Skip to main content

Supported Algorithms and PQC

This page lists the algorithms that the Smart Key Attributes (SKA) feature supports. It can be separated into two categories:

  • The SKA key itself. This is the key that ultimately signs the requested message (for example, a cryptocurrency transaction or a document). An SKA key has a policy attached.

  • The approver key pair. Approvers sign approval tokens to allow the use of an SKA key. The approver public keys are listed in the SKA policy.

These keys can use different algorithms, they don't need to be the same.

Asymmetric (Classical)

SKA keys and approver keys support the following algorithms:

  • RSA
  • DSA
  • ECDSA
  • EdDSA
  • BLS (JCE and TSB only)

Asymmetric (Post-Quantum)

SKA keys support the following algorithms:

AlgorithmMinimum HSM versionMinimum JCE versionMinimum TSB versionMinimum PKCS#11 version
ML-DSA3.1.02.4.42.4.02.8.0
SLH-DSA3.1.02.4.42.4.02.8.0
HSS-LMS3.1.02.4.32.1.02.8.0
XMSS3.1.02.4.32.8.52.8.0
ML-KEM3.2.13, 3.3.62.6.42.8.162.8.0

Approver keys support the following algorithms:

AlgorithmMinimum HSM versionMinimum JCE versionMinimum TSB version
ML-DSA3.2.13, 3.3.62.6.52.8.16
SLH-DSA3.2.13, 3.3.62.6.62.8.16
HSS-LMSunsupported--
XMSSunsupported--
ML-KEMnot a signing algorithm--

The PKCS#11 provider opaquely handles SKA policies and approval signatures. Therefore, any PKCS#11 version should work. It was tested with 2.8.0.

Symmetric

SKA keys and approver keys do not support symmetric algorithms (such as AES).

References

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?