Skip to main content
. 2023 May 26;9:e1391. doi: 10.7717/peerj-cs.1391

Table 5. The parameter comparison for the NTRU/D-NTRU-based IND-CCA2 KEM schemes.

ntruhps (Chen et al., 2022) Ours
Assumption NTRU D-NTRU
Lattice dimension (N) Prime Prime
Modulo value (q) 2k gcd( q1,q2) = 1
gcd( q1,p) = 1
q1 prime
Error bound q822N3 q1>ϕ
SPD ( Lf) T L(d,d1)
RPD ( Lg) T(q/82) L(d,d1)
RPD ( Lr) T L(d,d)×Rp
Message distribution T Rp
IND-CCA2 structure NAEP padding One-way encryption function

Note:

SPD, secret polynomial distribution; RPD, random polynomial distribution; T, ternary polynomials; T(q), the subset of T. q/2 coefficient of T(q) is equal to 1, the remaining q/2 coefficient is equal to −1.