Research Article
Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature
Table 3
Security of CRYSTALS-Dilithium.
| ā | Dilithium-II | Dilithium-III |
| SIS block size | 340 | 488 | Classical/quantum SIS security | 99.28/90.1 | 142.49/129.59 | LWE block size | 255 | 377 | Classical/quantum LWE security | 96.24/90.1 | 142.28/130.91 | | 300.43 | 317.58 | | 298.34 | 315.58 | Entropy of | 257 | 257 | Classical/quantum forgery attack | 257/128 | 257/128 | Security against known attacks | 90.1 | 128 |
|
|