the hardness assumption behind most practical lattice cryptography: given noisy inner products of a secret vector over a module of polynomial rings, recover the secret. the noise makes the linear system computationally opaque β solving it is as hard as worst-case lattice problems like the shortestβ¦