Protocol Simulations / PQC VPN Simulator

What you will do: Pick Classical, Hybrid (ECP-256 + ML-KEM) or Pure PQC key exchange, choose the ML-KEM size, set the MTU and fragmentation, choose PSK or certificate auth, then Start Daemon and watch two strongSwan WASM workers run IKEv2.

Worked example: Select Hybrid with ML-KEM-768 and Start Daemon: the charon log tags IKE_SA_INIT, IKE_INTERMEDIATE and IKE_AUTH lines, the status turns to Tunnel Established, and Tunnel Statistics report Total Bytes, Round Trips and Quantum-Safe: KEX ✓.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with VPN/IPsec & SSH

For your role

Developer / Engineer
Pick Classical (ECP-256), Hybrid (ECP-256 + ML-KEM) or Pure PQC (ML-KEM), Start Daemon, and step through IKE_SA_INIT and IKE_AUTH: the Live Wire Capture and Packet Inspector show the payloads, and Raw Config is the strongSwan configuration behind them.
Security Architect
Enable IKE Message Fragmentation (RFC 7383) and lower the MTU to see why IKE_SA_INIT cannot fragment and where a hybrid key share breaks a tunnel; the SKEYSEED Chaining panel explains the RFC 9370 intermediate exchange.
Researcher / Academic
Open What's Real vs Simulated in This Build first: key generation and signing run on softhsmv3 PKCS#11 in the two token slots, and the Tunnel Statistics compare handshake sizes across the three modes.
IT Ops / DevOps
Use Raw Config, then Download config bundle (.zip): it is the client and server configuration for the mode you chose, and Run algorithm matrix shows which combinations complete before you schedule a cutover.
What is real vs. simulated in this panel
REALPKCS#11 v3.2 on softhsmv3 WASM: key generation, C_Sign, C_EncapsulateKey, C_DecapsulateKey.
REALRSA-3072 + ML-DSA-{44,65,87} keygen & self-signed X.509 on the HSM; SKID/CKA_ID wired for PKCS#11 lookup.
REALCharon library: proposal parser (ML-KEM transforms 35/36/37), cert loader (RFC 9881 ML-DSA OIDs) — proven by every real negotiation this panel runs below.
REALCross-worker ML-KEM-768 round-trip (Alice/Bob workers share a real 32 B secret). OpenSSL x509 -text cert inspector.
REALIKE wire protocol: charon serializes real IKE_SA_INIT / IKE_INTERMEDIATE / IKE_AUTH messages and exchanges them between the two workers over a SharedArrayBuffer wire — inspect the bytes in Live Wire Capture. (The step diagram's payload sizes are a teaching model from ikev2Constants.ts.)
REALRFC 7383 fragmentation: both peers negotiate FRAGMENTATION_SUPPORTED; over-size messages (e.g. ML-DSA IKE_AUTH) are split into real SKF fragments sized byfragment_size and reassembled by the peer.
REALCHILD_SA: negotiated in IKE_AUTH with real ESP key derivation (SPIs come from a stub kernel). No ESP data plane yet — no user traffic actually crosses the tunnel.
SIMULATEDStep auto-advance: driven by log-string heuristics, not by charon bus events.
SIMULATEDIKE_AUTH cert auth: PSK mode only; switch to "PSK + Certificate" to run real ML-DSA signing.
Roadmap: remaining work is the ESP data plane (userspace libipsec port) so payload traffic actually crosses the CHILD_SA. For a kernel-backed deployment today, use the “Launch full-fidelity sandbox” button in the Raw Config tab (runs real strongSwan 6.0.5 in Docker).
Loading strongSwan WASM… (0s)

How to run a PQC VPN handshake

  1. Choose a VPN mode (Classical / Hybrid / Pure-PQC)
  2. For Dual Cert auth: click Generate Certs first
  3. Click Start Daemon and watch the IKEv2 exchange
Key Exchange Mode

Traditional IKEv2 using elliptic-curve Diffie-Hellman (ECP-256, DH Group 19 — the aes256-sha256-ecp256 proposal this simulator runs). Vulnerable to HNDL (Harvest Now, Decrypt Later): traffic captured today can be decrypted retroactively by a future CRQC. Provides no quantum-safe forward secrecy.

ML-KEM Size

Classical mode uses ECDH/MODP key exchange, not ML-KEM — this selector has no effect.

Network Constraints
1500 Bytes

PQC key exchange payloads are 3–24× larger than classical DH (ML-KEM-768encapsulation key: 1,184 B vs. ECP-256: 64 B), often exceeding UDP MTU. RFC 7383 splits oversized SK-carrying IKE messages into fragments reassembled before processing — IKE_SA_INIT itself can never be fragmented.

Initiator (Client)
Request
HDR28 B

SPIs, version, exchange type, flags

SA64 B

Proposed transforms (encryption, integrity, DH group, PRF)

KE72 B

ECP-256 public value (DH Group 19, 64 bytes)

Ni36 B

Random nonce (32 bytes)

IKE_AUTH Request
HDR28 B

Encrypted exchange header

SK480 B

IDi, AUTH, SAi2, TSi, TSr (encrypted; PSK auth — no CERT payload)

Responder (Gateway)
IKE_SA_INIT Response
HDR28 B

SPIs, version, exchange type, flags

SA48 B

Selected transforms

KE72 B

ECP-256 public value (DH Group 19, 64 bytes)

Nr36 B

Random nonce (32 bytes)

IKE_AUTH Response
HDR28 B

Encrypted exchange header

SK480 B

IDr, AUTH, SAr2, TSi, TSr (encrypted; PSK auth — no CERT payload)

Sequence 1 of 4Daemon: UNINITIALIZED
charon.log
WASM IKEv2 KEM Daemon
Awaiting daemon initialization...

