The LPN module implements the Learning Parity with Noise primitive used for pseudorandom function evaluation in PVAC-HFHE.Documentation Index
Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt
Use this file to discover all available pages before exploring further.
Core functions
prf_R()
Evaluates the main pseudorandom function to generate a randomizer element.Public key containing system parameters
Secret key containing PRF keys and LPN secret
Seed containing
ztag and 128-bit nonceA nonzero field element in the prime field
PRF_R1, PRF_R2, and PRF_R3.
prf_R_noise()
Evaluates the noise pseudorandom function.Public key containing system parameters
Secret key containing PRF keys and LPN secret
Seed containing
ztag and 128-bit nonceA nonzero field element representing cryptographic noise
prf_R() but uses noise-specific domain separators (PRF_NOISE1, PRF_NOISE2, PRF_NOISE3) for domain separation.
prf_R_core()
Core LPN evaluation function used internally.Public key containing system parameters
Secret key containing PRF keys and LPN secret
Seed for deterministic randomness
Domain separator string for cryptographic separation
A nonzero field element derived from LPN evaluation
Evaluation process
-
Generate LPN response - Computes
y = As + ewhere:Ais a random matrix derived from the seedsis the LPN secret from the secret keyeis Bernoulli noise with parametertau = lpn_tau_num/lpn_tau_den
- Apply Toeplitz hash - Uses a Toeplitz matrix multiplication to compress the LPN output to 127 bits
- Hash to field - Maps the 127-bit output to a nonzero field element
lpn_make_ybits()
Generates the LPN response vectory = As + e.
Public key containing LPN parameters
lpn_n, lpn_t, lpn_tau_num, lpn_tau_denSecret key containing the LPN secret bits
lpn_s_bitsSeed for generating the random matrix
Domain separator string
Output parameter receiving the computed bit vector (length
lpn_t bits)Algorithm
For each rowr = 0 to lpn_t - 1:
- Generate random row vector from PRG
- Compute dot product with secret:
dot = row · s - Generate noise bit:
e = 1with probabilitytau, elsee = 0 - Set output bit:
y[r] = dot ⊕ e
The noise parameter
tau = lpn_tau_num / lpn_tau_den determines the noise rate. Default is tau = 1/8.Cryptographic primitives
derive_aes_key()
Derives an AES-256 key and nonce from the secret key and seed.Public key (used for
canon_tag and H_digest)Secret key containing PRF keys
Seed for key derivation
Domain separator string
Output buffer for 256-bit AES key
Output parameter for the derived nonce
- The 4 PRF keys from the secret key
- The public key’s
canon_tag - The H matrix digest
- The seed’s
ztagandnonce - The domain separator hash
hash_to_fp_nonzero()
Maps 127 bits to a nonzero field element.Lower 64 bits
Upper 63 bits (most significant bit should be 0)
A nonzero field element in constant time
1 using constant-time masking to prevent timing attacks.
fnv1a_domain()
Computes a 64-bit hash of a domain separator string.Null-terminated domain separator string
64-bit FNV-1a hash
AES-CTR implementation
AesCtr256
Hardware-accelerated AES-256 in counter mode.Methods
Initialize the cipher with a 256-bit key and 64-bit nonce
Generate the next 64-bit pseudorandom value
Fill an array with
n pseudorandom 64-bit valuesGenerate a uniformly random value in
[0, M) without biasSecurity parameters
The default LPN parameters provide:- Information-theoretic bound: 2226 bits
- Classical security: 200+ bits
- Quantum security: 100+ bits
lpn_n = 4096(secret dimension)lpn_t = 16384(number of samples)tau = 1/8(noise rate)
The triple evaluation in
prf_R() and prf_R_noise() amplifies security beyond a single LPN call.Example usage
Related functions
toep_127()- Toeplitz matrix hashingkeygen()- Generates LPN secret during key generation