Protocol Simulations / TPM 2.0 PQC Playground

What you will do: Send raw TPM 2.0 commands from the Command Builder — TPM2_GetCapability, TPM2_CreatePrimary, TPM2_Encapsulate, TPM2_SignDigest — with ML-KEM or ML-DSA, then run Quote or Certify on the Attestation tab.

Worked example: On Attestation keep the ML-DSA-65 key, PCRs sha256:0,1,2,3,7 and the default nonce, press Run Quote: the result shows the 3309-byte signature, OpenSSL WASM verify says Signature Verified Successfully, plus a JSON bundle.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Secure Boot & Firmware PQC

For your role

Developer / Engineer
Run the eight tracks from Boot & discover to An honest TPM in the Learn tab, then use the Command Builder to send raw commands such as TPM2_GetCapability to the WebAssembly TPM: the Execution Log shows tags, return codes and the ML-KEM and ML-DSA primitives.
Security Architect
Track T3, Key establishment — transport vs encapsulation, and T6, Factory identity, show where a TPM's trust model changes under PQC; the V2.7 EKs and EK Certs tabs read the post-quantum endorsement key templates and certificates.
Researcher / Academic
Run the V1.85 Compliance Suite from the Command Builder and the ML-DSA Attestation tab's Quote / Certify with in-browser verify: track T8 shows how to detect fake crypto and spec drift yourself.

TPM 2.0 PQC Playground

Execute raw TPM 2.0 commands directly within the browser using the WebAssembly-compiledpqctpm emulator. Explore the new TCG V1.85 RC4 Post-Quantum primitives (ML-KEM and ML-DSA) via a dual-mode Semantic & Hex builder.

INITIALIZING WASM...
Core

Boot & discover — one chip, two cryptographic eras

The TPM booted when this page loaded. These steps interrogate the live chip: self-test, then the algorithm table — where RSA (0x0001) and ML-KEM (0x00A0) sit side by side — and finally a deliberate rule-break to see what an honest TPM refusal looks like.

TCG V1.85 (published March 2026) did not replace the TPM command set — it EXTENDED it. Everything classical still works; the PQC algorithms and commands were added alongside. GetCapability is the migration story in one response.

Waiting for the WASM TPM to initialize — steps enable once the engine is ready.

Steps

  1. TPM2_SelfTest(fullTest=YES)

    1. Run the full algorithm self-test

  2. TPM2_GetCapability(TPM_CAP_ALGS)

    2. Read the algorithm table — both eras in one list

  3. TPM2_GetCapability(TPM_CAP_TPM_PROPERTIES)

    3. Check the version this chip actually claims to be

  4. TPM2_GetRandom(32)

    4. Draw 32 bytes from the shared entropy source

  5. TPM2_Startup (again)

    5. Break a rule on purpose: start an already-started TPM

Try it

Track T5 says pure ML-DSA must see the whole message. What TPM command difference does that produce?

Next step

Turn it into a plan: Infrastructure Modernization Planner

This tool practises the Secure Boot & Firmware PQC module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.

Next in Protocol Simulations