NTRU-based Bootstrapping for MK-FHEs without using Overstretched Parameters

Published: 01 Jan 2024, Last Modified: 11 Feb 2025IACR Cryptol. ePrint Arch. 2024EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Recent attacks on NTRU lattices given by Ducas and van Woerden (ASIACRYPT 2021) showed that for moduli $q$ larger than the so-called fatigue point $n^{2.484+o(1)}$, the security of NTRU is noticeably less than that of (ring)-LWE. Unlike NTRU-based PKE with $q$ typically lying in the secure regime of NTRU lattices (i.e., $q
Loading