Post Quantum Algorithms

Demand for post-quantum computing safe algorithms is strong, wide-spread, and increasing.

Among the first such algorithms to receive official approval were LMS-HSS, which are useful in some scenarios while having drawbacks in others (such as not being copyable, thus no backup and no HA replication are possible). Thales released LMS-HSS for Luna HSMs in Luna HSM Firmware 7.8.9 and newer, fully compliant with the published standard.

ML-DSA and ML-KEM algorithms are available using Luna HSM Firmware 7.9.0 or newer, fully compliant with FIPS standards (see NIST's Cryptographic Algorithm Validation Program). The ML-DSA and ML-KEM mechanisms produce keys/keypairs that can be cloned from partition to partition, backed-up and restored, and used in HA groups.

Topics in this section provide information for developers creating applications that use our Luna implementations of PQC algorithms.

>ML-DSA Programming Guide for Luna HSM

>Example Create, backup and restore ML-DSA keys on a V1 partition

>PQC External Hash

>ML-KEM Programming Guide

>Example of ML-KEM creation, Backup and Restore

>ML-DSA examples creating a csr for ML-DSA-44 -65 or -87

>LMS and HSS