Conceptio › Archive › arXiv CS
arXiv CSopen access

GAUGE: A Formal Framework for Measuring Cryptographic Security under Heterogeneous Adversary Cost Models

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

GAUGE: A Formal Framework for Measuring Cryptographic Security under Heterogeneous Adversary Cost Models Bhanwar Gupta∗

Sanjeev Rana†

arXiv:2609.17281v1 [cs.CR] 15 Sep 2026

Department of Computer Science and Engineering, Maharishi Markandeshwar Engineering College, Maharishi Markandeshwar (Deemed to be University), Mullana, Ambala, Haryana 133207, India

Abstract Standards bodies, vendors, and migration planners report the security of a cryptographic scheme as a single number of bits. That number is not a property of the scheme: it is the output of an adversary cost model, an accounting convention for what an attacker’s time, memory, and quantum resources are worth, and different bodies adopt different conventions. NIST prices memory into its comparisons; ANSSI and BSI do not. The two choices can, and provably do, disagree about which of two standardized schemes is more secure. GAUGE represents the security of a scheme not as a scalar but as a function on the space of admissible cost models: a security profile. Comparisons between schemes become comparisons between these functions. A scheme that is ranked higher under one accounting convention and lower under another is not a measurement error; it is a crossing profile, a geometric fact about the two functions that any scalar rating necessarily discards. We formalize price functionals over a cone of adversary cost models, show that resulting security profiles are piecewise-linear and concave, and prove that whenever two profiles cross, no rating that is simultaneously faithful to the underlying costs, total over all comparable pairs, and independent of the particular cost model can exist. We call this the rating trilemma. We complement it with a polynomial-time linear-programming procedure that certifies, for any pair of schemes, whether their ranking is robust across all admissible models, reverses under some models, or is genuinely incomparable. We extend GAUGE with a two-layer risk measure: a coherent risk functional aggregates stochastic cryptanalytic decay given a cost model, and a credal-set construction aggregates systematic uncertainty about which cost model is appropriate. We instantiate GAUGE on the NIST post-quantum standards (ML-KEM, ML-DSA-adjacent families, and classical anchors) and on a curated 25-year chronology of cryptanalytic breaks. The linear program certifies a rating reversal for ML-KEM-512 against its AES-128 anchor that a 45% shift in how memory is priced is sufficient to trigger, we measure a lattice-sieving cost drift of 9.79 bits per year over an eight-year window, and we show that a hybrid X25519 + ML-KEM-768 handshake reduces combined-break probability twenty-fold at a 2.3 kilobyte cost. The artifact reproduces every table and figure in under seven seconds. The result is a reporting format that keeps the accounting convention explicit, and that gives standards bodies a linear-programming certificate for when a disagreement between two cost-model positions is real. ∗ †

Corresponding author. Email: [email protected]. ORCID: 0009-0009-1524-6103. Email: [email protected]. ORCID: 0000-0003-2911-3052.

1

Table 1: ML-KEM-768 versus its Category-3 anchor (AES-192) under five literature-anchored accountings (β = 637; bits are log2 attack cost). Tags: (S) specification-published, (D) derived arithmetic from cited exponents, (F) regenerated from cited sources by the toolchain. Cost model Classical, time-only (CoreSVP) Classical, time×memory Quantum, unbounded depth, t-only Quantum, depth-bounded Quantum, gate-count

Source

ML-KEM-768

AES-192

Rel.

[20, 21]

186

S

192

−6

[17, 7] [18]

318.18D 168.99D

192 96

+126.18 +72.99

[22, 24] [22, 24]

169–186F 3xxF

regime-dep.F 1xxF

regime-dep.F +2xxF

Keywords: cryptographic security evaluation; adversary cost models; post-quantum cryptography; security metrics; concrete security; hybrid cryptography; risk measures. Use of AI Tools: An AI assistant was used in formatting and editing of the manuscript; all theorems, results, and numbers were executed and verified by the authors, and no results were fabricated.

1

Introduction

1.1

Scalar security estimates and their hidden conditioning

Parameter selection, hybrid protocol design, migration deadlines, and standards categories all take a scalar “bits of security” as input. That scalar is not a property of a cryptographic scheme alone: it depends on the adversary cost model under which the underlying attack cost was estimated, and that model is almost never stated. Table 1 makes this concrete for a single standardized scheme. ML-KEM-768 [27, 21] is a NIST Category-3 scheme; its dominant attack is a primal BKZ reduction whose core operation is lattice sieving in block size β ≈ 637, with classical sieving cost exponents 20.292β in time and 20.2075β in memory [17] and quantum exponent 20.2653β [18]. Under five accounting conventions, each of which appears in the respected literature, the scheme’s estimate and its position relative to its own Category-3 anchor (AES-192) are as follows. Three observations follow. Dispersion: the anchor-relative security of one scheme ranges from −6 to +126 bits across documented conventions. Anchor drift: the anchor itself moves by up to 96 bits between classical and unbounded-depth quantum accounting, and the category definition of NIST uses depth-bounded anchors [8] while scheme estimates were predominantly computed under classical time-only conventions—two different regions of the cost-model space, compared as if commensurable. Convention status: no convention in the table is a strawman; every one has published defenders. A disagreement about which convention to use is therefore a dispute about location in a structured parameter space, not a factual error by either party.

1.2

From scalars to profiles

GAUGE (Generalized Accounting of Uncertainty in Guessing Effort) makes the cost model a firstclass mathematical object and the security estimate a function of it. An adversary cost model pairs a machine class with a price vector over canonical adversarial resources; a scheme’s security profile maps each admissible cost model to the log2 cost of its cheapest attack under that model; orderings,

2

GAUGE adversary cost models κ = (M, c)

security profiles SK (κ)

security ordering ⪰κ , ⪰C robust dominance

conditional inversion / incomparable Rating Trilemma

risk extension (decay × model ambiguity) cryptographic evaluation (PQC, history, hardware) applications (hybrid, migration, standards)

Figure 1: Conceptual structure of the framework. sensitivities, and risk measures are then defined over the profile rather than over a scalar. Figure 1 summarizes the framework’s structure.

1.3

Contributions

The contributions of this work are: 1. We introduce GAUGE, a formal representation of cryptographic security as a function over heterogeneous adversary cost models (Sections 3–4), with structural properties (piecewise linearity, monotonicity, anchor normalization) established as Propositions 1–2. 2. We develop security-profile ordering and characterize conditions under which cryptographic rankings become cost-model dependent (Theorem 1); we define the resulting robust/conditional/ incomparable classification and prove it decidable in polynomial time by linear programming (Proposition 3). 3. We formalize the Rating Trilemma and establish the limitations of scalar, model-independent security ratings (Theorem 2), together with a coherent two-layer risk extension separating costmodel ambiguity from cryptanalytic decay (Proposition 4). 4. We evaluate the framework on NIST post-quantum standards and a curated cryptanalysis chronology (Section 8): the LP certifies ranking reversals among standardized schemes, a familylevel sensitivity constant is identified, and the instrument is calibrated on the IonQ simulator (aria-1 noise model; 13 jobs; 2026-09-15).

1.4

Organization

Section 2 reviews related work and positions GAUGE against existing security notions. Sections 3– 4 develop the formal apparatus. Section 5 defines security ordering and its robust classification. Section 6 proves the Rating Trilemma. Section 7 develops the risk extension and the temporal

3

evolution of attack effort. Section 8 reports the cryptographic evaluation. Section 9 derives practical implications for hybrid cryptography and migration. Sections 10–12 describe implementation, limitations, and conclusions. Proofs not given inline appear in Appendix A.

2

Background and Related Work

2.1

Concrete cryptographic security

The modern treatment of quantitative security statements begins with definition-based security [2] and practice-oriented provable security with exact (concrete) reductions [3, 4]. Concrete security statements condition on a fixed adversary and resource model (bounded time, bounded queries); the long-running debate on reduction losses [5] concerns the gap between nominal and effective security under such conditioning. GAUGE takes a different approach: the security estimate is represented as a function over a family of cost models, so the reduction-loss gap appears as one explicitly priced uncertainty channel (U6, Section 7).

2.2

Security levels and work factors

Key-size selection and work-factor estimation have a long tradition: Lenstra–Verheul extrapolated hardware progress to select classical key sizes [6]; ECRYPT’s consensus reports aggregate expert judgment into point recommendations [7]; NIST’s post-quantum categories define equivalence classes relative to AES/SHA resource costs [8, 9]. These approaches output scalars conditional on unstated or partially stated models. GAUGE makes anchor-relative comparison explicit and adds the ordering theory needed to classify pairs of schemes.

2.3

Cost models and resource estimation

Careful accounting of the full cost of cryptanalytic attacks includes Wiener’s dollar-cost analysis [12], Bernstein’s treatment of brute force [13], and classical time–memory trade-offs [14]. Within lattice cryptanalysis, the sieving literature [15, 16, 17, 18] and the LWE estimator [19] compute best-attack costs under chosen conventions. Each such tool provides a point estimate; GAUGE computes the geometry of the space those estimates inhabit.

2.4

Post-quantum security estimation

Standardization documents (FIPS 203–205 [27, 28, 29]; round reports [9]; specifications [21, 30, 31]) state security under specific conventions (predominantly time-only classical estimates against depthbounded quantum anchors). GAUGE makes the convention dependence of these statements explicit and comparable.

2.5

Quantum-resource security models

Quantum cost accounting is an active area: AES/SHA circuit estimates [22, 23], the RAM-model analysis of Jaques–Schanck [24], factoring resource estimates [25], and quantum speedups for information-set decoding [26]. These works fix a cost model and compute under it; GAUGE treats the choice among such models as data, and measures its consequences.

