
At Asiacrypt'25, Lapiha & Prest proposed a lattice-based TKEM from a TIBE & signatures, but with 540 KiB ciphertexts. We optimize it via random oracles, approximate computing, and NTRU trapdoors, reducing ciphertext size 18x to under 30 KiB. hubs.li/Q04gPMsR0 #pqc #TKEM

English
















