Files
llm-wiki/raw/articles/wolftpm-pqc-tpm-2-0-v1-85-2026.md
T
2026-06-30 22:22:00 +09:00

50 lines
3.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
source_url: https://www.wolfssl.com/wolftpm-add-tpm-2-0-v1-85-pqc-post-quantum-support/
ingested: 2026-06-30
sha256: 56903e3f29834c03321ac031bd296fdb4dfa61736eff7ff3bd33944effcf2595
discovered_from:
platform: discord
channel_id: '1477793137064935675'
channel_name: tw
message_id: '1521324831096705217'
author_id: '1477793167486226708'
posted_at: 2026-06-30T01:21:44.582000000Z
context_url: https://x.com/yousukezan/status/2071752910283915461
message_excerpt: >-
TPM 2.0 v1.85 PQC support pointer; practical post-quantum hardware-backed security.
---
As the cybersecurity landscape prepares for the advent of quantum computing, the Trusted Platform Module (TPM) ecosystem is evolving to meet these new challenges. wolfSSL is proud to announce that **wolfTPM** now includes initial support for the **TPM 2.0 Library Specification v1.85**, bringing Post-Quantum Cryptography (PQC) capabilities to your hardware-backed security workflows.
This update introduces support for the National Institute of Standards and Technology (NIST) standardized algorithms: **ML-DSA (Dilithium)** and **ML-KEM (Kyber)**.
**ML-DSA: Quantum-Resistant Digital Signatures**
The transition to PQC requires more than just new algorithms; it requires new ways of interacting with TPM hardware. wolfTPM now supports the sequence-based signing and verification commands required by ML-DSA, including:
- TPM2\_SignSequenceStart / TPM2\_VerifySequenceStart
- TPM2\_SignSequenceComplete / TPM2\_VerifySequenceComplete
- TPM2\_SignDigest / TPM2\_VerifyDigestSignature
These commands allow for context-based signing, ensuring that large messages can be processed securely through the TPM’s post-quantum engines.
**ML-KEM: Enhanced Key Encapsulation**
For secure key exchange, wolfTPM now implements the ML-KEM (formerly Kyber) commands:
- **TPM2\_Encapsulate**: A public-key operation to generate a shared secret and a ciphertext.
- **TPM2\_Decapsulate**: A private-key operation used to recover the shared secret from the ciphertext.
**New PQC Types and Structures**
To support these advanced algorithms, we have integrated several new types and structure tags into our library, such as TPM2B\_KEM\_CIPHERTEXT, TPM2B\_SHARED\_SECRET, and TPM\_ST\_MESSAGE\_VERIFIED. These additions ensure that your application can seamlessly handle the larger key sizes and unique data structures associated with post-quantum algorithms.
**Getting Started**
To explore these new features, ensure you are using a TPM that supports the v1.85 specification. You can find new unit tests in the wolfTPM source code to help guide your implementation:
- test\_wolfTPM2\_MLDSA\_\*
- test\_wolfTPM2\_MLKEM\_\*
For more details, view the full [Pull Request #445](https://github.com/wolfSSL/wolfTPM/pull/445) on GitHub.
Interested in a commercial license or post-quantum consulting? Contact us at [[email protected]](mailto:[email protected]) or call [+1 425 245 8247](tel:14252458247).
**[Download](https://www.wolfssl.com/download/) wolfSSL Now**