Architecture-Derived CBOMs for Cryptographic Migration: A Security-Aware Architecture Tradeoff Method

📅 2026-03-23
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of existing cryptographic bill-of-materials (CBOMs), which lack architectural intent and security context, thereby hindering effective cryptographic migration planning. To overcome this gap, the authors propose the Security-Aware Trade-off Analysis Method (SATAM)—a novel approach that uniquely integrates architectural decisions with CBOM construction. By synthesizing established methods including ATAM, arc42, STRIDE, Architecture Decision Records (ADRs), and CARAF, SATAM produces an architecture-driven CBOM that embeds explicit security intent and migration-critical metadata. Leveraging design science research principles and an extension of the CycloneDX standard, the resulting CBOM demonstrably outperforms conventional asset inventory approaches, offering richer contextual information and more comprehensive support for cryptographic agility and informed migration decision-making.

Technology Category

Application Category

📝 Abstract
Cryptographic migration driven by algorithm deprecation, regulatory change, and post-quantum readiness requires more than an inventory of cryptographic assets. Existing Cryptographic Bills of Materials (CBOMs) are typically tool- or inventory-derived. They lack architectural intent, rationale, and security context, limiting their usefulness for migration planning. This paper introduces Security-Aware Architecture Tradeoff Analysis Method (SATAM), a security-aware adaptation of scenario-based architecture evaluation that derives an architecture-grounded, context-sensitive CBOM. SATAM integrates established approaches: ATAM, arc42, STRIDE, ADR, and CARAF. These are included to identify and analyze security-relevant cryptographic decision points and document them as explicit architectural decisions. These artifacts are used to annotate CBOM entries with architectural context, security intent, and migration-critical metadata using CycloneDX-compatible extensions. Following a Design Science Research approach, the paper presents the method design, a conceptual traceability model, and an illustrative application. The results demonstrate that architecture-derived CBOMs capture migration-relevant context that is typically absent from inventory-based approaches. Thereby, SATAM improves availability of information required for informed cryptographic migration planning and long-term cryptographic agility.
Problem

Research questions and friction points this paper is trying to address.

Cryptographic Migration
Cryptographic Bill of Materials
Architecture-Aware Security
Security Context
Migration Planning
Innovation

Methods, ideas, or system contributions that make the work stand out.

SATAM
architecture-derived CBOM
cryptographic migration
security-aware architecture
CycloneDX
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
E
Eduard Hirsch
University of Applied Sciences Amberg-Weiden, Amberg 92224, Germany
K
Kristina Raab
Fraunhofer AISEC, Garching 85748, Germany