Module 9

Key management and HSMs

5 lessonsabout 150 minPractitioner / Advisor

After this module you can

  • Recognize the PKCS#11 v3.2 post-quantum mechanisms
  • Separate CAVP, CMVP and production support with HSM-specific examples
  • Explain the storage and latency impact of PQC in a smart card or QSCD scenario

Before thisM8: Protocols

  1. 01PKCS#11 v3.2 post-quantum mechanismsRecognize, in a code example, the new mechanisms and functions PKCS#11 v3.2 defines for ML-DSA and ML-KEM (including C_EncapsulateKey/C_DecapsulateKey)
  2. 02HSM validation reality: CAVP vs CMVPState, in NIST's own words, the difference between CAVP (algorithm validation) and CMVP (module validation) and which is the prerequisite for which
  3. 03Key ceremonies and KMIPList what concretely changes in a key ceremony when the root key is ML-DSA (backups, fingerprint verification, entropy)
  4. 04PQC and smart cardsCalculate, with real size figures, the storage and transmission limits ML-DSA/SLH-DSA keys and signatures hit on a smart card or QSCD
  5. 05The cost of an HSM fleet refreshExplain, component by component, that the real bottleneck of an HSM fleet refresh is not hardware cost but the certification, procurement and ceremony timeline
Next moduleM10: Payment cryptography