Research

Watch · narrated whiteboard episodesL3

Lattice Foundations: The Hard Problems Behind the New Standards

ML-KEM and ML-DSA rest on one family of assumptions — Learning With Errors and its structured variants. The lattice problems, the worst-case-to-average-case reductions, and the concrete parameter methodology, derived from scratch. Grounded in the primary papers.

Murali Chillakuru·5 episodes
  1. 17 min Episode 1Lattices and Their Hard Problems: SVP, CVP, and the Geometry of SecurityA moderator and a cryptography expert build the foundation of lattice cryptography from the ground up — what a lattice is, why a good basis is a trapdoor, the canonical hard problems, and why worst-case hardness makes lattices such a trustworthy anchor.
  2. 18 min Episode 2Learning With Errors: The Distribution, the Decision-Search Equivalence, and Regev's ReductionA moderator and a cryptography expert unpack Learning With Errors — the workhorse assumption behind modern lattice crypto — showing how a pinch of deliberate noise turns easy linear algebra into a quantum-hard problem, and how it connects back to lattice geometry.
  3. 18 min Episode 3Ring-LWE and Module-LWE: Buying Efficiency with Algebraic StructureA moderator and a cryptography expert show how plain LWE's big keys get shrunk by adding algebraic structure — Ring-LWE's dramatic compression, the extra attack surface it introduces, and why Module-LWE's tunable middle ground won standardization.
  4. 18 min Episode 4Parameters and the Security Estimate: Core-SVP, BKZ Block Size, and NIST LevelsA moderator and a cryptography expert demystify lattice security estimation — the lattice-reduction attack that sets the bar, the conservative Core-SVP cost model, how block size maps to security levels, and why a moving target is absorbed by margin.
  5. 19 min Episode 5Where the Assumptions Could Fail: Algebraic and Dual Attacks on Structured LatticesA moderator and a cryptography expert close the series with intellectual honesty — the three ways lattice cryptography could conceivably fail, why none of them is a present danger, and how to build systems that respect the residual uncertainty.