Foundation Erasure: Bounded Cryptographic Dependence After Repeated Algorithm Migration
Cryptographic agility is usually discussed as the ability to replace algorithms without disrupting a running system. That view leaves a harder question unresolved: after migration is declared complete, does compromise of a retired cryptographic foundation still contribute to the security of the current canonical state? We study this question for mutable authenticated state and introduce foundation erasure, a retirement criterion under which a retired foundation leaves the active security frontier of current-state verification. We formalize retirement debt, post-finalization collapse non-interference, and a retirement point separating periods in which old authority remains security-critical from periods in which it no longer has current write authority. We then develop a semantic re-anchoring construction with atomic finality and evaluate it in a reproducible software framework. Across repeated migrations, an executable verifier trace remains constant at two security-resource calls—current foundation plus finality—with zero retired-foundation calls through 128 epochs, whereas a historical-chain comparator grows to 130 calls. Collapse-timing experiments exhibit a sharp phase boundary: four attack classes succeed before finalization and are rejected after finalization. Cross-family post-finalization tests across RSA, ECDSA, and ML-DSA reject all 12 current-state replacement attempts, while a cumulative 128-epoch experiment rejects all 768 attacks launched from compromised retired epochs. Primitive benchmarks confirm feasibility across classical and post-quantum signatures. The results motivate telescoping security: cryptographic history may grow without current security dependence growing with it.
Authors
- Md. Amir Khusru Akhtar (ORCID: https://orcid.org/0000-0002-3432-4199)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-21
- DOI
- https://doi.org/10.5281/zenodo.22878897
- Primary Topic
- Security and Verification in Computing
- Type
- preprint