CÁC MECHANISM PKCS#11

Sổ đăng ký mechanism và tham số

Mã mechanism, cấu trúc tham số, loại khóa và thao tác được công bố cho đúng cặp thư viện/header.

01

Ma trận mechanism

MechanismKey typeOperationMaturity
CKM_ECDSAECSign/verifyAvailable/validated backend scope
CKM_RSA_PKCS_PSSRSASign/verifyAvailable/validated backend scope
CKM_SHA256_HMACGeneric secretMACBy release
ML-DSA mechanism profilePQCSign/verifyControlled pilot; exact identifier/header
ML-KEM mechanism profilePQCEncapsulate/decapsulate or derive mappingControlled pilot
Vendor hybrid mechanismHybridSign or key establishmentProject-specific; not portable

02

Quy tắc mechanism do nhà cung cấp định nghĩa

No portability inference

A vendor-defined ML-DSA, ML-KEM or hybrid identifier must include the vendor namespace, numeric identifier, C structure definition, byte order, encoding and verifier/provider compatibility. It must not be represented as a standard Cryptoki mechanism unless standardized and implemented accordingly.