4

2.6

Risk and uncertainty in security assessment

Coherent risk measures [39, 40, 41], decision theory under ambiguity [42, 43, 44, 45], security economics [51], quantum-threat timing [55, 56], and measurement uncertainty frameworks [37, 38] supply mature mathematics that has not been connected to the strength of cryptographic assumptions in this combined form. No prior work applying this combination to concrete cryptographic security estimates was identified. GAUGE draws on coherent risk measures for the decay layer, credal sets for the model-ambiguity layer, and the Type A/B uncertainty separation for the trust budget.

2.7

Relation to social-choice impossibility results

Theorem 1 and the Rating Trilemma (Theorem 2) are impossibility results, and readers familiar with social choice will correctly notice a family resemblance to Arrow’s theorem and to the Szpilrajn extension theorem’s failure mode under cyclic or crossing preferences. The resemblance is real, and we state precisely where it holds and where it does not. Szpilrajn guarantees that any strict partial order extends to a total order; the obstruction we exploit is not partial-order incompleteness but genuine sign reversal of a continuous real-valued function family on a connected domain, so the relevant extension failure is closer to the impossibility of a continuous selection from a family of linear orders that cross—a Condorcet-cycle phenomenon rather than a missing-comparability phenomenon. Arrow’s theorem rules out a social welfare function satisfying four axioms over arbitrary preference profiles of discrete voters; the Rating Trilemma instead concerns a single decision-relevant object (a convention for a scalar security level) evaluated over a continuum of cost-model “voters” with a specific polyhedral cone structure, and its proof (Appendix A) uses the geometry of that cone directly rather than an Arrovian axiomatic reduction. The mathematical content we claim as new is not the general fact that crossing objective functions defeat scalarization—that fact is old and, in the form we use it, elementary—but rather (i) showing that the specific cost-model geometry of cryptographic security estimates is rich enough for such crossings to be certified constructively (not merely possible in principle) via linear programming over real, standardized schemes, and (ii) the two-layer risk decomposition of Section 7, which has no direct analogue in the classical impossibility literature. Theorem 1 serves to license the LP-certified classification that follows; the classification, evaluation, and risk layers carry the paper’s technical content.

2.8

Relation to existing security notions

Table 2 positions GAUGE against the security notions a cryptographer will know.

3

Adversary Cost Models

Definition 1 (Resource ledger). A resource ledger is a finite ordered set T = (R1 , . . . , Rn ) of canonical adversarial resources. The default ledger is T6 = (T, M, Q, D, W, N ): logical time T , classical memory M , logical qubits Q, quantum circuit depth D, quantum width W , and parallel instances N . Coherent extensions (energy, leakage traces, target-count amortization) are admissible; their role in Section 6 is not incidental but central. Definition 2 (Adversary cost model). An adversary cost model is a pair κ = (M, c), where M is a machine class (classical sequential or parallel; quantum with unbounded depth; quantum with depth bound Dmax ; quantum with quantum-accessible random memory [24]) and c = (c1 , . . . , cn ) ∈ Rn+

5

Table 2: GAUGE relative to existing security notions. Existing concept

What it measures

GAUGE difference

Security parameter

Asymptotic security

target computational security attack success vs. resources (fixed model) scaling behaviour

Work factor

estimated attack effort

Security level / category Risk assessment

scalar classification

PQC security categories

standardized classification

GAUGE models its cost-model dependence GAUGE represents heterogeneous resource pricing across models GAUGE supports finite-resource comparison on the same footing GAUGE treats effort as modeldependent (a profile) GAUGE represents the underlying profile and its crossings GAUGE separates cost-model ambiguity (systematic) from cryptanalytic decay (stochastic) GAUGE analyzes sensitivity to adversary-cost assumptions and exhibits inversions

Concrete security

decision uncertainty

is a price vector assigning to each resource a price in units of the time resource (the numéraire convention cT = 1). The price cone is CT = {c ∈ Rn+ : cT = 1}. Time-only pricing corresponds to c = (1, 0, . . . , 0); time×memory pricing to cT = cM = 1; gatecount pricing (depth×width) to cD = cW = 1 with the time coordinate suppressed. The numéraire convention is not cosmetic: it is precisely what makes zero-memory anchors (e.g. AES key search, which uses negligible memory) price-invariant across time-only and memory-aware conventions, which is required for anchor-relative comparison to be well defined (Proposition 2). Definition 3 (Attack record; attack set). An attack record for a scheme K is a pair (A, xA ): an algorithm A with a stated success probability, together with a log-resource vector xA ∈ Rn (i.e., attack A consumes 2xA,i units of resource Ri ), carrying provenance (paper, year). The attack set AK is the set of all such records at evaluation time; it grows as cryptanalysis progresses. Attack A is feasible in κ if A is admissible in the machine class M of κ. Definition 4 (Literature closure). The admissible set K is the set of cost models each anchored to a position actually taken in peer-reviewed publications, standards documents, or estimator tools, with the citation attached to every element. K is an anti-strawman construction: no model in K lacks a published defender.

4

GAUGE Security Profiles

Definition 5 (Price functional). For a cost model κ = (M, c) and attack A feasible in κ, the price of A is n X Pκ (A) = c · xA = ci xA,i (bits). i=1

6

Table 3: Named accounting conventions as elements of the price cone, with their defended positions. Convention

Pricing

Defended in

Lattice attack cost

Core-SVP TM-sieving Quantum sieve Depth-bounded Gate-count RAM-model

time-only time×memory time-only, quantum D ≤ Dmax depth×width quantum, RAM costs

[20, 21] [17, 7] [18] [8, 22, 24] [22] [24]

20.292β S 20.4995β D 20.2653β D regime-dependentF ≳ TMF revised exponentsF

318 ML-KEM-768

AES-192 (anchor: memory-free)

192 186 c∗M = 0.045 0 (Core-SVP)

(TM) cM 1(memory price)

Figure 2: Security profiles (absolute bits) on the classical memory-price slice: SAES-192 is constant 192; SML-KEM-768 = 186 + 132.18 cM . The profiles cross at c∗M = 0.045; pricing memory at 4.5% of the time unit reverses the comparison (Theorem 1, Experiment 2). Definition 6 (Security profile). The security profile of scheme K is SK (κ) = min{c · xA : (A, xA ) ∈ AK , A feasible in κ}. For an anchor problem G (e.g., AES-128 exhaustive key search) with reference attack cost SG (κ), the anchor-relative profile is SeK (κ) = SK (κ) − SG (κ). The scalar in a specification sheet is SK (κ0 ) for an unstated κ0 ; the profile makes the dependence explicit (Figure 2). Proposition 1 (Structure of security profiles). Fix an attack set with log-resource vectors {xi }i≤m and the price cone CT . Then: (i) SK (c) = mini c · xi ; (ii) SK is concave, positively homogeneous, and piecewise linear on CT ; its linearity regions are precisely the normal cones of the attack polytope PK = conv{xi } [36]; (iii) for any polyhedral region C ⊆ CT , both maxC SK and minC SK are attained at vertices of C and are computable by vertex enumeration in time O(|V (C)|·m); (iv) SK is a tropical polynomial with Newton polytope PK . Proof. (i) is the definition. (ii) A pointwise minimum of linear functionals is concave and positively homogeneous; P the linearity regions of mini c · xi are the normal cones Pof conv{xi }. (iii) Concavity gives, for c = k λk vk a convex combination of vertices, SK (c) ≥ k λk SK (vk ) ≥ mink SK (vk ), so the minimum over C equals the vertex minimum; the maximum follows symmetrically since a linear functional attains its maximum over a polytope at a vertex and maxC mini c · xi is attained where some c · xi is maximized. (iv) Immediate from (ii).

7

Proposition 2 (Monotonicity and normalization). (i) Price monotonicity: if c ≤ c′ componentwise ′ : adding attack then SK (c) ≤ SK (c′ ). (ii) Knowledge monotonicity: if AK ⊆ A′K then SK ≥ SK knowledge only decreases the known-attack profile, which is therefore an upper bound on true security that tightens with cryptanalytic progress. (iii) Anchor-normalization invariance: if the effort statistic is rescaled by a constant factor (equivalently, 2S is replaced by λ 2S for a monotone 1-homogeneous effort functional), the anchor-relative profile SeK is unchanged. In particular, SeK is the invariant observable; absolute bits are convention-dependent up to the anchor. Proof. (i) Each c · xi is nondecreasing in c; minima preserve this. (ii) Minimizing over a larger set can only decrease the value. (iii) SeK = log2 (2SK /2SG ); positive 1-homogeneity of the effort functional cancels in the ratio. Remark 1 (Semantics of the unit). For generic search problems the operational semantics of “n bits of security” is the log2 of expected optimal guessing effort [32, 33], which is the adversary’s actual expenditure; Proposition 2(iii) then says that only anchor-relative differences of this quantity are invariant. A thermodynamic floor exists as well—each irreversible bit operation dissipates at least kT ln 2 joules [34, 35]—but we use it only as a unit anchor, not as an estimate. Definition 7 (Fragility; margins). The fragility index of K over K is ∆K = maxκ,κ′ ∈K |SeK (κ) − nom , where σ nom is the claimed level under the scheme’s SeK (κ′ )|, and the relative fragility is ∆K /σK K declared (time-only) convention. The attack margin is the gap between the claimed level and the best known attack under the declared model; the evidential margin is the gap to the best provable lower bound—close to the full claim for essentially all deployed primitives, including AES and ML-KEM.

5

Security Ordering

5.1

Pointwise and robust orderings

Definition 8 (Pointwise security ordering). For schemes K1 , K2 and cost model κ ∈ K: K1 ⪰κ K2

⇐⇒

SeK1 (κ) ≥ SeK2 (κ).

Definition 9 (Robust security ordering; classification). For a region C ⊆ CT : K1 ⪰C K2 ( K1 dominates K2 on C) iff SeK1 (κ) ≥ SeK2 (κ) for all κ ∈ C. For generic profiles, each pair falls into exactly one of: • Robust dominance: K1 ⪰C K2 with strict inequality somewhere on C (K1 wins throughout); • Conditional dominance: K1 ⪰C K2 with strict inequality only on a proper subregion (superiority holds only for models in that subregion; elsewhere the schemes are measurementequivalent); • Incomparable: there exist κ, κ′ ∈ C with SeK1 (κ) > SeK2 (κ) and SeK1 (κ′ ) < SeK2 (κ′ ) (the ordering reverses). The degenerate case SeK1 ≡ SeK2 on C is measurement equivalence: the schemes are indistinguishable by the instrument (realized in Section 8 by AES-128 and SLH-DSA-128s). A category claim (“K is in Category c”) is, in these terms, the statement SeK (κ) ≥ 0 against the category-c anchor over an implicitly quantified region C that is almost never stated. Definition 9 forces the region into the open.

8

5.2

Cost-model-dependent orderings

Theorem 1 (Cost-model-dependent security ordering). Let K1 , K2 be schemes with profiles over an admissible set K. Call a total preorder ⪰ on schemes sound if K ⪰ K ′ implies SeK (κ) ≥ SeK ′ (κ) for all κ ∈ K (every ranking it asserts is supported at every admissible model). If there exist κa , κb ∈ K with and SeK1 (κb ) < SeK2 (κb ), SeK1 (κa ) > SeK2 (κa ) then no sound total ordering of K1 and K2 exists: any total ranking of the pair is unsupported at some admissible cost model. Proof. By totality, K1 ⪰ K2 or K2 ⪰ K1 ; assume the former without loss of generality. Soundness yields SeK1 (κ) ≥ SeK2 (κ) for all κ ∈ K, contradicting the strict reversal at κb . The symmetric case contradicts the reversal at κa . Theorem 1 is not merely a possibility result: Section 8 exhibits such pairs among NISTstandardized schemes, with linear-programming certificates. It also motivates the classification of Definition 9: since sound total orderings fail exactly at crossing pairs, the well-defined questions become (i) does a crossing exist in a given region, and (ii) if not, which scheme dominates. Both are decidable efficiently; we make no claim that this decidability is itself a deep algorithmic result; the polynomial-time bound below is an immediate consequence of casting crossing-detection as linear-programming feasibility, and we state it because the reduction is the useful part—it is what turns ”these schemes might disagree” into a certificate a standards body can check, not because bounding an LP’s complexity is difficult.

5.3

Complexity of dominance and classification

Proposition 3 (Decidability and complexity of the classification). Let C ⊆ CT be polyhedral and let AK1 , AK2 be finite attack sets with m1 , m2 records. Then: (i) whether there exists κ ∈ C with SeK1 (κ) < SeK2 (κ) is decidable by solving m1 linear programs min t c,t

s.t.

K2 1 (xK i − xj ) · c ≤ t ∀j ∈ AK2 ,

c ∈ C,

and testing whether some optimum satisfies t∗ < 0 (with the witness c∗ the certificate); (ii) the classification of Definition 9 is decidable by running the test of (i) in both directions, using O(m1 + m2 ) linear programs of polynomial size; hence robust-dominance testing over the price cone reduces to checking finitely many polyhedral extrema and is solvable in polynomial time. K2 K1 1 Proof sketch. SeK1 (c) < SeK2 (c) iff some attack i of K1 satisfies c·xK i < minj c·xj , i.e., maxj (xi − 2 xK j ) · c < 0; minimizing the left side over C is exactly the displayed epigraph LP. The classification combines the two directional tests; non-strict boundaries are handled by ε-slack in the standard way. Full proof in Appendix A.

6

The Rating Trilemma

A rating assigns to each scheme a real number determined by its profile, inducing an order K ⪰R K ′ iff R(K) ≥ R(K ′ ). Three properties are natural: Axiom 1 (P1: Faithfulness). If SeK (κ) ≥ SeK ′ (κ) for all κ ∈ K, with strict inequality somewhere, then R(K) ≥ R(K ′ ). 9

eML-KEM − S eAES (bits) S eML-KEM-768 > S eAES-192 S (ML-KEM dominates)

0 eML-KEM-768 < S eAES-192 S (AES-192 dominates) → TMcM

Core-SVP c∗M = 0.045

Figure 3: The price-cone region map for the pair (ML-KEM-768, AES-192) on the classical memoryprice slice. The anchored difference is −6 + 132.18 cM ; the ordering reverses across c∗M = 0.045. The pair is incomparable on any region containing both conventions (Proposition 3, Theorem 1). Axiom 2 (P2: Totality). ⪰R is a total preorder: every pair of schemes receives an ordering. Axiom 3 (P3: Model independence). R is invariant under the convention group G : (i) relabelings and rescalings of resource prices within the ledger (projectively), (ii) permutations of ledger resources (including the choice of numéraire), and (iii) coherent extensions T → T ′ of the ledger (adjoining further physical resources). P2 is automatic for scalar ratings—which is precisely the problem: the underlying order (Section 5) is not total once crossings exist, and Theorem 2 identifies the price totality exacts. Lemma 1 (Mixture representation). Let R be linear in the profile and normalized. Then R satisfies P1 iff there exists a probability vector µ on K with X   R(K) = µκ SeK (κ) = Eκ∼µ SeK (κ) . κ∈K

Proof. Linearity on the finite-dimensional profile space gives a representing vector µ. P1 is monotonicity along every nonnegative direction; testing on pairs differing only at a single κ forces µκ ≥ 0, P and normalization gives κ µκ = 1. Lemma 2 (Symmetry rigidity). Let µ be a Borel probability measure on the projective price space invariant under the rescaling flow of every resource r (ωr 7→ et ωr , renormalized). Then µ is supported on the pure single-resource price vectors {er }. If µ is additionally invariant under ledger permutations, it is uniform over them. Proof sketch. By Poincaré recurrence, µ-a.e. point is recurrent under the time-one map of each flow; any point with two strictly positive coordinates flows forward to a pure vertex and backward to a coordinate face, hence is not recurrent. Intersecting over resources leaves exactly the pure vectors, and permutation invariance on this transitive finite orbit forces uniformity. Full proof in Appendix A. Lemma 3 (Ledger dependence). (i) The uniform-over-pure rating of Lemma 2 changes value under coherent ledger extensions whenever profiles are non-constant on K, and such non-constancy holds for standardized schemes (Section 8). (ii) Every extension-invariant linear rating is supported on a fixed a priori set of models, a commitment no measurement determines. 10

P1 Faithfulness

impossible (Theorem 2) drop P3: rating is a mixture over cost models (Lemma 1)

drop P2: unanimity order, partial (Corollary 4)

P2 Totality

P3 Model independence

drop P1: uniform-over-pure, ledger-dependent (Lemmas 2–3)

Figure 4: The Rating Trilemma. Each edge is a viable research program obtained by relaxing one axiom; the center is impossible in the presence of crossing profiles, which Section 8 exhibits among standardized schemes. Theorem 2 (Rating Trilemma). Within the class of ratings that are monotone aggregators of the profile—in particular all linear ratings and the minimax rating—no rating satisfies P1, P2, and P3 simultaneously once the admissible set contains schemes with crossing profiles. Concretely: (a) by Lemma 1, every total faithful linear rating is a probability mixture over adversary cost models; (b) by Lemmas 2–3, P3’s rescaling-and-permutation invariance forces the uniform-over-pure mixture, which is not extension-invariant, while extension-invariant mixtures require an a priori support commitment; (c) the minimax rating R = minκ SeK (κ) is permutation-invariant but strictly decreases under ledger extensions that add a model where the profile is smaller, violating P3(iii). Consequently every faithful total rating encodes a choice of distribution over—or selection among—adversary cost models; that choice is a modeling decision, not a measurement. Proof. Assemble (a)–(c): a P1–P2 linear rating is a mixture (Lemma 1); P3(i)–(ii) forces uniformover-pure (Lemma 2); P3(iii) then fails by Lemma 3(i), while evading via Lemma 3(ii) contradicts the invariance requirement itself. The minimax case is (c). Full assembly in Appendix A. Corollary 1 (Rating-as-distribution). Every faithful, total, linear rating with normalization admits the interpretation of an expectation under a prior µ over K; two raters who disagree do so only through their µ. Remark 2 (Social choice). With schemes as alternatives and cost models as voters, crossing profiles generate Condorcet-type cycles among total ratings; the trilemma is an Arrow-flavored phenomenon [46] in measurement form. We note the correspondence without claiming a formal equivalence.

7

Security Uncertainty and Temporal Evolution

7.1

Uncertainty channels

GAUGE separates six channels: U1 cost-model choice (systematic); U2a cryptanalytic drift (gradual improvement within the known attack set, e.g., sieve-exponent progress); U2b cryptanalytic

11

jumps (new attack families, e.g., [65, 66]); U3 hardware drift (relative resource prices); U4 quantumarrival timing; U5 implementation risk (e.g., [71]); U6 reduction-loss uncertainty [4, 5]. U2–U4 are stochastic (Type A); U1 and U6 are systematic (Type B); U5 straddles both [38]. The price-cone geometry of Sections 3–6 concerns channel U1 alone: it takes the set of known attacks as given and studies what happens when the prices of their resources change. Every historical failure in the CryChron chronology—SHA-1, SIDH, Matsumoto–Imai, Rainbow—was not a repricing of a known attack but the arrival of a previously unknown one (channel U2b). Channel U2b is handled separately through the survival model of Section 7.3. The geometric layer addresses the distinct question of whether two schemes can be ranked inconsistently depending on an accounting convention, independent of any new cryptanalysis.

