HSM / PKCS#11 / Envelope Encryption
What you will do: Pick a KEK algorithm (ML-KEM-512/768/1024 or RSA-2048/4096) and a wrap mechanism (AES-KW, AES-KWP or AES-GCM), press Execute (Live WASM), then step through the five-step classical-vs-PQC comparison.
Worked example: With ML-KEM-768 and AES-KW the run generates an AES-256 DEK, encapsulates a 1088 B KEM ciphertext, wraps the DEK into 40 B and unwraps it again; the Key Integrity Verification panel shows the DEK before and after match.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
Browse all Crypto Lab tools · Learn with KMS & PQC Key Management
For your role
- Security Architect
- Set the KEK algorithm to RSA-2048 and then ML-KEM-768 and run the five steps for each: the Artifact Sizes by Step chart shows what the three-step encapsulate, KDF and AES-wrap flow costs against a one-step RSA-OAEP wrap.
- Researcher / Academic
- Choose AES-KW, AES-KWP or AES-GCM as the wrap mechanism and compare the wrapped-key sizes in the Envelope Encryption Flow; the KMS PQC Known Answer Tests panel checks the ML-KEM and wrap implementations and labels each result with its evidence class.
- IT Ops / DevOps
- Run the ML-KEM-768 / AES-KW flow with Execute (Live WASM): the PKCS#11 call log is the sequence of calls a KMS makes for every data key, which is what a migration changes on your HSM partitions.
Envelope Encryption Demo
Step through the complete envelope encryption flow. Compare how RSA-OAEP directly wraps a DEK in one step versus the 3-step ML-KEM process: encapsulate → KDF → AES wrap (AES-KW / AES-KWP / AES-GCM).
Initializing SoftHSM…
C_Initialize → C_InitToken → C_OpenSession → C_Login
Generate KEK Pair
Generate RSA-2048 key pair. Public key is used by clients to wrap DEKs.
RSA-2048 Public Key
Generate ML-KEM-768 key pair. Public encapsulation key is distributed to clients.
ML-KEM-768 Encapsulation Key
ML-KEM-768 encapsulation keys are 4.6x larger than RSA-2048 public keys (1,184 B vs 256 B). This impacts certificate sizes and key distribution bandwidth.
| Step | Operation | Classical | PQC (ML-KEM-768) |
|---|---|---|---|
| 1 | Generate KEK Pair | 256 B | 1,184 B |
| 2 | Encapsulate / Wrap | 256 B | 1,088 + 32 B |
| 3 | Derive Wrapping Key (PQC only) | N/A | 32 B |
| 4 | Wrap DEK | 256 B | 1,088 + 40 B |
| 5 | Decapsulate / Unwrap | 32 B | 32 B |
Run the live demo for this step to unlock Complete & Next.
Migration Path: Use Hybrid (Classical + PQC)
This demo shows a binary choice — RSA-OAEP or ML-KEM. NIST SP 800-227 and current migration guidance recommend running both simultaneously during the transition period: combine classical ECDH or RSA with ML-KEM so that security holds even if one scheme is broken. A combined shared secret is derived via HKDF from both outputs (e.g. P-256 ECDH ‖ ML-KEM-768 → HKDF → AES-256 KEK). This hybrid approach is available in the HSM / PKCS#11 → Key Wrapping tool which supports P-256+ML-KEM and X25519+ML-KEM combiner modes per SP 800-227.
KMS PQC Known Answer Tests
FIPS 203 · SP 800-56C Rev 2 · SP 800-38D · RFC 3394 · RFC 5649 · RFC 5869
Click Run validation tests to run 8 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity.; Published standard KAT — Expected values printed in a cited standard or consensus RFC.; Functional round-trip — Output produced by an implementation is consumed by the same or paired implementation..
Reference samples from the public NIST ACVP-Server repository · FIPS 203 · SP 800-56C Rev 2 · SP 800-38D · RFC 3394 · RFC 5649 · RFC 5869 · Generated keys are for educational use only.
Try it
Compare the RSA-2048 and ML-KEM-768 runs: how many steps does the ML-KEM path add before the AES wrap?
Next step
Turn it into a plan: Infrastructure Modernization PlannerThis tool practises the KMS & PQC Key Management module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.
Related content
Next in HSM / PKCS#11