Freeman Yue Fang created WSS-730:
------------------------------------

             Summary: Add post-quantum cryptography (ML-DSA / ML-KEM) support
                 Key: WSS-730
                 URL: https://issues.apache.org/jira/browse/WSS-730
             Project: WSS4J
          Issue Type: New Feature
            Reporter: Freeman Yue Fang
            Assignee: Colm O hEigeartaigh


h2. Description

Apache Santuario (XML Security for Java) is adding support for the NIST 
post-quantum algorithms ML-DSA (FIPS 204, digital signatures) and ML-KEM (FIPS 
203, key encapsulation used for key transport via the W3C "Generic Hybrid 
Cipher" structure) — see SANTUARIO-634 and PRs #651 (ML-DSA) / #652 (ML-KEM) 
against santuario-xml-security-java. Both algorithm families use the finalized 
URIs from draft-eastlake-rfc9231bis-xmlsec-uris-09 
({{http://www.w3.org/2026/08/xmldsig-more#...}}).

WS-Security / WS-SecurityPolicy has no corresponding support today: WSS4J 
cannot sign with an ML-DSA key or protect a session key with ML-KEM key 
transport, and {{AlgorithmSuite}}/{{AlgorithmSuiteValidator}} reject the new 
algorithm URIs as unrecognized.

A baseline implementation building directly on the Santuario PQC work has 
already been put together locally, and is ready to open as a starter PR once a 
Santuario build containing PR #651/#652 is available to depend on.

h3. Implementation

*Common / policy*
* Added ML-DSA-44/65/87 and ML-KEM-512/768/1024 algorithm URI constants to 
{{WSS4JConstants}} and {{SPConstants}}.
* {{AlgorithmSuite}} and {{AlgorithmSuiteValidator}} now recognize the PQC 
algorithm URIs, so WS-SecurityPolicy assertion checks accept them (asymmetric 
signature suite for ML-DSA, symmetric key-wrap/encryption suite for ML-KEM).
* Added {{KeyUtils}} helpers for the ML-KEM generic-hybrid-cipher key handling 
shared by the DOM and StAX paths.

*DOM*
* {{WSSecSignature}} / {{WSSecSignatureSAML}}: sign with ML-DSA keys.
* {{WSSecEncrypt}} / {{WSSecEncryptedKey}}: encrypt the session key with ML-KEM 
via the generic hybrid cipher structure.
* {{EncryptedKeyProcessor}}: decrypt an ML-KEM-protected {{EncryptedKey}}.

*StAX*
* Outbound: {{EncryptedKeyOutputProcessor}}, {{OutboundWSSec}}.
* Inbound: {{WSSEncryptedKeyInputHandler}}, {{WSSSignatureInputHandler}}, 
{{SecurityTokenFactoryImpl}}.
* Updated the bundled {{xenc-schema}}/{{xenc-schema-11}} XSDs to allow the new 
key-transport content shape.

*Tests*
* {{PQCSignatureTest}}, {{PQCEncryptionTest}} (DOM) and 
{{PQCEncryptionStaxTest}} (StAX) — signature and key-transport round-trip 
coverage.
* Tests require JDK 21+ ({{javax.crypto.KEM}}, JEP 452) and a JCA provider 
offering ML-DSA/ML-KEM (Bouncy Castle 1.84+ today; JDK's own ML-DSA provider on 
JDK 24+ per JEP 497 is a reasonable secondary target).



I will send the initial PR soon




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to