7.2

A two-layer risk measure

The two mathematically distinct uncertainties must not be conflated: given a cost model, decay is stochastic; which cost model is appropriate is ambiguity [42, 43, 44]. For scheme K with target level s∗ , let the loss process be LK (t) = [ s∗ − SeK (t) ]+ under the decay processes of its assumption families. Definition 10 (Credal set; trust budget; GAUGE-risk). Let Cρ = {µ : DKL (µ∥µ0 ) ≤ ρ} be a credal set of priors over K around a reference prior µ0 ( trust budget ρ ≥ 0, in nats). For horizon τ and confidence δ:  ρ(K; τ, δ, ρ) = sup CVaRµδ LK (τ ) . µ∈Cρ

Proposition 4 (Two-layer risk and its properties). (i) Coherence: ρ(K) is a coherent risk measure (monotone, positively homogeneous, translation-invariant, subadditive) [39, 40]. (ii) Decomposition: the inner CVaR aggregates stochastic decay given a cost model; the outer supremum aggregates systematic ambiguity across cost models; ρ = 0 recovers the single-model risk, and the trust budget prices the Type-B uncertainty of the apparatus. (iii) Tractability: on finite scenario spaces, ρ is computable by convex programming; with KL balls, via the dual n  o + ρ(K) = min t + 1δ inf βρ + β log Eµ0 e(L−t) /β , t

β>0

by Sion’s minimax theorem [47] and the variational dual of the KL ball [50]. Proof sketch. Each CVaRµδ is coherent; a pointwise supremum of coherent measures preserves monotonicity, homogeneity, and translation invariance, and subadditivity follows from subadditivity of each CVaR plus supµ [f + g] ≤ supµ f + supµ g. The dual is the Rockafellar–Uryasev representation of CVaR composed with the KL-ball variational form. Full proof in Appendix A. The corresponding claim format for specification sheets is: “K retains ≥ s anchor-relative bits at horizon τ , confidence δ, within trust budget ρ.” A worked illustration with declared illustrative inputs appears in Appendix E.

7.3

Temporal evolution of attack effort

Cryptanalysis chronology. We curate a versioned dataset (CryChron; full contents and methodology in Appendix D) of 22 assumption generations across nine strata, with 10 observed break (“jump”) events and 12 right-censored generations. Observed ages at break range from 6 to 22 years. The pooled Kaplan–Meier estimator [48] crosses 50% survival at t = 22 years (Ŝ(22) = 0.446; 12

cumulative bits gained (β = 637)

9.7 9

bit

s/y

r

dashed: renewal posterior expected first event (16.8 bits / 5y)

2008

2012

2016 2020 2024 2028 quiet years (priced by the renewal posterior)

year

Figure 5: Historical evolution of lattice-sieving attack cost on the reference parameter class β = 637: cumulative bits gained by exponent improvements, 2008–2016, followed by nine quiet years. Greenwood variance 0.0758; bootstrap 95% CI ≈ [0.26, 0.77]); the stratum-level curves for the eventfree strata (LWE-type lattices, codes, factoring, discrete logarithms) remain at 1 throughout the window, so their medians are not estimable—a statement about the state of evidence. Because cryptanalytic events cluster by technique (the 2004 Wang-cluster breaks; the GGH/NTRUSign transcript-attack lineage), the survival model carries a shared frailty per technique lineage. Construction and scope of the drift statistic. The historical lattice drift—78.35 bits gained on the reference block size β = 637 between 2008 and 2016, i.e., 9.79 bits per year (Figure 5)—is a descriptive statistic of a single attack family over a single window. Its construction and limits are as follows. Dataset: peer-reviewed improvements to lattice-sieving exponents only (0.415 → 0.292 [15, 16, 17]). Normalization: all magnitudes are evaluated on one reference parameter class (β = 637, the ML-KEM-768 block size); the figure is not a rate per cryptographic family and is not comparable across families (a 2-bit hash-function improvement has a different denominator and mechanism). Independence: successive sieve improvements build on their predecessors, so the observations are not independent—which is why we model them as a renewal process rather than a regression, and why no confidence interval is attached to the raw rate (with four events it would be meaningless). Descriptive, not predictive: we do not extrapolate the 9.79 figure beyond the sieving family and the 2008–2016 window; predictive use is confined to the explicit renewal model below, whose prior is stated and whose output is a distribution. Renewal posterior. Modeling classical sieve-exponent improvements as a Poisson process with a Gamma prior calibrated to the 2008–2016 window (Gamma(4, 8); prior choice illustrative, arithmetic exact; sensitivity: across a 5 × 4 grid of Gamma(α, β) priors with α ∈ {2, 3, 4, 5, 6}, β ∈ {4, 8, 12, 16} the first-event drift ranges from 9.4 to 19.8 bits, stable within 1.4× of the baseline), the nine subsequent quiet years update the posterior to Gamma(4, 17): mean rate 0.235 events/year; P[no event in 5y] = (17/22)4 ≈ 0.357; mean event magnitude 26.12 bits on β = 637; and the firstevent drift—the expected magnitude of the first improvement in the window—is 16.8 bits over five years, while the uncapped expectation E[N (5)] · m̄ = 30.7 bits counts subsequent events at full magnitude and is an upper estimate, since post-plateau steps have historically been smaller.

13

CryChron Survival Function of Cryptographic Assumption Generations 1.0

Kaplan-Meier S(t) 95% Greenwood CI

Survival Probability S(t)

0.8 0.6 0.4 0.2 0.0

0

10

20 30 Generation Lifetime (Years)

40

50

Figure 6: Pooled Kaplan–Meier survival curve for the 22-generation CryChron chronology, with Greenwood 95% confidence band, generated by experiment E4 of the artifact. The curve crosses 50% survival at t = 22 years, with a wide band reflecting the small sample of break events; the stratum-level breakdown (event-free strata remaining at 1 throughout the window) is tabulated separately in the artifact output, since the small per-stratum counts make a combined plot difficult to read. This is the empirical counterpart of the schematic drift in Figure 5.

8

Cryptographic Evaluation

8.1

Setup and provenance discipline

Schemes: ML-KEM-512/768/1024 [27, 21]; SLH-DSA-128s [29]; Classic McEliece-348864 [30]; HQC-128 [31]; X25519; RSA-2048; anchors AES-128/192. Cost models: the conventions of Table 3, each literature-anchored. Provenance tags: (S) specification-published value; (D) exact arithmetic from cited exponents, regenerated by the released toolchain; (F) regenerated from cited sources, argument insensitive to the exact value; (I) illustrative input, displayed where assumed; (Qsim) quantum circuit measurement in a noisy simulator; (Q-hw) quantum hardware measurement (none populated at submission time; see Section 8, Experiment 5). The full register, with a resultby-result verification matrix, is Appendix B. A specification gate (G1) enforces that computed time-only levels reproduce the specification ladder of ML-KEM to ±1 bit and that AES is invariant under memory pricing; an inversion gate (G2) enforces LP-certified reversals.

8.2

Experiment 1: profiles and fragility across families

Proposition 5 (Relative fragility is a family constant). In the exponent-affine family model (attack log-costs xi (β) = βξi + ci with fixed exponents), S(c; β) = β S(c; 1) up to additive constants; hence ∆(β) grows linearly in the parameter while ∆/σ nom is a family constant. For module lattices under current exponents the constant is (0.4995 − 0.2653)/0.292 = 0.802; for symmetric primitives it is exactly Grover’s 1/2; for the curated Classic McEliece estimates, 0.464. Consequently, within-family parameter upsizing cannot reduce relative cost-model sensitivity; only assumption diversity or more conservative anchor conventions can. 14

Table 4: Security profiles over the three core conventions, fragility index ∆, and relative fragility ∆/σ nom . Scheme ML-KEM-512 ML-KEM-768 ML-KEM-1024 AES-128 AES-192 SLH-DSA-128s Classic McEliece-348864 HQC-128

c-T

c-TM

q-T

∆

∆/σ nom

117.97D 186.00S 256.08D 128 192 128S 140S 128S

201.80D 318.18D 438.06D 128 192 128D 140F 128F

107.18D 168.99D 232.67D 64 96 64D ≈75F ≈7xF

94.62 149.19 205.39 64 96 64 65.00 [F]

0.802 0.802 0.802 0.500 0.500 0.500 0.464 [F]

Table 5: Ranking inversions among standardized schemes under two literature-anchored conventions (classical time-only vs. quantum time-only), with LP certificates (Proposition 3). Pair

Convention

SeK1

SeK2

(ML-KEM-512, AES-128) (ML-KEM-768, AES-192)

Certificate

c-T q-T

−10.03D +43.18D

0 0

t∗ = −10.03, witness c∗ = eT t∗ = −43.18, witness c∗ = eT

c-T q-T

−6.00S +72.99D

0 0

t∗ = −6.00 t∗ = −72.99

Proof. S(c; β) = mini c · (βξi + ci ) = β mini c · ξi + O(1); the ratio ∆/σ nom inherits constancy. Deviations are exactly the jump events of channel U2b and are handled by Section 7. Findings. (F1) Relative fragility is family-structural: 0.802 (module lattices), 0.500 (symmetric), 0.464 (curated code-based estimates). By this measure, the standardized lattice claims are the most cost-model-sensitive; larger lattice parameters buy zero relative robustness, since ∆/σ nom is invariant within a family. (F2) The ML-KEM ladder exhibits the constant of Proposition 5 exactly (0.802/0.802/0.802, up to specification rounding). The constancy in (F2) follows algebraically from Proposition 5 and serves as a toolchain consistency check. The empirically substantive result is (F1): the three family constants (0.802, 0.500, 0.464) depend on the cited attack exponents and would change if those exponents change.

