LLL Lattice Reduction Tool
One instance per line according to the input mode: lattice -> one basis vector per line; knapsack -> a1,...,an; S; publickey -> w1,...,wn; c
Input mode:   Algorithm:   
  Basis output:   Iteration steps:      
     
Calculation Result Download CSV
No. Type Vector / item Value Note

Introduction to the tool and how to use it

This tool is for cryptography education and security research: it shows why LLL lattice basis reduction works and why low-density subset-sum (knapsack) ciphers can be broken. Use it for learning and authorised testing only - never to attack systems you do not own.

Each input line is one instance, interpreted according to the input mode: lattice - one basis vector per line (e.g. 1,1,1); knapsack - a1,...,an; S (e.g. 1,3,5,11,21; 24); publickey - knapsack public key plus ciphertext w1,...,wn; c.

Precision trade-off: basis vectors are kept exact with BigInt while the Gram-Schmidt mu coefficients and the squared norms of b* use JavaScript Number floats. This keeps the code simple and fast; it is reliable as long as each value has at most maxBits digits (default 128), and longer values are reported explicitly.

Limits: dimension up to maxDim (default 12, since LLL is O(n^4)), maxBits digits per value, at most 10000 iterations (reported instead of hanging) and maxRows output rows. After the knapsack attack finds a solution it always verifies the subset sum equals the target; if verification fails or no short vector appears it reports "not recovered this time (density too high / dimension too large)" rather than claiming success.

Message board

All messages →
0/200

  • No one has spoken up yet — want to go first?