Module-LWE
August 25, 20265 min readbeginner
Ring-LWE fixes everything through one number. The ring degree n determines the key size, the security level, and the shape of the multiplication all at once.
Ring-LWE fixes everything through one number. The ring degree determines the key size, the security level, and the shape of the multiplication all at once.
That coupling is a practical problem. Raising security means raising , which changes the ring, which changes the multiplication algorithm, which changes the hardware. A chip built for one security level would not serve another.
Module-LWE breaks the coupling.
01.The definition
Keep the ring fixed, and introduce a second parameter: the module rank , a small integer.
A Module-LWE sample is a pair
where is a vector of uniform ring elements, the secret is a vector of short ring elements, the error is a short ring element, and
So the secret is now polynomials rather than one, and producing a sample takes ring multiplications rather than one.
The two extremes are worth naming, because they show that Module-LWE is not a third thing but an interpolation between the two you already know.
Set and the sum has one term, so a Module-LWE sample is exactly a Ring-LWE sample.
Set , so that collapses to and each polynomial is a single number, and a Module-LWE sample is exactly a plain LWE sample of dimension .
Everything in between is available by choosing and independently.
02.What the extra knob buys
The lattice an attacker faces has dimension . That product is what determines security.
Because it is a product, security can be raised by increasing either factor. Module-LWE raises and leaves alone.
The consequence is the one that mattered to the standards committee. Every ML-KEM parameter set uses and . Every ML-DSA parameter set uses and . Only changes across security levels.
So one implementation of the length- transform serves every parameter set of a scheme. In software that means one optimised routine rather than three. In hardware it means one datapath, and a chip that can be configured for any security level without re-synthesis. For a book whose eventual subject is hardware acceleration, this is the single most consequential design decision in the standards.
03.The parameter sets
| Scheme | module shape | effective lattice dimension | ||
|---|---|---|---|---|
| ML-KEM-512 | 256 | 3329 | 512 | |
| ML-KEM-768 | 256 | 3329 | 768 | |
| ML-KEM-1024 | 256 | 3329 | 1024 | |
| ML-DSA-44 | 256 | 8380417 | 1024 | |
| ML-DSA-65 | 256 | 8380417 | 1536 | |
| ML-DSA-87 | 256 | 8380417 | 2048 |
Two things to read out of the table.
The numbers in the ML-KEM names are the effective lattice dimensions, not key sizes. ML-KEM-768 works over a lattice of dimension , and it is the parameter set NIST recommends as the general-purpose default.
ML-DSA carries two ranks rather than one. Signature schemes need a rectangular matrix, rows by columns, because signing and verification are not symmetric operations the way encryption and decryption are. Chapter 6 explains where each dimension goes.
Why not just use Ring-LWE with a bigger
Given that Ring-LWE is simpler, the obvious question is why the standards took on the extra parameter.
Three reasons, in increasing order of importance.
Powers of two are coarse. Ring degrees have to be powers of two for the transform to work, so the available security levels with pure Ring-LWE would be , then , then . That is a factor of two between adjacent levels, with nothing in between. Module rank gives , , , which is finer and lets ML-KEM-768 exist at all.
Hardware reuse, as above. One transform length serves everything.
And structure hedging. Ring-LWE at dimension needs a single ring of degree , which is a large algebraic object with correspondingly more structure for an attacker to exploit. Module-LWE at effective dimension uses four independent polynomials of degree each. The algebraic structure is confined to each degree- piece, and the relationship between the pieces is unstructured, exactly as in plain LWE. If a future attack exploits ring structure, it has a quarter as much to work with.
Module-LWE is therefore the deliberate middle of the range: most of Ring-LWE's compression, some of plain LWE's lack of structure, and a security knob that leaves the arithmetic alone.
The rest of this chapter is about that arithmetic, and specifically about making fast.