Skip to main navigation Skip to search Skip to main content

Compact Lattice-Coded (Multi-recipient) Kyber Without CLT Independence Assumption

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

This work presents a joint design of encoding and encryption procedures for public key encryptions (PKEs) and key encapsulation mechanism (KEMs) such as Kyber, without relying on the assumption of independent decoding noise components, achieving reductions in both communication overhead (CER) and decryption failure rate (DFR). Our design features two techniques: ciphertext packing and lattice packing. First, we extend the Peikert-Vaikuntanathan-Waters (PVW) method to Kyber: ℓ plaintexts are packed into a single ciphertext. This scheme is referred to as P-Kyber. We prove that the P-Kyber is IND-CCA secure under the M-LWE hardness assumption. We show that the decryption decoding noise entries across the ℓ plaintexts (also known as layers) are mutually independent. Second, we propose a cross-layer lattice encoding scheme for the P-Kyber, where every ℓ cross-layer information symbols are encoded to a lattice point. This way we obtain a coded P-Kyber, where the decoding noise entries for each lattice point are mutually independent. Therefore, the DFR analysis does not require the assumption of independence among the decryption decoding noise entries. Both DFR and CER are greatly decreased thanks to ciphertext packing and lattice packing. We demonstrate that with ℓ=24 and Leech lattice encoder, the proposed coded P-KYBER1024 achieves DFR <2-281 and CER =4.6, i.e., a decrease of CER by 90% compared to KYBER1024. If minimizing CPU runtime is the priority, our C implementation shows that the E8 encoder provides the best trade-off among runtime, CER, and DFR. Additionally, for a fixed plaintext size matching that of standard Kyber (256 bits), we introduce a truncated variant of P-Kyber that deterministically removes ciphertext components carrying surplus information bits. Using ℓ=8 and E8 lattice encoder, we show that the proposed truncated coded P-KYBER1024 achieves a 10.2% reduction in CER and improves DFR by a factor of 230 relative to KYBER1024. Finally, we demonstrate that constructing a multi-recipient PKE and a multi-recipient KEM (mKEM) using the proposed truncated coded P-KYBER1024 results in a 20% reduction in bandwidth consumption compared to the existing schemes.

Original languageEnglish
Title of host publicationAdvances in Cryptology - ASIACRYPT 2025 - 31st International Conference on the Theory and Application of Cryptology and Information Security Melbourne, VIC, Australia, December 8–12, 2025 Proceedings, Part III
EditorsGoichiro Hanaoka, Bo-Yin Yang
Place of PublicationSingapore Singapore
PublisherSpringer
Pages363-395
Number of pages33
ISBN (Electronic)9789819550999
ISBN (Print)9789819550982
DOIs
Publication statusPublished - 2026
EventInternational Conference on the Theory and Application of Cryptology and Information Security 2025 - Melbourne, Australia
Duration: 8 Dec 202512 Dec 2025
Conference number: 31st
https://link.springer.com/book/10.1007/978-981-95-5116-3 (Published proceedings)
https://asiacrypt.iacr.org/2025/ (Website)

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume16247
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Conference on the Theory and Application of Cryptology and Information Security 2025
Abbreviated titleASIACRYPT 2025
Country/TerritoryAustralia
CityMelbourne
Period8/12/2512/12/25
Internet address

Keywords

  • Ciphertext expansion
  • Ciphertext packing
  • Key Encapsulation Mechanisms
  • Lattice packing
  • Module leaning with errors
  • Multi-Recipient
  • Public key encryption

Cite this