Research Article

Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature

Table 4

Parameters of the adapted scheme I.

ParametersDilithium-IIThis Work-IDilithium-IIIThis Work-II

8380417838041783804178380417
14141414
Weight of 60606060
Entropy of 257257257257
523776523776523776523776
261888261888261888261888
325275
170180
170180
80809696
pk size (bytes)1184118414721472
sig size (bytes)2044204427012701
Expectation of repeats5.742.496.563.42
keygen (ms)0.100.100.150.15
Sign (ms)0.550.340.850.60
Verify (ms)0.120.120.170.17
SIS block size340340488488
Classical/quantum SIS security99.28/90.199.28/90.1142.49/129.59142.49/129.59
LWE block size255255377377
Classical/quantum LWE security96.24/90.196.24/90.1142.28/130.91142.28/130.91
300.4395.19317.58129.77
298.3493.19315.58128.0
Classical/quantum forgery attack257/128196/98257/128257/128
Security against known attacks90.190.1128128