Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM

Cryptographic inventories and runtime detection identify cryptographic use but do not establish implementation conformance or policy satisfaction. We present a deterministic composition linking admitted runtime evidence, provenance closure, exact implementation identity, Contract-registered NIST test-vector conformance, and content-addressed policy appraisal to ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 runtime executions and six provenance-distinct occurrences. The frozen subjects produced expected outputs for all 130 SHA-256 inventory entries and 375 AES-256-GCM ENCRYPT cases, yielding two conformance results. A policy precommitted before authentic appraisal produced six positive-path ACCEPT verdicts; controls demonstrated REJECT and REVIEW. Conformance replay was byte-identical in 10/10 executions per subject, and the complete six-occurrence appraisal reconstructed identically in 10/10 replays. All 12 conformance and 25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. Public access supports validation of released non-secret evidence and eligible tests, not full regeneration of the original experiment: the workload key, private history, and runnable registered OCI images are unavailable in that release. The contribution is a bounded assurance composition; finite test success and policy ACCEPT do not establish exhaustive correctness, certification, or production authorization.

Authors

Publication Details

Journal
Computers
Published
2026-09-29
DOI
https://doi.org/10.3390/computers15100659
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM

Robert D. Campbell
Computers
Security and Verification in Computing
article

Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM

Robert D. Campbell
article en

Abstract

Cryptographic inventories and runtime detection identify cryptographic use but do not establish implementation conformance or policy satisfaction. We present a deterministic composition linking admitted runtime evidence, provenance closure, exact implementation identity, Contract-registered NIST test-vector conformance, and content-addressed policy appraisal to ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 runtime executions and six provenance-distinct occurrences. The frozen subjects produced expected outputs for all 130 SHA-256 inventory entries and 375 AES-256-GCM ENCRYPT cases, yielding two conformance results. A policy precommitted before authentic appraisal produced six positive-path ACCEPT verdicts; controls demonstrated REJECT and REVIEW. Conformance replay was byte-identical in 10/10 executions per subject, and the complete six-occurrence appraisal reconstructed identically in 10/10 replays. All 12 conformance and 25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. Public access supports validation of released non-secret evidence and eligible tests, not full regeneration of the original experiment: the workload key, private history, and runnable registered OCI images are unavailable in that release. The contribution is a bounded assurance composition; finite test success and policy ACCEPT do not establish exhaustive correctness, certification, or production authorization.

ComputersVol. 15(10)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM — Robert D. Campbell · Computers (2026) | TGRS Research Map | TGRS