the root problem of lattice cryptography: in a lattice of points generated by integer combinations of basis vectors, find the shortest nonzero one. easy in two dimensions, believed exponentially hard in hundreds — for quantum computers too, which is why lattices survive Shor where discrete logs fall
every practical assumption above it — module learning with errors, module short integer solution — reduces to worst-case problems of this family: break the scheme anywhere, solve SVP everywhere