Introduction

Lore is a lattice-based key encapsulation mechanism based on the Module Learning with Rounding (Module-LWR) problem. It combines a variable modulus with Chinese Remainder Theorem (CRT) compression to reduce public-key and ciphertext sizes while controlling the decryption failure rate.

Specification & software

SpecificationICCS · PDF
ImplementationsICCS · ZIP

All resources

Parameters

Classical security targets are given in bits; key and ciphertext sizes are given in bytes as reported in the specification. Bandwidth is calculated as public key plus ciphertext. The supplied implementations use different serialized sizes. The specification treats the SHAKE/SM3 backends for the 384- and 512-bit targets as temporary reference implementations.

Lore instance sizes and security parameters
InstanceClassical security
target
Public keySecret keyCiphertextBandwidth
Lore-1281285458216411186
Lore-2562561058194211532211
Lore-3843841763370419213684
Lore-5125122626537328865512