We consider a key encapsulation mechanism (KEM) based on Module-LWE where reconciliation is performed on the 8-dimensional lattice $E_8$, which admits a fast CVP algorithm. Our scheme generates 256 bits of key and requires 3 or 4 bits of reconciliation per dimension. We show that it can outperform Kyber in terms of the modulus q with comparable error probability. We prove that our protocol is IND-CPA secure and improves the security level of Kyber by 7.3%.
翻译:我们考虑的是基于模块-LWE的关键封装机制(KEM),根据模块-LWE,对8维方格的8美元进行对账,这允许快速的 CVP 算法。我们的计划生成256位键,每个维度需要3或4位调和。我们显示,它能够以差错概率可比的模模数 q 优于Kyber。我们证明,我们的协议是IND-CPA安全的,并且提高了Kyber的安保水平7.3%。