Commit fa81c8f
committed
Add ML-KEM (FIPS 203) post-quantum KEM support
Adds support for ML-KEM (Kyber, FIPS 203) key encapsulation
mechanism, following the same patterns established by the ML-DSA
integration. Disabled by default; enable with --enable-mlkem
(autotools) or -DWOLFPKCS11_MLKEM=yes (CMake). Enabling ML-KEM
automatically enables PKCS#11 v3.2 support.
Capabilities added:
- Key generation (CKM_ML_KEM_KEY_PAIR_GEN) for KEM-512/768/1024
- Key import/export via C_CreateObject / C_GetAttributeValue
- Token persistence (WOLFPKCS11_STORE_MLKEMKEY_PRIV/PUB, 0x0E/0x0F)
- Encapsulation (C_EncapsulateKey / CKM_ML_KEM)
- Decapsulation (C_DecapsulateKey / CKM_ML_KEM)
- New PKCS#11 constants: CKK_ML_KEM, CKM_ML_KEM_KEY_PAIR_GEN,
CKM_ML_KEM, CKA_ENCAPSULATE, CKA_DECAPSULATE, CKF_ENCAPSULATE,
CKF_DECAPSULATE, CKP_ML_KEM_512/768/1024
- New internal flags: WP11_FLAG_ENCAPSULATE, WP11_FLAG_DECAPSULATE
Tests added to tests/pkcs11v3test.c (inside WOLFPKCS11_MLKEM guard):
- Key generation in session and with ID
- Token key persistence round-trip
- Export/reimport round-trip (exercises import path)
- Encapsulate/decapsulate shared-secret equality check
- Wrong-key implicit-rejection test1 parent 8fec695 commit fa81c8f
16 files changed
Lines changed: 2546 additions & 47 deletions
File tree
- .github/workflows
- cmake
- src
- tests
- wolfpkcs11
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
65 | | - | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
106 | 106 | | |
107 | 107 | | |
108 | 108 | | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
109 | 113 | | |
110 | 114 | | |
111 | 115 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
46 | 49 | | |
47 | 50 | | |
48 | 51 | | |
| |||
54 | 57 | | |
55 | 58 | | |
56 | 59 | | |
| 60 | + | |
57 | 61 | | |
58 | 62 | | |
| 63 | + | |
59 | 64 | | |
60 | 65 | | |
61 | 66 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
474 | 474 | | |
475 | 475 | | |
476 | 476 | | |
477 | | - | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
478 | 484 | | |
479 | 485 | | |
480 | 486 | | |
481 | 487 | | |
482 | 488 | | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
483 | 513 | | |
484 | 514 | | |
485 | 515 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
67 | 77 | | |
68 | 78 | | |
69 | 79 | | |
| |||
207 | 217 | | |
208 | 218 | | |
209 | 219 | | |
210 | | - | |
| 220 | + | |
| 221 | + | |
211 | 222 | | |
212 | 223 | | |
213 | 224 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
94 | 94 | | |
95 | 95 | | |
96 | 96 | | |
| 97 | + | |
| 98 | + | |
97 | 99 | | |
98 | 100 | | |
99 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
533 | 533 | | |
534 | 534 | | |
535 | 535 | | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
536 | 540 | | |
537 | 541 | | |
538 | 542 | | |
539 | 543 | | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
540 | 569 | | |
541 | 570 | | |
542 | 571 | | |
| |||
725 | 754 | | |
726 | 755 | | |
727 | 756 | | |
| 757 | + | |
728 | 758 | | |
729 | 759 | | |
730 | 760 | | |
| |||
0 commit comments