CALI research

Algorithm profiles

Versioned profiles for RSA, ECC, ML-DSA and migration policy without exposing provider-specific configuration at application call sites.

Profile purpose

An algorithm profile is a versioned policy object. It fixes identifiers, parameters, approved uses, provider constraints and migration relationships so applications reference an intent rather than reproducing cryptographic configuration.

Signature profiles in v2

Profile Algorithm Role Notes
rsa-pss-sha256 RSA-PSS with SHA-256 classical compatibility minimum modulus and salt policy required
ecdsa-p256-sha256 ECDSA P-256 with SHA-256 current ECC application signing verifier compatibility must be inventoried
mldsa-65 ML-DSA-65 post-quantum target provider capability and larger artifacts must be tested
ecdsa-p256-to-mldsa-65 staged profile transition migration creates a new ML-DSA key; does not convert ECC key material

Example profile record

{
  "schemaVersion": "2.0.0",
  "profileId": "pqc-application-signing-v2",
  "intent": "application-authentication",
  "algorithms": [
    { "identifier": "ECDSA-P256-SHA256", "state": "verify-only" },
    { "identifier": "ML-DSA-65", "state": "preferred" }
  ],
  "constraints": {
    "privateKeyExport": false,
    "silentFallback": false,
    "evidenceRequired": true
  }
}

Profile evolution

Profile versions are immutable. A policy authority publishes a new version, defines activation and overlap windows and identifies verifier readiness. The broker pins one version per request. Expired policy fails explicitly.