10.1145/1536414.1536440</mixed-citation></ref><ref id="scirp.120004-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Cassels, J.W.S. (1971) An Introduction to the Geometry of Numbers. Springer, Berlin, Heidelberg, New York.</mixed-citation></ref><ref id="scirp.120004-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Cassels, J.W.S. (1963) Introduction to Diophantine Approximation. Cambridge University Press, Cambridge.</mixed-citation></ref><ref id="scirp.120004-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Davis, P.J. (1994) Circulant Matrices. 2nd Edition, Chelsea Publishing, New York.</mixed-citation></ref><ref id="scirp.120004-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Shi, B. (2018) The Spectral Norms of Geometric Circulant Matrices with the Generalized k-Horadam Numbers. Journal of Inequalities and Applications, 2018, Article No. 14. https://doi.org/10.1186/s13660-017-1608-4</mixed-citation></ref><ref id="scirp.120004-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Yasin, Y. and Taskara, N. (2013) On the Inverse of Circulant Matrix via Generalized k-Horadam Numbers. Applied Mathematics and Computation, 223, 191-196. https://doi.org/10.1016/j.amc.2013.07.078</mixed-citation></ref><ref id="scirp.120004-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Zheng, Z., Liu, F., Huang, W., Xu, J. and Tian, K. (2022) A Generalization of NTRUEncrypt—Cryptosystem Based on Ideal Lattice. Journal of Information Security, 13, 165-180. https://doi.org/10.4236/jis.2022.133010</mixed-citation></ref><ref id="scirp.120004-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Lint, J.H.V. (1999) Introduction to Coding Theory. Springer-Verlag, Berlin.</mixed-citation></ref><ref id="scirp.120004-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Feige, U. and Micciancio, D. (2004) The Inapproximability of Lattice and Coding Problems with Preprocessing. Journal of Computer and System Sciences, 69, 45-67. https://doi.org/10.1016/j.jcss.2004.01.002</mixed-citation></ref><ref id="scirp.120004-ref14"><label>14</label><mixed-citation publication-type="book" xlink:type="simple">Micciancio, D. and Regev, O. (2009) Lattice-based Cryptography. In: Bernstein, D.J., Buchmann, J. and Dahmen, E., Eds., Post-Quantum Cryptography, Springer, Berlin, Heidelberg, 147-191. https://doi.org/10.1007/978-3-540-88702-7_5</mixed-citation></ref><ref id="scirp.120004-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Peikert, C. (2016) A Decade of Lattice Cryptography. Foundations and Trends in Theoretical Computer Science. NOW Publishers, Boston. https://doi.org/10.1561/9781680831139</mixed-citation></ref><ref id="scirp.120004-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Plantard, T. and Schneider, M. (2013) Creating a Challenge for Ideal Lattices. IACR Cryptology ePrint Archive, Paper 2013/039.</mixed-citation></ref><ref id="scirp.120004-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Pradhan, P.K., Rakshit, S. and Datta, S. (2019) Lattice Based Cryptography: Its Applications, Areas of Interest and Future Scope. Proceedings of the 3rd International Conference on Computing Methodologies and Communication, Erode, 27-29 March 2019, 988-993. https://doi.org/10.1109/ICCMC.2019.8819706</mixed-citation></ref><ref id="scirp.120004-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Stehle, D. and Steinfeld, R. (2011) Making NTRU as Secure as Worst-Case Problems over Ideal Lattices. 30th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tallinn, 15-19 May 2011, 27-47. https://doi.org/10.1007/978-3-642-20465-4_4</mixed-citation></ref><ref id="scirp.120004-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">El-Saady, K. and Al-Nabbat, F. (2015) Ideal Convergence in Generalized Topological Molecular Lattices. Advances in Pure Mathematics, 5, 653-659. https://doi.org/10.4236/apm.2015.511059</mixed-citation></ref><ref id="scirp.120004-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Micciancio, D. and Regev, O. (2007) Worst-Case to Average-Case Reductions Based on Gaussian Measures. SIAM Journal on Computing, 37, 267-302. https://doi.org/10.1137/S0097539705447360</mixed-citation></ref><ref id="scirp.120004-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Banaszczyk, W. (1993) New Bounds in Some Transference Theorems in the Geometry of Numbers. Mathematische Annalen, 296, 625-635. https://doi.org/10.1007/BF01445125</mixed-citation></ref></ref-list></back></article>