Skip to content

[release/11.0] Add Composite ML-KEM Windows implementation - #134165

Merged
artl93 merged 1 commit into
release/11.0from
ps-rc2-pqc-4-windows-ml-kem
Sep 20, 2026
Merged

artl93 merged 1 commit into
release/11.0from
ps-rc2-pqc-4-windows-ml-kem

Conversation

@PranavSenthilnathan

@PranavSenthilnathan PranavSenthilnathan commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

main PR: #132687

Description

Add Windows Composite ML-KEM support, including BCrypt/NCrypt integration,
CNG APIs, and key-blob handling. Straight backport; no additional code
changes. Stack layer 4/4, based on #134164, targeting RC2.

Customer Impact

Enables the new hybrid PQC APIs on Windows systems with supporting
cryptographic providers.

Regression

No. New APIs and platform implementation.

Testing

Includes the original Windows provider, CNG, and key-blob tests.
Cherry-pick equivalence verified; no local builds or tests run for
this layer.

Risk

Low. Adds support for new experimental APIs without changing existing
cryptographic API behavior.

Note

This PR description was generated with GitHub Copilot.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

@bartonjs bartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed via patch-diffing that this is the same as 6bc923c (except for line numbers in System.Security.Cryptography.csproj, which only suggests some other edit to that file hasn't been ported to 11... or my direction's wrong, and the other edit got ported first)

@PranavSenthilnathan

Copy link
Copy Markdown
Member Author

/ba-g #124079 and #133311

@PranavSenthilnathan PranavSenthilnathan added the Servicing-consider Issue for next servicing release review label Sep 19, 2026

@artl93 artl93 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New PQC. Approved.

@artl93 artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 19, 2026
@artl93
artl93 self-requested a review September 19, 2026 04:06

@artl93 artl93 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still approved.

Copilot AI lite review requested due to automatic review settings September 19, 2026 04:24
@artl93
artl93 force-pushed the ps-rc2-pqc-4-windows-ml-kem branch from bcc556a to 6486609 Compare September 19, 2026 04:24
artl93 pushed a commit that referenced this pull request Sep 19, 2026
main PR: #132440

# Description

Add the experimental Composite ML-KEM base APIs, algorithm identifiers,
and key import/export support. Straight backport; no additional code
changes. Stack layer 2/4, based on #134162, targeting RC2.

# Customer Impact

Provides the new hybrid PQC API surface. Requires the implementation
layers #134164 and #134165.

# Regression

No. New APIs.

# Testing

Includes the original contract and import/export tests. Cherry-pick
equivalence verified; no local builds or tests run for this layer.

# Risk

Low. Adds new experimental APIs without changing existing API behavior.
Ships together with the implementation layers.

> [!NOTE]
> This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
Copilot-Session: 17bb5da2-badb-480f-a196-71dc1e23dc7b

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The added public CNG members need API approval or removal before shipping.

Review effort: Lite
Findings: None

What changed in this PR

Adds Windows BCrypt/NCrypt support for Composite ML-KEM, including CNG APIs, key-blob handling, implementation wiring, and provider tests.

Changes:

  • Implements BCrypt and NCrypt Composite ML-KEM operations.
  • Adds CNG identifiers, blob helpers, and public CNG support.
  • Adds Windows-specific tests and project wiring.
File Summary
src/​libraries/​System.Security.Cryptography/​tests/​System.Security.Cryptography.Tests.csproj Registers Composite ML-KEM CNG tests.
src/​libraries/​System.Security.Cryptography/​src/​System/​Security/​Cryptography/​CngKeyBlobFormat.cs Adds Composite ML-KEM blob formats.
src/​libraries/​System.Security.Cryptography/​src/​System/​Security/​Cryptography/​CngAlgorithmGroup.cs Adds the Composite ML-KEM algorithm group.
src/​libraries/​System.Security.Cryptography/​src/​System/​Security/​Cryptography/​CngAlgorithm.cs Adds the Composite ML-KEM algorithm identifier.
src/​libraries/​System.Security.Cryptography/​src/​System/​Security/​Cryptography/​Cng.NotSupported.cs Adds non-Windows stubs.
src/​libraries/​System.Security.Cryptography/​src/​System.Security.Cryptography.csproj Wires implementation sources.
src/​libraries/​System.Security.Cryptography/​src/​Resources/​Strings.resx Adds CNG validation text.
src/​libraries/​System.Security.Cryptography/​ref/​System.Security.Cryptography.cs Adds public CNG API entries; API approval/update is required.
src/​libraries/​Microsoft.Bcl.Cryptography/​tests/​Microsoft.Bcl.Cryptography.Tests.csproj Registers shared CNG tests.
src/​libraries/​Microsoft.Bcl.Cryptography/​src/​System/​Security/​Cryptography/​CngIdentifierExtensions.cs Adds compatibility CNG identifiers.
src/​libraries/​Microsoft.Bcl.Cryptography/​src/​Resources/​Strings.resx Adds matching validation text.
src/​libraries/​Microsoft.Bcl.Cryptography/​src/​Microsoft.Bcl.Cryptography.Forwards.cs Adds type forwarding.
src/​libraries/​Microsoft.Bcl.Cryptography/​src/​Microsoft.Bcl.Cryptography.csproj Wires BCL implementation sources.
src/​libraries/​Common/​tests/​TestUtilities/​System/​PlatformDetection.Windows.cs Adjusts Windows registry detection.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemTestsBase.cs Adapts shared tests for provider-specific behavior.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemTestHelpers.cs Adds BCrypt support detection.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemTestHelpers.Cng.cs Adds CNG key-generation and import helpers.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemImplementationTests.cs Updates implementation gating and assertions.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemFactoryTests.cs Updates Windows support expectations.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemCngTests.Windows.cs Adds Windows CNG behavior tests.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemCngTests.cs Adds cross-platform constructor validation.
src/​libraries/​Common/​src/​System/​Security/​Cryptography/​PqcBlobHelpers.CompositeMLKem.cs Adds Composite ML-KEM blob encoding and decoding.
src/​libraries/​Common/​src/​System/​Security/​Cryptography/​CompositeMLKemImplementation.Windows.cs Implements BCrypt operations.
src/​libraries/​Common/​src/​System/​Security/​Cryptography/​CompositeMLKemCng.Windows.cs Implements NCrypt-backed CNG operations.
src/​libraries/​Common/​src/​System/​Security/​Cryptography/​CompositeMLKemCng.cs Defines the public CNG implementation.
src/​libraries/​Common/​src/​Interop/​Windows/​BCrypt/​Interop.Blobs.cs Adds native blob structures and constants.
src/​libraries/​Common/​src/​Interop/​Windows/​BCrypt/​Cng.cs Adds the BCrypt algorithm name.

@PranavSenthilnathan
PranavSenthilnathan force-pushed the ps-rc2-pqc-4-windows-ml-kem branch from 6486609 to c460c3e Compare September 19, 2026 05:13

@artl93 artl93 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still approved.

@PranavSenthilnathan

Copy link
Copy Markdown
Member Author

/ba-g #133311

Base automatically changed from ps-rc2-pqc-3-managed-ml-kem to release/11.0 September 20, 2026 04:04
Add BCrypt and NCrypt support for the Windows provider, the approved CNG
surface, native blob handling, and Windows provider tests.

Contributes to #129633
Fixes #132680

---------

Copilot-Session: 67901feb-14f5-4029-bedd-84864cf3ea53
Copilot-Session: 11ffe761-e9d2-47c2-ace0-857272c52b10
(cherry picked from commit 6bc923c)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Security Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants