Select secure parameters for LWE-based schemes without running a lattice estimator over every candidate. The security level, the LWE dimension, the ciphertext modulus and the error standard deviation are mutually constrained: fix any three and this tool solves for the fourth.
It is built on an analysis of the uSVP, BDD and hybrid attacks, from which closed-form relations between the parameters are derived. The details are in the paper: A Tool for Fast and Secure LWE Parameter Selection: the FHE case.
Full documentation, including what the tool does not cover, is at readthedocs.
SageMath is required and cannot be installed by pip: nd.py imports
sage.all, and the Lattice Estimator used by -v is a Sage library.
Install Sage first, by whichever route suits your system:
sudo apt install sagemath # Debian/Ubuntu
conda install -c conda-forge sage # condaThen install this package into that interpreter. Install from a checkout, in
editable mode, so that -v keeps working:
git clone https://github.com/Crypto-TII/fastparameterselection
cd fastparameterselection
pip install -e .This provides a fastparams command that runs from any directory:
fastparams --param "lambda" --n "1024" --logq "27" --secret "binary" --std "3.19"Editable mode matters for -v. The Lattice Estimator is vendored in the
repository and is located relative to the package, so an editable install finds
it, while a copying install (pip install . or
pip install git+https://...) does not. With a copying install -v prints
Failed to import lattice_estimator and the verification columns are skipped;
everything else still works.
Without installing at all, the module form works from a checkout:
python3 -m fastparameterselection.estimate --param "lambda" --n "1024" --logq "27" --secret "binary" --std "3.19"Installing needs setuptools >= 61 for PEP 621 metadata, and >= 64 for
the editable install above. Older versions fail in two confusing ways: an
editable install reports a missing build_editable hook, and a regular
install silently produces an empty wheel named UNKNOWN-0.0.0 and exits
successfully.
On distributions that ship an old pip (Ubuntu 22.04 ships pip 22.0.2 and setuptools 59.6), the system setuptools leaks into pip's isolated build environment, so the build fails this way even when a newer setuptools is available. Upgrade both first:
pip install --user -U pip setuptoolsThe remaining Python dependencies (numpy, scipy, lmfit) are installed automatically.
On some MacOS setups python3 cannot see Sage even when it is installed. Run
the tool through Sage itself in that case:
sage --fastparams --param "lambda" --n "1024" --logq "27" --secret "binary"Estimate the security level of a parameter set:
fastparams --param "lambda" --n "1024" --logq "20;35;40" --secret "binary" --std "3.19"secret dist. | lwe dim. | log q | output
-------------+----------+-------+-------
Binary | 1024 | 20 | 173
Binary | 1024 | 35 | 95
Binary | 1024 | 40 | 83
Estimate the LWE dimension needed for a target security level:
fastparams --param "n" --lambda "80" --logq "20-23" --secret "binary" --std "3.19"secret dist. | lambda | log q | output | pow
-------------+--------+-------+--------+----
Binary | 80 | 20 | 513 | 512
Binary | 80 | 21 | 537 | 512
Binary | 80 | 22 | 561 | 512
Binary | 80 | 23 | 586 | 512
Estimate the largest usable modulus:
fastparams --param "logq" --lambda "80" --n "1024" --secret "binary" --error "gaussian" --std "3.19"secret dist. | lambda | lwe dim. | output
-------------+--------+----------+-------
Binary | 80 | 1024 | 41
Estimate the smallest usable error:
fastparams --param "std_e" --lambda "192" --n "2048" --logq "64" --secret "binary"secret dist. | lambda | lwe dim. | log q | output
-------------+--------+----------+-------+------------------
Binary | 192 | 2048 | 64 | 28.60
Add --table to see each formula and solver separately, and -v to check
the result against the Lattice Estimator. Add --ntru to check whether the
parameters fall in the overstretched NTRU regime.
The tool answers the security question only, and not every part of it. It does
not model dual or quantum attacks, says nothing about whether a parameter set
supports your circuit, and its fitted constants were learned at a standard
deviation of 3.19 for binary and ternary secrets. The hybrid --param logq
search can return a modulus below the target.
The full list is on the limitations
page. Confirm candidate parameters with -v before deploying them.
