[release/11.0] Add Composite ML-KEM Windows implementation - #134165
Conversation
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
|
Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security |
bartonjs
left a comment
There was a problem hiding this comment.
Confirmed via patch-diffing that this is the same as 6bc923c (except for line numbers in System.Security.Cryptography.csproj, which only suggests some other edit to that file hasn't been ported to 11... or my direction's wrong, and the other edit got ported first)
bcc556a to
6486609
Compare
main PR: #132440 # Description Add the experimental Composite ML-KEM base APIs, algorithm identifiers, and key import/export support. Straight backport; no additional code changes. Stack layer 2/4, based on #134162, targeting RC2. # Customer Impact Provides the new hybrid PQC API surface. Requires the implementation layers #134164 and #134165. # Regression No. New APIs. # Testing Includes the original contract and import/export tests. Cherry-pick equivalence verified; no local builds or tests run for this layer. # Risk Low. Adds new experimental APIs without changing existing API behavior. Ships together with the implementation layers. > [!NOTE] > This PR description was generated with GitHub Copilot. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30 Copilot-Session: 17bb5da2-badb-480f-a196-71dc1e23dc7b
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The added public CNG members need API approval or removal before shipping.
Review effort: Lite
Findings: None
What changed in this PR
Adds Windows BCrypt/NCrypt support for Composite ML-KEM, including CNG APIs, key-blob handling, implementation wiring, and provider tests.
Changes:
- Implements BCrypt and NCrypt Composite ML-KEM operations.
- Adds CNG identifiers, blob helpers, and public CNG support.
- Adds Windows-specific tests and project wiring.
| File | Summary |
|---|---|
src/libraries/System.Security.Cryptography/tests/System.Security.Cryptography.Tests.csproj |
Registers Composite ML-KEM CNG tests. |
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/CngKeyBlobFormat.cs |
Adds Composite ML-KEM blob formats. |
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/CngAlgorithmGroup.cs |
Adds the Composite ML-KEM algorithm group. |
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/CngAlgorithm.cs |
Adds the Composite ML-KEM algorithm identifier. |
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/Cng.NotSupported.cs |
Adds non-Windows stubs. |
src/libraries/System.Security.Cryptography/src/System.Security.Cryptography.csproj |
Wires implementation sources. |
src/libraries/System.Security.Cryptography/src/Resources/Strings.resx |
Adds CNG validation text. |
src/libraries/System.Security.Cryptography/ref/System.Security.Cryptography.cs |
Adds public CNG API entries; API approval/update is required. |
src/libraries/Microsoft.Bcl.Cryptography/tests/Microsoft.Bcl.Cryptography.Tests.csproj |
Registers shared CNG tests. |
src/libraries/Microsoft.Bcl.Cryptography/src/System/Security/Cryptography/CngIdentifierExtensions.cs |
Adds compatibility CNG identifiers. |
src/libraries/Microsoft.Bcl.Cryptography/src/Resources/Strings.resx |
Adds matching validation text. |
src/libraries/Microsoft.Bcl.Cryptography/src/Microsoft.Bcl.Cryptography.Forwards.cs |
Adds type forwarding. |
src/libraries/Microsoft.Bcl.Cryptography/src/Microsoft.Bcl.Cryptography.csproj |
Wires BCL implementation sources. |
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.Windows.cs |
Adjusts Windows registry detection. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemTestsBase.cs |
Adapts shared tests for provider-specific behavior. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemTestHelpers.cs |
Adds BCrypt support detection. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemTestHelpers.Cng.cs |
Adds CNG key-generation and import helpers. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemImplementationTests.cs |
Updates implementation gating and assertions. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemFactoryTests.cs |
Updates Windows support expectations. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemCngTests.Windows.cs |
Adds Windows CNG behavior tests. |
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemCngTests.cs |
Adds cross-platform constructor validation. |
src/libraries/Common/src/System/Security/Cryptography/PqcBlobHelpers.CompositeMLKem.cs |
Adds Composite ML-KEM blob encoding and decoding. |
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemImplementation.Windows.cs |
Implements BCrypt operations. |
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemCng.Windows.cs |
Implements NCrypt-backed CNG operations. |
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemCng.cs |
Defines the public CNG implementation. |
src/libraries/Common/src/Interop/Windows/BCrypt/Interop.Blobs.cs |
Adds native blob structures and constants. |
src/libraries/Common/src/Interop/Windows/BCrypt/Cng.cs |
Adds the BCrypt algorithm name. |
6486609 to
c460c3e
Compare
|
/ba-g #133311 |
Add BCrypt and NCrypt support for the Windows provider, the approved CNG surface, native blob handling, and Windows provider tests. Contributes to #129633 Fixes #132680 --------- Copilot-Session: 67901feb-14f5-4029-bedd-84864cf3ea53 Copilot-Session: 11ffe761-e9d2-47c2-ace0-857272c52b10 (cherry picked from commit 6bc923c) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
c460c3e to
ca5fe5b
Compare
main PR: #132687
Description
Add Windows Composite ML-KEM support, including BCrypt/NCrypt integration,
CNG APIs, and key-blob handling. Straight backport; no additional code
changes. Stack layer 4/4, based on #134164, targeting RC2.
Customer Impact
Enables the new hybrid PQC APIs on Windows systems with supporting
cryptographic providers.
Regression
No. New APIs and platform implementation.
Testing
Includes the original Windows provider, CNG, and key-blob tests.
Cherry-pick equivalence verified; no local builds or tests run for
this layer.
Risk
Low. Adds support for new experimental APIs without changing existing
cryptographic API behavior.
Note
This PR description was generated with GitHub Copilot.