Research Article

Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature

Table 5

Parameters of the adapted scheme II.

ParametersCRYSTALS-Dilithium-IIThis Work-III

8380417
1410
Weight of 6060
Entropy of 257196
523776
26188832736()
Error distributionUniform in Central binomial in
325
46
48
8080
pk size (bytes)11841184
sig size (bytes)20441756
Expectation of repeats5.747.7
keygen (ms)0.100.10
Sign (ms)0.550.54
Verify (ms)0.120.12
SIS block size340449
Classical/quantum SIS security99.28/90.1130.82/118.99
LWE block size255349
Classical/quantum LWE security96.24/90.1101.91/92.49
300.4392.46
298.3494.15
Classical/quantum forgery attack257/128196/98
Security against known attacks90.192.46