HSM / PKCS#11 / Envelope Encryption

What you will do: Pick a KEK algorithm (ML-KEM-512/768/1024 or RSA-2048/4096) and a wrap mechanism (AES-KW, AES-KWP or AES-GCM), press Execute (Live WASM), then step through the five-step classical-vs-PQC comparison.

Worked example: With ML-KEM-768 and AES-KW the run generates an AES-256 DEK, encapsulates a 1088 B KEM ciphertext, wraps the DEK into 40 B and unwraps it again; the Key Integrity Verification panel shows the DEK before and after match.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with KMS & PQC Key Management

For your role

Security Architect
Set the KEK algorithm to RSA-2048 and then ML-KEM-768 and run the five steps for each: the Artifact Sizes by Step chart shows what the three-step encapsulate, KDF and AES-wrap flow costs against a one-step RSA-OAEP wrap.
Researcher / Academic
Choose AES-KW, AES-KWP or AES-GCM as the wrap mechanism and compare the wrapped-key sizes in the Envelope Encryption Flow; the KMS PQC Known Answer Tests panel checks the ML-KEM and wrap implementations and labels each result with its evidence class.
IT Ops / DevOps
Run the ML-KEM-768 / AES-KW flow with Execute (Live WASM): the PKCS#11 call log is the sequence of calls a KMS makes for every data key, which is what a migration changes on your HSM partitions.

Envelope Encryption Demo

Step through the complete envelope encryption flow. Compare how RSA-OAEP directly wraps a DEK in one step versus the 3-step ML-KEM process: encapsulate → KDF → AES wrap (AES-KW / AES-KWP / AES-GCM).

Initializing SoftHSM…

C_Initialize → C_InitToken → C_OpenSession → C_Login

Progress0% Complete
Step 1 of 5

Generate KEK Pair

ML-KEM-768 encapsulation keys are 4.6x larger than RSA-2048 public keys (1,184 B vs 256 B). This impacts certificate sizes and key distribution bandwidth.
CLASSICALRSA-OAEP

Generate RSA-2048 key pair. Public key is used by clients to wrap DEKs.

Artifact

RSA-2048 Public Key

Size:256 bytes
PQCML-KEM-768

Generate ML-KEM-768 key pair. Public encapsulation key is distributed to clients.

Artifact

ML-KEM-768 Encapsulation Key

Size:1,184 bytes

ML-KEM-768 encapsulation keys are 4.6x larger than RSA-2048 public keys (1,184 B vs 256 B). This impacts certificate sizes and key distribution bandwidth.

Classical (RSA-OAEP)
1. Generate RSA-2048 key pair
2. RSA-OAEP wrap DEK → 256 B
3. (no KDF step)
4. (DEK already wrapped)
5. RSA-OAEP unwrap → DEK · KCV ✓
PQC (ML-KEM-768 + AES-KW)
1. Generate ML-KEM-768 key pair
2. Encaps → ct + shared secret
3. HKDF(ss) → wrapping key (RFC 5869)
4. AES-KW wrap DEK
5. Decaps → HKDF → unwrap → DEK · KCV ✓
StepOperationClassicalPQC (ML-KEM-768)
1Generate KEK Pair256 B1,184 B
2Encapsulate / Wrap256 B1,088 + 32 B
3Derive Wrapping Key (PQC only)N/A32 B
4Wrap DEK256 B1,088 + 40 B
5Decapsulate / Unwrap32 B32 B

Run the live demo for this step to unlock Complete & Next.

Migration Path: Use Hybrid (Classical + PQC)

This demo shows a binary choice — RSA-OAEP or ML-KEM. NIST SP 800-227 and current migration guidance recommend running both simultaneously during the transition period: combine classical ECDH or RSA with ML-KEM so that security holds even if one scheme is broken. A combined shared secret is derived via HKDF from both outputs (e.g. P-256 ECDH ‖ ML-KEM-768 → HKDF → AES-256 KEK). This hybrid approach is available in the HSM / PKCS#11 → Key Wrapping tool which supports P-256+ML-KEM and X25519+ML-KEM combiner modes per SP 800-227.

KMS PQC Known Answer Tests

FIPS 203 · SP 800-56C Rev 2 · SP 800-38D · RFC 3394 · RFC 5649 · RFC 5869

Click Run validation tests to run 8 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity.; Published standard KAT — Expected values printed in a cited standard or consensus RFC.; Functional round-trip — Output produced by an implementation is consumed by the same or paired implementation..

Reference samples from the public NIST ACVP-Server repository · FIPS 203 · SP 800-56C Rev 2 · SP 800-38D · RFC 3394 · RFC 5649 · RFC 5869 · Generated keys are for educational use only.

Try it

Compare the RSA-2048 and ML-KEM-768 runs: how many steps does the ML-KEM path add before the AES wrap?

Next step

Turn it into a plan: Infrastructure Modernization Planner

This tool practises the KMS & PQC Key Management module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.