Protocol Simulations / PQC SSH Simulator

What you will do: Pick a PQC KEX (hybrid or pure ML-KEM) and an ML-DSA or SLH-DSA host key, press Run both handshakes, then compare the classical curve25519 baseline with the PQC run in the Handshake Log, PKCS#11 Calls and Wire tabs.

Worked example: With the default mlkem768-curve25519-sha256 + ssh-mldsa-65 a real OpenSSH handshake runs: the log reports host and user C_Sign sizes and auth time, and the comparison bars show host pubkey, signature and KEX share bytes.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with VPN/IPsec & SSH

For your role

Developer / Engineer
Pick a key exchange such as mlkem768-curve25519-sha256 (marked REAL) and a host key like ssh-mldsa-65, press Run both handshakes, and read the Handshake Log, PKCS#11 Calls and Wire Packets tabs beside the classical baseline.
Security Architect
The side-by-side telemetry compares Classical (ecdsa-nistp256 + curve25519) with PQC (ML-DSA-65 + ML-KEM-768 × X25519) on packet sizes and round trips; the Host Trust & TOFU note covers what changes when host keys change algorithm.
Researcher / Academic
Variants marked REAL run on softhsmv3 and those marked MODEL are computed; compare an ML-DSA host key with an SLH-DSA one on the Wire Packets tab to measure the difference in the KEXINIT and signature payloads.

PQC SSH Simulator

Real softhsmv3 PKCS#11 SSH handshakes — pick any ML-KEM KEX (hybrid or pure) plus an ML-DSA or SLH-DSA host-key variant and compare it against the classical curve25519 + ECDSA P-256 baseline. All key material lives inside the softhsmv3 WASM token; no network or container required.

PQC KEX Algorithmhybrid = classical ECDH ⊕ ML-KEM; pure = ML-KEM only (CNSA 2.0)
PQC Host-Key Algorithmsofthsmv3 generates and signs with the chosen ML-DSA or SLH-DSA parameter set

Runs the real OpenSSH binary. This combo drives the genuine OpenSSH 10.x handshake compiled to WASM — both the host-key and user-key signatures are produced by C_Sign inside the embedded softhsmv3 token. The private keys never leave the HSM. (Client and server run in one WASM process over an in-memory transport; all crypto and wire formats are real.)

The handshakes need a Chromium-based browser (Chrome, Edge or Brave) for the live softhsmv3 session.

SSH authentication — side-by-side telemetry

Classical (ecdsa-nistp256 + curve25519)

Not executed — click the matching run button above.

PQC (ML-DSA-65 + ML-KEM-768 × X25519)

Not executed — click the matching run button above.

Migrating SSH to post-quantum cryptography replaces classical key exchange (ECDH / Curve25519) and signatures (ECDSA / Ed25519) with a NIST-standardised ML-KEM hybrid or pure KEX and ML-DSA (FIPS 204) or SLH-DSA (FIPS 205) signatures — run the classical and PQC handshakes above to see the exact byte-size deltas for your selected combo. Both operations are delegated to softhsmv3 via PKCS#11 v3.2 C_Sign, ensuring private key material never leaves the token boundary.

Click "Run both handshakes" to start.

Keys are generated for educational purposes only and are discarded when the tool is reset.

Try it

Which host-key variants run on the real OpenSSH binary in this simulator?

Next step

Turn it into a plan: Hybrid Transition Planner

This tool practises the VPN/IPsec & SSH module, phase 5 (Pilots & Migration); Hybrid Transition Planner produces a deliverable of that phase.

Next in Protocol Simulations