Researchers Map Reversals in Crypto Scheme Rankings with GAUGE

Standards bodies have previously reported cryptographic security as a single number of bits dependent on attacker resource pricing. For the first time, Maharishi Markandeshwar Engineering College introduces GAUGE, a framework representing security not as one value but as a function dependent on admissible cost models; it allows explicit comparison between schemes under different accounting conventions. A new system called GAUGE assesses cryptographic security by considering various potential costs for attackers rather than relying upon a single numerical value.

The framework represents security as a range of possibilities, dependent on these cost factors, enabling direct comparison between encryption methods regardless of differing economic assumptions. Maharishi Markandeshwar Engineering College has developed GAUGE, a new framework for evaluating cryptographic security that moves beyond reporting it as a single number of bits. Instead, GAUGE represents security as a function dependent on various cost models which account for an attacker’s resources; this is akin to assessing a car by price but also considering fuel efficiency and safety features in a thorough graph showing strengths and weaknesses.

This approach allows explicit comparison between encryption methods even when different organisations use differing economic assumptions about attack costs, such as including or excluding the price of memory. The team formalised ‘price functionals’, mathematical formulas calculating these costs much like a recipe lists ingredients needed for baking. However, can this system accurately predict shifts in cryptographic vulnerabilities over time, given the ever-evolving tactics employed by attackers attempting lattice-sieving, essentially trying every combination lock setting until successful.

Cryptographic Algorithm Security Shifts With Resource Cost Variation

A hybrid X25519 + ML-KEM-768 handshake achieved a twenty-fold reduction in combined break probability with only 2.3 kilobyte communication overhead. Previously, such substantial gains in security necessitated larger data transfers or complex protocol modifications. GAUGE accurately captures shifts in cryptographic advantage when resource costs fluctuate, revealing an inherent ranking reversal between ML-KEM-512 and AES-128 following just a four to five per cent change in estimated memory pricing; this sensitivity level is unseen in prior evaluations.

This new framework formalises ‘price functionals’, mathematical formulas calculating the cost of resources for attackers; it allows explicit comparison even when different organisations have differing economic assumptions about attack expenditure. A nuanced approach to evaluating cryptographic security reveals previously hidden vulnerabilities and strengths among algorithms.

Their framework, named GAUGE, Generalised Accounting of Uncertainty in Guessing Effort, moves beyond simple ‘bits of security’ estimates by explicitly modelling adversary costs for computation time and memory. Analysis using GAUGE showed that ML-KEM-512, a post-quantum standard, experiences a ranking reversal against AES-128 with only a four to five per cent change in estimated memory pricing, highlighting sensitivity not captured by conventional methods.

Formalising Cryptographic Strength via Multi-criteria Security Profiles and Price Functionals

The core new development enabling this work was the creation of ‘security profiles’, representing cryptographic strength as a graph showing an item’s strengths and weaknesses across multiple criteria; it is analogous to compare cars based on price, fuel efficiency, and safety ratings. These profiles map security against various cost models detailing how many attackers value resources like computation or memory, allowing for direct comparison even when different analysts assign differing values to those resources. The team formalised these relationships using ‘price functionals’, mathematical formulas calculating costs akin to listing ingredients in a baking recipe, establishing precise rules for evaluating schemes under diverse economic assumptions.

Formalising cryptographic price allows subtle evaluation of attack economics

Researchers at Deemed to be University and Maharishi Markandeshwar Engineering College present a framework addressing inconsistencies in measuring cryptographic security; current methods rely on single numerical values vulnerable to manipulation by varying assumptions about attacker resources such as computation time or memory costs. The team’s formalisation of ‘price functionals’ offers an auditable system for comparing schemes under varied economic models, but it does not resolve the fundamental difficulty of accurately determining those underlying cost parameters themselves. Even acknowledging that pinpointing precise costs for attacks remains challenging, this formalisation provides substantial value to practitioners and standards bodies alike.

The research demonstrates a new method representing cryptographic security using “security profiles” which map strengths and weaknesses across multiple criteria. This approach allows comparisons between encryption methods even with varying assumptions about attacker resource valuations, unlike current systems relying on single numerical values.

Analysis of NIST post-quantum standards revealed ranking reversals are possible with small shifts in estimated memory pricing, such as the observed change for ML-KEM-512 versus AES-128 from a four to five per cent shift. The authors developed a linear-programming procedure to certify whether rankings are robust or susceptible to changes in cost models; they also measured an annual drift in lattice-sieving costs over eight years.

👉 More information
🗞 GAUGE: A Formal Framework for Measuring Cryptographic Security under Heterogeneous Adversary Cost Models
✍️ Bhanwar Gupta and Sanjeev Rana
🧠 ArXiv: https://arxiv.org/abs/2609.17281

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Dr. Donovan

Latest Posts by Dr. Donovan: