Skip to content

Add generic ML-DSA KeyFactory and Signature - #1667

Open
jasonkatonica wants to merge 2 commits into
IBM:mainfrom
jasonkatonica:katonica/issue1567/genericmldsa
Open

Add generic ML-DSA KeyFactory and Signature#1667
jasonkatonica wants to merge 2 commits into
IBM:mainfrom
jasonkatonica:katonica/issue1567/genericmldsa

Conversation

@jasonkatonica

@jasonkatonica jasonkatonica commented Jul 22, 2026

Copy link
Copy Markdown
Member

Register a family-level ML-DSA KeyFactory and Signature service so that callers can use the algorithm name ML-DSA without specifying a parameter set, matching the JEP 497 / JDK 24+ API contract.

  • Register PQCKeyFactory$MLDSA and PQCSignatureImpl$MLDSA as the ML-DSA service. Remove the ML-DSA alias from ML-DSA-65 (it was a
    mis-mapping that silently directed all generic lookups to ML-DSA-65).
  • Split the single name field into familyName (returned by getAlgorithm() such as ML-DSA) and paramSetName (the concrete parameter set such as ML-DSA-65). Add getters and setters for these values such that other code can act accordingly.
  • Add tests to BaseTestPQCKeyInterop. These tests cover all three ML-DSA parameter sets via @ParameterizedTest.
  • Add tests to BaseTestPQCKeys. Expand alias coverage to include case variants, OID aliases, and bare OID strings. Added tests for getAlgorithm() family-name correctness for all ML-DSA and ML-KEM aliases
  • Add tests to BaseTestPQCSignature for generic ML-DSA sign/verify tests to all three parameter sets.

Fixes: #1567

Signed-off-by: Jason Katonica katonica@us.ibm.com

Register a family-level `ML-DSA` `KeyFactory` and `Signature` service so
that callers can use the algorithm name `ML-DSA` without specifying a
parameter set, matching the JEP 497 / JDK 24+ API contract.

- Register `PQCKeyFactory$MLDSA` and `PQCSignatureImpl$MLDSA` as the
`ML-DSA` service. Remove the `ML-DSA` alias from `ML-DSA-65` (it was a
  mis-mapping that silently directed all generic lookups to ML-DSA-65).
- Split the single `name` field into `familyName` (returned by
`getAlgorithm()` such as `ML-DSA`) and `paramSetName` (the concrete
parameter set such as `ML-DSA-65`). Add getters and setters for these
values such that other code can act accordingly.
- Add tests to `BaseTestPQCKeyInterop`. These tests cover all three
`ML-DSA` parameter sets via `@ParameterizedTest`.
- Add tests to `BaseTestPQCKeys`. Expand alias coverage to include case
variants, OID aliases, and bare OID strings. Added tests for
`getAlgorithm()` family-name correctness for all ML-DSA and ML-KEM
aliases
- Add tests to `BaseTestPQCSignature` for generic `ML-DSA` sign/verify
tests to all three parameter sets.

Fixes: IBM#1567

Signed-off-by: Jason Katonica <katonica@us.ibm.com>
Comment thread src/main/java/com/ibm/crypto/plus/provider/MLKEMImpl.java Outdated
Comment thread src/main/java/com/ibm/crypto/plus/provider/MLKEMImpl.java Outdated
Comment thread src/main/java/com/ibm/crypto/plus/provider/MLKEMImpl.java Outdated
Comment thread src/main/java/com/ibm/crypto/plus/provider/MLKEMImpl.java Outdated

@JinhangZhang JinhangZhang left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support generic ML-DSA

3 participants