Our conclusion is that the basic LPN-based scheme is in several respects not competitive with existing practical schemes, as the public key, ciphertexts and encryption time become very large already for 80-bit security. On the other hand, the scheme based on transposed Ring-LPN is far better in all these respects. Although the public key and ciphertexts are still larger than for, say, RSA at comparable security levels, they are not prohibitively large; moreover, for decryption, the scheme outperforms RSA for security levels of 112 bits or more. The Ring-LPN based scheme is less efficient, however. Thus, LPN-based public-key cryptography seems to be somewhat more promising for practical use than has been generally assumed so far.
Category / Keywords: LPN, ring-LPN, public-key encryption Date: received 11 Dec 2012, last revised 21 Apr 2014 Contact author: sunoo at csail mit edu Available format(s): PDF | BibTeX Citation Note: This version takes into account the recent attacks on LPN that invalidated the conclusions of the previous version. Version: 20140421:210907 (All versions of this report) Short URL: ia.cr/2012/699 Discussion forum: Show discussion | Start new discussion