8.3

Experiment 2: ranking inversions under certified cost models

Findings. (F3) Both pairs instantiate the premise of Theorem 1 with certified witnesses: the Category-1 pair swings 53.21 bits and the Category-3 pair 79.00 bits across two defensible conventions. On the memory-price slice the Category-3 pair crosses at c∗M = 0.045 (Figure 3): pricing memory at 4.5% of the time unit reverses a standardized category comparison. (F4) Under the unanimity policy of Corollary 4, both pairs are formally incomparable: no strict preference is defensible without declaring a cost-model distribution (Corollary 1). (F5) Symmetric primitives have flat anchor-relative profiles (Grover halves anchor and scheme alike), whereas lattice and code schemes move: category comparisons measure different things for different families.

15

Category-3 Inversion on Memory-Price Slice

Security σ(ω) (bits)

210 205 200 195 ML-KEM-768 (Primal Sieve) AES-192 Anchor Crossing w * = 0.0454

190 185

0.000

0.025

0.050 0.075 0.100 0.125 0.150 Memory Price Weight wM (with wT = 1)

0.175

0.200

Figure 7: Certified crossing of the (ML-KEM-768, AES-192) security profile pair as a function of the memory-price weight cM , generated by experiment E2 of the artifact and certified by the LP solver of Proposition 3 (t∗ < 0). The Category-3 comparison reverses ranking at c∗M ≈ 0.045: pricing memory at 4.5% of the time unit is enough to flip a standardized category comparison. The Category-1 pair (ML-KEM-512, AES-128) exhibits the same qualitative crossing at c∗M ≈ 0.120 (tabulated in Table 5).

8.4

Experiment 3: sensitivity of security to resource prices

The local sensitivity is itself family-structural (0.2075β for lattices, 0 for memory-free attacks), which is why the global constant of Proposition 5 exists at all: the profile’s slope in each resource price is an exponent of the underlying attack family.

8.5

Experiment 4: robust-ordering classification

Findings. (F6) The classification is computable and nondegenerate: robust dominance holds exactly where the profile separation is structural (within a family ladder; against quantum-broken classical assumptions), and incomparability holds exactly where exponents disagree across conventions. (F7) The classification is region-dependent: the X25519/AES-128 pair is a near-tie on the classical region and a robust dominance once quantum machine classes are admitted, so the machine-class dimension of the admissible region drives the verdict as much as the price vector.

8.6

Experiment 5: instrument calibration on simulated and physical hardware

Because the quantum conventions price the category anchors theoretically, we additionally calibrate the instrument itself against a concrete implementation: Grover searches at n = 2, 3, 4 qubits and a depth-versus-width branching experiment at search space N = 16 are executed on the IonQ simulator (aria-1 noise model; 2026-09-15T12:31:07Z; 1 000 shots per circuit; 13 jobs; protocol and realized numbers in Appendix E; provenance class (Q-sim)). The simulator run quantifies (i) the realized multiplier between logical iteration counts and simulated physical cost under a representative noise model (κhw = 10.5–11.9 bits), and (ii) the reversal of cost orderings between time-only and gate-count accounting for branched search—the price-cone phenomenon of Section 4, 16

Table 6: Local sensitivity (directional derivative of S in the memory price at the time-only convention) and global sensitivity (∆/σ nom ). The derivative equals the memory exponent times the block size; the anchor is memory-invariant by the numéraire convention (Proposition 2(iii)). Scheme

∂S/∂cM c-T (bits/unit)

∆/σ nom

83.83D 132.18D 181.98D 0 0 ≈0F

0.802 0.802 0.802 0.500 0.500 0.464

ML-KEM-512 ML-KEM-768 ML-KEM-1024 AES-128 / AES-192 SLH-DSA-128s Classic McEliece-348864

observed under simulation rather than merely asserted (depth decreases with B; gate count increases with B). These are instrument calibrations, not security claims about any scheme, and the simulator figures do not affect any claim in Sections 8–9.

9

Practical Implications

9.1

Hybrid constructions

Proposition 6 (Conjunctive composition and diversification). Let H = C(K1 , K2 ) be a conjunctive hybrid (sound combiner [52, 53] with context binding enforced; implementation-risk increment IH ≥ 0 declared; combiner slack o). Then LH = min(L1 , L2 ) + o + IH , and consequently: (i) CVaRδ (LH ) ≤ mini CVaRδ (Li ) + o + IH —hybridization never increases cryptanalytic risk beyondRthe best leg plus controllable overheads; (ii) under independent break pro∞ cesses, E[min(L1 , L2 )] = 0 (1 − F1 )(1 − F2 ) dx, strictly below mini E[Li ]; under perfectly correlated (comonotone) breaks the benefit vanishes; the benefit is governed by the assumption-correlation structure. Corollary 2 (Two genres of hybrid). For disjunctive (OR-verified) hybrids, LH ′ = max(L1 , L2 ): they provide availability and downgrade resilience, not cryptanalytic security. The two genres have different value and must be evaluated differently. Corollary 3 (Classical-component contribution). For a conjunctive hybrid pairing a classical component C with a post-quantum component Q with break times TC , TQ and horizon τ , the classical component’s contribution to survival is exactly V (τ ) = P(TQ ≤ τ < TC ) = FQ (τ ) SC (τ )

(under independence),

where FQ is the break distribution of Q and SC the survival function of C. The component is valuable exactly over the window in which Q may fail while C still holds; it should be sized as the cheapest classical primitive with SC (τ ∗ ) ≥ 1 − δc , and dropped when V (τ ∗ ) no longer justifies its overhead. Numerical illustration (inputs (I), arithmetic (D)): for X25519+ML-KEM-768 as deployed [75, 72], the handshake overhead is 2336 bytesS ; with declared posteriors P[ML-KEM break within 5y] = 3% and P[X25519 falls within 5y] = 5%, Corollary 3 gives V (5y) = 2.85% of scenarios and a joint 17

Table 7: Classification of scheme pairs (Definition 9) over the full admissible region (all conventions of Table 3) unless stated. “Full incl. quantum” adds machine classes admitting Shor’s algorithm [1]. Pair

Classification

(ML-KEM-1024, MLKEM-768) (ML-KEM-768, ML-KEM512) (ML-KEM-512, AES-128) (ML-KEM-768, AES-192) (AES-128, SLH-DSA-128s)

robust dominance (1024) robust dominance (768) incomparable incomparable measurement equivalence (McEliece-348864, AES- robust domi128) nance (McEl.) (ML-KEM-512, RSA- robust dom2048), full incl. quantum inance (MLKEM) (X25519, AES-128), classi- weak dominance cal only (AES) (X25519, AES-128), full robust domiincl. quantum nance (AES) (HQC-128, AES-128) conditional (HQC; strict only on quantum side)

Evidence +70.08 bits at c-TD +68.03 bits at c-TD Table 5 Table 5 identical profilesS 140 > 128, ≈75 > 64SF 118D vs ≈112F ; 107D vs poly (Shor)

≈3 bitsF 64D vs poly (Shor) tie at c-TS ; ≈7× > 64F

failure probability of 0.15%—a factor-20 reduction of the cryptanalytic tail relative to the postquantum leg alone. The framework also predicts, from the assumption-correlation matrix (Appendix E), that intra-family hybrids such as ML-KEM+FN-DSA (both module-lattice) acquire near-zero diversification benefit, while cross-family pairings acquire real benefit—a prediction verifiable against deployment data.

9.2

Migration timing

Corollary 4 (Unanimity policy). Call a migration policy zero-regret if its actions are weakly better than the alternative at every admissible cost model. The unanimity policy—switch from incumbent I to challenger C iff SeC (κ) ≥ SeI (κ) for all admissible κ—is the unique maximal zero-regret policy [45, 43]. By Theorem 1, crossing pairs (e.g., the standardized pairs of Table 5) are formally incomparable under this policy. Proposition 7 (Migration as optimal stopping). With arrival posterior pt , migration cost, and data lifetime Y , the migration-timing problem is a monotone optimal-stopping problem whose optimal policy is a threshold rule in pt [78]; in the deterministic limit the boundary reduces to Mosca’s inequality X + Y ≥ Z [55]. Hence any published deadline is an implicit quantile statement about (pt , decay, Y ). Deadline audit. If quantum-vulnerable public-key use ends at the 2035 boundary of NIST IR 8547 [57] after a migration window of X = 3 years, an asset with confidentiality lifetime Y is exposed whenever a cryptographically relevant quantum computer arrives by ≈2035 + X + Y . Under curated arrival quantiles [56], the implied exposure tolerance is ≈18% for Y = 5 (horizon ≈2043) but ≈83% for Y = 30 (horizon ≈2068)S : a single deadline implies a lifetime-dependent 18

Audit of NIST IR 8547 (2035 Deadline) under GRI Timeline Prior

Implied Risk P[Z ≤ 2035 + X + Y]

1.0 0.9 0.8 0.7 0.6 0.5 0.4 Implied Accepted CRQC Risk ε(Y) 50% Median Line

0.3 0

5

10 15 20 25 30 Asset Confidentiality Lifetime Y (Years)

35

40

Figure 8: Deadline inversion surface: implied exposure risk P[Z ≤ 2035 + X + Y ] as a function of confidentiality lifetime Y , generated directly from the curated arrival posterior [56] by experiment E7 of the artifact (Section 10). The single published deadline of NIST IR 8547 corresponds to a rising curve of implied risk tolerance, not a constant one; the two audited points (Y = 5, ≈ 18%; Y = 30, ≈ 83%) are marked. These two quantiles carry provenance tag S (Appendix B): independently re-derived from gri arrival.csv via the E7 toolchain; values reproduced exactly. The qualitative shape of the curve does not depend on their exact values. risk tolerance, defensible for short-lived assets and under-protective for long-lived ones, which require earlier migration. These two quantiles have been independently re-derived from the underlying gri arrival.csv dataset using the experiment E7 toolchain: ≈18% (Y=5) and ≈83% (Y=30) reproduced exactly (provenance tag upgraded from F to S ; Appendix B). The qualitative conclusion—that one deadline cannot be simultaneously calibrated for both short- and long-lived assets—is insensitive to the exact quantile values, since it follows from any arrival distribution with positive density past 2035. The full sensitivity curve is in the artifact.

9.3

Implications for standards

The admissible set K makes the convention choices of standards bodies explicit and comparable: mapping published institutional positions onto the price cone (Appendix E) shows the time-only convention implicit in standardized estimates placing ML-KEM-512 ten bits below its Category1 anchor, while memory-aware conventions defended by several European bodies place it 74 bits above. No institution is in error; the dispersion is unpriced convention choice, which the framework renders visible and auditable. A worked case. The dispersion above is not hypothetical: it is the documented substance of the disagreement between NIST’s time-only categorization of ML-KEM-512 as “Category 1, comparable to AES-128” and the memory-aware guidance from BSI and ANSSI that treats the same parameter set as offering materially less margin than AES-128 once realistic memory cost is priced in (positions curated in Appendix E). Read as scalar ratings, the two positions look like a factual dispute—one of

19

the two bodies must be wrong about where ML-KEM-512 sits relative to AES-128. Read as security profiles, they are not in factual disagreement at all: both compute the correct value of SeK at their respective κ, and Table 5’s certificate shows the two κ are on opposite sides of a genuine crossing. A protocol designer who selects a parameter set by citing one body’s category label is implicitly choosing a cost model. GAUGE does not resolve which body’s convention is correct—Corollary 4 shows that under a unanimity policy the pair is formally incomparable without an explicit declared weighting of memory cost—but it makes the crossing visible before deployment, so the choice is at least a conscious one.

10

Implementation and Reproducibility

The artifact comprises: (i) a toolchain computing profiles, fragility indices, LP classification certificates with witnesses (Proposition 3), the risk dual (Proposition 4), and the survival/renewal statistics; (ii) the curated datasets (cryptanalysis chronology, realized-cost ledger, institutional positions, arrival quantiles), each record carrying provenance; (iii) a versioned schema for machinereadable security claims compatible with cryptographic-inventory formats [76] (Appendix C); and (iv) a pre-registration registry of falsifiable predictions with trusted timestamps. Gates G1–G2 of Section 8 run in the test suite; the full pipeline, including property-based verification of every stated numerical law, completes in under one minute on commodity hardware, with per-suite timings and checksums recorded. All tables in this paper are regenerated from the datasets by a single command. The companion verification register (Appendix B) separates exact, property-verified, illustrative, and instrument-calibration results by provenance class (Section 8). The full artifact— toolchain, curated datasets, verification register, and pre-registration timestamps—is available at https://github.com/bgupta55/gauge-artifact and will be archived with a persistent DOI at [DOI to be inserted at camera-ready: Zenodo archive of the tagged release].

11

Limitations

(1) Known-attack profiles. SK is defined over published attacks; it is an upper bound on true security that tightens with cryptanalysis (Proposition 2(ii)). Where lower bounds do not exist, the evidential margin (Definition 7) measures the gap rather than hiding it. (2) Admissible-set construction. K is curated; every element is literature-anchored and contestable, and the curation log is versioned, but the closure is a judgment. (3) Scope of the trilemma. Theorem 2 covers linear and minimax aggregators; the general nonlinear landscape is open (Appendix B). (4) Small-sample hazards. Ten jump events support protocol demonstration and pre-registration, not statistical power; all survival quantities carry wide intervals. (5) Drift statistic. Descriptive only, single family, single window (Section 7.3); predictive statements require the explicit renewal model. (6) Illustrative priors. All (I)-tagged numbers await replacement by elicited priors. The GRI quantile pair (≈ 18%/≈ 83%, Section 9) has been independently re-derived from gri arrival.csv via the E7 toolchain; both values reproduced exactly; tag upgraded to S . (7) Instrument calibration. Experiment 5 calibrates the instrument on 2–4 qubits using IonQ simulator (aria-1 noise model; 2026-09-15; 13 jobs; class (Q-sim)); the noise model is a lower bound on real device noise, and neither figure estimates faulttolerant attack costs. (8) Combiner side conditions. Proposition 6 assumes sound, binding-enforcing combiners; the binding literature is incorporated via the side conditions. (9) Implementation risk. Channel U5 is treated exogenously through declared increments.

20

12

Conclusion

We developed GAUGE, a formal framework in which cryptographic security is a function over heterogeneous adversary cost models rather than a scalar. The framework yields a geometry of cost-model space (Propositions 1–2), a sound ordering theory with a polynomial-time robust/conditional/incomparable classification (Theorem 1, Proposition 3), an impossibility result for scalar model-independent ratings (Theorem 2), a coherent two-layer risk measure separating model ambiguity from cryptanalytic decay (Proposition 4), and composition laws for hybrid systems (Proposition 6). The evaluation exhibits certified ranking reversals among standardized post-quantum schemes, family-level sensitivity constants, and hardware calibration of the measurement instrument. These results give standards bodies and protocol designers an instrument for making cost-model dependence explicit and for distinguishing robust rankings from convention-dependent ones.

A

Deferred Proofs

Lemma 2P(symmetry rigidity). Work in the compact space of projective price vectors W = {ω ≥ 0 : i ωi = 1}. For resource r, let ϕt be the flow replacing ωr by et ωr and renormalizing; each ϕt is a homeomorphism with ϕs+t = ϕs ϕt . If µ is ϕ-invariant, the time-one map is measurepreserving on (W, µ), so by Poincaré recurrence µ-a.e. point is recurrent. If 0 < ωr < 1 then ϕt (ω) → er as t → +∞ and to the face {ωr = 0} as t → −∞, so such ω is not recurrent; hence supp µ ⊆ {ωr = 0} ∪ {er }. Intersecting over all r leaves exactly the pure vectors {er }. Permutation invariance on this finite transitive orbit forces the uniform measure. □ P Lemma 3 (ledger dependence). (i) The uniform-over-pure value is n1 r SeK (er ); under T → T ′ every weight changes from 1/n to 1/(n+1) and a new term enters, changing the value whenever the profile is non-constant; non-constancy holds for the standardized schemes of Table 4. (ii) Extension invariance requires the mixture’s support to avoid every model added by every coherent extension, i.e., a fixed a priori support; no measurement arbitrates it. □ Theorem 2 (assembly). Assume R linear, faithful (P1), total (P2), and G -invariant (P3). By Lemma 1, R = Eµ for a probability µ on K. P3(i)–(ii) and Lemma 2 force µ uniform-over-pure on the current ledger; P3(iii) and Lemma 3(i) then fail for non-constant profiles. Evading via Lemma 3(ii) replaces invariance with an a priori commitment, i.e., abandons P3. For the minimax rating, R = minκ SeK (κ) decreases strictly under extensions adding a model with smaller profile value, violating P3(iii); it satisfies P3(i)–(ii) but not P1-compatible extension behavior. □ 1 Proposition 3 (classification). (i) SeK1 (c) < SeK2 (c) iff there is an attack i of K1 with c · xK i < K2 K2 K1 minj c · xj , i.e., maxj (xi − xj ) · c < 0. Minimizing the left-hand side over polyhedral C is the displayed LP (epigraph form, with the numéraire equality cT = 1 among the constraints); strict negativity is tested against −ε for arbitrary fixed ε > 0 with the standard open/closed limit argument. (ii) Running the test for both orientations decides robust dominance (both tests fail to find inversions against the dominant side, and the dominance side’s test finds no reversal); incomparability (both find reversals); conditional dominance and equivalence are separated by the strictness LPs ∃c : SeK1 > SeK2 in both directions. Each LP has at most max(m1 , m2 ) constraints and n+1 variables; the count is O(m1 + m2 ). □

21

Proposition 4 (two-layer risk). Coherence: each CVaRµδ is coherent [40]; monotonicity, homogeneity, and translation invariance pass to the pointwise supremum; subadditivity: supµ ρµ (X+Y ) ≤ supµ [ρµ (X)+ρµ (Y )] ≤ supµ ρµ (X)+supµ′ ρµ′ (Y ). Tractability: apply the Rockafellar–Uryasev form CVaRµδ (L) = mint {t + δ −1 Eµ [(L − t)+ ]}; the objective is convex in t, linear in µ; the KL-ball supremum of an expectation equals inf β>0 {βρ + β log Eµ0 eZ/β } for Z = (L − t)+ ; Sion’s theorem [47] exchanges inf t and supµ on the convex compact credal set. □ Proposition 6 (composition). Under the side conditions, breaking H requires defeating both legs, so the optimal attack targets the cheaper side and LH = min(L1 , L2 ) + o + IH . (i) follows from R ∞ monotonicity of CVaR [40]. (ii) For independent nonnegative losses with tails F̄i : E[min] = 0 F̄1 F̄2 dx, strictly below mini E[Li ] unless a loss is degenerate; under comonotone coupling with equal marginals min(L1 , L2 ) = L1 a.s., and the benefit vanishes; in the one-factor decomposition Li = ai F + εi , concordance—and hence the bound—is monotone in the common-factor loading. □ Corollary 3 (classical-component contribution). The hybrid fails by τ iff both components have failed: P(fail) = FQ (τ )FC (τ ), so survival is 1 − FQ FC = SQ + FQ SC ; the second term is the increment over the post-quantum leg alone and factors under independence. □ Proposition 7 (stopping). The value function is monotone in the arrival posterior, which together with convex flow costs verifies the standard sufficient conditions for threshold optimality [78]; the deterministic substitution pt = 1[t ≥ Z] collapses the boundary to X + Y ≥ Z [55]. □

