“in 2^[0.6039n+o(n)] time” could be a better edit than the paper’s provided title, though I selected [] rather than {} for human use. I defer to experts in the field on whether it matters to declare O(n) or not.
And yes the o(n) is relevant. Though I guess implied to some extent.
So it's tangentially related, but does not itself imply an improvement on the (heuristically assumed) SOTA for these problems.
Since when? Can you cite the relevant paper(s)?
https://eprint.iacr.org/2022/922.pdf
for some history
https://eprint.iacr.org/2022/922.pdf
it's hard to precisely analyze BDGL16, but to leading order it takes ~ (3/2)^n time, which is roughly 2^{.292n} time.
When I say it takes roughly this amount of time, this is likely modulo several heuristics. With the caveat that I'm not a lattice cryptanalyst, my understanding of the heuristics is the following. BDGL16 is a "sieving" algorithm. To find a short vector v, you
1. start with many long vectors v1, ..., vn.
2. take their pairwise differences. this may produce shorter vectors (and if vi are suitably randomly distributed, this is provably true).
3. repeat
there are other tricks on top of that you do, but that's the conceptual core. As I mentioned, if the
1. initial vi were suitably randomly distributed, and
2. you could prove the pairwise differences were also suitably randomly distributed
you could likely get a provable running time bound on things. At least the 2nd likely breaks down (maybe the first as well though), so you instead only get a running time bound under the above 1+2 heuristic assumptions. In cryptanalysis this is typically viewed as good enough, as long as the heuristics are solid (for example, SOTA for factoring, the Number Field Sieve, only has heuristically understood running time iirc).
This paper is instead about provable algorithms. They can be conceptually interesting, and useful if there is not community consensus that the heuristics are solid. But in lattice cryptography everyone thought BDGL16 used reasonable heuristics, so SVP took 2^{0.292n} time practically, even if it was too difficult to formally prove this.
It's not clear if this is solely a possible theoretical result or if it has any practical value. I.e. is it only useful on lattices that are so large as to not be of use, or could it be used for cryptanalysis? If one is using AI to generate a theory paper such as this, why not use the AI to also generate code that uses it, put it on GitHub, and show the results, say against fplll and the tool in the paper below?