Adaptive Encryption Framework for Web Applications: A Risk-Based Approach to Dynamic Algorithm Selection
Flavius G. Stașac, Cornelia Aurora Győrödi, Robert Ștefan Győrödi · Applied Sciences · 2026
Web applications increasingly handle sensitive data in diverse use cases, but conventional encryption implementations apply a uniform level of cryptographic protection to all traffic, regardless of the associated risk. This static approach results in either excessive computational overhead when applying maximum encryption universally, or inadequate protection when using lightweight encryption to preserve performance. This paper proposes an Adaptive Encryption Framework (AEF) designed to bridge the gap between performance and security in web applications. Rather than relying on a static protocol, AEF dynamically adjusts encryption algorithms based on a real-time composite risk score (0–100). This score is derived from six weighted variables: network risk (25%), authentication strength (20%), behavioral risk (20%), device trust (15%), data sensitivity (15%), and temporal risk (5%). Depending on the calculated risk, the system automatically transitions between three distinct security tiers: GREEN (utilizing ChaCha20-Poly1305), YELLOW (AES-256-GCM), or RED (AES-256-GCM with per-request HKDF key derivation for key isolation). All three profiles use exclusively standardized cryptographic primitives. The proposed weighting distribution was evaluated through sensitivity analysis on 27 framework-executed scenarios and further calibrated using 40,000 labeled application requests. Within these experimental conditions, it achieved complete agreement with the expected scenario classifications, and no alternative weight configuration produced better held-out performance. Additional validation on 61,065 HTTP requests from the CSIC 2010 dataset yielded an area under the ROC curve (ROC AUC) of 0.860, with no attack request assigned to the lightweight profile under the evaluated operating conditions. Across three hardware platforms and four payload sizes, all encryption profiles maintained sub-millisecond latency. Extended load testing showed that a four-worker Node.js cluster sustained 4948 requests per second at 2000 concurrent connections, a 7.1-fold improvement over a single process. When hardware cryptographic acceleration was disabled, ChaCha20-Poly1305 became up to 9.1 times faster than AES-256-GCM, supporting its use as the lightweight profile. The framework proposed in this paper operationalizes the qualitative risk assessment guidelines from NIST SP 800-30 and SP 800-63 into a quantitative, automated encryption selection mechanism for web applications, evaluated under the hardware platforms, concurrency levels and traffic assumptions described in this study.