Stable discovery contract
C_GetSlotList, token-presence behavior, slot labels, serial numbers, event handling and HA/failover rules are recorded per release.
BỘ NHÀ CUNG CẤP MẬT MÃ PQC TIN CẬY
Thư viện native theo phiên bản cung cấp slot, session, object, thao tác khóa và cơ chế ký/KEM được quản trị cho ứng dụng doanh nghiệp, đồng thời giữ thực thi khóa riêng trong token, HSM, QSCD hoặc ranh giới ký từ xa được phê duyệt.
MÔ HÌNH CRYPTOKI
The provider contract identifies the library filename, ABI, supported Cryptoki version, threading rules, slot stability, login scope, object attributes, mechanism identifiers and return-code behavior. Vendor-defined PQC or hybrid mechanisms are never implied to be portable across providers.
C_GetSlotList, token-presence behavior, slot labels, serial numbers, event handling and HA/failover rules are recorded per release.
RO/RW sessions, User/SO roles, context-specific authentication, session pooling, timeout and PIN lockout are documented.
CKO_PRIVATE_KEY, CKO_PUBLIC_KEY and CKO_CERTIFICATE templates define CKA_ID, CKA_LABEL, sensitivity, extractability and permitted operations.
Classical mechanisms and controlled ML-DSA/ML-KEM or hybrid vendor profiles are tied to exact headers, parameter structures and evidence.
MA TRẬN HÀM
| Nhóm hàm | Hàm đại diện | Bằng chứng phiên bản |
|---|---|---|
| Initialization | C_GetFunctionList, C_Initialize, C_Finalize | ABI/threading and lifecycle test |
| Slot/token | C_GetSlotList, C_GetTokenInfo, C_WaitForSlotEvent | Stable slot and token-removal behavior |
| Sessions/authentication | C_OpenSession, C_Login, C_Logout, C_CloseSession | Role, pooling, expiry and lockout tests |
| Object discovery | C_FindObjectsInit, C_FindObjects, C_GetAttributeValue | Visibility and attribute profile |
| Key lifecycle | C_GenerateKeyPair, C_DestroyObject, C_DeriveKey | Mechanism, policy and zeroization result |
| Signature | C_SignInit, C_Sign, C_VerifyInit, C_Verify | Mechanism, encoding and test vectors |
LUỒNG THAM CHIẾU
Khớp nền tảng, ABI, phiên bản header và checksum thư viện.
Xác định định danh slot ổn định, token presence và hành vi HA.
Áp dụng session RO/RW, vai trò User/SO hoặc đăng nhập theo ngữ cảnh.
Tìm khóa/chứng thư theo attribute và quy tắc hiển thị được phê duyệt.
Chạy ký, xác minh hoặc KEM có kiểm soát với tham số chính xác.
Kết thúc session, ghi mã trả về, trạng thái object và audit backend.
BỘ TÀI LIỆU LẬP TRÌNH
Công bố ABI Cryptoki, tên shared library, phiên bản header, cờ khởi tạo và hành vi function table cần thiết để nạp provider an toàn.
Open function matrix →Xác định mã mechanism chuẩn và theo profile nhà cung cấp, loại khóa, cấu trúc tham số, encoding và mức trưởng thành cho thao tác classical, PQC và hybrid.
Open mechanism matrix →Đặc tả template khóa riêng, khóa công khai và chứng thư gồm liên kết CKA_ID, sensitivity, extractability, mutability, persistence và quy tắc hiển thị.
Open attribute profile →Mô tả session RO/RW, đăng nhập User/SO/theo ngữ cảnh, pooling, timeout, đa luồng, đa tiến trình và vô hiệu handle khi token bị tháo hoặc failover.
Open auth model →Ánh xạ mã CKR tới nguyên nhân, khả năng retry, cách khắc phục, liên kết backend và audit mà không làm lộ PIN hoặc vật liệu khóa nhạy cảm.
Open error catalogue →Bao gồm mã C và CMake minh họa cho khởi tạo, nhận diện slot, đăng nhập, tìm object, ký, xác minh, dọn dẹp và kiểm thử đường lỗi.
View samples →RANH GIỚI CÔNG BỐ
Các giới hạn này ngăn hồ sơ pilot bị hiểu thành tuyên bố hỗ trợ chung không có bằng chứng.
PILOT CÓ KIỂM SOÁT
The acceptance report must include multi-process/session behavior, token removal, error paths, object persistence and exact mechanism identifiers.