Skip to main content

PRI7

Crypto-agile

Every cryptographic choice — curve, hash, commitment scheme, proof system — is a named, versioned parameter of the artifact, never an assumption of the code, so each artifact records the algorithms it was made under and stronger suites can be adopted for new work as they standardise — the planned, budgetable path to post-quantum-ready cryptography as those algorithms are ratified, rather than a present-day post-quantum claim.

Rationale

Cryptographic algorithms have finite working lives; treating each choice as a named, versioned parameter means you can adopt stronger ones as they standardise without rebuilding systems — protecting long-lived investments against the day today’s algorithms weaken. This is the concrete path to post-quantum-ready protection — a migration you plan and budget for as standards land, not a present-day post-quantum claim — and it depends on this principle taking precedence over convenience: verification rejects weakened suites, or configurability becomes a way in for attackers.

Implications

  • Your minimum acceptable cryptography is set as policy and enforced at verification, so a misconfiguration or a pressured shortcut cannot silently downgrade the protection your customers were promised.
  • Each artifact records the algorithms it was made under and stays verifiable against them, so your minimum cryptography can be strengthened as a planned, incremental change — new work adopts the stronger suite as it standardises — rather than a coordinated rebuild of your whole estate.
  • Post-quantum readiness is a path you can plan and budget for as standards land — a forward migration you adopt as algorithms are ratified, not a security property claimed today.
‹ All twelve principles

Build on the principles
from day one.

Join the waitlist