Table 5. The parameter comparison for the NTRU/D-NTRU-based IND-CCA2 KEM schemes.
| ntruhps (Chen et al., 2022) | Ours | |
|---|---|---|
| Assumption | NTRU | D-NTRU |
| Lattice dimension (N) | Prime | Prime |
| Modulo value (q) | gcd(
) = 1 gcd( ) = 1 prime |
|
| Error bound | ||
| SPD ( ) | T | |
| RPD ( ) | ||
| RPD ( ) | T | |
| Message distribution | T | |
| IND-CCA2 structure | NAEP padding | One-way encryption function |
Note:
SPD, secret polynomial distribution; RPD, random polynomial distribution; T, ternary polynomials; , the subset of . coefficient of is equal to 1, the remaining coefficient is equal to −1.