Scott Fluhrer edited untitled.tex  over 8 years ago

Commit id: 0d50b3744d4faf370a92fd9eec658a93c1457f6e

deletions | additions      

       

The above shows how ring-LWE based key exchange can practically be broken if the same key share is reused.  One place where this can potentially come up is in the current TLS 1.3 draft. draft\cite{Rescorla_2015}.  These results have been specific to ring-LWE, however it would appear likely that these results would also extend to similar LWE-based protocols.