arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.17281cs.CRquant-ph

GAUGE:异构对手成本模型下密码安全性度量的形式化框架

GAUGE: A Formal Framework for Measuring Cryptographic Security under Heterogeneous Adversary Cost Models

  • Maharishi Markandeshwar Engineering College(玛哈里希·马克南德什瓦工程学院)
  • Maharishi Markandeshwar (Deemed to be University)(玛哈里希·马克南德什瓦(视为大学))

机构由 AI 辅助整理,请以论文原文为准。

Bhanwar Gupta, Sanjeev Rana

AI总结:

GAUGE提出形式化框架,将密码安全性表示为成本模型上的函数,证明评级三难困境,并用线性规划认证排名稳健性,在NIST后量子标准上验证了排名反转与成本漂移。

AI中文摘要:

标准机构将密码安全性报告为单一的比特数,但该值取决于用于为时间、内存和量子资源定价的对手成本模型。因此,不同的约定可能产生不同的密码方案排名。GAUGE将安全性表示为可接受成本模型上的函数,称为安全配置文件。比较随后变为配置文件之间的比较,排名反转成为明确的结构属性而非测量误差。我们在对手成本模型的锥体上形式化价格泛函,证明安全配置文件是分段线性和凹的,并证明一个评级三难困境:当两个配置文件交叉时,任何评级都不能同时忠实于底层成本、在可比较对上保持总体性以及独立于所选成本模型。我们提供一种多项式时间的线性规划程序,用于认证两个方案的排名是稳健的、在可接受模型下反转还是真正不可比较。我们通过结合随机密码分析衰减与适当成本模型不确定性的两层风险度量来扩展GAUGE。我们在NIST后量子标准、经典锚点以及25年密码分析突破年表上评估该框架。分析认证了ML-KEM-512与AES-128之间因内存定价4-5%的变动而产生的排名反转,并测量了八年间每年9.79比特的格筛成本漂移。混合X25519+ML-KEM-768握手在2.3千字节成本下将组合破解概率降低二十倍。该工件在七秒内重现所有表格和图形。GAUGE为在竞争成本模型下报告密码安全性提供了明确且可审计的框架。

英文摘要:

Standards bodies report cryptographic security as a single number of bits, but this value depends on the adversary cost model used to price time, memory, and quantum resources. Different conventions can therefore produce different rankings of cryptographic schemes. GAUGE represents security as a function over admissible cost models, called a security profile. Comparisons then become comparisons between profiles, and ranking reversals become an explicit structural property rather than a measurement error. We formalize price functionals over a cone of adversary cost models, show that security profiles are piecewise-linear and concave, and prove a rating trilemma: when two profiles cross, no rating can simultaneously be faithful to underlying costs, total over comparable pairs, and independent of the chosen cost model. We provide a polynomial-time linear-programming procedure that certifies whether the ranking of two schemes is robust, reverses under admissible models, or is genuinely incomparable. We extend GAUGE with a two-layer risk measure combining stochastic cryptanalytic decay with uncertainty over the appropriate cost model. We evaluate the framework on NIST post-quantum standards, classical anchors, and a 25-year chronology of cryptanalytic breaks. The analysis certifies a ranking reversal for ML-KEM-512 versus AES-128 from a 4-5% shift in memory pricing, and measures a lattice-sieving cost drift of 9.79 bits per year over eight years. A hybrid X25519 + ML-KEM-768 handshake reduces combined-break probability twenty-fold at a 2.3 kilobyte cost. The artifact reproduces all tables and figures in under seven seconds. GAUGE provides an explicit and auditable framework for reporting cryptographic security under competing cost models.

补充信息

↑