Introduction
Lore is a lattice-based key encapsulation mechanism based on the Module Learning with Rounding (Module-LWR) problem. It combines a variable modulus with Chinese Remainder Theorem (CRT) compression to reduce public-key and ciphertext sizes while controlling the decryption failure rate.
Specification & software
Parameters
Classical security targets are given in bits; key and ciphertext sizes are given in bytes as reported in the specification. Bandwidth is calculated as public key plus ciphertext. The supplied implementations use different serialized sizes. The specification treats the SHAKE/SM3 backends for the 384- and 512-bit targets as temporary reference implementations.
| Instance | Classical security target | Public key | Secret key | Ciphertext | Bandwidth |
|---|---|---|---|---|---|
| Lore-128 | 128 | 545 | 821 | 641 | 1186 |
| Lore-256 | 256 | 1058 | 1942 | 1153 | 2211 |
| Lore-384 | 384 | 1763 | 3704 | 1921 | 3684 |
| Lore-512 | 512 | 2626 | 5373 | 2886 | 5512 |