← Back to Chapter 13, A core-SVP estimator in Python
Core-SVP estimator
The chapter's estimator finds the smallest BKZ block size β whose primal-attack inequality holds, then reads bit-security off the core-SVP cost curve. Pick a parameter set and slide β: the inequality evaluates live in log space, the dot moves on the cost curve against the NIST category floors, and at the search's optimal m the flag flips the moment β reaches the chapter's verified threshold β*. Scrub m away from that optimum and the inequality at that m decides. The floors are AES gate counts and the curves are core-SVP proxy bits (the Kyber specification keeps the two in separate rows of its Table 4), so the graph shows where the coarse baseline falls against the floor, and the distance between them is not a margin in either unit. The refined gate counts of 151.5, 215.1 and 287.3 bits are what clear the floors.