Submitted:
24 August 2026
Posted:
24 August 2026
You are already at the latest version
Abstract
Cryptographic inventories and runtime detection can identify declared or observed cryptographic use, but they do not by themselves establish whether the exact implementation exhibited externally specified behavior or whether an evidence-backed use satisfies explicit policy. We present a deterministic cryptographic assurance composition that connects admitted runtime behavior to provenance-closed evidence, exact implementation identity, separately bound conformance against Contract-registered NIST test vectors, content-addressed policy appraisal, and explainable ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 authentic runtime executions and six provenance-distinct occurrences. The frozen implementation subjects produced expected outputs for all 505 registered inventory entries—130/130 SHA-256 and 375/375 AES-256-GCM ENCRYPT—yielding two authentic conformance results. Under a policy frozen before authentic appraisal, all six occurrences followed the positive path to ACCEPT; controls independently demonstrated REJECT for supported policy violations and REVIEW for missing or out-of-coverage evidence. Conformance and appraisal/verdict evidence reconstructed byte-identically in 10/10 replays; 12/12 conformance controls and 25/25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. These results demonstrate a reproducible bounded assurance chain across two cryptographic classes, without claiming exhaustive correctness, CAVP/CMVP validation, FIPS certification, generalized discovery, regulatory compliance, or production authorization.

Keywords:
cryptographic assurance
; runtime evidence
; cryptographic conformance
; provenance
; policy appraisal
; assurance verdict
; reproducible computing
; semantic identity
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.