K09 · bounded executable evidence infrastructure

Cryptographic Migration Graph

Direct answer

The K09 reference graph contains 19 nodes and 24 edges and remains DEGRADED because planned, test-required, and unavailable dependencies are preserved.

Authority and disclosure boundary. K09 publishes static tools, synthetic fixtures, source-derived event records, signed offline imports, non-certifying traces, redacted procurement structures, and public/protected partition schemas. It does not perform live monitoring, reveal protected topology or credentials, decide awards, certify facilities, authorize operations, or prove factual truth from a signature.

Migration readiness

19dependency nodes
24typed edges
DEGRADEDreference readiness
12nodes affected by unavailable HSM support

Dependency inventory

Cryptographic migration nodes
IDTypeNameState
CMG-PROTO-TLSprotocolTLS profileINVENTORIED
CMG-PROTO-DNSSECprotocolDNSSEC profileINVENTORIED
CMG-LIB-OPENSSLlibraryCryptographic libraryMIGRATION_TEST_REQUIRED
CMG-HW-HSMhardwareHardware security moduleSUPPLIER_CONFIRMATION_REQUIRED
CMG-HW-TPMhardwarePlatform trust moduleINVENTORIED
CMG-CERT-WEBcertificatePublic service certificateCLASSICAL
CMG-CERT-DEVICEcertificateDevice identity certificatesCLASSICAL
CMG-KEY-SIGNkeyEvidence signing keysHYBRID_PLAN_REQUIRED
CMG-KEY-KEKkeyKey-encryption keysROTATION_PLAN_REQUIRED
CMG-REC-RECEIPTSrecordLong-lived evidence receiptsLONG_TERM_VERIFY_REQUIRED
CMG-BACKUP-OFFLINEbackupOffline recovery evidenceINVENTORIED
CMG-SUPPLIER-HSMsupplierHSM supplier supportUNAVAILABLE
CMG-SUPPLIER-LIBsupplierLibrary maintenance supportCURRENT
CMG-HYBRID-KEMmigrationHybrid key-establishment profilePLANNED
CMG-HYBRID-SIGmigrationHybrid signature profilePLANNED
CMG-ROLLBACKcontrolControlled rollbackDESIGNED
CMG-DOWNGRADEcontrolDowngrade resistanceTEST_REQUIRED
CMG-ARCHIVEcontrolLong-lived verification archiveDESIGNED
CMG-ROOTclaimCryptographic transition preserves required services and evidenceDEGRADED

Relationships

  • CMG-ROOT DEPENDS_ON CMG-HYBRID-KEM
  • CMG-ROOT DEPENDS_ON CMG-HYBRID-SIG
  • CMG-ROOT DEPENDS_ON CMG-ROLLBACK
  • CMG-ROOT DEPENDS_ON CMG-DOWNGRADE
  • CMG-ROOT DEPENDS_ON CMG-ARCHIVE
  • CMG-HYBRID-KEM USES CMG-LIB-OPENSSL
  • CMG-HYBRID-KEM USES CMG-HW-HSM
  • CMG-HYBRID-SIG USES CMG-LIB-OPENSSL
  • CMG-HYBRID-SIG USES CMG-KEY-SIGN
  • CMG-PROTO-TLS USES CMG-CERT-WEB
  • CMG-CERT-WEB PROTECTED_BY CMG-HYBRID-SIG
  • CMG-PROTO-DNSSEC USES CMG-KEY-SIGN
  • CMG-CERT-DEVICE USES CMG-HW-TPM
  • CMG-CERT-DEVICE PROTECTED_BY CMG-HYBRID-SIG
  • CMG-KEY-SIGN CUSTODIED_BY CMG-HW-HSM
  • CMG-KEY-KEK CUSTODIED_BY CMG-HW-HSM
  • CMG-HW-HSM SUPPORTED_BY CMG-SUPPLIER-HSM
  • CMG-LIB-OPENSSL SUPPORTED_BY CMG-SUPPLIER-LIB
  • CMG-REC-RECEIPTS VERIFIED_WITH CMG-KEY-SIGN
  • CMG-REC-RECEIPTS ARCHIVED_BY CMG-ARCHIVE
  • CMG-BACKUP-OFFLINE PROTECTS CMG-ARCHIVE
  • CMG-ROLLBACK DEPENDS_ON CMG-BACKUP-OFFLINE
  • CMG-DOWNGRADE GOVERNS CMG-PROTO-TLS
  • CMG-DOWNGRADE GOVERNS CMG-PROTO-DNSSEC

Migration rule

Standardized algorithms are necessary but insufficient. Migration must cover protocol negotiation, implementation support, hardware custody, certificate and key issuance, long-lived receipt verification, backups, hybrid operation, rollback, downgrade resistance, supplier support, and recovery. The graph remains degraded while mandatory support or tests are unavailable.