estimator.BKZ.qsieve

static BKZ.qsieve(beta, d, B=None)

Runtime estimation for quantum sieving.

Parameters:
  • beta – block size
  • n – LWE dimension n > 0
  • B – bit-size of entries
[LaaMosPol14]Thijs Laarhoven, Michele Mosca, & Joop van de Pol. Finding shortest lattice vectors faster using quantum search. Cryptology ePrint Archive, Report 2014/907, 2014. https://eprint.iacr.org/2014/907.
[Laarhoven15]Laarhoven, T. (2015). Search problems in cryptography: from fingerprinting to lattice sieving (Doctoral dissertation). Eindhoven University of Technology. http://repository.tue.nl/837539