Module 9
Key management and HSMs
5 lessonsabout 150 minPractitioner / Advisor
After this module you can
- Recognize the PKCS#11 v3.2 post-quantum mechanisms
- Separate CAVP, CMVP and production support with HSM-specific examples
- Explain the storage and latency impact of PQC in a smart card or QSCD scenario
Before thisM8: Protocols
- 01PKCS#11 v3.2 post-quantum mechanismsRecognize, in a code example, the new mechanisms and functions PKCS#11 v3.2 defines for ML-DSA and ML-KEM (including C_EncapsulateKey/C_DecapsulateKey)
- 02HSM validation reality: CAVP vs CMVPState, in NIST's own words, the difference between CAVP (algorithm validation) and CMVP (module validation) and which is the prerequisite for which
- 03Key ceremonies and KMIPList what concretely changes in a key ceremony when the root key is ML-DSA (backups, fingerprint verification, entropy)
- 04PQC and smart cardsCalculate, with real size figures, the storage and transmission limits ML-DSA/SLH-DSA keys and signatures hit on a smart card or QSCD
- 05The cost of an HSM fleet refreshExplain, component by component, that the real bottleneck of an HSM fleet refresh is not hardware cost but the certification, procurement and ceremony timeline