K09 · bounded executable evidence infrastructure
Cryptographic Migration Graph
Direct answer
The K09 reference graph contains 19 nodes and 24 edges and remains DEGRADED because planned, test-required, and unavailable dependencies are preserved.
Authority and disclosure boundary. K09 publishes static tools, synthetic fixtures, source-derived event records, signed offline imports, non-certifying traces, redacted procurement structures, and public/protected partition schemas. It does not perform live monitoring, reveal protected topology or credentials, decide awards, certify facilities, authorize operations, or prove factual truth from a signature.
Migration readiness
19dependency nodes
24typed edges
DEGRADEDreference readiness
12nodes affected by unavailable HSM support
Dependency inventory
| ID | Type | Name | State |
|---|---|---|---|
CMG-PROTO-TLS | protocol | TLS profile | INVENTORIED |
CMG-PROTO-DNSSEC | protocol | DNSSEC profile | INVENTORIED |
CMG-LIB-OPENSSL | library | Cryptographic library | MIGRATION_TEST_REQUIRED |
CMG-HW-HSM | hardware | Hardware security module | SUPPLIER_CONFIRMATION_REQUIRED |
CMG-HW-TPM | hardware | Platform trust module | INVENTORIED |
CMG-CERT-WEB | certificate | Public service certificate | CLASSICAL |
CMG-CERT-DEVICE | certificate | Device identity certificates | CLASSICAL |
CMG-KEY-SIGN | key | Evidence signing keys | HYBRID_PLAN_REQUIRED |
CMG-KEY-KEK | key | Key-encryption keys | ROTATION_PLAN_REQUIRED |
CMG-REC-RECEIPTS | record | Long-lived evidence receipts | LONG_TERM_VERIFY_REQUIRED |
CMG-BACKUP-OFFLINE | backup | Offline recovery evidence | INVENTORIED |
CMG-SUPPLIER-HSM | supplier | HSM supplier support | UNAVAILABLE |
CMG-SUPPLIER-LIB | supplier | Library maintenance support | CURRENT |
CMG-HYBRID-KEM | migration | Hybrid key-establishment profile | PLANNED |
CMG-HYBRID-SIG | migration | Hybrid signature profile | PLANNED |
CMG-ROLLBACK | control | Controlled rollback | DESIGNED |
CMG-DOWNGRADE | control | Downgrade resistance | TEST_REQUIRED |
CMG-ARCHIVE | control | Long-lived verification archive | DESIGNED |
CMG-ROOT | claim | Cryptographic transition preserves required services and evidence | DEGRADED |
Relationships
CMG-ROOTDEPENDS_ONCMG-HYBRID-KEMCMG-ROOTDEPENDS_ONCMG-HYBRID-SIGCMG-ROOTDEPENDS_ONCMG-ROLLBACKCMG-ROOTDEPENDS_ONCMG-DOWNGRADECMG-ROOTDEPENDS_ONCMG-ARCHIVECMG-HYBRID-KEMUSESCMG-LIB-OPENSSLCMG-HYBRID-KEMUSESCMG-HW-HSMCMG-HYBRID-SIGUSESCMG-LIB-OPENSSLCMG-HYBRID-SIGUSESCMG-KEY-SIGNCMG-PROTO-TLSUSESCMG-CERT-WEBCMG-CERT-WEBPROTECTED_BYCMG-HYBRID-SIGCMG-PROTO-DNSSECUSESCMG-KEY-SIGNCMG-CERT-DEVICEUSESCMG-HW-TPMCMG-CERT-DEVICEPROTECTED_BYCMG-HYBRID-SIGCMG-KEY-SIGNCUSTODIED_BYCMG-HW-HSMCMG-KEY-KEKCUSTODIED_BYCMG-HW-HSMCMG-HW-HSMSUPPORTED_BYCMG-SUPPLIER-HSMCMG-LIB-OPENSSLSUPPORTED_BYCMG-SUPPLIER-LIBCMG-REC-RECEIPTSVERIFIED_WITHCMG-KEY-SIGNCMG-REC-RECEIPTSARCHIVED_BYCMG-ARCHIVECMG-BACKUP-OFFLINEPROTECTSCMG-ARCHIVECMG-ROLLBACKDEPENDS_ONCMG-BACKUP-OFFLINECMG-DOWNGRADEGOVERNSCMG-PROTO-TLSCMG-DOWNGRADEGOVERNSCMG-PROTO-DNSSEC
Migration rule
Standardized algorithms are necessary but insufficient. Migration must cover protocol negotiation, implementation support, hardware custody, certificate and key issuance, long-lived receipt verification, backups, hybrid operation, rollback, downgrade resistance, supplier support, and recovery. The graph remains degraded while mandatory support or tests are unavailable.