GAUGE: A Formal Framework for Measuring Cryptographic Security under Heterogeneous Adversary Cost Models
GAUGE introduces a formal framework that represents cryptographic security as a function over heterogeneous adversary cost models, enabling rigorous comparisons, certifying ranking robustness or reversals via linear programming, and providing an auditable alternative to single-number security ratings.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the digital world, the safety of our secrets relies on mathematical locks that are incredibly difficult to pick. For decades, experts have tried to measure the strength of these locks with a single number, usually expressed as a certain number of "bits." This number is meant to tell us how much effort, in terms of time and computing power, an attacker would need to break the code. However, this single number hides a crucial complication: the value depends entirely on how we decide to count that effort. If we value computer memory as free, a lock might seem very strong. If we decide that memory is expensive to use, that same lock might suddenly look weak. Different organizations, such as government standards bodies and security agencies, use different ways of counting these costs. When they do, they often end up with different answers about which lock is safer, leading to confusion about which systems to trust and when to switch to new ones.
A new study introduces a framework called GAUGE, which changes how we look at this problem. Instead of forcing every security system into a single, rigid number, the researchers treat security as a flexible profile that shifts depending on the rules of the game. Imagine a map where the terrain changes shape based on the price of resources; a path that looks safe under one set of prices might become dangerous under another. By mapping out these entire landscapes, the team can see exactly where and why different security systems cross paths. They found that for many of the new, advanced locks being prepared for the future, the answer to "which is safer?" is not a simple fact. It is a question that depends entirely on which accounting method you choose.
The researchers applied this new method to the latest generation of cryptographic standards, specifically those designed to withstand attacks from future quantum computers. They took a specific, widely used system called ML-KEM and compared it against a classic, well-understood system called AES. Under the standard rules used by the US National Institute of Standards and Technology, which count only the time it takes to run an attack, the new system appeared slightly weaker than the classic one. However, when the researchers adjusted the rules to include the cost of memory—a factor that some European security agencies consider critical—the new system suddenly appeared much stronger. The study proved that a tiny shift in how memory is priced, just a 4.5% difference in its value relative to time, is enough to flip the ranking completely. This is not a mistake or a calculation error; it is a fundamental geometric fact about how these systems behave. The researchers showed that no single, perfect number can ever capture the truth for everyone, because the systems genuinely cross over each other depending on the perspective.
To solve the problem of making decisions when the answer depends on your perspective, the team developed a way to classify these relationships. They created a system that can tell you if one lock is strictly better than another regardless of the rules, if it is better only under specific conditions, or if the two are simply incomparable because they cross paths. For the new quantum-resistant locks, the study found that they are often incomparable to their classical counterparts. This means that choosing one over the other is not a matter of finding the objectively stronger lock, but rather a conscious choice about which cost model you want to trust. The study provides a mathematical certificate that can verify these crossings, allowing standards bodies to see exactly where their disagreements lie and to understand that both sides might be mathematically correct within their own chosen frameworks.
Beyond just comparing locks, the framework helps in planning for the future. The researchers looked at the history of how fast hackers have improved their ability to break codes over the last twenty years. They found that for certain types of mathematical problems, the effort required to break them has dropped by nearly ten bits of security every year for a specific period. Using this data, they built a risk model that separates the uncertainty of "how fast will hackers get better" from the uncertainty of "which cost model is right." This allows organizations to calculate how long they can safely keep a secret. For example, if a company needs to protect a document for five years, the study suggests a specific strategy for mixing old and new locks to minimize risk. But if they need to protect it for thirty years, the math shows that the same strategy might be insufficient, requiring a much earlier switch to new technology.
The study also tested these ideas on real hardware simulations to ensure the measurements were accurate. They ran experiments on a simulated quantum computer to see how the cost of breaking a code changes when you count the physical gates of the machine versus the time it takes. The simulation confirmed that the order of safety can indeed reverse depending on how you count, validating the theoretical predictions. The researchers packaged all their tools, data, and verification steps into a public toolset that can reproduce every table and finding in under seven seconds. This transparency ensures that the results are not just a theoretical exercise but a practical instrument that anyone can use to audit security claims.
Ultimately, this work does not tell us which lock is the best. Instead, it gives us a better way to ask the question. It reveals that the debate between different security agencies is often not about who is right or wrong, but about which version of reality they are measuring. By making the rules of the game explicit, the framework allows policymakers and engineers to see the full picture. They can now understand that a disagreement about security levels is often a disagreement about how to value resources, and they can make their choices with that knowledge in mind. The result is a clearer, more honest conversation about digital safety, where the uncertainty is not hidden behind a single number but is laid out clearly for everyone to see.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.