Research Article

Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature

Table 3

Security of CRYSTALS-Dilithium.

ā€‰Dilithium-IIDilithium-III

SIS block size340488
Classical/quantum SIS security99.28/90.1142.49/129.59
LWE block size255377
Classical/quantum LWE security96.24/90.1142.28/130.91
300.43317.58
298.34315.58
Entropy of 257257
Classical/quantum forgery attack257/128257/128
Security against known attacks90.1128