Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Policy-Governed Post-Quantum Migration for Legacy Microservices Using Ephemeral Sidecar Architectures

A dynamic, reversible framework for transparent post-quantum cryptography adoption in cloud-native enterprise systems
Nirmal Kumar Jingarยท 2026ยท DOI 10.48550/arXiv.2609.14286

The core problem

The rapid advancement of quantum computing poses a substantial threat to classical cryptographic primitives widely deployed in cloud-native and microservice-based enterprise systems. Legacy microservices are tightly coupled with traditional cryptography, making direct migration to post-quantum cryptography (PQC) intricate, hazardous, and disruptive. This research addresses these challenges by introducing the Policy-Governed Post-Quantum Migration through Ephemeral Sidecar Architectures (PG-PQMES) framework. The framework enables dynamic and reversible migration, allowing transparent adoption of PQC without requiring modifications to legacy application code. The core problem is the tension between the need for quantum-resistant security and the operational risk of disrupting existing microservice architectures. The proposed solution combines three coherent layers: an Ephemeral Crypto Sidecar Layer for runtime cryptography injection, a Policy Governance Layer for centralized migration management, and a Migration Safety and Observability Layer for performance measurement and automatic rollback. An innovative Policy-Governed Ephemeral PQ Migration (PG-EPM) algorithm is proposed to opti

Innovation

Experimental assessment in a simulated microservices environment demonstrates that PG-PQMES substantially reduces migration time, service downtime, latency overhead, and rollback recovery time compared to existing migration strategies. The sidecar-based approach enables runtime injection of PQC without modifying legacy code, resulting in minimal disruption. Quantitative results show significant improvements across all measured metrics. For instance, migration time is reduced by an order of magnitude, and service downtime approaches zero due to the ephemeral nature of sidecars. Latency overhead remains within acceptable bounds, and rollback recovery time is minimized through automated policy-driven rollback. The PG-EPM algorithm effectively balances performance, compliance, and trust, ensuring that migration decisions align with organizational policies. The findings confirm that a policy-governed, sidecar-based migration strategy offers a viable, scalable, and enterprise-grade path to post-quantum security transformation.
The rapid advancement of quantum computing poses a substantial threat to classical cryptographic primitives widely deployed in cloud-native and microservice-based enterprise systems. Legacy microservices are tightly coupled with traditional cryptography, making direct migration to post-quantum cryptography (PQC) intricate, hazardous, and disruptive. This research addresses these challenges by introducing the Policy-Governed Post-Quantum Migration through Ephemeral Sidecar Architectures (PG-PQMES) framework. The framework enables dynamic and reversible migration, allowing transparent adoption of PQC without requiring modifications to legacy application code. The core problem is the tension between the need for quantum-resistant security and the operational risk of disrupting existing microservice architectures. The proposed solution combines three coherent layers: an Ephemeral Crypto Sidecar Layer for runtime cryptography injection, a Policy Governance Layer for centralized migration management, and a Migration Safety and Observability Layer for performance measurement and automatic rollback. An innovative Policy-Governed Ephemeral PQ Migration (PG-EPM) algorithm is proposed to optimize performance, compliance, and trust-based migration decisions.

The PG-PQMES framework is structured around three integrated layers. The Ephemeral Crypto Sidecar Layer injects cryptographic operations at runtime, decoupling PQC adoption from application code. The Policy Governance Layer centrally manages migration policies, enabling fine-grained control over which services migrate, when, and under what conditions. The Migration Safety and Observability Layer continuously monitors performance metrics and triggers automatic rollback upon detecting anomalies or policy violations. The PG-EPM algorithm formalizes the migration decision process. Let

be the set of microservices, and for each service , let denote its compliance requirement, its performance sensitivity, and its trust level. The algorithm selects a migration schedule that maximizes a weighted objective:

Why it matters

The PG-PQMES framework addresses a critical gap in enterprise cybersecurity: the need to migrate legacy microservices to PQC without disrupting operations. By decoupling cryptographic migration from application code, the framework enables transparent, reversible adoption. The three-layer architecture ensures that migration is governed by policy, monitored for safety, and automatically rolled back if issues arise. The PG-EPM algorithm provides a formal mechanism for optimizing migration decisions based on compliance, performance, and trust. The use of ephemeral sidecars minimizes overhead and downtime, making the approach practical for large-scale deployments. The results indicate that policy-governed migration can achieve significant reductions in migration time and downtime, while maintaining low latency overhead. The automatic rollback capability enhances safety and trust. The framework is scalable and suitable for enterprise environments. Future work may explore integration with service meshes, extension to multi-cloud environments, and refinement of the PG-EPM algorithm for dynamic policy updates. Overall, the research demonstrates that a sidecar-based, policy-governed migration strategy is a viable and effective solution for post-quantum transformation in legacy microservice architectures.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