BỘ NHÀ CUNG CẤP MẬT MÃ PQC TIN CẬY

Nhà cung cấp PKCS#11
Hợp đồng Cryptoki được công bố, không phải tuyên bố middleware chung.

Thư viện native theo phiên bản cung cấp slot, session, object, thao tác khóa và cơ chế ký/KEM được quản trị cho ứng dụng doanh nghiệp, đồng thời giữ thực thi khóa riêng trong token, HSM, QSCD hoặc ranh giới ký từ xa được phê duyệt.

MÔ HÌNH CRYPTOKI

Slot, session, object và mechanism có hành vi rõ ràng.

The provider contract identifies the library filename, ABI, supported Cryptoki version, threading rules, slot stability, login scope, object attributes, mechanism identifiers and return-code behavior. Vendor-defined PQC or hybrid mechanisms are never implied to be portable across providers.

SLOT & TOKEN

Stable discovery contract

C_GetSlotList, token-presence behavior, slot labels, serial numbers, event handling and HA/failover rules are recorded per release.

SESSION & AUTH

Defined login semantics

RO/RW sessions, User/SO roles, context-specific authentication, session pooling, timeout and PIN lockout are documented.

OBJECTS

Versioned attribute profile

CKO_PRIVATE_KEY, CKO_PUBLIC_KEY and CKO_CERTIFICATE templates define CKA_ID, CKA_LABEL, sensitivity, extractability and permitted operations.

MECHANISMS

Published operation mapping

Classical mechanisms and controlled ML-DSA/ML-KEM or hybrid vendor profiles are tied to exact headers, parameter structures and evidence.

MA TRẬN HÀM

Các hàm Cryptoki cốt lõi được mô tả trước khi tích hợp.

Nhóm hàmHàm đại diệnBằng chứng phiên bản
InitializationC_GetFunctionList, C_Initialize, C_FinalizeABI/threading and lifecycle test
Slot/tokenC_GetSlotList, C_GetTokenInfo, C_WaitForSlotEventStable slot and token-removal behavior
Sessions/authenticationC_OpenSession, C_Login, C_Logout, C_CloseSessionRole, pooling, expiry and lockout tests
Object discoveryC_FindObjectsInit, C_FindObjects, C_GetAttributeValueVisibility and attribute profile
Key lifecycleC_GenerateKeyPair, C_DestroyObject, C_DeriveKeyMechanism, policy and zeroization result
SignatureC_SignInit, C_Sign, C_VerifyInit, C_VerifyMechanism, encoding and test vectors

LUỒNG THAM CHIẾU

Trình tự tích hợp theo phiên bản.

01

Nạp thư viện được phê duyệt

Khớp nền tảng, ABI, phiên bản header và checksum thư viện.

02

Nhận diện slot và token

Xác định định danh slot ổn định, token presence và hành vi HA.

03

Mở session và xác thực

Áp dụng session RO/RW, vai trò User/SO hoặc đăng nhập theo ngữ cảnh.

04

Tìm object được bảo vệ

Tìm khóa/chứng thư theo attribute và quy tắc hiển thị được phê duyệt.

05

Thực thi mechanism

Chạy ký, xác minh hoặc KEM có kiểm soát với tham số chính xác.

06

Đóng và ghi bằng chứng

Kết thúc session, ghi mã trả về, trạng thái object và audit backend.

BỘ TÀI LIỆU LẬP TRÌNH

Tài liệu được tách theo đúng câu hỏi mà đội tích hợp cần giải đáp.

FUN

Hỗ trợ hàm

Công bố ABI Cryptoki, tên shared library, phiên bản header, cờ khởi tạo và hành vi function table cần thiết để nạp provider an toàn.

Open function matrix →
MEC

Sổ đăng ký mechanism

Xác định mã mechanism chuẩn và theo profile nhà cung cấp, loại khóa, cấu trúc tham số, encoding và mức trưởng thành cho thao tác classical, PQC và hybrid.

Open mechanism matrix →
OBJ

Object và attribute

Đặc tả template khóa riêng, khóa công khai và chứng thư gồm liên kết CKA_ID, sensitivity, extractability, mutability, persistence và quy tắc hiển thị.

Open attribute profile →
AUT

Session và xác thực

Mô tả session RO/RW, đăng nhập User/SO/theo ngữ cảnh, pooling, timeout, đa luồng, đa tiến trình và vô hiệu handle khi token bị tháo hoặc failover.

Open auth model →
ERR

Mã trả về

Ánh xạ mã CKR tới nguyên nhân, khả năng retry, cách khắc phục, liên kết backend và audit mà không làm lộ PIN hoặc vật liệu khóa nhạy cảm.

Open error catalogue →
SDK

Mã mẫu C có thể biên dịch

Bao gồm mã C và CMake minh họa cho khởi tạo, nhận diện slot, đăng nhập, tìm object, ký, xác minh, dọn dẹp và kiểm thử đường lỗi.

View samples →

RANH GIỚI CÔNG BỐ

Giới hạn và ranh giới phiên bản

Các giới hạn này ngăn hồ sơ pilot bị hiểu thành tuyên bố hỗ trợ chung không có bằng chứng.

PILOT CÓ KIỂM SOÁT

Freeze library, header, mechanism list, backend and application before acceptance.

The acceptance report must include multi-process/session behavior, token removal, error paths, object persistence and exact mechanism identifiers.