Several numerical solvers (the hybrid attack, and --param std_e) restart from randomised initial points. Each such call derives its own generator from a base seed and the call's own parameters, so a given set of LWE parameters always produces the same answer -- independently of how many other rows were computed in the same invocation. Pass --seed to change the base seed; see fastparameterselection/rng.py.
The hybrid solvers are sensitive to their restart budget. At --param logq --lambda 192 --n 1024 --hw 64 --secret sparse the default budget can settle on a log q that the Lattice Estimator scores far below the target, while --nrestart 1000 finds the right one. Run the hybrid with -v and check the reported est hybrid against your target.
The fitted constants in fastparameterselection/const.py can be regenerated from dataset/ with:
bash find_all_constants.shThe tables of the paper can be regenerated with:
bash regenerate_tables.shResults land in tables/; tables/README.md maps columns to tables.
pip install pytest
python3 -m pytest # everything
python3 -m pytest -m "not slow" # skip refitting the constantsThe suite pins values printed in the paper, so a change to a formula that
would move a published table fails the build. Tests marked needs_sage run
the command line and skip themselves when SageMath is not installed; the rest
cover the formulas, the numerical solvers and the per-call generators and need
only numpy and scipy.
You can build and run the repository with Docker using the following command:
docker-compose -f ./docker/docker-compose.yaml up --buildTo only run the container, use:
docker-compose -f ./docker/docker-compose.yaml upCurrently, it runs estimate.py to obtain the parameter lambda, given n = 1024, logq = 35, binary secret distribution, and standard deviation of the error distribution 3.19. To run the estimation with your parameters, you can modify the command line in docker-compose.yaml as follows:
Find an estimation of the security level:
command: [ "sage", "--python3", "-m", "fastparameterselection.estimate", "--param", "lambda", "--n", "1024", "--logq", "20-30;35;40-60", "--secret", "binary", "--error", "gaussian", "--std", "3.19"]Find an estimation of the security level and verify it against the Lattice Estimator:
command: [ "sage", "--python3", "-m", "fastparameterselection.estimate", "--param", "lambda", "--n", "1024", "--logq", "20-30;35;40-60", "--secret", "binary", "--error", "gaussian", "--std", "3.19", "-v" ]Find an estimation of the LWE dimension:
command: ["sage", "--python3", "-m", "fastparameterselection.estimate", "--param", "n", "--lambda", "80", "--logq", "20", "--secret", "binary", "--error", "gaussian", "--std", "3.19"]Find an estimation of the size of the modulus q:
command: ["sage", "--python3", "-m", "fastparameterselection.estimate", "--param", "logq", "--lambda", "80", "--n", "1024", "--secret", "binary", "--error", "gaussian", "--std", "3.19"]Find an estimation of the standard deviation of the error distribution:
command: ["sage", "--python3", "-m", "fastparameterselection.estimate", "--param", "std_e", "--lambda", "80", "--n", "1024", "--logq", "20", "--secret", "binary"]Note: for a standard deviation of the error much larger than 3.19, the Lattice Estimator becomes imprecise, so the est bdd column of --param std_e should be treated as indicative only.
- Include meet-in-the-middle for the hybrid attack. Challenge: derive a compact formula for the admissibility probability. Current status: equations for the optimisation including the mitm speed-up for enumeration are in place, untested.
- Improve the runtime of
numerical_lambda_hybrid(). Computingprobability_enum()andss_enum()on the log scale is both faster and removes their dependency on Sage; a prototype agreed with the current code to 1e-10 and ran up to 750x faster. - Make the hybrid
--param logqsearch reject a modulus its own lambda model does not vouch for, instead of returning it with a warning.
Please report bugs through the GitHub issue tracker.
@misc{cryptoeprint:2024/1895,
author = {Beatrice Biasioli and Elena Kirshanova and Chiara Marcolla and Sergi Rovira},
title = {A Tool for Fast and Secure {LWE} Parameter Selection: the {FHE} case},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1895},
year = {2024},
url = {https://eprint.iacr.org/2024/1895}
}The paper associated with our tool is a follow-up and extension of the following paper presented at Africacrypt 2024. The pre-prints of both papers are available at: