Starting with version 10.5.3, we now offer the following Post-Quantum (PQ) features in the Cryptographic Security Platform Vault for Cryptographic APIs, with and without HSM.
Currently, the channel between the client and the Cryptographic Security Platform Vault for Cryptographic APIs is not using PQ-TLS. This means the channel is still vulnerable to a harvest-now, decrypt-later attack.
PQ object creation
You can create the following PQ-safe objects.
ML-DSA
SLH-DSA
PQ operations
The following operations are considered PQ-safe:
Sign (ML-DSA, SLH-DSA)
Verify (ML-DSA, SLH-DSA)
Import from HSM
Import from HSM (Hardware Security Module) to Cryptographic Security Platform Vault for Cryptographic APIs—You can import the public part of PQ keys from your HSM to the Cryptographic Security Platform Vault for Cryptographic APIs. This allows the Cryptographic Security Platform Vault for Cryptographic APIs to verify the PQ signature.