heir icon indicating copy to clipboard operation
heir copied to clipboard

LWE Parameter selection

Open WoutLegiest opened this issue 1 year ago • 4 comments

For the LWE parameter selection we could use the LWE estimator: https://github.com/malb/lattice-estimator Another approach would be to use approximated formulas: https://eprint.iacr.org/2024/1001

WoutLegiest avatar Nov 22 '24 17:11 WoutLegiest

Ooh and they have a github repo with the formulas implemented in python: https://github.com/sergirovira/fastparameterselection/

j2kun avatar Nov 22 '24 18:11 j2kun

If we are talking about selecting N and Q, the above tools suffices. Another alternative is Homomorphic Encryption Standard which recommended a set of LWE parameters for different security levels, implementation could look up that table as long as Q does not exceed Qmax for a specific N.

OpenFHE select N/Q in this way.

Yet there are still more steps to select other parameters like qi.

ZenithalHourlyRate avatar Nov 23 '24 14:11 ZenithalHourlyRate

Looks also like there is just published a follow up work: https://eprint.iacr.org/2024/1895.pdf

WoutLegiest avatar Nov 24 '24 20:11 WoutLegiest

Seems duplicate of #1617

ZenithalHourlyRate avatar Apr 02 '25 15:04 ZenithalHourlyRate