vix.ing · top · new · best · stats · spec

Error Correction for FrodoKEM Using the Gosset Lattice

2021/10/04 by Charbel Saliba, Saliba, Charbel, Laura Luzzi +3
Computer Science · #Cryptographic Implementations and Security #Cryptography and Data Security #Cryptography and Residue Arithmetic #Cryptography and Security (cs.CR) #FOS: Computer and information sciences

paper · pdf · doi:10.48550/arxiv.2110.01740

openalex publication_date 2021/10/04 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

We consider FrodoKEM, a lattice-based cryptosystem based on LWE, and propose a new error correction mechanism to improve its performance. Our encoder maps the secret key block-wise into the Gosset lattice E8. We propose two sets of parameters for our modified implementation. Thanks to the improved error correction, the first implementation outperforms FrodoKEM in terms of concrete security by 10 to 13 bits by increasing the error variance; the second allows to reduce the bandwidth by 7% by halving the modulus q. In both cases, the decryption failure probability is improved compared to the original FrodoKEM. Unlike some previous works on error correction for lattice-based protocols, we provide a rigorous error probability bound by decomposing the error matrix into blocks with independent error coefficients.

Citations

Related