From: Shorter ZK-SNARKs from square span programs over ideal lattices
Scheme | d | p | n | n′ | k | k′ | log Q | log Q′ | Security (Classical) | Security (Quantum) |
---|---|---|---|---|---|---|---|---|---|---|
Basic Scheme | \(2^{16}\) | 547 | 32 | - | 155 | - | 115 | 40 | 128.5 | 149.3 |
\(2^{16}\) | 283 | 64 | – | 77 | – | 114 | 40 | 129.1 | 149.8 | |
\(2^{20}\) | 643 | 32 | – | 162 | – | 120 | 41 | 128.2 | 149.1 | |
\(2^{20}\) | 283 | 64 | – | 80 | – | 118 | 40 | 129.4 | 150.1 | |
Optimized Scheme | \(2^{16}\) | 547 | 32 | 256 | 158 | 8 | 117 | 50 | 128.8 | 149.6 |
\(2^{16}\) | 283 | 64 | 512 | 78 | 4 | 116 | 50 | 128.2 | 149 | |
\(2^{20}\) | 643 | 32 | 256 | 165 | 8 | 122 | 51 | 128.5 | 149.4 | |
\(2^{20}\) | 283 | 64 | 512 | 81 | 4 | 120 | 50 | 128.2 | 149.1 |