TransWikia.com

LWR parameter estimation

Cryptography Asked by MeV on December 4, 2021

I am trying to estimate parameters for LWR $(n,q,p)$ instance using the LWE estimator. My $q,p$ are $283,256$-bit prime numbers and I am trying to find required $n$ for 128 bit security.

For this, I need to know the $alpha$ to be used in the estimator.

In the paper introducing LWR, the authors mention the analogous error rate is of the order of $frac{1}{p}$.

What is the $alpha$ I may need to use, is it $alpha = frac{1}{p}$ or is there more to that?

Add your own answers!

Ask a Question

Get help from others!

© 2024 TransWikia.com. All rights reserved. Sites we Love: PCI Database, UKBizDB, Menu Kuliner, Sharing RPP