NTRU leads to Anonymous, Robust Public-Key Encryption

Keita Xagawa

Abstract: This short note shows that NTRU in NIST PQC Round~3 finalist is anonymous in the QROM if the underlying NTRU PKE is strongly disjoint-simulatable and a hybrid PKE scheme constructed from NTRU as KEM and appropriate DEM is anonymous and robust.

This solves the open problem to investigate anonymity and robustness of NTRU posed by Grubbs, Maram, and Paterson (Cryptography ePrint Archive 2021/708).}

Category / Keywords: public-key cryptography / anonymity, robustness, post-quantum cryptography, NIST PQC standardization, KEM, PKE

Date: received 3 Jun 2021, last revised 3 Jun 2021

Contact author: keita xagawa zv at hco ntt co jp

Version: 20210603:151357 (All versions of this report)

