LLL Lattice Reduction Tool
One instance per line according to the input mode: lattice -> one basis vector per line; knapsack -> a1,...,an; S; publickey -> w1,...,wn; c
Input mode:
Algorithm:
Basis output:
Iteration steps:
Calculation Result
Download CSV
| No. | Type | Vector / item | Value | Note |
|---|
Introduction to the tool and how to use it
This tool is for cryptography education and security research: it shows why LLL lattice basis reduction works and why low-density subset-sum (knapsack) ciphers can be broken. Use it for learning and authorised testing only - never to attack systems you do not own.
Each input line is one instance, interpreted according to the input mode:
Precision trade-off: basis vectors are kept exact with BigInt while the Gram-Schmidt mu coefficients and the squared norms of b* use JavaScript Number floats. This keeps the code simple and fast; it is reliable as long as each value has at most maxBits digits (default 128), and longer values are reported explicitly.
Limits: dimension up to maxDim (default 12, since LLL is O(n^4)), maxBits digits per value, at most 10000 iterations (reported instead of hanging) and maxRows output rows. After the knapsack attack finds a solution it always verifies the subset sum equals the target; if verification fails or no short vector appears it reports "not recovered this time (density too high / dimension too large)" rather than claiming success.
Each input line is one instance, interpreted according to the input mode:
lattice - one basis vector per line (e.g. 1,1,1); knapsack - a1,...,an; S (e.g. 1,3,5,11,21; 24); publickey - knapsack public key plus ciphertext w1,...,wn; c.Precision trade-off: basis vectors are kept exact with BigInt while the Gram-Schmidt mu coefficients and the squared norms of b* use JavaScript Number floats. This keeps the code simple and fast; it is reliable as long as each value has at most maxBits digits (default 128), and longer values are reported explicitly.
Limits: dimension up to maxDim (default 12, since LLL is O(n^4)), maxBits digits per value, at most 10000 iterations (reported instead of hanging) and maxRows output rows. After the knapsack attack finds a solution it always verifies the subset sum equals the target; if verification fails or no short vector appears it reports "not recovered this time (density too high / dimension too large)" rather than claiming success.
Message board
All messages →-
No one has spoken up yet — want to go first?