HSM / PKCS#11 / TEE-HSM Secure Channel
What you will do: Open a trusted channel from an enclave to the HSM: an ML-DSA-65 attestation key, ML-KEM key agreement, and an AES key wrapped across the channel.
Worked example: Run the flow end to end; the PKCS#11 call log shows which call each algorithm makes, and the generated-keys panel shows what ended up where.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
Browse all Crypto Lab tools · Learn with Confidential Computing & TEEs
For your role
- Security Architect
- Choose one of the presets such as Intel SGX + Thales Luna or AMD SEV-SNP + Entrust nShield, then Execute (Live WASM): the tool loads that pairing's documented integration architecture and shows which keys end up in the enclave and which in the HSM.
- Researcher / Academic
- Open What runs live vs. simulated? before reading the results: the ML-DSA-65 attestation key, ML-KEM key agreement and the AES key wrap run in the PKCS#11 call log, and the attestation transport is simulated.
Design and explore TEE-HSM integration architectures with mutual attestation and PQC key provisioning. Select a TEE vendor and HSM vendor to visualize the trusted channel.
Live HSM Mode Active
SoftHSM3 · PKCS#11 v3.2 · Rust · session open
Select a TEE vendor and HSM vendor below. The tool will load the documented integration architecture and live provisioning demo for that combination. Not all pairings are supported — try using a preset below.
Quantum Threat Analysis
Each component of a TEE-HSM deployment faces distinct quantum risks. Vectors marked HNDL are subject to harvest-now-decrypt-later attacks — adversaries recording traffic today can decrypt it once a cryptographically-relevant quantum computer (CRQC) is available.
Shor's algorithm breaks ECDSA in polynomial time. An attacker with a CRQC can forge attestation quotes, impersonate legitimate enclaves, and bypass all trust decisions based on attestation.
Grover's algorithm halves AES key strength. If sealing keys use AES-128, effective post-quantum security is 64-bit — feasible for a CRQC to brute-force. Combined with side-channel leakage of key bits, recovery becomes more practical.
Grover's algorithm reduces AES-128 (NIST Category 1) effective security to 64-bit. While brute-forcing AES-128 memory encryption keys in real-time is unlikely even with a CRQC (requires sustained high qubit count), it leaves a much thinner margin than AES-256 (Category 5).
Shor's algorithm breaks ECDH key exchange. An attacker recording TLS sessions between a TEE and HSM can retroactively decrypt all key provisioning data once a CRQC is available (HNDL attack on key material in transit).
Shor's algorithm can forge firmware signatures. An attacker could sign malicious TEE firmware, security monitor updates, or microcode patches that pass signature verification. Particularly dangerous for remote firmware update channels.
Enclave sealing keys and memory encryption are often AES-128 (NIST Category 1), which Grover's algorithm halves to 64-bit effective post-quantum security — a much thinner margin than AES-256 (Category 5).
AES-128 (NIST Category 1) effective security drops to 64-bit under Grover's algorithm — a much thinner margin than AES-256 (Category 5). Upgrade path: AES-XTS-256 in future CPU generations.
AES-128 effective security drops to 64-bit under Grover. AMD has not announced AES-256 memory encryption for future EPYC generations. RMP integrity is hash-based (quantum-safe for collision resistance).
AES-256 (NIST Category 5) provides 128-bit effective post-quantum security under Grover. However, TrustZone relies on access control (TZASC) rather than encryption for most isolation, which is not cryptographically affected by quantum.
AWS Nitro uses a hardware security chip for platform-level encryption with 256-bit keys (Grover-resilient). The primary protection mechanism is hypervisor-enforced isolation rather than memory encryption.
Run TEE-HSM Key Provisioning (Classical)
Try it
After Execute, which key is generated as the attestation key in the PKCS#11 call log?
Next step
Turn it into a plan: Infrastructure Modernization PlannerThis tool practises the Confidential Computing & TEEs module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.
Related content
Next in HSM / PKCS#11