Research Article
Rejection Sampling Revisit: How to Choose Parameters in Lattice-Based Signature
Table 5
Parameters of the adapted scheme II.
| | Parameters | CRYSTALS-Dilithium-II | This Work-III |
| | 8380417 | | | 14 | 10 | | Weight of | 60 | 60 | | Entropy of | 257 | 196 | | 523776 | | | 261888 | 32736() | | | | | Error distribution | Uniform in | Central binomial in | | 325 | — | | — | 46 | | — | 48 | | 80 | 80 | | pk size (bytes) | 1184 | 1184 | | sig size (bytes) | 2044 | 1756 | | Expectation of repeats | 5.74 | 7.7 | | keygen (ms) | 0.10 | 0.10 | | Sign (ms) | 0.55 | 0.54 | | Verify (ms) | 0.12 | 0.12 | | SIS block size | 340 | 449 | | Classical/quantum SIS security | 99.28/90.1 | 130.82/118.99 | | LWE block size | 255 | 349 | | Classical/quantum LWE security | 96.24/90.1 | 101.91/92.49 | | 300.43 | 92.46 | | 298.34 | 94.15 | | Classical/quantum forgery attack | 257/128 | 196/98 | | Security against known attacks | 90.1 | 92.46 |
|
|