HSM / PKCS#11 / Hybrid Signature Spectrums

What you will do: Choose Concatenation, Nesting or Silithium (Fused), then Generate Key Pairs, Sign the message and Verify to see whether the EC-Schnorr and ML-DSA-65 halves still verify once stripped apart.

Worked example: Concatenation verifies but both halves strip cleanly (Separable); with Silithium the Verification Results show EC-Schnorr alone and ML-DSA alone as Blocked, and Recombination Attack tries to reassemble the parts.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Hybrid Cryptography

For your role

Developer / Engineer
Choose Concatenation, Nesting or Silithium (Fused), then Generate Key Pairs, Sign and Verify on your message: the PKCS#11 trace shows the ML-DSA-65 calls through softhsmv3 and the description says whether a component signature can be stripped and verified alone.
Security Architect
The three modes differ in non-separability: concatenation offers none, nesting weak, Silithium strong; the Why hybrid signatures? panel and each mode's IETF reference are the basis for choosing one for a migration-period certificate.
Researcher / Academic
Sign the same message under all three constructions and compare signature layouts: the trace and the descriptions let you reproduce each composition and its separability property.
Certification & Validation Engineer
Sign one message under Concatenation, Nesting and Silithium (Fused): the PKCS#11 trace isolates the ML-DSA-65 calls — the primitive that algorithm testing covers — from the composition wrapped around them.

Hybrid Signature Spectrums

Compare concatenation, nesting, and Silithium — ranging from no non-separability to Strong Non-Separability (SNS).

softhsmv3 WASM ready · CKM_ML_DSA (PKCS#11 v3.2) active for concatenation / nesting
Why hybrid signatures? — Migration context

During the PQC transition, systems must support verifiers that understand only classical algorithms (legacy) and verifiers that require post-quantum algorithms (future-safe). Hybrid signatures let one signed artifact satisfy both.

The critical security question is: what prevents an attacker from stripping the PQC component? If they can, the document is no longer quantum-safe — it degrades silently to classical security. This is the non-separability problem this tool demonstrates.

Standards: IETF draft-ietf-lamps-pq-composite-sigs (Concatenation), draft-ietf-pquip-hybrid-signature-spectrums (Nesting/Silithium).

Concatenationsig₁ ‖ sig₂Non-separability: None / WNS

Two independent signatures concatenated. Either component can be stripped and verified alone. Provides defence in depth but no separability resistance.

IETF draft §1.3.3
ML-DSA-65 — softhsmv3 WASM (CKM_ML_DSA, PKCS#11 v3.2)EC-Schnorr — @noble/curves (no PKCS#11 Schnorr)
Educational demonstration. Keys are ephemeral and never leave your browser. Silithium uses the fused Fiat-Shamir construction from ePrint 2025/2059 (Devevey, Guerreau, Roméas) with ML-DSA external-μ mode (FIPS 204 §5.2).

Try it

Which construction lets a verifier strip one component signature and verify the other alone?

Next step

Turn it into a plan: Hybrid Transition Planner

This tool practises the Hybrid Cryptography module, phase 5 (Pilots & Migration); Hybrid Transition Planner produces a deliverable of that phase.