What a Lattice Is
August 25, 20265 min readbeginner
Here is the whole definition, and it is one word different from the previous note.
Here is the whole definition, and it is one word different from the previous note.
A lattice is the set of all linear combinations of a fixed set of vectors, where the coefficients are required to be integers.
That is it. Not real numbers. Integers.
01.What the restriction does
In Vectors and the Plane, letting and range over all real numbers with and produced the entire plane, every point of it, with no gaps.
Now require and to be whole numbers. You can take once, or twice, or minus three times. You cannot take it half a time.
The result is a set of isolated points. They go on forever in every direction, they are spread evenly, and between any two of them there is empty space. A grid rather than a surface.
That emptiness is where every hard problem in this chapter comes from. It is worth saying plainly, because it is easy to read past: a lattice is hard to work with precisely because you cannot take fractional steps. If you could, everything below would be schoolbook algebra.
The relationship is the same as the one between and from Sets and Notation. The real line is continuous. The integers sitting inside it are a lattice in one dimension.
02.The simplest lattice
Take the standard basis and , and allow only integer coefficients. The combinations give exactly the points with whole-number coordinates:
This is graph paper. Every corner where two ruled lines cross is a point of , and nothing in between is.
is the same idea in dimensions and is the standard against which other lattices are compared.
03.A skewed lattice, worked by hand
Now use the basis from the previous note, and , with integer coefficients only. Every lattice point has the form
Compute a few. Each line is one substitution and two small sums.
| point | what it is | |
|---|---|---|
| the origin | ||
Check the fifth row by hand: .
Plotted, these fill out an infinite grid that has been sheared. The cells are rhombuses rather than squares, but the pattern is perfectly regular and repeats forever.
The dashed parallelogram is the cell spanned by the two basis vectors. Copies of it, placed at every lattice point, tile the plane with no gaps and no overlaps. That observation becomes a measurement in Measuring a Lattice: Determinant and Minkowski's Theorem.
04.The general definition
Two dimensions was for drawing. The definition works in any number.
Let be linearly independent vectors in . The lattice they generate is
It is usually more convenient to pack the basis vectors as the columns of a matrix. Writing
for the running example, the lattice is
which reads as "take every integer vector and multiply it by ". The matrix form is what an implementation actually uses.
Two words of vocabulary. The number of basis vectors is the rank. The dimension of the space they live in is the embedding dimension. When the lattice is full-rank, meaning it is spread through the whole space rather than confined to a lower-dimensional slice inside it. Essentially every lattice in cryptography is full-rank, including the running example, where .
For scale: the lattices inside ML-KEM have rank per polynomial, with two, three or four polynomials stacked depending on the parameter set. So the real object is a full-rank lattice in , or dimensions. Everything on this page is still true of it. You just cannot draw it.
The next note takes this one lattice and describes it two different ways, and the difference between those two descriptions is where the cryptography comes from.