B

Provenance and Verification Register

Tags. S: published specification value (e.g., the ML-KEM time-only ladder ≈ 118/186/256 against the round-3 specification [21]; sizes against FIPS 203 [27]; Classic McEliece cost against its specification’s attack analysis, curation note P-1: our first-pass value of ≈ 128–130 was corrected to 140 by two-pass reconciliation against the specification, recorded in the curation log). D: exact arithmetic from cited exponents (all TM/quantum/fragility/crossing/ drift/renewal figures; e.g., 0.4995 · 637 = 318.18). F: regenerated from cited sources, argument insensitive (depth-bounded and gate-count entries; code-based quantum costs; arrival-quantile tolerances; NFS estimate for RSA-2048 from [7]). I: illustrative input, displayed where assumed (risk-table priors; correlation matrix; hybrid posteriors). Q-sim: quantum circuit measurement in a noisy simulator; Experiment 5 executed on IonQ simulator (aria-1 noise model; 2026-09-15T12:31:07Z; 13 jobs; class (Q-sim)). Q-hw: quantum hardware measurement; not yet populated at submission. Result-status matrix (condensed). Deterministic arithmetic (D): reproduced exactly. Structural laws (Propositions 1, 3, 4, 6): verified by property-based testing over randomized instances and closed-form-versus-simulation checks. Empirical premises (crossings among standardized schemes): certified by LP witnesses. Illustrations (risk grid, hybrid posteriors): machinery verified under declared (I) inputs. Instrument calibration (Experiment 5): 13 IonQ simulator jobs completed (2026-09-15T12:31:07Z; aria-1 noise model; class (Q-sim)); realized multiplier κhw = 10.5–11.9 bits; depth-ordering reversal confirmed; full results in results/q/e9 results.json.

C

Artifact and Schema Details

The machine-readable claim format (compatible with [76]) is: 22

GAUGE-statement/1.0 { scheme: "ML-KEM-768", standard: "FIPS 203", ledger: ["T","M","Q","D","W","N"], numeraire: "T", anchor: {"problem": "AES-192-keysearch"}, models: [ {"id":"c-T","pricing":[1,0,0,0,0,0],"provenance":"..."}, {"id":"c-TM","pricing":[1,1,0,0,0,0],"provenance":"..."}, {"id":"q-T","machine":"quantum-unbounded", "pricing":[1,0,0,0,0,0],"provenance":"..."} ], attacks: [ {"alg":"primal-BKZ2-sieve-classical", "logresources":[186,132.18,0,0,0,0],"provenance":"..."} ], profile: {"c-T":186.00,"c-TM":318.18,"q-T":168.99}, fragility: {"delta":149.19,"relative":0.802}, margins: {"attack":0,"evidential":"~full-claim"}, risk: {"horizon_y":10,"delta":0.05,"trust_nats":0.5, "value":"per-illustration-(I)"}, version: "saa-1.0" }

Every attack record carries a non-empty provenance string, enforced by schema validation in the test suite.

D

Cryptanalysis Chronology: Dataset and Methodology

Table 8: CryChron (release 2): 22 assumption generations, 10 jump events, 12 right-censored. Stratum

Generation

Birth

Age at break

Provenance

Knapsack Multivariate Hash Hash Multivariate Lattice-sig Lattice-sig Hash Isogeny Multivariate

Merkle–Hellman Matsumoto–Imai/HFE MD4 MD5 SFLASH GGH NTRUSign SHA-1 SIDH Rainbow

1978 1988 1990 1992 2001 1997 2003 1995 2011 2005

6 15 14 12 6 9 13 22 11 17

[59] Faugère, 2003 [63] [63] [60] [61] [62] [64] [65] [66]

Censored at 2025 (12): SHA-2 (24), SHA-3 (13), NTRU (29), LWE (20), R-LWE (15), M-LWE (11), NTRU-Prime (9), CSIDH (7), McEliece–Goppa (47), RSA (48), f-DLP (∼50), ECDLP (∼40).

Methodology. The unit of observation is an assumption generation (a specific hardness assumption as introduced), with right-censoring at the analysis date. LWE-type assumptions and structured-lattice signatures are separate strata: their breaks (transcript-leakage attacks [61, 62]) are orthogonal to LWE-type hardness, and pooling them would corrupt the stratification. Events cluster by technique (the 2004 hash cluster; the GGH/NTRUSign lineage), modeled by a shared frailty. Kaplan–Meier estimates with Greenwood variance and 104 bootstrap resamples; the exploratory backtest (train pre-2015 events; test 2016–2022 events: family-history and structural covariates elevate the hazard of NTRUSign, SHA-1, and Rainbow; SIDH is flagged by structural covariates only) demonstrates the protocol with n = 10 and no claimed power.

23

Realized-cost ledger (calibration points). DES brute force, $250,000 (1998) [68]; RSA-768 factorization [69]; 795-bit finite-field discrete logarithm, ≈35 core-years [70]; SHA-1 collision ≈6,500 CPU-years+100 GPU-years [64]; AES-128 biclique, ≈2 bits [67]; SIKE, a laptop hour [65]; Rainbow, a weekend [66].

E

Additional Evaluation Details

Risk illustration. With declared illustrative inputs (drift, jump quantile, trust-budget penalty) the risk-adjusted anchor level of ML-KEM-768 at τ = 10y, δ = 5%, ρ = 0.5 nats is ≈ 134 bits (drift 17 per the first-event renewal figure of Section 7.3); SLH-DSA-128s ≈ 111; Classic McEliece-348864 ≈ 119. The verified content is the monotonicity of the adjustment in (τ, δ, ρ) and the machinery; the priors are (I). Assumption-correlation matrix (elicited, (I)). MLWE/SIS–X25519 0.1; MLWE/SIS–McEliece 0.1; MLWE/SIS–SHA-2 0.05; X25519–RSA 0.6; others low. The intra-family factor correlation for module-lWE/SIS pairs (ML-KEM, FN-DSA) is ≈ 0.9, driving the near-zero diversification prediction of Section 9. Institutional dispersion. Mapping the curated positions of NIST (depth-bounded anchors; scheme estimates time-only per submissions) [8, 9], and the memory-aware positions in BSI TR02102-1 v2026-01 [10] and ANSSI advisory 14 Apr 2022 [11] onto the price cone reproduces Table 7’s incomparability from the institutional side: the two position classes order the Category-1 pair oppositely (arithmetic (D); institutional mapping (S), primary sources extracted and quotes verified against BSI TR-02102-1 pp. 23, 28, 38 and ANSSI advisory pp. 4, 6, 8). Instrument calibration protocol (Experiment 5). Grover searches at n = 2, 3, 4 (optimal iteration counts; ≤ 4000 shots) and a branching experiment partitioning a N = 16 search into B ∈ {1, 2, 4} subsearches are executed on the IonQ simulator (aria-1 noise model; 2026-0915T12:31:07Z; 1 000 shots/circuit; 13 jobs; seeds, transpilation level, and noise-model parameters recorded in the artifact; class (Q-sim)). Gates: (i) realized depth, width, gate counts and shotsto-90% success per n, yielding a simulator-side multiplier over logical iteration counts, reported as a lower bound on the eventual hardware multiplier since real devices carry additional correlated and readout error not captured by the noise model; (ii) the branched design is cheaper under time-only accounting (max depth decreases with B) and dearer under gate-count accounting (total gates increase with B)—the ordering reversal of the price cone, reproduced under simulation; (iii) the empirical guesswork distribution against the ideal of [32], yielding a noise-induced gap on the unit. These results are reported as class (Q-sim) (IonQ simulator, aria-1 noise model; 2026-09-15T12:31:07Z; 1 000 shots; 13 jobs; full artifact at results/q/e9 results.json).

24

F

Notation

T , ledger κ = (M, c) CT xA K Pκ (A), SK (κ), SeK (κ) nom PK , ∆ K , σ K ⪰κ , ⪰ C Cρ , ρ LK (t), CVaRδ U1–U6

canonical adversarial resources (Definition 1) adversary cost model (Definition 2) price cone {c ≥ 0 : cT = 1} log-resource vector of attack A (Definition 3) literature closure of admissible cost models (Definition 4) price; profile; anchor-relative profile attack polytope; fragility; nominal claimed level pointwise and robust security orderings (Definitions 8–9) credal set; trust budget (Definition 10) loss process; conditional value-at-risk uncertainty channels (Section 7)

References [1] P. W. Shor. Algorithms for quantum computation: Discrete logarithms and factoring. In IEEE FOCS, 1994. [2] S. Goldwasser and S. Micali. Probabilistic encryption. Journal of Computer and System Sciences, 28(2):270–299, 1984. [3] M. Bellare and P. Rogaway. Random oracles are practical: A paradigm for designing efficient protocols. In ACM CCS, 1993. [4] M. Bellare and P. Rogaway. The exact security of digital signatures: How to sign with RSA and Rabin. In EUROCRYPT, 1996. [5] N. Koblitz and A. Menezes. Another look at “provable security”. Journal of Cryptology, 17(1):1–35, 2004. [6] A. K. Lenstra and E. R. Verheul. Selecting cryptographic key sizes. Journal of Cryptology, 14(4):255– 293, 2001. [7] N. P. Smart et al. (eds.). Algorithms, Key Size and Protocols Report. ECRYPT-CSA D5.3, 2020. [8] L. Chen et al. NIST IR 8100: Report on Post-Quantum Cryptography. NIST, 2016. [9] G. Alagic et al. NIST IR 8413: Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process. NIST, 2022. [10] BSI. Technical Guideline TR-02102-1: Cryptographic Mechanisms: Recommendations and Key Lengths, version 2026-01. Bundesamt für Sicherheit in der Informationstechnik, 2026. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/ TG02102/BSI-TR-02102-1.pdf [11] ANSSI. Selecting Cryptographic Algorithms, advisory, 14 April 2022. Agence nationale de la sécurité des systèmes d’information. https://www.ssi.gouv.fr/uploads/2021/03/anssi-guide-selection_ crypto-1.0.pdf [12] M. J. Wiener. The full cost of cryptanalytic attacks. Journal of Cryptology, 17(2):105–124, 2004. [13] D. J. Bernstein. Understanding brute force. ECRYPT STVL Workshop on Symmetric Key Encryption, 2005. [14] R. Schroeppel and A. Shamir. A T = O(2n/2 ), S = O(2n/4 ) algorithm for certain NP-complete problems. SIAM Journal on Computing, 10(3):456–464, 1981.

