Paper 2026/1701

DTRU: A Versatile, Compact, Simple, and Robust NTRU KEM with Double $E_8$ Encoding

Hengchuan Zou, Fudan University
Songlin Li, Fudan University
Jieyu Zheng, Fudan University
Xiaowen Hu, Fudan University
Hanyu Wei, Fudan University
Weizhi Ao, Fudan University
Yifan Dong, Fudan University
Wenbo Guo, Fudan University
Yunlei Zhao, Fudan University
Abstract

Responding to China's 2025 call for commercial cryptographic standards mandating 128-bit, 256-bit, and 512-bit security (optional 384-bit), we propose DTRU, a versatile, compact, simple, and robust NTRU-based key encapsulation mechanism (KEM). Our principal design contribution is double $E_8$ encoding, which constructs 16-dimensional lattice codes from $E_8$ with low decoding complexity. We further provide a detailed analysis of decryption-failure probability under this encoding mechanism. DTRU's design achieves a careful balance among versatility, compactness, simplicity, and robustness. To accommodate diverse application requirements, it supports multiple ring structures, including power-of-two cyclotomic rings, tricyclotomic rings, and large-Galois-group prime-degree prime-ideal number fields (LPPNF). The double $E_8$ encoding enables DTRU to achieve enhanced error correction with compact bandwidth. The design prioritizes simplicity to facilitate deployment on low-power devices, achieved by eschewing additional coefficient compression techniques and redundant invertibility checks during key generation, while enabling circuit/code reuse. Security robustness is guaranteed through parameter selections that offer adequate security redundancy, mitigating potential cyclotomic ring risks via LPPNF, and precluding sparse noise distributions in the recommended parameter sets. Complementing our theoretical advances, we present comprehensive implementations of all the parameter sets with dedicated support for C, AVX2, and ARM platforms, leveraging architecture-specific optimizations. For example, compared to NTRU-HRSS and Kyber at the same security levels, our KEM is 49%-52% more compact and 3.84–15.69$\times$ faster than NTRU-HRSS in the round-trip time of ephemeral key exchange, and is 7%-27% more compact and 1.05–1.32$\times$ faster than Kyber.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Minor revision. ESORICS 2026
Keywords
Lattice based CryptographyNTRUKey Encapsulation Mechanism
Contact author(s)
hczou25 @ m fudan edu cn
slli22 @ m fudan edu cn
jyzheng23 @ m fudan edu cn
xiaowenhu_hust @ 163 com
hywei24 @ m fudan edu cn
wzao25 @ m fudan edu cn
yfdong24 @ m fudan edu cn
guowenbo @ fudan edu cn
ylzhao @ fudan edu cn
History
2026-08-16: approved
2026-08-16: received
See all versions
Short URL
https://ia.cr/2026/1701
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1701,
      author = {Hengchuan Zou and Songlin Li and Jieyu Zheng and Xiaowen Hu and Hanyu Wei and Weizhi Ao and Yifan Dong and Wenbo Guo and Yunlei Zhao},
      title = {{DTRU}: A Versatile, Compact, Simple, and Robust {NTRU} {KEM} with Double $E_8$ Encoding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1701},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1701}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.