The platform and the Go SDK support hybrid post-quantum key wrapping: hpqt:secp256r1-mlkem768 and hpqt:secp384r1-mlkem1024 (composite ML-KEM + ECDH per draft-ietf-lamps-pq-composite-kem-14, hybrid-wrapped key access objects), described in lib/ocrypto/HYBRID_NIST_KEY_WRAPPING.md and implemented in lib/ocrypto/hybrid_nist.go and sdk/tdf.go. A KAS can publish such keys with hybrid_tdf_enabled.
The web SDK (0.21.0) supports ec:*, rsa:* and mlkem:768 / mlkem:1024, but no hpqt:* algorithm: a browser application cannot encrypt for a KAS hybrid key, nor read a TDF whose key access is hybrid-wrapped.
We are building a browser-based document labelling and encryption demonstrator, linagora/dcs-onlyoffice (ONLYOFFICE plugin, STANAG 4774/4778 labels) where hybrid wrapping with P-384 + ML-KEM-1024 is a requirement, and we would like to contribute this support.
Questions before we start:
- Is hybrid wrapping in the web SDK on your roadmap, or already in progress?
- Would you accept a contribution that adds
hpqt:secp256r1-mlkem768 and hpqt:secp384r1-mlkem1024 to the key algorithms, hybrid-wrapped key access objects on encrypt, and their rewrap on decrypt, reusing the existing ML-KEM code and WebCrypto ECDH, with interoperability tests against the Go SDK and a KAS?
- Is
hpqt:xwing expected too, or can it come later?
The platform and the Go SDK support hybrid post-quantum key wrapping:
hpqt:secp256r1-mlkem768andhpqt:secp384r1-mlkem1024(composite ML-KEM + ECDH per draft-ietf-lamps-pq-composite-kem-14,hybrid-wrappedkey access objects), described inlib/ocrypto/HYBRID_NIST_KEY_WRAPPING.mdand implemented inlib/ocrypto/hybrid_nist.goandsdk/tdf.go. A KAS can publish such keys withhybrid_tdf_enabled.The web SDK (0.21.0) supports
ec:*,rsa:*andmlkem:768/mlkem:1024, but nohpqt:*algorithm: a browser application cannot encrypt for a KAS hybrid key, nor read a TDF whose key access ishybrid-wrapped.We are building a browser-based document labelling and encryption demonstrator, linagora/dcs-onlyoffice (ONLYOFFICE plugin, STANAG 4774/4778 labels) where hybrid wrapping with P-384 + ML-KEM-1024 is a requirement, and we would like to contribute this support.
Questions before we start:
hpqt:secp256r1-mlkem768andhpqt:secp384r1-mlkem1024to the key algorithms,hybrid-wrappedkey access objects on encrypt, and their rewrap on decrypt, reusing the existing ML-KEM code and WebCrypto ECDH, with interoperability tests against the Go SDK and a KAS?hpqt:xwingexpected too, or can it come later?