Skip to main content

Table 1 The connection between \({{B}_{i}}\) and \({{B}_{i-1}}\) in sample reduction of BKW algorithms

From: Security estimation of LWE via BKW algorithms

The BKW algorithms

The connection between \({{B}_{i}}\) and \({{B}_{i-1}}\)

Plain BKW

\({{B}_{i}}={{B}_{i-1}}=0\)

LMS-BKW/Coded-BKW

\({{B}_{i}}=\sqrt{2}{{B}_{i-1}}\)

Sieve-Coded-BKW

\({{B}_{i}}={{B}_{i-1}}\ne 0\)

\(\gamma\)-Sieve-Coded-BKW

\({{B}_{i}}=\gamma {{B}_{i-1}}\)

\({{\gamma }_{i}}\)-Sieve-Coded-BKW

\({{B}_{i}}={{\gamma }_{i}}{{B}_{i-1}}\)

BKW-FWHT-SR

\({{B}_{i}}=\lfloor \sqrt{2}{{B}_{i-1}} \rceil\)