Research Article
Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature
Table 4
Parameters of the adapted scheme I.
| Parameters | Dilithium-II | This Work-I | Dilithium-III | This Work-II |
| | 8380417 | 8380417 | 8380417 | 8380417 | | 14 | 14 | 14 | 14 | Weight of | 60 | 60 | 60 | 60 | Entropy of | 257 | 257 | 257 | 257 | | 523776 | 523776 | 523776 | 523776 | | 261888 | 261888 | 261888 | 261888 | | | | | | | | | | | | 325 | — | 275 | — | | — | 170 | — | 180 | | — | 170 | — | 180 | | 80 | 80 | 96 | 96 | pk size (bytes) | 1184 | 1184 | 1472 | 1472 | sig size (bytes) | 2044 | 2044 | 2701 | 2701 | Expectation of repeats | 5.74 | 2.49 | 6.56 | 3.42 | keygen (ms) | 0.10 | 0.10 | 0.15 | 0.15 | Sign (ms) | 0.55 | 0.34 | 0.85 | 0.60 | Verify (ms) | 0.12 | 0.12 | 0.17 | 0.17 | SIS block size | 340 | 340 | 488 | 488 | Classical/quantum SIS security | 99.28/90.1 | 99.28/90.1 | 142.49/129.59 | 142.49/129.59 | LWE block size | 255 | 255 | 377 | 377 | Classical/quantum LWE security | 96.24/90.1 | 96.24/90.1 | 142.28/130.91 | 142.28/130.91 | | 300.43 | 95.19 | 317.58 | 129.77 | | 298.34 | 93.19 | 315.58 | 128.0 | Classical/quantum forgery attack | 257/128 | 196/98 | 257/128 | 257/128 | Security against known attacks | 90.1 | 90.1 | 128 | 128 |
|
|