Intent-Based Cryptographic API Design for Cryptographic Agility

📅 2026-06-11
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of current cryptographic APIs, which are tightly coupled to specific algorithms and lack policy-driven control and key migration capabilities, thereby hindering smooth transitions to post-quantum cryptography. To overcome these challenges, the paper proposes a novel API architecture designed for cryptographic agility, grounded in five core principles: abstraction, stability, temporal flexibility, separation of concerns, and extensibility. By introducing scoped intent vocabularies and abstract policy interfaces, the design decouples algorithm selection from key management. Leveraging Protocol Buffers schemas alongside stable key identifiers and evolvable operations—such as rotation, transformation, and migration—the approach transforms algorithm updates into operational procedures that require no application code changes, significantly enhancing the feasibility and efficiency of migrating systems to post-quantum cryptographic standards.
📝 Abstract
As organizations move toward post-quantum cryptography, they face the major challenge of updating cryptographic algorithms across large, complex software portfolios. However, most cryptographic APIs in use today were designed around specific algorithms. These APIs expect explicit use of specific algorithms, provide little or no support for policy-based algorithm selection, and offer no straightforward way to migrate existing keys to newer algorithms. This makes the transition to post-quantum cryptography challenging. The companion assessment framework identifies the barriers to cryptographic agility and explains why algorithm transition is largely a software engineering problem. To address the limitations of current cryptographic APIs, we identify the principles necessary to design a cryptographically agile API. The design principles are derived from five fundamental architectural characteristics (Abstraction, Stability, Temporal Flexibility, Separation, and Extensibility). We also show how the design principles can be implemented using several examples of Protocol Buffers API design patterns. In particular, we present an intent vocabulary that is based on scopes which allows for decoupling key creation from algorithm identities. It also supports transparent substitutions of algorithms in the applicable scope. Cryptographic governance is enabled by an abstract policy API that does not prescribe the policy format. Keys are represented by stable identifiers and support key evolution operations (rotation, transformation, migration), facilitating migration between algorithms and providers while tracking both the original key identity and its evolution history. With this approach, updating cryptography becomes an operational process without the need to rewrite application code.
Problem

Research questions and friction points this paper is trying to address.

cryptographic agility
post-quantum cryptography
cryptographic API
algorithm migration
software engineering
Innovation

Methods, ideas, or system contributions that make the work stand out.

Intent-Based API
Cryptographic Agility
Post-Quantum Cryptography
Key Evolution
Policy-Driven Cryptography
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Navaneeth Rameshan
IBM Research Europe, Zurich, Switzerland
G
Gregoire Messmer
IBM Research Europe, Zurich, Switzerland