Paper 2026/2078

Radical Ring-LWR: Efficient Key Encapsulation and Signatures from Structured Rounding

Joost Renes, NXP Semiconductors
Joppe W. Bos, NXP Semiconductors
Haochen Huang, University of Chinese Academy of Sciences
Selim Kirbiyik, Graz University of Technology
Alberto Ovena, Graz University of Technology
Sujoy Sinha Roy, Graz University of Technology
Frederik Vercauteren, KU Leuven
Peng Wang, University of Chinese Academy of Sciences
Fangyu Zheng, University of Chinese Academy of Sciences
Chenxin Zhong, University of Chinese Academy of Sciences
Abstract

State-of-the-art lattice-based cryptography requires a power-of-two cyclotomic field that limits the attainable security levels, or a module structure for which the cost grows quadratically in the module rank. Radical rings were recently proposed as a solution in the context of Learning With Errors (LWE) based Key Encapsulation Mechanisms (KEMs) with heuristic hardness arguments for the Ring-LWE security and failure probability. We develop the Learning With Rounding counterpart, Radical Ring-LWR (RR-LWR). We give a proved closed-form bound on the distortion incurred from the error sampling independent of the radical ring parameters: this places RR-LWR inside the regime identified by Peikert as safe for instantiating Ring-LWE/LWR. We instantiate two schemes: Mithril, an IND-CCA KEM, and Octarine, an EF-CMA signature scheme. They are built on a single radical-ring arithmetic foundation based on powers of two (favorable for sampling, rounding and masking) and we provide security reductions in the QROM to RR-LWR and SelfTarget-RR-SIS, a radical-ring variant of SIS. We show that the KEM failure probability estimators used for power-of-two cyclotomics are insufficient and provide an exact solution tailored to the RR-LWR setting. Finally, we instantiate Mithril and Octarine with concrete parameters and benchmark optimized AVX2 and Arm Cortex-M4 implementations, showing that both are competitive with (and in some cases significantly faster than) the MLKEM and MLDSA standards.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-quantum cryptographyRadical ringsLearning with roundingKey encapsulationDigital signatures
Contact author(s)
joost renes @ nxp com
joppe bos @ nxp com
History
2026-09-19: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2078
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2078,
      author = {Joost Renes and Joppe W. Bos and Haochen Huang and Selim Kirbiyik and Alberto Ovena and Sujoy Sinha Roy and Frederik Vercauteren and Peng Wang and Fangyu Zheng and Chenxin Zhong},
      title = {Radical Ring-{LWR}: Efficient Key Encapsulation and Signatures from Structured Rounding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2078},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2078}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.