Skip to content

KEM support for EnvelopedCms - #133046

Merged
vcsjones merged 24 commits into
dotnet:mainfrom
vcsjones:ml-kem-enveloped-cms-managed
Sep 20, 2026
Merged

vcsjones merged 24 commits into
dotnet:mainfrom
vcsjones:ml-kem-enveloped-cms-managed

Conversation

@vcsjones

@vcsjones vcsjones commented Sep 1, 2026

Copy link
Copy Markdown
Member

This implements ML-KEM and Composite ML-KEM API surface for EnvelopedCms. For the managed implementation, this implements ML-KEM entirely per RFC 9936.

What is not in this PR

  1. Windows support. Windows is entirely incapable of even decoding a KEMRecipientInfo currently, let alone decrypting it. This will be follow up work as Windows' capabilities come up.
  2. Composite ML-KEM. The API shape is there but it is entirely PlatformNotSupportedExceptions for all implementations. This will be follow up work, but let's get the API shape in now.

There are still some open questions on Windows' implementation that may affect this pull request. At the moment it appears they only support SHA256 for the KDF, whereas the managed implementation landed on using SHA384.

vcsjones and others added 14 commits August 28, 2026 15:16
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

@bartonjs bartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Posting what I have so far since I have to step away for a few hours, or more.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The managed KEM KDF is non-conforming and the new public API surface lacks documented API approval.

Get a fresh assessment by requesting another Copilot review.

Review tier: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds managed ML-KEM support for EnvelopedCms, including KEM recipient APIs, ASN.1 handling, encryption/decryption, and test coverage. Composite ML-KEM APIs are exposed but unsupported.

Changes:

  • Adds KEM recipient models, OIDs, and public APIs.
  • Implements managed ML-KEM processing and platform-specific behavior.
  • Adds encryption, decryption, interoperability, and unsupported-platform tests.
File Summary
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​System.Security.Cryptography.Pkcs.Tests.csproj Includes KEM tests.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​Oids.cs Adds test OIDs.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​MLKemEncryptTests.cs Tests ML-KEM encryption and round trips.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​MLKemDecryptTests.cs Tests ML-KEM decryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​KemTestDocuments.cs Provides KEM test fixtures.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​KemNotSupportedTests.cs Tests unsupported-platform behavior.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​KemGeneralTests.cs Tests general KEM behavior.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​RecipientInfoType.cs Adds the KEM recipient type.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​RecipientInfo.cs Integrates KEM recipient handling.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​KemRecipientInfo.cs Adds public KEM recipient metadata.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​EnvelopedCms.Kem.cs Adds KEM decryption APIs.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​EnvelopedCms.cs Integrates KEM decryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​CmsRecipient.cs Adds KEM recipient factories.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​RecipientInfoAsn.xml.cs Generated recipient-choice model.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​RecipientInfoAsn.xml Defines the recipient choice.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​OtherRecipientInfoAsn.xml.cs Generated other-recipient model.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​OtherRecipientInfoAsn.xml Defines other-recipient ASN.1.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​KemRecipientInfoAsn.xml.cs Generated KEM recipient model.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​KemRecipientInfoAsn.xml Defines KEM recipient ASN.1.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​CmsOriForKemOtherInfoAsn.xml.cs Generated KEM metadata model.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​Asn1/​CmsOriForKemOtherInfoAsn.xml Defines KEM metadata ASN.1.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​NetStandardShims.cs Provides compatibility shims.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System.Security.Cryptography.Pkcs.csproj Includes KEM sources.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​PkcsHelpers.cs Adds KEM algorithm handling.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​Windows/​DecryptorPalWindows.Decrypt.cs Handles unsupported Windows KEM decryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.KeyTrans.cs Updates key transport integration.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.Kem.cs Implements managed KEM operations.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.Encrypt.cs Routes KEM encryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.Decrypt.cs Routes KEM decryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.Decode.cs Decodes KEM recipients.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​KemRecipientInfoPal.cs Adds the KEM PAL abstraction.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​EnvelopedCmsKey.cs Defines supported KEM decryption keys.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​DecryptorPal.cs Supports union-based private keys.
src/​libraries/​System.Security.Cryptography.Pkcs/​ref/​System.Security.Cryptography.Pkcs.cs Adds public KEM API declarations.
src/​libraries/​System.Private.CoreLib/​src/​System/​Runtime/​CompilerServices/​UnionAttribute.cs Adjusts union attribute visibility.
src/​libraries/​System.Private.CoreLib/​src/​System/​Runtime/​CompilerServices/​IUnion.cs Adjusts union interface visibility.
src/​libraries/​Common/​src/​System/​Security/​Cryptography/​Oids.cs Adds KEM-related OIDs.

@bartonjs bartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems to be down to some test nits. I'm happy with merging this to main (and opening the port to 11) and doing any followup in main alone.

@vcsjones
vcsjones merged commit 12921b1 into dotnet:main Sep 20, 2026
135 of 138 checks passed
@vcsjones

Copy link
Copy Markdown
Member Author

/backport to release/11.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/11.0 (link to workflow run)

@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Sep 21, 2026
artl93 pushed a commit that referenced this pull request Sep 21, 2026
Backport of #133046 to release/11.0

/cc @vcsjones

## Customer Impact

- [ ] Customer reported
- [X] Found internally

This is a post quantum algorithm addition to EnvelopedCms - ML-KEM.

## Regression

- [ ] Yes
- [X] No

## Testing

Existing tests ensure existing functionality continues to pass. New
tests were added for the new functionality.

## Risk

Low. New functionality and changes to existing functionality is minimal.

Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@bartonjs bartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Security cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants