Post Quantum Cryptography for our PKCS#11 libraries!

We are pleased to announce that our PKCS#11 Provider and Wrapper now support the NIST standardized ML-DSA digital signature algorithm according to FIPS 204 and PKCS #11 3.2. This is the first step of our PKCS#11 libraries towards the age of post-quantum cryptography!

We have implemented both variants, pure ML-DSA as well as HashML-DSA, with all three parameter sets ML-DSA-44, ML-DSA-65, ML-DSA 87. HashML-DSA supports all approved hash functions of the SHA-family (internal and external hashing).

At this point, we would like to express our thanks to Thales for giving us the opportunity to test our implementation with their Luna HSM, one of the first hardware security modules that supports ML-DSA according to the new PKCS#11 3.2 specification. This gives you the assurance that our implementation works in a real-world application scenarios.

Please have a look the PKCS#11 Provider and Wrapper product pages for a list of all features and changes. Please visit our download center to get the new versions.

Kind regards Your SIC/IAIK Java Security Team