Profile purpose
An algorithm profile is a versioned policy object. It fixes identifiers, parameters, approved uses, provider constraints and migration relationships so applications reference an intent rather than reproducing cryptographic configuration.
Signature profiles in v2
| Profile | Algorithm | Role | Notes |
|---|---|---|---|
rsa-pss-sha256 |
RSA-PSS with SHA-256 | classical compatibility | minimum modulus and salt policy required |
ecdsa-p256-sha256 |
ECDSA P-256 with SHA-256 | current ECC application signing | verifier compatibility must be inventoried |
mldsa-65 |
ML-DSA-65 | post-quantum target | provider capability and larger artifacts must be tested |
ecdsa-p256-to-mldsa-65 |
staged profile transition | migration | creates a new ML-DSA key; does not convert ECC key material |
Example profile record
{
"schemaVersion": "2.0.0",
"profileId": "pqc-application-signing-v2",
"intent": "application-authentication",
"algorithms": [
{ "identifier": "ECDSA-P256-SHA256", "state": "verify-only" },
{ "identifier": "ML-DSA-65", "state": "preferred" }
],
"constraints": {
"privateKeyExport": false,
"silentFallback": false,
"evidenceRequired": true
}
}
Profile evolution
Profile versions are immutable. A policy authority publishes a new version, defines activation and overlap windows and identifies verifier readiness. The broker pins one version per request. Expired policy fails explicitly.