Gaussian Sampling in Lattice Based Cryptography

János Folláth


Modern lattice-based cryptosystems require sampling from discrete
Gaussian distributions. We review lattice based schemes and collect
their requirements for sampling from discrete Gaussians. Then we
survey the algorithms implementing such sampling and assess their
practical performance. Finally we draw some conclusions regarding
the best candidates for implementation on different platforms in the
typical parameter range.

