Name | Value | Description |
---|---|---|
q | 3329 | Order of base field |
n | 256 | Degree of polynomials |
zeta | 17 | nth root of unity in base field |
Primitive | Instantiation |
---|---|
XOF | SHAKE-128 |
H | SHA3-256 |
G | SHA3-512 |
PRF(s,b) | SHAKE-256(s || b) |
KDF | SHAKE-256 |
Name | Description |
---|---|
k | Dimension of module |
eta1, eta2 | Size of "small" coefficients used in the private key and noise vectors. |
d_u | How many bits to retain per coefficient of u, the private-key independent part of the ciphertext |
d_v | How many bits to retain per coefficient of v, the private-key dependent part of the ciphertext. |
Parameter set | k | eta1 | eta2 | d_u | d_v | sec | DFP |
---|---|---|---|---|---|---|---|
Kyber512 | 2 | 3 | 2 | 10 | 4 | I | 2^-139 |
Kyber768 | 3 | 2 | 2 | 10 | 4 | III | 2^-164 |
Kyber1024 | 4 | 2 | 2 | 11 | 5 | V | 2^-174 |
Parameter set | ss | pk | ct | sk |
---|---|---|---|---|
Kyber512 | 32 | 800 | 768 | 1632 |
Kyber768 | 32 | 1184 | 1088 | 2400 |
Kyber1024 | 32 | 1568 | 1568 | 3168 |