Dear Saber team and dear all in PQC community:
Recently, we proposed compact NTRU based on RLWR, referred to CNTR. The paper is available from:
https://arxiv.org/abs/2205.05413
To our knowledge, CNTR has almost the smallest ciphertext size. Compared with Saber, it has smaller ciphertext size, stronger security, and lower error probabilities. By combining NTRU and RLWR, it could eliminate most of the existing patent threats. In addition, CNTR has flexible plaintext message space that is ${0,1}^{n/2}$ where $n$ is the polynomial dimension, compared to the fixed message size of 256 bits of Saber. The comparison between CNTR and Saber is summarized in the attached table.
Any feedbacks and suggestions are appreciated from you.
All the best
Yunlei