Skip to main content

Table 5 Concrete security estimation of LWE instances from Regev’s and Lindner-Peikert’s cryptosystems

From: Security estimation of LWE via BKW algorithms

Parameters

The BKW Algorithms

The Lattice-based Algorithms

n

q

\(\sigma\)

Plain BKW

LMS-BKW

FFT-BKW

Coded-BKW

Sieve-Coded-BKW

BKW-FWHT-SR

Primal

Decoding

Dual

Regev parameters

128

16411

11.81

119.4

114.7

107.5

84.5

84.2

59.2

57.3

61.9

69.2

256

65537

25.53

269.6

220.3

200.8

145.1

130.0

107.0

103.6

121.7

121.0

512

262147

57.06

429.4

403.4

384.6

287.6

247.6

243.3

201.6

252.7

231.2

Lindner-Peikert parameters

128

2053

2.7

104.4

100.0

95.7

69.7

69.2

48.8

53.4

57.1

67.5

256

4099

3.34

181.8

176.0

167.9

123.8

112.9

98.5

95.2

111.8

112.3

512

4099

2.9

338.8

327.7

308.0

209.2

197.3

188.7

179.0

226.5

207.8

  1. Among these different estimation methods, bold-faced numbers are the smallest