Skip to main content

Table 1 Security of post-quantum digital signature schemes. Two values of security bits for CRYSTALS-DILITHIUM are given with respect to short integer solution (SIS) and learning with errors (LWE) problems, correspondingly

From: Towards security recommendations for public-key infrastructures for production environments in the post-quantum era

Algorithm

Basic approach

Variant of the algorithm

Classical security, bit

Quantum security, bit

Falcon

Lattice

n = 768

195

172

CRYSTALS-DILITHIUM

Lattice

Very high

176/174

160/158

Rainbow

Multivariate

Classic

207

169

Compressed

207

169

GeMSS

Multivariate cryptography

GeMSS192

192

112.2

BlueGeMSS192

192

112.2

RedGeMSS192

192

112.2

Picnic

Zero-knowledge proof systems

picnic-L3-FS

192

96

picnic-L3-UR

192

96

picnic2-L3-FS

192

96

SPHINCS+

Hash functions

sphincs-haraka-192f

194

97

sphincs-sha256-192s

196

98

sphincs-shake256-192f

194

97