TY - JOUR
ID - 23172
TI - A Provably Secure Variant of ETRU Based on Extended Ideal Lattices Over Direct Product of Dedekind Domains
JO - Journal of Computing and Security
JA - JCS
LA - en
SN - 2322-4460
AU - Ebrahimi Atani, Reza
AU - Ebrahimi Atani, Shahabaddin
AU - Hassani Karbasi, Amir
AD - Department of Computer Engineering, University of Guilan, P. O. Box 3756, Rasht, Iran.
AD - Department of Mathematics, University of Guilan, P. O. Box 1914, Rasht, Iran.
Y1 - 2018
PY - 2018
VL - 5
IS - 1
SP - 13
EP - 34
KW - Lattice-Based Cryptography
KW - ETRU
KW - Ideal Lattices
KW - Dedekind Domains
KW - Provable Security
DO - 10.22108/jcs.2018.106856.0
N2 - Jarvis and Nevins presented ETRU in 2013 which has applausive performance with moderate key-sizes and conjectured resistance to quantum computers. ETRU, as an efficient NTRUEncrypt-like cryptosystem, is over the ring of Eisenstein integers that is faster with smaller keys for the same or better level of security than does NTRUEncrypt which is a desirable alternative to public-key cryptosystems based on factorisation and discrete logarithm problem. However, because of its construction, doubts have regularly arisen on its security. In this paper, we propose how to modify ETRU to make it provably secure, under our modified assumption of quantum hardness of standard worst-case lattice problems, restricted to extended ideal lattices related to some extensions of cyclotomic fields structures. We describe the structure of all generated polynomial rings of quotient over direct product of Dedekind domains Z and Z[ζ3], where ζ3 is complex cube root of unity. We give a detailed description to show that if the private key polynomials of the ETRU are selected from direct product of some Dedekind domains using discrete Gaussians, then the public key, which is their ratio, is statistically indistinguishable from uniform over its range. The security then proves for our main system from the already proven hardness of the R-SIS and R-LWE problems by their extensions.
UR - http://jcomsec.ui.ac.ir/article_23172.html
L1 - http://jcomsec.ui.ac.ir/article_23172_72dc58a05ff98b8579781b5cbd9ccce7.pdf
ER -