Skip to content

Variable: Upgrader ​

const Upgrader: object

Defined in: migrate.ts:105

Upgrades classical keys to hybrid post-quantum keys.

Type Declaration ​

checkNeedsUpgrade() ​

readonly checkNeedsUpgrade(keyOrState): boolean

True if the key is still classical_only and should be upgraded. Accepts a key pair or a state.

Parameters ​

keyOrState ​

MigrationState | KeyPair

Returns ​

boolean

describeKey() ​

readonly describeKey(keyPair): object

Describes a key's migration status for reports and dashboards. Never includes secret material.

Parameters ​

keyPair ​

KeyPair

Returns ​

object

algorithm ​

algorithm: string

fingerprint ​

fingerprint: string

isHybrid ​

isHybrid: boolean

migrationState ​

migrationState: MigrationState

needsUpgrade ​

needsUpgrade: boolean

publicKeySize ​

publicKeySize: number

recommendation ​

recommendation: string

stripClassicalComponent() ​

readonly stripClassicalComponent(keyPair): KeyPair

Removes the classical half of a hybrid key pair, producing a PQC-only pair in pqc_only state. One-way: classical clients can no longer use the result. Log the action in your migration audit trail.

Parameters ​

keyPair ​

KeyPair

Returns ​

KeyPair

Throws ​

if the key pair is not hybrid.

upgradeKemKey() ​

readonly upgradeKemKey(input): UpgradeResult

Adds a fresh post-quantum KEM key to an existing classical KEM key. The classical key bytes are kept unchanged inside the hybrid key, so the same X25519/P-256 identity continues. Both halves are required by this library's own HybridKEM.

Parameters ​

input ​

UpgradeKemKeyInput

Returns ​

UpgradeResult

Throws ​

for wrong key lengths.

Throws ​

for an unapproved pairing.

upgradeSigningKey() ​

readonly upgradeSigningKey(input): UpgradeResult

Adds a fresh post-quantum signing key to an existing classical signing key. The classical key is retained unchanged. New signatures carry both sub-signatures and verifiers must accept both; existing classical-only signatures do not verify as hybrid signatures.

Parameters ​

input ​

UpgradeSigningKeyInput

Returns ​

UpgradeResult

Apache-2.0.