Core functions
prf_R()
Evaluates the main pseudorandom function to generate a randomizer element.const PubKey&
Public key containing system parameters
const SecKey&
Secret key containing PRF keys and LPN secret
const RSeed&
Seed containing
ztag and 128-bit nonceFp
A nonzero field element in the prime field
PRF_R1, PRF_R2, and PRF_R3.
prf_R_noise()
Evaluates the noise pseudorandom function.const PubKey&
Public key containing system parameters
const SecKey&
Secret key containing PRF keys and LPN secret
const RSeed&
Seed containing
ztag and 128-bit nonceFp
A nonzero field element representing cryptographic noise
prf_R() but uses noise-specific domain separators (PRF_NOISE1, PRF_NOISE2, PRF_NOISE3) for domain separation.
prf_R_core()
Core LPN evaluation function used internally.const PubKey&
Public key containing system parameters
const SecKey&
Secret key containing PRF keys and LPN secret
const RSeed&
Seed for deterministic randomness
const char*
Domain separator string for cryptographic separation
Fp
A nonzero field element derived from LPN evaluation
Evaluation process
-
Generate LPN response - Computes
y = As + ewhere:Ais a random matrix derived from the seedsis the LPN secret from the secret keyeis Bernoulli noise with parametertau = lpn_tau_num/lpn_tau_den
- Apply Toeplitz hash - Uses a Toeplitz matrix multiplication to compress the LPN output to 127 bits
- Hash to field - Maps the 127-bit output to a nonzero field element
lpn_make_ybits()
Generates the LPN response vectory = As + e.
const PubKey&
Public key containing LPN parameters
lpn_n, lpn_t, lpn_tau_num, lpn_tau_denconst SecKey&
Secret key containing the LPN secret bits
lpn_s_bitsconst RSeed&
Seed for generating the random matrix
const char*
Domain separator string
std::vector<uint64_t>&
Output parameter receiving the computed bit vector (length
lpn_t bits)Algorithm
For each rowr = 0 to lpn_t - 1:
- Generate random row vector from PRG
- Compute dot product with secret:
dot = row · s - Generate noise bit:
e = 1with probabilitytau, elsee = 0 - Set output bit:
y[r] = dot ⊕ e
The noise parameter
tau = lpn_tau_num / lpn_tau_den determines the noise rate. Default is tau = 1/8.Cryptographic primitives
derive_aes_key()
Derives an AES-256 key and nonce from the secret key and seed.const PubKey&
Public key (used for
canon_tag and H_digest)const SecKey&
Secret key containing PRF keys
const RSeed&
Seed for key derivation
const char*
Domain separator string
uint8_t[32]
Output buffer for 256-bit AES key
uint64_t&
Output parameter for the derived nonce
- The 4 PRF keys from the secret key
- The public key’s
canon_tag - The H matrix digest
- The seed’s
ztagandnonce - The domain separator hash
hash_to_fp_nonzero()
Maps 127 bits to a nonzero field element.uint64_t
Lower 64 bits
uint64_t
Upper 63 bits (most significant bit should be 0)
Fp
A nonzero field element in constant time
1 using constant-time masking to prevent timing attacks.
fnv1a_domain()
Computes a 64-bit hash of a domain separator string.const char*
Null-terminated domain separator string
uint64_t
64-bit FNV-1a hash
AES-CTR implementation
AesCtr256
Hardware-accelerated AES-256 in counter mode.Methods
void(const uint8_t[32], uint64_t)
Initialize the cipher with a 256-bit key and 64-bit nonce
uint64_t()
Generate the next 64-bit pseudorandom value
void(uint64_t*, size_t)
Fill an array with
n pseudorandom 64-bit valuesuint64_t(uint64_t)
Generate a uniformly random value in
[0, M) without biasSecurity parameters
The default LPN parameters provide:- Information-theoretic bound: 2226 bits
- Classical security: 200+ bits
- Quantum security: 100+ bits
lpn_n = 4096(secret dimension)lpn_t = 16384(number of samples)tau = 1/8(noise rate)
The triple evaluation in
prf_R() and prf_R_noise() amplifies security beyond a single LPN call.Example usage
Related functions
toep_127()- Toeplitz matrix hashingkeygen()- Generates LPN secret during key generation