Cryptology ePrint Archive: Report 2017/615

A Framework to Select Parameters for Lattice-Based Cryptography

Nabil Alkeilani Alkadri and Johannes Buchmann and Rachid El Bansarkhani and Juliane Krämer

Abstract: Selecting parameters in lattice-based cryptography is a challenging task, which is essentially accomplished using one of two approaches. The first (very common) approach is to derive parameters assuming that the desired security level is equivalent to the bit hardness of the underlying lattice problem, ignoring the gap implied by available security reductions. The second (barely used) approach takes the gap and thus the security reduction into account. In this work, we investigate how efficient lattice-based schemes are if they respect existing security reductions. Thus, we present a framework to systematically select parameters for any lattice-based scheme using either approaches. We apply our methodology to the schemes by Lindner and Peikert (LP), by El Bansarkhani (LARA), and by Ducas et al. (BLISS). We analyze their security reductions and derive a gap of 3, 5, and 63 bits, respectively. We show how parameters impact the schemes' efficiency when involving these gaps.

Category / Keywords: Lattice-Based Cryptography, Ideal Lattices, Parameter Selection, Security Reduction, Tightness, Lattice-Based Assumptions

Original Publication (in the same form): -

Date: received 23 Jun 2017, last revised 26 Jun 2017

Contact author: nalkeilani_alkadri at cdc informatik tu-darmstadt de

Available format(s): PDF | BibTeX Citation

Version: 20170627:191051 (All versions of this report)

Short URL: ia.cr/2017/615

Discussion forum: Show discussion | Start new discussion


[ Cryptology ePrint archive ]