arXiv Science⌕ Search

arXiv · 2609.34996

Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli

Abstract

The Learning With Errors (LWE) problem is a fundamental assumption in post-quantum cryptography. Regev established a quantum reduction from LWE to the Dihedral Coset Problem (DCP). Later, Brakerski et al. introduced the Extrapolated Dihedral Coset Problem (EDCP), proving its equivalence to LWE. However, unlike DCP, EDCP no longer admits a coset structure. This limits the direct application of techniques for hidden subgroup problems. In this work, we introduce the Cyclotomic Coset Problem (CCP), a cyclotomic generalization of DCP that preserves an exact hidden-subgroup structure. Let $ζ_p$ be a primitive $p$-th root of unity, let $π=ζ_p-1$, and write $q=p^t$ and $L=t(p-1)$. We work over $R_q=\mathbb Z_q[ζ_p] \cong \mathbb Z[ζ_p]/(π^L)$, where the isomorphism follows from the total ramification identity $(p)=(π)^{p-1}$. We exploit the resulting $π$-adic ideal chain to construct a quantum sieve that successively reduces phase states modulo $π^{L},π^{L-1},\ldots,π$. For every fixed prime $p$ and modulus $q=p^t$, our algorithm solves the CCP in time and sample complexity $2^{O_p(\log n\log q)}$, using polynomial quantum space. The sieve also applies to uniform EDCP and Gaussian S|LWE>, yielding quasi-polynomial time algorithms for all the above problems when $q=\text{poly}(n)$. This extends the power-of-two EDCP sieve of Bai et al. (CRYPTO 2025) to a cyclotomic setting. However, we emphasize that our result does not, by itself, yield a quasi-polynomial-time algorithm for standard LWE, because the currently known reduction produces only a limited number of approximate CCP states.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Mathias Boucher, Pierre-Alain Fouque, Yixin Shen. 2026-09-28. Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli. https://arxiv.org/abs/2609.34996

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Self-duality and Jordan structure of quantum theory follow from homogeneity and pure transitivity

Quantum theory satisfies the mathematically powerful property of self-duality, meaning that its state and effect spaces are made isomorphic by an inner product. This is why both quantum states and effects can be represented by positive Hermitian operators. The seminal Koecher-Vinberg theorem shows that self-duality is a rather special property: any system that is self-dual and also homogeneous, meaning that the group of symmetries of its cone of unnormalised states acts transitively on the strictly positive states, must be isomorphic to a Euclidean Jordan algebra. EJAs have been classified and are known to be just a slight generalisation of quantum systems. This is why the Koecher-Vinberg theorem, and hence self-duality and homogeneity, have been used in several reconstructions of quantum theory from first principles. While homogeneity has an operational derivation from the ability to steer states, self-duality currently lacks such a clear operational motivation. In this paper we prove an alternative to the Koecher-Vinberg theorem, substituting for self-duality the more operational property of pure transitivity: symmetries of the normalised state space act transitively on the pure states. We show that any system that is homogeneous and satisfies pure transitivity must be self-dual, and hence isomorphic to an EJA. Together with various ways of singling out the complex matrix algebras from among EJAs, and known ways of ruling out classicality in these, this yields several new and concise reconstructions of quantum theory. For example, quantum systems, classical systems, and composites of these are the only ones that are homogeneous, satisfy pure transitivity, and allow locally tomographic composites; fully quantum systems are the only ones that are homogeneous, have continuous pure transitivity, and allow a correspondence between observables and generators of reversible transformations.

quant-ph↗

Quantum algorithm for the gradient of a logarithm-determinant

The logarithm-determinant is a widely-present operation in many areas of physics and computer science. Derivatives of the logarithm-determinant compute physically relevant quantities in statistical physics models, quantum field theories, as well as the inverses of matrices. A multi-variable version of the quantum gradient algorithm is developed here to evaluate the derivative of the logarithm-determinant. From this, the pseudo-inverse of a sparse-rank input operator may be determined efficiently. Measuring an expectation value of the quantum state--instead of all $N^2$ elements of the input operator--can be accomplished in $O(k/\varepsilon^2)$ time in the idealized case for $k$ relevant eigenvectors of the input matrix with precision $\varepsilon$. A practical implementation of the required operator will likely need $\log_2N$ overhead, giving an overall complexity of $O((k\log_2 N)/\varepsilon^2)$. The method applies widely and converges super-linearly in $k$ when the condition number is high. The best classical method we are aware of scales as $N$. Given the same resource assumptions as other algorithms, such that an equal superposition of eigenvectors is available efficiently, the algorithm is evaluated in the practical case as $O(\log_2 N/\varepsilon^2)$. The output is given in $O(1)$ queries of an oracle, which is given explicitly here and only relies on time-evolution operators that can be implemented with arbitrarily small error. The algorithm is envisioned for fully error-corrected quantum computers but may be implementable on near-term machines. We discuss how this algorithm can be used for kernel-based quantum machine-learning.

quant-ph↗

Spinor Bose-Einstein condensate as an analog simulator of molecular bending vibrations

We demonstrate that spinor Bose-Einstein condensates (BECs) can be operated as an analog simulator of the two-dimensional vibron model. This algebraic model describes bending vibrations of molecules and, in the case of triatomic molecules, exhibits two phases where linear and bent configurations are stabilised. Spinor BECs can be engineered to simulate states that correspond to linear or bent triatomic molecules, with the Wigner function of the BEC encoding information about the molecular configuration. We show how quantum simulations of the bending dynamics of linear molecules can be realised, and how preparing a linear configuration in the bent phase leads to a dynamical instability. In the dynamics triggered by the corresponding instability, a significant amount of entanglement is generated, and we characterise the dynamics with the squeezing parameter and the quantum Fisher information (QFI). The scaling of the non-Gaussian sensitivity, described by the difference between squeezing and QFI, grows with the system size once the spinor system crosses from the linear to the bent phase, thus serving as a dynamical witness for the quantum phase transition.

quant-ph↗