REFERENCE SCENARIOS

Architecture patterns without unsupported customer claims.

Reference architectures and acceptance criteria; not customer claims unless explicitly identified.

01
Reference scenario

Windows hybrid-signing pilot

Enterprise application and endpoint teams

Introduce a controlled hybrid-signature profile without breaking existing Windows application workflows.

Architecture pattern

  • Windows CNG/KSP provider
  • Hardware-backed key custody
  • Classical and PQC signature orchestration
  • Signed corpus and independent verification

Success criteria

  • Exact Windows/provider/application manifest
  • Repeatable sign and verify result
  • Performance and object-size report
  • Documented fallback and rollback
02
Reference scenario

CA/RA/VA/TSA migration blueprint

Trust service providers and government PKI

Plan a policy-led transition across certificate issuance, revocation, validation, timestamping and relying parties.

Architecture pattern

  • Root and issuing CA profiles
  • RA approval and enrollment
  • OCSP/CRL and path validation
  • TSA and LTV/LTA evidence

Success criteria

  • Approved target profiles
  • Relying-party test plan
  • Cutover and rollback design
  • CP/CPS and operational impact register
03
Reference scenario

Remote signing with transaction evidence

Banks, digital services and document platforms

Protect centralized signing keys and bind user authentication, consent and transaction intent into an auditable record.

Architecture pattern

  • OIDC/FIDO2 authentication
  • QSCD/HSM signing service
  • Transaction binding and policy
  • TSA/VA and immutable evidence

Success criteria

  • Strong signer-to-transaction linkage
  • Signed-object verification
  • Complete audit package
  • Operational and incident runbook
04
Reference scenario

Long-term document evidence

Government, finance, healthcare and archives

Keep signed records verifiable through certificate expiry, algorithm transition and archive renewal cycles.

Architecture pattern

  • PAdES/CAdES/XAdES profiles
  • Embedded revocation and timestamp data
  • Archive timestamp renewal
  • Evidence repository and verifier

Success criteria

  • Verifiable sample corpus
  • Renewal schedule and ownership
  • Verifier compatibility report
  • Retention and integrity controls
05
Reference scenario

Code and firmware signing transition

Software vendors, telecom and critical infrastructure

Preserve release integrity and long-lived device trust while introducing new signing profiles.

Architecture pattern

  • Offline root and protected signing keys
  • Approval workflow and build integration
  • Classical/hybrid signature packaging
  • Device and verifier compatibility testing

Success criteria

  • Signed release provenance
  • Device acceptance matrix
  • Key-rotation and emergency plan
  • Long-term verification strategy
06
Reference scenario

Enterprise cryptographic discovery

Banks and large regulated enterprises

Create a defensible inventory across certificates, APIs, TLS, HSMs, applications and suppliers before planning migration.

Architecture pattern

  • Certificate and traffic discovery
  • Application and supplier questionnaire
  • CBOM and ownership registry
  • Risk heatmap and migration waves

Success criteria

  • Coverage and confidence metrics
  • Owned asset and dependency register
  • Prioritized HNDL and signature risk
  • Executive-approved roadmap