Protocol Simulations / PQC VPN Simulator
What you will do: Pick Classical, Hybrid (ECP-256 + ML-KEM) or Pure PQC key exchange, choose the ML-KEM size, set the MTU and fragmentation, choose PSK or certificate auth, then Start Daemon and watch two strongSwan WASM workers run IKEv2.
Worked example: Select Hybrid with ML-KEM-768 and Start Daemon: the charon log tags IKE_SA_INIT, IKE_INTERMEDIATE and IKE_AUTH lines, the status turns to Tunnel Established, and Tunnel Statistics report Total Bytes, Round Trips and Quantum-Safe: KEX ✓.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
For your role
- Developer / Engineer
- Pick Classical (ECP-256), Hybrid (ECP-256 + ML-KEM) or Pure PQC (ML-KEM), Start Daemon, and step through IKE_SA_INIT and IKE_AUTH: the Live Wire Capture and Packet Inspector show the payloads, and Raw Config is the strongSwan configuration behind them.
- Security Architect
- Enable IKE Message Fragmentation (RFC 7383) and lower the MTU to see why IKE_SA_INIT cannot fragment and where a hybrid key share breaks a tunnel; the SKEYSEED Chaining panel explains the RFC 9370 intermediate exchange.
- Researcher / Academic
- Open What's Real vs Simulated in This Build first: key generation and signing run on softhsmv3 PKCS#11 in the two token slots, and the Tunnel Statistics compare handshake sizes across the three modes.
- IT Ops / DevOps
- Use Raw Config, then Download config bundle (.zip): it is the client and server configuration for the mode you chose, and Run algorithm matrix shows which combinations complete before you schedule a cutover.
x509 -text cert inspector.ikev2Constants.ts.)fragment_size and reassembled by the peer.How to run a PQC VPN handshake
- Choose a VPN mode (Classical / Hybrid / Pure-PQC)
- For Dual Cert auth: click Generate Certs first
- Click Start Daemon and watch the IKEv2 exchange
Traditional IKEv2 using elliptic-curve Diffie-Hellman (ECP-256, DH Group 19 — the aes256-sha256-ecp256 proposal this simulator runs). Vulnerable to HNDL (Harvest Now, Decrypt Later): traffic captured today can be decrypted retroactively by a future CRQC. Provides no quantum-safe forward secrecy.
Classical mode uses ECDH/MODP key exchange, not ML-KEM — this selector has no effect.
PQC key exchange payloads are 3–24× larger than classical DH (ML-KEM-768encapsulation key: 1,184 B vs. ECP-256: 64 B), often exceeding UDP MTU. RFC 7383 splits oversized SK-carrying IKE messages into fragments reassembled before processing — IKE_SA_INIT itself can never be fragmented.
SPIs, version, exchange type, flags
Proposed transforms (encryption, integrity, DH group, PRF)
ECP-256 public value (DH Group 19, 64 bytes)
Random nonce (32 bytes)
Encrypted exchange header
IDi, AUTH, SAi2, TSi, TSr (encrypted; PSK auth — no CERT payload)
SPIs, version, exchange type, flags
Selected transforms
ECP-256 public value (DH Group 19, 64 bytes)
Random nonce (32 bytes)
Encrypted exchange header
IDr, AUTH, SAr2, TSi, TSr (encrypted; PSK auth — no CERT payload)
Live Wire Capture
Real IKE messages routed between the two charon WASM workers. Click a packet to inspect its ISAKMP header and hex dump.
The Wire
Packet Inspector
No packets captured yet.
Click a packet on The Wire or in the list above to inspect.
Tunnel Statistics
PKCS#11 Cryptographic Diagnostic Boundary
PSK can be distributed via QKD for quantum-safe key establishment.
left=192.168.0.1 leftsubnet=192.168.0.1/32 leftauth=psk
No keys yet — click Execute to run the provisioning flow.
IKEv2 handshake — classical vs hybrid vs pure-PQC
Classical (ECP-256)
selected- Key exchange
- ECP-256 (DH Group 19)
- Round trips
- 2
Handshake total (PSK baseline)
KE payload (SA_INIT →)
KE payload (SA_INIT ←)
Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).
Hybrid (ECP-256 + ML-KEM)
- Key exchange
- ECP-256 (IKE_SA_INIT) + ML-KEM (Additional KE 1, IKE_INTERMEDIATE)
- Round trips
- 3 (incl. IKE_INTERMEDIATE)
Handshake total (PSK baseline)
KE payload (SA_INIT →)
KE payload (SA_INIT ←)
Additional KE (IKE_INTERMEDIATE ⇄)
Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).
Pure PQC (ML-KEM)
- Key exchange
- ML-KEM (IKE_SA_INIT, Key Exchange Method 35/36/37)
- Round trips
- 2
Handshake total (PSK baseline)
KE payload (SA_INIT →)
KE payload (SA_INIT ←)
Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).
IKE_AUTH growth by authentication method (SK payload, one message)
Certificate authentication adds the peer certificate plus the AUTH signature to the encrypted IKE_AUTH payload. ML-DSA pushes IKE_AUTH well past the 1,500 B Ethernet MTU (RFC 894) — this is the message that most needs RFC 7383 fragmentation (IKE_SA_INIT cannot fragment at all).
| Auth method | Estimated SK payload | Quantum-safe |
|---|---|---|
| PSK | 480 B | ✓ |
| RSA-2048 | 1,400 B | ✗ |
| RSA-3072 | 1,750 B | ✗ |
| RSA-4096 | 2,100 B | ✗ |
| ML-DSA-44 | 6,600 B | ✓ |
| ML-DSA-65 | 9,000 B | ✓ |
| ML-DSA-87 | 12,300 B | ✓ |
ML-KEM key exchange uses IANA-assigned IKEv2 KE Methods 35/36/37 (ML-KEM-512/768/1024); the ML-DSA IKEv2 AUTH method (draft-sfluhrer-ipsecme-ikev2-mldsa) has no IANA assignment yet. ML-DSA X.509 certificate OIDs are standardised in RFC 9881. PSK authentication is symmetric and therefore quantum-resistant, provided the key is distributed securely and has sufficient entropy.
Migrating IKEv2 to post-quantum cryptography swaps the plaintext key exchange first — that is where HNDL bites. Hybrid mode keeps ECP-256 in IKE_SA_INIT and adds ML-KEM-768 as Additional KE 1 in an extra, encrypted IKE_INTERMEDIATE round trip (draft-ietf-ipsecme-ikev2-mlkem Appendix A), where RFC 7383 can fragment it (3,784 B / 3 RTT vs 1,400 B / 2 RTT classical), re-deriving SKEYSEED per RFC 9370 §2.2.2 so both algorithms must fall before the session keys do. Pure-PQC drops the classical exchange entirely and carries ML-KEM in the unfragmentable IKE_SA_INIT (3,544 B / 2 RTT). In this simulator the ML-KEM-768 encapsulation and decapsulation run as real C_EncapsulateKey / C_DecapsulateKey calls on softhsmv3 WASM, keeping the shared secret inside the PKCS#11 token boundary.
Try it
Run IKE_SA_INIT in Hybrid mode with fragmentation off and a small MTU. What does the wire capture show?
Next step
Turn it into a plan: Hybrid Transition PlannerThis tool practises the VPN/IPsec & SSH module, phase 5 (Pilots & Migration); Hybrid Transition Planner produces a deliverable of that phase.
Related content
Next in Protocol Simulations