← Back to Chapter 13, A core-SVP estimator in Python

Core-SVP estimator

The chapter's estimator finds the smallest BKZ block size β whose primal-attack inequality holds, then reads bit-security off the core-SVP cost curve. Pick a parameter set and slide β: the inequality evaluates live in log space, the dot moves on the cost curve against the NIST category floors, and at the search's optimal m the flag flips the moment β reaches the chapter's verified threshold β*. Scrub m away from that optimum and the inequality at that m decides. The floors are AES gate counts and the curves are core-SVP proxy bits (the Kyber specification keeps the two in separate rows of its Table 4), so the graph shows where the coarse baseline falls against the floor, and the distance between them is not a margin in either unit. The refined gate counts of 151.5, 215.1 and 287.3 bits are what clear the floors.

parameter set
block size β = 406
samples m = 486 of 768
 
classical core-SVP proxy 0.292β quantum core-SVP proxy 0.265β current β NIST category floor (AES gate count) estimator threshold β*