Research Article
Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature
Table 5
Parameters of the adapted scheme II.
| Parameters | CRYSTALS-Dilithium-II | This Work-III |
| | 8380417 | | | 14 | 10 | Weight of | 60 | 60 | Entropy of | 257 | 196 | | 523776 | | | 261888 | 32736() | | | | Error distribution | Uniform in | Central binomial in | | 325 | — | | — | 46 | | — | 48 | | 80 | 80 | pk size (bytes) | 1184 | 1184 | sig size (bytes) | 2044 | 1756 | Expectation of repeats | 5.74 | 7.7 | keygen (ms) | 0.10 | 0.10 | Sign (ms) | 0.55 | 0.54 | Verify (ms) | 0.12 | 0.12 | SIS block size | 340 | 449 | Classical/quantum SIS security | 99.28/90.1 | 130.82/118.99 | LWE block size | 255 | 349 | Classical/quantum LWE security | 96.24/90.1 | 101.91/92.49 | | 300.43 | 92.46 | | 298.34 | 94.15 | Classical/quantum forgery attack | 257/128 | 196/98 | Security against known attacks | 90.1 | 92.46 |
|
|