50 lines
3.0 KiB
Markdown
50 lines
3.0 KiB
Markdown
---
|
||
source_url: https://www.wolfssl.com/wolftpm-add-tpm-2-0-v1-85-pqc-post-quantum-support/
|
||
ingested: 2026-06-30
|
||
sha256: 56903e3f29834c03321ac031bd296fdb4dfa61736eff7ff3bd33944effcf2595
|
||
discovered_from:
|
||
platform: discord
|
||
channel_id: '1477793137064935675'
|
||
channel_name: tw
|
||
message_id: '1521324831096705217'
|
||
author_id: '1477793167486226708'
|
||
posted_at: 2026-06-30T01:21:44.582000000Z
|
||
context_url: https://x.com/yousukezan/status/2071752910283915461
|
||
message_excerpt: >-
|
||
TPM 2.0 v1.85 PQC support pointer; practical post-quantum hardware-backed security.
|
||
---
|
||
|
||
As the cybersecurity landscape prepares for the advent of quantum computing, the Trusted Platform Module (TPM) ecosystem is evolving to meet these new challenges. wolfSSL is proud to announce that **wolfTPM** now includes initial support for the **TPM 2.0 Library Specification v1.85**, bringing Post-Quantum Cryptography (PQC) capabilities to your hardware-backed security workflows.
|
||
|
||
This update introduces support for the National Institute of Standards and Technology (NIST) standardized algorithms: **ML-DSA (Dilithium)** and **ML-KEM (Kyber)**.
|
||
|
||
**ML-DSA: Quantum-Resistant Digital Signatures**
|
||
The transition to PQC requires more than just new algorithms; it requires new ways of interacting with TPM hardware. wolfTPM now supports the sequence-based signing and verification commands required by ML-DSA, including:
|
||
|
||
- TPM2\_SignSequenceStart / TPM2\_VerifySequenceStart
|
||
- TPM2\_SignSequenceComplete / TPM2\_VerifySequenceComplete
|
||
- TPM2\_SignDigest / TPM2\_VerifyDigestSignature
|
||
|
||
These commands allow for context-based signing, ensuring that large messages can be processed securely through the TPM’s post-quantum engines.
|
||
|
||
**ML-KEM: Enhanced Key Encapsulation**
|
||
For secure key exchange, wolfTPM now implements the ML-KEM (formerly Kyber) commands:
|
||
|
||
- **TPM2\_Encapsulate**: A public-key operation to generate a shared secret and a ciphertext.
|
||
- **TPM2\_Decapsulate**: A private-key operation used to recover the shared secret from the ciphertext.
|
||
|
||
**New PQC Types and Structures**
|
||
To support these advanced algorithms, we have integrated several new types and structure tags into our library, such as TPM2B\_KEM\_CIPHERTEXT, TPM2B\_SHARED\_SECRET, and TPM\_ST\_MESSAGE\_VERIFIED. These additions ensure that your application can seamlessly handle the larger key sizes and unique data structures associated with post-quantum algorithms.
|
||
|
||
**Getting Started**
|
||
To explore these new features, ensure you are using a TPM that supports the v1.85 specification. You can find new unit tests in the wolfTPM source code to help guide your implementation:
|
||
|
||
- test\_wolfTPM2\_MLDSA\_\*
|
||
- test\_wolfTPM2\_MLKEM\_\*
|
||
|
||
For more details, view the full [Pull Request #445](https://github.com/wolfSSL/wolfTPM/pull/445) on GitHub.
|
||
|
||
Interested in a commercial license or post-quantum consulting? Contact us at [[email protected]](mailto:[email protected]) or call [+1 425 245 8247](tel:14252458247).
|
||
|
||
**[Download](https://www.wolfssl.com/download/) wolfSSL Now**
|