Skip to content

Support hybrid post-quantum key wrapping (hpqt:*) in the web SDK #1048

Description

@mmaudet

The platform and the Go SDK support hybrid post-quantum key wrapping: hpqt:secp256r1-mlkem768 and hpqt:secp384r1-mlkem1024 (composite ML-KEM + ECDH per draft-ietf-lamps-pq-composite-kem-14, hybrid-wrapped key access objects), described in lib/ocrypto/HYBRID_NIST_KEY_WRAPPING.md and implemented in lib/ocrypto/hybrid_nist.go and sdk/tdf.go. A KAS can publish such keys with hybrid_tdf_enabled.

The web SDK (0.21.0) supports ec:*, rsa:* and mlkem:768 / mlkem:1024, but no hpqt:* algorithm: a browser application cannot encrypt for a KAS hybrid key, nor read a TDF whose key access is hybrid-wrapped.

We are building a browser-based document labelling and encryption demonstrator, linagora/dcs-onlyoffice (ONLYOFFICE plugin, STANAG 4774/4778 labels) where hybrid wrapping with P-384 + ML-KEM-1024 is a requirement, and we would like to contribute this support.

Questions before we start:

  1. Is hybrid wrapping in the web SDK on your roadmap, or already in progress?
  2. Would you accept a contribution that adds hpqt:secp256r1-mlkem768 and hpqt:secp384r1-mlkem1024 to the key algorithms, hybrid-wrapped key access objects on encrypt, and their rewrap on decrypt, reusing the existing ML-KEM code and WebCrypto ECDH, with interoperability tests against the Go SDK and a KAS?
  3. Is hpqt:xwing expected too, or can it come later?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions