Cipher Plain

Applied cryptography research institute

Open brief

126 · Applied cryptography research institute

Security claims should survive notation, implementation and hostile review.

Cipher Plain is a fictional applied-cryptography institute helping public systems and infrastructure teams choose, implement and migrate cryptographic protocols. The identity reads like an annotated paper rather than a cybersecurity sales page.

About / field note

Cipher Plain is a fictional applied-cryptography institute helping public systems and infrastructure teams choose, implement and migrate cryptographic protocols. The identity reads like an annotated paper rather than a cybersecurity sales page.

Unit: protocol decisionEvidence: threat model, primitive choice, implementation boundary, test vector and migration plan

Reading room

1

Post-quantum migration begins with inventory

Post-quantum migration begins with inventory. A working note from Cipher Plain on the decisions hidden inside applied cryptography research institute. It connects the claim back to protocol decision and names where professional judgement or uncertainty remains.

2

A key ceremony is an operational control

A key ceremony is an operational control. A working note from Cipher Plain on the decisions hidden inside applied cryptography research institute. It connects the claim back to threat model, primitive choice, implementation boundary, test vector and migration plan and names where professional judgement or uncertainty remains.

3

Protocol proofs do not automatically prove implementations

Protocol proofs do not automatically prove implementations. A working note from Cipher Plain on the decisions hidden inside applied cryptography research institute. It connects the claim back to threat model, primitive choice, implementation boundary, test vector and migration plan and names where professional judgement or uncertainty remains.

Offerings

Scope before spectacle.

01

Protocol review

Protocol review is scoped through the protocol decision, with threat model, primitive choice, implementation boundary, test vector and migration plan. The boundary, exclusions and handover evidence are stated before work begins.

02

Key-management architecture

Key-management architecture is scoped through the protocol decision, with threat model, primitive choice, implementation boundary, test vector and migration plan. Capacity, constraints and decision ownership stay visible from intake to closeout.

03

Post-quantum migration planning

Post-quantum migration planning is scoped through the protocol decision, with threat model, primitive choice, implementation boundary, test vector and migration plan. The boundary, exclusions and handover evidence are stated before work begins.

04

Implementation test suites

Implementation test suites is scoped through the protocol decision, with threat model, primitive choice, implementation boundary, test vector and migration plan. Capacity, constraints and decision ownership stay visible from intake to closeout.

Method / sequence

1

Write the threat model

Write the threat model is the entry control point for a protocol decision. The team records threat model, primitive choice, implementation boundary, test vector and migration plan so the next decision is made from an explicit state, not memory or assumption.

2

Reduce the claim

Reduce the claim is the next control point for a protocol decision. The team records threat model, primitive choice, implementation boundary, test vector and migration plan so the next decision is made from an explicit state, not memory or assumption.

3

Test the implementation

Test the implementation is the next control point for a protocol decision. The team records threat model, primitive choice, implementation boundary, test vector and migration plan so the next decision is made from an explicit state, not memory or assumption.

4

Plan the migration path

Plan the migration path is the next control point for a protocol decision. The team records threat model, primitive choice, implementation boundary, test vector and migration plan so the next decision is made from an explicit state, not memory or assumption.

Projects

Work becomes interesting where the constraint changed the plan.

Archive 1

Municipal signing service

A fragmented document-signing estate was reduced to one managed trust model with explicit offline root procedures.

Archive 2

PQC inventory

A transport operator mapped certificate, VPN and firmware dependencies before selecting any replacement algorithm.

Archive 3

Device key ceremony

Manufacturing keys moved from shared workstations into witnessed hardware-backed issuance with revocation drills.

People

Named responsibility

P01

Dr Ines Raman

Applied cryptographer

Dr Ines Raman leads applied cryptographer and owns the decisions that touch each protocol decision. The role is described by responsibility, not decorative biography.

P02

Malik Petersen

Protocol engineer

Malik Petersen leads protocol engineer and owns the decisions that touch each protocol decision. The role is described by responsibility, not decorative biography.

P03

Kgomotso Seleka

Assurance researcher

Kgomotso Seleka leads assurance researcher and owns the decisions that touch each protocol decision. The role is described by responsibility, not decorative biography.

Evidence

Proof is useful when the denominator is visible.

126

public fictional test vectors

0

proprietary cryptographic primitives

4

witnesses in root-key ceremony

18 mo

migration horizon modelled before cutover

Objections / answers

No accordion required

Do you invent new encryption algorithms?
Rarely. The default is established, publicly reviewed primitives and clear composition; new cryptography requires exceptional justification.
Can you certify a system as unbreakable?
No. Security statements are scoped to threat models, assumptions and evidence, not absolute guarantees.
Is post-quantum migration urgent?
Inventory is urgent for long-lived systems and data. Algorithm replacement should follow standards maturity, interoperability and realistic asset lifecycles.

Conversion / next step

Bring the protocol diagram and the claim you need to defend.

Write to the fictional team