Dear Leo, Yang and all,
having taken into consideration your work, we have decided to change our key setup to provide secret keys without the structure you have attacked.
Vectors of the noise matrix of the diagonal dominant basis are now randomly taken in the set of all the possible ones i.e. all vectors of taxicab norm inferior to the diagonal coefficient.
As a result, the noise matrix is as random as the definition of a diagonal dominant matrix allows.
As discuss at the conference, changing the secret key implies larger dimensions. Detailed specification with proper parameters are provided in our website linked below.
Furthermore, we have improved other parts of our implementation and provided timing with and without AVX.
Here is the link to our website:
Best Regards.
Thomas Plantard on behalf of DRS submitters.