· Michal Pietrus  · 2 min read

Czy crypto-agility to kolejny buzzword z dobrą narracją, ale kłopotliwy w adopcji w praktyce?

Wraz z przejściem od protokołów do systemów i governance, crypto-agility staje się coraz trudniejsze. Zaczynają dominować koszty, heterogeniczność, potrzeba koordynacji i gotowość do automatyzacji.

Wraz z przejściem od protokołów do systemów i governance, crypto-agility staje się coraz trudniejsze. Zaczynają dominować koszty, heterogeniczność, potrzeba koordynacji i gotowość do automatyzacji.
Polskie tłumaczenie tego wpisu nie jest jeszcze dostępne. Oryginalna wersja angielska jest wyświetlona poniżej.

The emergence of post-quantum cryptographic algorithms has brought crypto-agility back into the mainstream. A concept that is supposed to address a broadly unsolved problem, namely how to change the underlying cryptographic algorithm while keeping the need for large scale planning, synchronization/coordination, and operational disruption under control.

Crypto-agility as per NIST CSWP 39

NIST CSWP 39 distinguishes crypto-agility depending on the context, including the agility of:

  • a protocol,
  • a system,
  • an organisation’s governance.

In other words, the broader the level of agility, the greater the organisational, operational, and infrastructural challenges it creates.

Thus, crypto-agility is a cost that, depending on the organization’s digital strategy posture, will at best be a heterogeneous mix of the three approaches above.

Establishing the rationale for the spending requires considering aspects such as:

  • structural challenges,
  • cost-benefit ratio,
  • ecosystem complexity, heterogeneity, inertia, and slow convergence.

Homogeneous and heterogeneous trust ecosystems

For example, the WebPKI trust ecosystem, while massive in scale, is relatively homogeneous in its trust model and purpose, mainly authenticating websites through their domain names.

On the other hand, another trust ecosystem spanning:

  • physical access,
  • digital access,
  • transactional/organizational/legal authority,

may encompass several semantically distinct trust domains. Such heterogeneous, distributed trust ecosystems, likely spanning different vendors and relying on various cryptosystems, require synchronization, coordination, and careful upgrades.

Crypto-agility and the need for automation posture

Orthogonal to this is organizational readiness for large-scale automation, essential even for system-level agility. The recently published paper “Intent-based crypto API design” provides a conceptual answer of how this could work in practice. It abstracts crypto-related operations into a separate component, delegating their execution while possibly creating an enforcement point through which governance/control plane imposes what cryptography is used across the organisation.

BUT, whether such a strategy is executable in practice depends heavily on the organisation’s digitial (not merely crypto) agility and its posture towards automation.

What next?

Before all this fluffy buzzwords reach operationalization, build a CBOM.

It will not undermine your “migration spirit”, and upon this you can decide what next steps make sense, including whatever level of-agility is actually reasonable.

Back to Blog

Related Posts

View All Posts »