estimate-all-the-lwe-ntru-schemes / estimate-all-the-lwe-ntru-schemes.github.io

Repository and website for the Estimate all the {LWE, NTRU} schemes! code and paper.
23 stars 7 forks source link

Lizard estimates #11

Closed rachelplayer closed 6 years ago

rachelplayer commented 6 years ago

The security of Lizard is based on an n-dimensional LWE problem (secret key recovery) and an m-dimensional LWR problem (ephemeral secrets). At the moment, only the LWR problem is considered in the estimates, but attacking the secret key may be easier.

malb commented 6 years ago

This should be fixed with the most recent update.