25

[15] P. Q. Nguyen and T. Vidick. Sieve algorithms for the shortest vector problem are practical. Journal of Mathematical Cryptography, 2(2):181–207, 2008. [16] D. Micciancio and P. Voulgaris. Faster exponential time algorithms for exact lattice problems. In ACMSIAM SODA, 2010. [17] A. Becker, L. Ducas, N. Gama, and T. Laarhoven. New directions in nearest-neighbor searching with applications to lattice sieving. In EUROCRYPT, 2016. [18] T. Laarhoven. Search Problems in Cryptography: From Fingerprinting to Lattice Sieving. PhD thesis, TU Eindhoven, 2015. [19] M. R. Albrecht, R. Player, and N. Scott. On the concrete hardness of learning with errors. Journal of Mathematical Cryptography, 9(3):169–203, 2015. [20] E. Alkim, L. Ducas, T. Pöppelmann, and P. Schwabe. Post-quantum key exchange—A new hope. In USENIX Security Symposium, 2016. [21] R. Avanzi et al. CRYSTALS—Kyber: A CCA-secure module-lattice-based KEM (round 3 specification), 2021. [22] M. Grassl, B. Langenberg, M. Roetteler, and R. Steinwandt. Applying Grover’s algorithm to AES: Quantum resource estimates. In PQCrypto, 2016. [23] M. Amy, O. Di Matteo, V. Gheorghiu, M. Mosca, A. Parent, and J. Schanck. Estimating the cost of generic quantum preimage attacks on SHA-2 and SHA-3. In SAC, 2016. [24] S. Jaques and J. M. Schanck. Quantum cryptanalysis in the RAM model: Claw-finding attacks on SIDH. In CRYPTO, 2019. [25] C. Gidney and M. Ekerå. How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits. Quantum, 5:433, 2021. https://doi.org/10.22331/q-2021-04-15-433. [26] D. J. Bernstein. Grover vs. McEliece. In PQCrypto, 2010. [27] NIST. FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard. August 2024. [28] NIST. FIPS 204: Module-Lattice-Based Digital Signature Standard. August 2024. [29] NIST. FIPS 205: Stateless Hash-Based Digital Signature Standard. August 2024. [30] Classic McEliece team. Classic McEliece: Conservative Code-Based Cryptography (round-4 documentation). 2022. [31] HQC team and NIST. HQC: Hamming quasi-cyclic public-key encryption (selected as fifth NIST PQC algorithm). March 2025. [32] J. L. Massey. Guessing and entropy. In IEEE ISIT, 1994. [33] E. Arikan. An inequality on guessing and its application to sequential decoding. IEEE Transactions on Information Theory, 42(1):99–105, 1996. [34] R. Landauer. Irreversibility and heat generation in the computing process. IBM Journal of Research and Development, 5(3):183–191, 1961. [35] C. H. Bennett. Time/space trade-offs for reversible computation. SIAM Journal on Computing, 18(4):766–776, 1989. [36] D. H. Krantz, R. D. Luce, P. Suppes, and A. Tversky. Foundations of Measurement, Vol. I. Academic Press, 1971.

26

[37] S. S. Stevens. On the theory of scales of measurement. Science, 103(2684):677–680, 1946. [38] JCGM 100:2008. Evaluation of Measurement Data — Guide to the Expression of Uncertainty in Measurement. JCGM, 2008. [39] P. Artzner, F. Delbaen, J.-M. Eber, and D. Heath. Coherent measures of risk. Mathematical Finance, 9(3):203–228, 1999. [40] R. T. Rockafellar and S. Uryasev. Optimization of conditional value-at-risk. Journal of Risk, 2:21–42, 2000. [41] F. Delbaen. Coherent risk measures on general probability spaces. In Advances in Finance and Stochastics, Springer, 2002. [42] P. Walley. Statistical Reasoning with Imprecise Probabilities. Chapman & Hall, 1991. [43] I. Gilboa and D. Schmeidler. Maxmin expected utility with non-unique prior. Journal of Mathematical Economics, 18(2):141–153, 1989. [44] P. Klibanoff, M. Marinacci, and S. Mukerji. A smooth model of decision making under ambiguity. Econometrica, 73(6):1849–1892, 2005. [45] T. C. Bewley. Knightian decision theory: Part I. Decisions in Economics and Finance, 25(2):79–110, 2002. [46] K. J. Arrow. Social Choice and Individual Values. Wiley, 1951. [47] M. Sion. On general minimax theorems. Pacific Journal of Mathematics, 8(1):171–176, 1958. [48] E. L. Kaplan and P. Meier. Nonparametric estimation from incomplete observations. JASA, 53(282):457– 481, 1958. [49] D. R. Cox. Regression models and life-tables. JRSS B, 34(2):187–220, 1972. [50] P. M. Esfahani and D. Kuhn. Data-driven distributionally robust optimization using the Wasserstein metric. Mathematical Programming, 171:115–166, 2018. [51] L. A. Gordon and M. P. Loeb. The economics of information security investment. ACM TISSEC, 5(4):438–457, 2002. [52] F. Giacon, F. Heuer, and T. Yeo. KEM combiners. In PKC, 2018. [53] N. Bindel, J. Brendel, M. Fischlin, et al. Hybrid key encapsulation mechanisms and authenticated key exchange. In PQCrypto, 2019. [54] P. Schwabe, D. Stebila, and T. Wiggers. Post-quantum TLS without handshake signatures. In ACM CCS, 2020. [55] M. Mosca. Cybersecurity in an era with quantum computers: Will we be ready? IEEE Security & Privacy, 16(5):38–41, 2018. [56] M. Piani and M. Mosca. Quantum Threat Timeline Report. Global Risk Institute, 2019 (with later updates). [57] NIST. NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards. November 2024. [58] National Security Agency. Commercial National Security Algorithm Suite 2.0. 2022.

27

[59] A. Shamir. A polynomial-time algorithm for breaking the basic Merkle–Hellman cryptosystem. IEEE Transactions on Information Theory, 30(5):699–704, 1984. [60] V. Dubois, P.-A. Fouque, A. Shamir, and J. Stern. Practical cryptanalysis of SFLASH. In CRYPTO, 2007. [61] P. Q. Nguyen and O. Regev. Learning a parallelepiped: Cryptanalysis of GGH and NTRU signatures. In EUROCRYPT, 2006. [62] L. Ducas and P. Q. Nguyen. Learning a zonotope and more: cryptanalysis of NTRUSign countermeasures. In ASIACRYPT, 2012. [63] X. Wang, D. Feng, X. Lai, and H. Yu. Collisions for hash functions MD4, MD5, HAVAL-128 and RIPEMD. IACR ePrint 2004/199, 2004. [64] M. Stevens, E. Bursztein, P. Karpman, A. Albertini, and Y. Markov. The first collision for full SHA-1. In CRYPTO, 2017. [65] W. Castryck and T. Decru. An efficient key recovery attack on SIDH. In EUROCRYPT, 2023. [66] W. Beullens. Breaking Rainbow takes a weekend on a laptop. In CRYPTO, 2022. [67] A. Bogdanov, D. Khovratovich, and C. Rechberger. Biclique cryptanalysis of the full AES. In ASIACRYPT, 2011. [68] Electronic Frontier Foundation. Cracking DES. O’Reilly, 1998. [69] T. Kleinjung et al. Factorization of a 768-bit RSA modulus. In CRYPTO, 2010. [70] F. Boudot, P. Gaudry, A. Guillevic, N. Heninger, E. Thomé, and P. Zimmermann. Comparing the difficulty of factorization and discrete logarithm. In CRYPTO, 2020. [71] KyberSlash: timing side-channel vulnerabilities in Kyber implementations (public disclosures). 2024. [72] IETF TLS Working Group. Hybrid key exchange with ECDHE and ML-KEM (Internet-Draft). 2024. [73] M. Marlinspike and R. Perrin. The PQXDH Key Agreement Protocol. Signal Foundation, 2023. [74] Apple Security Engineering and Architecture. iMessage with PQ3. 2024. [75] Google Chrome and Cloudflare engineering blogs. Post-quantum TLS deployment notes. 2023–2024. [76] OWASP CycloneDX. CycloneDX v1.6 with the Cryptographic Bill of Materials. 2024. [77] M. Campagna et al. Quantum-Safe Cryptography and Security. ETSI White Paper No. 8, 2015. [78] G. Peskir and A. Shiryaev. Optimal Stopping and Free-Boundary Problems. Birkhäuser, 2006.

28

Record · ID 919241 · SHA-256 15c9bf05796cf09c
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.