Compact and Efficient KEMs over NTRU Lattices
Zhichuang Liang, Boyue Fang, Jieyu Zheng, Yunlei Zhao

TL;DR
This paper introduces new NTRU-based KEM schemes, CTRU and CNTR, that achieve better integrated performance, smaller ciphertexts, and faster computation compared to existing LWE-based and NTRU schemes, with strong security guarantees.
Contribution
The paper presents the first NTRU-based KEM schemes with scalable ciphertext compression and superior overall performance, bridging lattice codes with NTRU cryptography.
Findings
CNTR-768 has 12% smaller ciphertext than Kyber.
CNTR-768 is faster than Kyber-768 by up to 2.6X.
CNTR-768 outperforms NTRU-HRSS in ciphertext size and speed.
Abstract
The NTRU lattice is a promising candidate to construct practical cryptosystems, in particular key encapsulation mechanism (KEM), resistant to quantum computing attacks. Nevertheless, there are still some inherent obstacles to NTRU-based KEM schemes in having integrated performance, taking security, bandwidth, error probability, and computational efficiency \emph{as a whole}, that is as good as and even better than their \{R,M\}LWE-based counterparts. In this work, we solve this problem by presenting a new family of NTRU-based KEM schemes, referred to as CTRU and CNTR. By bridging low-dimensional lattice codes and high-dimensional NTRU-lattice-based cryptography with careful design and analysis, to the best of our knowledge CTRU and CNTR are the first NTRU-based KEM schemes with scalable ciphertext compression via only one \emph{single} ciphertext polynomial, and are the first that could…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCoding theory and cryptography · Cryptography and Data Security · Cryptographic Implementations and Security
