4

I am trying to estimate parameters for LWR $(n,q,p)$ instance using the LWE estimator. My $q,p$ are $283,256$-bit prime numbers and I am trying to find required $n$ for 128 bit security.

For this, I need to know the $\alpha$ to be used in the estimator.

In the paper introducing LWR, the authors mention the analogous error rate is of the order of $\frac{1}{p}$.

What is the $\alpha$ I may need to use, is it $\alpha = \frac{1}{p}$ or is there more to that?

MeV
  • 149
  • 5

0 Answers0