Live Wire Capture

Real IKE messages routed between the two charon WASM workers. Click a packet to inspect its ISAKMP header and hex dump.

The Wire

Bytes in flight: 0Packets: 0
Initiator192.168.0.1Responder192.168.0.2No packets yet — click "Establish IKEv2 Tunnel" to begin.

Packet Inspector

No packets captured yet.

Click a packet on The Wire or in the list above to inspect.

Tunnel Statistics

...Status
1,400Total Bytes
708Initiator Bytes
2Round Trips
N/ANIST Sec. Level
ECP-256 (DH Group 19)KE Algorithm
PSKAuth Algorithm
NoQuantum-Safe

PKCS#11 Cryptographic Diagnostic Boundary

HSM: Awaiting Start
Authentication Mode
Client PSK

PSK can be distributed via QKD for quantum-safe key establishment.

Authentication Key Type
Keys generated in worker HSM
Client Identity Parameter Mappingleftauth=psk
left=192.168.0.1
leftsubnet=192.168.0.1/32
leftauth=psk

No keys yet — click Execute to run the provisioning flow.

IKEv2 handshake — classical vs hybrid vs pure-PQC

Classical (ECP-256)

selected
KEX quantum-safe HNDL-safe
Key exchange
ECP-256 (DH Group 19)
Round trips
2

Handshake total (PSK baseline)

1,400 B

KE payload (SA_INIT →)

72 B

KE payload (SA_INIT ←)

72 B

Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).

Hybrid (ECP-256 + ML-KEM)

KEX quantum-safe HNDL-safe
Key exchange
ECP-256 (IKE_SA_INIT) + ML-KEM (Additional KE 1, IKE_INTERMEDIATE)
Round trips
3 (incl. IKE_INTERMEDIATE)

Handshake total (PSK baseline)

3,784 B

KE payload (SA_INIT →)

72 B

KE payload (SA_INIT ←)

72 B

Additional KE (IKE_INTERMEDIATE ⇄)

2,360 B

Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).

Pure PQC (ML-KEM)

KEX quantum-safe HNDL-safe
Key exchange
ML-KEM (IKE_SA_INIT, Key Exchange Method 35/36/37)
Round trips
2

Handshake total (PSK baseline)

3,544 B

KE payload (SA_INIT →)

1,192 B

KE payload (SA_INIT ←)

1,096 B

Authentication is a separate axis: PSK or RSA certificates remain classical in every mode — only ML-DSA certificates make IKE_AUTH quantum-safe (see table below).

IKE_AUTH growth by authentication method (SK payload, one message)

Certificate authentication adds the peer certificate plus the AUTH signature to the encrypted IKE_AUTH payload. ML-DSA pushes IKE_AUTH well past the 1,500 B Ethernet MTU (RFC 894) — this is the message that most needs RFC 7383 fragmentation (IKE_SA_INIT cannot fragment at all).

Auth methodEstimated SK payloadQuantum-safe
PSK
480 B
✓
RSA-2048
1,400 B
✗
RSA-3072
1,750 B
✗
RSA-4096
2,100 B
✗
ML-DSA-44
6,600 B
✓
ML-DSA-65
9,000 B
✓
ML-DSA-87
12,300 B
✓

ML-KEM key exchange uses IANA-assigned IKEv2 KE Methods 35/36/37 (ML-KEM-512/768/1024); the ML-DSA IKEv2 AUTH method (draft-sfluhrer-ipsecme-ikev2-mldsa) has no IANA assignment yet. ML-DSA X.509 certificate OIDs are standardised in RFC 9881. PSK authentication is symmetric and therefore quantum-resistant, provided the key is distributed securely and has sufficient entropy.

Migrating IKEv2 to post-quantum cryptography swaps the plaintext key exchange first — that is where HNDL bites. Hybrid mode keeps ECP-256 in IKE_SA_INIT and adds ML-KEM-768 as Additional KE 1 in an extra, encrypted IKE_INTERMEDIATE round trip (draft-ietf-ipsecme-ikev2-mlkem Appendix A), where RFC 7383 can fragment it (3,784 B / 3 RTT vs 1,400 B / 2 RTT classical), re-deriving SKEYSEED per RFC 9370 §2.2.2 so both algorithms must fall before the session keys do. Pure-PQC drops the classical exchange entirely and carries ML-KEM in the unfragmentable IKE_SA_INIT (3,544 B / 2 RTT). In this simulator the ML-KEM-768 encapsulation and decapsulation run as real C_EncapsulateKey / C_DecapsulateKey calls on softhsmv3 WASM, keeping the shared secret inside the PKCS#11 token boundary.

Try it

Run IKE_SA_INIT in Hybrid mode with fragmentation off and a small MTU. What does the wire capture show?

Next step

Turn it into a plan: Hybrid Transition Planner

This tool practises the VPN/IPsec & SSH module, phase 5 (Pilots & Migration); Hybrid Transition Planner produces a deliverable of that phase.

Next in Protocol Simulations