%0 Journal Article
%T Better Sampling Method of Enumeration Solution for BKZ-Simulation
%J The ISC International Journal of Information Security
%I Iranian Society of Cryptology
%Z 2008-2045
%A Moghissi, Gholam Reza
%A Payandeh, Ali
%D 2021
%\ 07/01/2021
%V 13
%N 2
%P 177-208
%! Better Sampling Method of Enumeration Solution for BKZ-Simulation
%K BKZ Simulation
%K Coefficient Vector
%K GNR Enumeration
%K Optimal Bounding Function
%K Sampling Method
%K Solution Norm
%R 10.22042/isecure.2021.225886.531
%X The exact manner of BKZ algorithm for higher block sizes cannot be studied by practical running, so simulation of BKZ can be used to predict the total cost and output quality of BKZ algorithm. Sampling method of enumeration solution vector v is one of the main components of designing BKZ-simulation and can be divided into two phases: sampling norm of solution vector v and sampling corresponding coefficient vectors. This paper introduces a simple and efficient idea for sampling the norm of enumeration solution v for any success probability of enumeration bounding functions, while to the best of our knowledge, no such sampling method for norm of enumeration solution is proposed in former studies. Next, this paper analyzes the structure and probability distribution of coefficient vectors (corresponding with enumeration solution v), and consequently introduces the sampling methods for these coefficient vectors which are verified by our test results, while no such a deep analysis for sampling coefficient vectors is considered in design of former BKZ-simulations. Moreover, this paper proposes an approximation for cost of enumerations pruned by optimal bounding functions.
%U https://www.isecure-journal.com/article_132591_584d76797c42719b61d770a041296119.pdf