• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Architecture-Derived CBOMs for Cryptographic Migration: A Security-Aware Architecture Tradeoff Method
 
  • Details
  • Full
Options
2026
Conference Paper
Title

Architecture-Derived CBOMs for Cryptographic Migration: A Security-Aware Architecture Tradeoff Method

Abstract
Cryptographic migration driven by algorithm deprecation, regulatory change, and post-quantum readiness requires more than an inventory of cryptographic assets. Existing Cryptographic Bills of Materials (CBOMs) are typically tool- or inventory-derived. They lack architectural intent, rationale, and security context, limiting their usefulness for migration planning. This paper introduces Security-Aware Architecture Tradeoff Analysis Method (SATAM), a security-aware adaptation of scenario-based architecture evaluation that derives an architecture-grounded, context-sensitive CBOM. SATAM integrates established approaches: ATAM, arc42, STRIDE, ADR, and CARAF. These Generated artifacts are used to annotate CBOM entries with architectural context, security intent, and migration-critical metadata using CycloneDX-compatible extensions. Following a Design Science Research approach, the paper presents the method design, a conceptual traceability model, and an illustrative application. The results demonstrate that architecture-derived CBOMs capture migration-relevant context that is typically absent from inventory-based approaches. Thereby, SATAM improves availability of information required for informed cryptographic migration planning and long-term cryptographic agility.
Author(s)
Hirsch, Eduard
Fachhochschule Amberg-Weiden
Raab, Kristina
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Mainwork
Migration and Agility in Cryptographic Systems. First International Workshop, MAgiCS 2026. Proceedings  
Conference
International Workshop on Migration and Agility in Cryptographic Systems 2026  
Open Access
DOI
10.1007/978-3-032-28946-9_2
Additional link
Full text
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Keyword(s)
  • Architecture Tradeoff Analysis

  • Cryptographic Bill of Materials

  • Cryptographic Migration

  • Post-Quantum Cryptography

  • Security-Aware Architecture

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024