Proposed by: Vadim Lyubashevsky, Chris Peikert & Oded Regev (2010); module generalization by Adeline Langlois & Damien Stehlé (2015); precursor SPLWE ideas in NTRU Category: Lattice / post-quantum (structured)
Let with a power of two, .
Ring-LWE (decision). For secret (or from the error distribution), distinguish
where and (small-coefficient Gaussian in ).
Module-LWE. Interpolates between LWE and Ring-LWE: secret , samples with . Rank is Ring-LWE; recovers plain [[lwe]]. One Ring-LWE sample packs pseudorandom scalars — the source of the efficiency gain.
LPR 2010: quantum reduction from worst-case approximate SVP on ideal lattices of ; Langlois–Stehlé: from module lattices. The structured worst-case problems are possibly easier than unstructured ones (quantum unit-group algorithms give subexponential Ideal-SVP for large factors), but no attack exploits the ring structure of Ring/Module-LWE itself for standard parameters.
Same lattice attacks as unstructured LWE (BKZ core-SVP); the algebraic structure gives only constant-factor savings today. Believed exponentially hard, classically and quantumly.