Cryptsetup development
 help / color / mirror / Atom feed
* [feature] PQC KEM
@ 2026-06-29 16:27 cyper
  2026-06-29 16:42 ` Milan Broz
  0 siblings, 1 reply; 5+ messages in thread
From: cyper @ 2026-06-29 16:27 UTC (permalink / raw)
  To: Cryptsetup

Interested in introducing a new LUKS2 "xwing" keyslot type unlocked by an X-Wing
post-quantum hybrid KEM (ML-KEM-768 + X25519, draft-connolly-cfrg-xwing-kem)
instead of a passphrase to encrypt the kek (volume key)?

1) asymmetric model won't shine in single user case but will be attractive in multiple user/image enrollment cases.
2) if per-device fresh wrapping key is desired


I've implemented such keyslot type and tested.  But don't know if the aforementioned two cases is worth discussion.

Kind regards,
Alan

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-06-30 13:51 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-29 16:27 [feature] PQC KEM cyper
2026-06-29 16:42 ` Milan Broz
2026-06-29 17:50   ` cyper
2026-06-29 18:40   ` Arno Wagner
2026-06-30 13:51     ` cyper

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox