Lattice points Ciphertext c Babai estimate Bx̂ Active basis (b₁, b₂)
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Lattice Cryptography: The Closest-Vector Trapdoor

Post-quantum standards like CRYSTALS-Kyber (ML-KEM) rest on lattice problems that stay hard even for a quantum computer. This simulator makes the core trapdoor tangible: a message bit is hidden as a point near a lattice, and decryption means solving the Closest Vector Problem with Babai's rounding algorithm. Toggle between decoding with the short, near-orthogonal private basis — where rounding reliably lands on the right point — and decoding with a skewed public basis that spans the exact same lattice but whose sliver-shaped Voronoi cells make the same rounding step land on the wrong point and flip the bit. Sliders for channel noise and public-basis skew let you push both regimes to their breaking point live in 3D.