Starting with version 10.5.3, we now offer the following Post-Quantum (PQ) features in the Cryptographic Security Platform Vault for Cryptographic APIs, with and without HSM.

Currently, the channel between the client and the Cryptographic Security Platform Vault for Cryptographic APIs is not using PQ-TLS. This means the channel is still vulnerable to a harvest-now, decrypt-later attack.

 PQ object creation

You can create the following PQ-safe objects.

  • ML-DSA

  • SLH-DSA

PQ operations

The following operations are considered PQ-safe: 

  • Sign (ML-DSA, SLH-DSA)

  • Verify (ML-DSA, SLH-DSA)

Import from HSM

Import from HSM (Hardware Security Module) to Cryptographic Security Platform Vault for Cryptographic APIs—You can import the public part of PQ keys from your HSM to the Cryptographic Security Platform Vault for Cryptographic APIs. This allows the Cryptographic Security Platform Vault for Cryptographic APIs to verify the PQ signature.