Protocol Simulations / TPM 2.0 PQC Playground
What you will do: Send raw TPM 2.0 commands from the Command Builder — TPM2_GetCapability, TPM2_CreatePrimary, TPM2_Encapsulate, TPM2_SignDigest — with ML-KEM or ML-DSA, then run Quote or Certify on the Attestation tab.
Worked example: On Attestation keep the ML-DSA-65 key, PCRs sha256:0,1,2,3,7 and the default nonce, press Run Quote: the result shows the 3309-byte signature, OpenSSL WASM verify says Signature Verified Successfully, plus a JSON bundle.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
Browse all Crypto Lab tools · Learn with Secure Boot & Firmware PQC
For your role
- Developer / Engineer
- Run the eight tracks from Boot & discover to An honest TPM in the Learn tab, then use the Command Builder to send raw commands such as TPM2_GetCapability to the WebAssembly TPM: the Execution Log shows tags, return codes and the ML-KEM and ML-DSA primitives.
- Security Architect
- Track T3, Key establishment — transport vs encapsulation, and T6, Factory identity, show where a TPM's trust model changes under PQC; the V2.7 EKs and EK Certs tabs read the post-quantum endorsement key templates and certificates.
- Researcher / Academic
- Run the V1.85 Compliance Suite from the Command Builder and the ML-DSA Attestation tab's Quote / Certify with in-browser verify: track T8 shows how to detect fake crypto and spec drift yourself.
TPM 2.0 PQC Playground
Execute raw TPM 2.0 commands directly within the browser using the WebAssembly-compiledpqctpm emulator. Explore the new TCG V1.85 RC4 Post-Quantum primitives (ML-KEM and ML-DSA) via a dual-mode Semantic & Hex builder.
Boot & discover — one chip, two cryptographic eras
The TPM booted when this page loaded. These steps interrogate the live chip: self-test, then the algorithm table — where RSA (0x0001) and ML-KEM (0x00A0) sit side by side — and finally a deliberate rule-break to see what an honest TPM refusal looks like.
TCG V1.85 (published March 2026) did not replace the TPM command set — it EXTENDED it. Everything classical still works; the PQC algorithms and commands were added alongside. GetCapability is the migration story in one response.
Waiting for the WASM TPM to initialize — steps enable once the engine is ready.
Steps
TPM2_SelfTest(fullTest=YES)
1. Run the full algorithm self-test
TPM2_GetCapability(TPM_CAP_ALGS)
2. Read the algorithm table — both eras in one list
TPM2_GetCapability(TPM_CAP_TPM_PROPERTIES)
3. Check the version this chip actually claims to be
TPM2_GetRandom(32)
4. Draw 32 bytes from the shared entropy source
TPM2_Startup (again)
5. Break a rule on purpose: start an already-started TPM
Try it
Track T5 says pure ML-DSA must see the whole message. What TPM command difference does that produce?
Next step
Turn it into a plan: Infrastructure Modernization PlannerThis tool practises the Secure Boot & Firmware PQC module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.
Related content
Next in Protocol Simulations