Preprint
Article

This version is not peer-reviewed.

Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM

Submitted:

24 August 2026

Posted:

24 August 2026

You are already at the latest version

Abstract
Cryptographic inventories and runtime detection can identify declared or observed cryptographic use, but they do not by themselves establish whether the exact implementation exhibited externally specified behavior or whether an evidence-backed use satisfies explicit policy. We present a deterministic cryptographic assurance composition that connects admitted runtime behavior to provenance-closed evidence, exact implementation identity, separately bound conformance against Contract-registered NIST test vectors, content-addressed policy appraisal, and explainable ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 authentic runtime executions and six provenance-distinct occurrences. The frozen implementation subjects produced expected outputs for all 505 registered inventory entries—130/130 SHA-256 and 375/375 AES-256-GCM ENCRYPT—yielding two authentic conformance results. Under a policy frozen before authentic appraisal, all six occurrences followed the positive path to ACCEPT; controls independently demonstrated REJECT for supported policy violations and REVIEW for missing or out-of-coverage evidence. Conformance and appraisal/verdict evidence reconstructed byte-identically in 10/10 replays; 12/12 conformance controls and 25/25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. These results demonstrate a reproducible bounded assurance chain across two cryptographic classes, without claiming exhaustive correctness, CAVP/CMVP validation, FIPS certification, generalized discovery, regulatory compliance, or production authorization.
Keywords: 
;  ;  ;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.