Freeman Yue Fang created WSS-730:
------------------------------------
Summary: Add post-quantum cryptography (ML-DSA / ML-KEM) support
Key: WSS-730
URL: https://issues.apache.org/jira/browse/WSS-730
Project: WSS4J
Issue Type: New Feature
Reporter: Freeman Yue Fang
Assignee: Colm O hEigeartaigh
h2. Description
Apache Santuario (XML Security for Java) is adding support for the NIST
post-quantum algorithms ML-DSA (FIPS 204, digital signatures) and ML-KEM (FIPS
203, key encapsulation used for key transport via the W3C "Generic Hybrid
Cipher" structure) — see SANTUARIO-634 and PRs #651 (ML-DSA) / #652 (ML-KEM)
against santuario-xml-security-java. Both algorithm families use the finalized
URIs from draft-eastlake-rfc9231bis-xmlsec-uris-09
({{http://www.w3.org/2026/08/xmldsig-more#...}}).
WS-Security / WS-SecurityPolicy has no corresponding support today: WSS4J
cannot sign with an ML-DSA key or protect a session key with ML-KEM key
transport, and {{AlgorithmSuite}}/{{AlgorithmSuiteValidator}} reject the new
algorithm URIs as unrecognized.
A baseline implementation building directly on the Santuario PQC work has
already been put together locally, and is ready to open as a starter PR once a
Santuario build containing PR #651/#652 is available to depend on.
h3. Implementation
*Common / policy*
* Added ML-DSA-44/65/87 and ML-KEM-512/768/1024 algorithm URI constants to
{{WSS4JConstants}} and {{SPConstants}}.
* {{AlgorithmSuite}} and {{AlgorithmSuiteValidator}} now recognize the PQC
algorithm URIs, so WS-SecurityPolicy assertion checks accept them (asymmetric
signature suite for ML-DSA, symmetric key-wrap/encryption suite for ML-KEM).
* Added {{KeyUtils}} helpers for the ML-KEM generic-hybrid-cipher key handling
shared by the DOM and StAX paths.
*DOM*
* {{WSSecSignature}} / {{WSSecSignatureSAML}}: sign with ML-DSA keys.
* {{WSSecEncrypt}} / {{WSSecEncryptedKey}}: encrypt the session key with ML-KEM
via the generic hybrid cipher structure.
* {{EncryptedKeyProcessor}}: decrypt an ML-KEM-protected {{EncryptedKey}}.
*StAX*
* Outbound: {{EncryptedKeyOutputProcessor}}, {{OutboundWSSec}}.
* Inbound: {{WSSEncryptedKeyInputHandler}}, {{WSSSignatureInputHandler}},
{{SecurityTokenFactoryImpl}}.
* Updated the bundled {{xenc-schema}}/{{xenc-schema-11}} XSDs to allow the new
key-transport content shape.
*Tests*
* {{PQCSignatureTest}}, {{PQCEncryptionTest}} (DOM) and
{{PQCEncryptionStaxTest}} (StAX) — signature and key-transport round-trip
coverage.
* Tests require JDK 21+ ({{javax.crypto.KEM}}, JEP 452) and a JCA provider
offering ML-DSA/ML-KEM (Bouncy Castle 1.84+ today; JDK's own ML-DSA provider on
JDK 24+ per JEP 497 is a reasonable secondary target).
I will send the initial PR soon
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]