<?xml version='1.0' encoding='utf-8'?>
<?xml-stylesheet type="text/xsl" href="/v2/static/oai2.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-10-08T13:00:06Z</responseDate>
  <request identifier="oai:figshare.com:article/34046034" metadataPrefix="oai_dc" verb="GetRecord">https://api.figshare.com/v2/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:figshare.com:article/34046034</identifier>
        <datestamp>2026-10-02T16:45:20Z</datestamp>
        <setSpec>category_28903</setSpec>
        <setSpec>category_28924</setSpec>
        <setSpec>category_28909</setSpec>
        <setSpec>category_28906</setSpec>
        <setSpec>item_type_14</setSpec>
        <setSpec>month_year_10_2026</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"  xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>&lt;b&gt;cryptoflex v0.5.4: A Security-Hardened Local-First Crypto-Agility Policy Engine for Hybrid Classical and Post-Quantum Key Exchange&lt;/b&gt;</dc:title>
          <dc:creator>KEERTHIVASAN S (24566574)</dc:creator>
          <dc:subject>Cryptography</dc:subject>
          <dc:subject>Cybersecurity and privacy not elsewhere classified</dc:subject>
          <dc:subject>Data security and protection</dc:subject>
          <dc:subject>Data and information privacy</dc:subject>
          <dc:subject>ML-KEM, X25519</dc:subject>
          <dc:subject>local-first security</dc:subject>
          <dc:subject>policy engine</dc:subject>
          <dc:subject>authenticated encryption</dc:subject>
          <dc:subject>streaming AEAD</dc:subject>
          <dc:subject>reproducible builds</dc:subject>
          <dc:subject>post-quantum cryptography</dc:subject>
          <dc:subject>crypto-agility</dc:subject>
          <dc:subject>key encapsulation mechanism</dc:subject>
          <dc:subject>hybrid key exchange</dc:subject>
          <dc:description>&lt;p dir="ltr"&gt;The transition from classical to post-quantum cryptography (PQC) presents a critical challenge for software systems that rely on hardcoded algorithmic choices. Most encryption tools select a single cryptographic stack at build time and never revisit that decision, creating a maintainability and security liability as algorithms are deprecated or broken. While large-scale network protocols such as Signal’s PQXDH and Chrome’s X25519Kyber768 have already shipped hybrid classical+PQC key exchange, the local-first domain — file encryption utilities, desktop applications, and embedded/IoT systems — remains underserved.&lt;br&gt;&lt;br&gt;This paper presents cryptoflex v0.5.4, a security-hardened local-first crypto-agility policy engine for Python that orchestrates existing, independently audited cryptographic primitives behind a runtime decision layer. The system combines classical X25519 elliptic-curve Diffie-Hellman with NIST-standardized Module-Lattice-Based Key Encapsulation Mechanism (ML-KEM) via the Open Quantum Safe (liboqs) library. A versioned, bundled risk table enables algorithm deprecation without network dependency. A deterministic hybrid combiner binds all shared secrets and ciphertexts into a single 256-bit root key via HKDFSHA384 with injective length-prefixed encoding, achieving the standard “at-least-as-strongas-the-strongest-component” design goal.&lt;/p&gt;</dc:description>
          <dc:date>2026-10-02T16:45:20Z</dc:date>
          <dc:type>Text</dc:type>
          <dc:type>Conference contribution</dc:type>
          <dc:identifier>10.6084/m9.figshare.34046034.v2</dc:identifier>
          <dc:relation>https://figshare.com/articles/conference_contribution/_b_cryptoflex_v0_5_4_A_Security-Hardened_Local-First_Crypto-Agility_Policy_Engine_for_Hybrid_Classical_and_Post-Quantum_Key_Exchange_b_/34046034</dc:relation>
          <dc:rights>CC BY 4.0</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
