Skip to content

Add generic ML-DSA KeyFactory and Signature - #1763

Open
jasonkatonica wants to merge 2 commits into
IBM:java17from
jasonkatonica:katonica/issue1567/genericmldsa-java17
Open

Add generic ML-DSA KeyFactory and Signature#1763
jasonkatonica wants to merge 2 commits into
IBM:java17from
jasonkatonica:katonica/issue1567/genericmldsa-java17

Conversation

@jasonkatonica

Copy link
Copy Markdown
Member

Register a family-level ML-DSA KeyFactory and Signature service so
that callers can use the algorithm name ML-DSA without specifying a
parameter set, matching the JEP 497 / JDK 24+ API contract.

  • Register PQCKeyFactory$MLDSA and PQCSignatureImpl$MLDSA as the
    ML-DSA service. Remove the ML-DSA alias from ML-DSA-65 (it was a
    mis-mapping that silently directed all generic lookups to ML-DSA-65).
  • Split the single name field into familyName (returned by
    getAlgorithm() such as ML-DSA) and paramSetName (the concrete
    parameter set such as ML-DSA-65). Add getters and setters for these
    values such that other code can act accordingly.
  • Add tests to BaseTestPQCKeyInterop. These tests cover all three
    ML-DSA parameter sets via @ParameterizedTest.
  • Add tests to BaseTestPQCKeys. Expand alias coverage to include case
    variants, OID aliases, and bare OID strings. Added tests for
    getAlgorithm() family-name correctness for all ML-DSA and ML-KEM
    aliases
  • Add tests to BaseTestPQCSignature for generic ML-DSA sign/verify
    tests to all three parameter sets.

Fixes: #1567

Back-ported from: #1667

Signed-off-by: Jason Katonica katonica@us.ibm.com

Register a family-level `ML-DSA` `KeyFactory` and `Signature` service so
that callers can use the algorithm name `ML-DSA` without specifying a
parameter set, matching the JEP 497 / JDK 24+ API contract.

- Register `PQCKeyFactory$MLDSA` and `PQCSignatureImpl$MLDSA` as the
`ML-DSA` service. Remove the `ML-DSA` alias from `ML-DSA-65` (it was a
  mis-mapping that silently directed all generic lookups to ML-DSA-65).
- Split the single `name` field into `familyName` (returned by
`getAlgorithm()` such as `ML-DSA`) and `paramSetName` (the concrete
parameter set such as `ML-DSA-65`). Add getters and setters for these
values such that other code can act accordingly.
- Add tests to `BaseTestPQCKeyInterop`. These tests cover all three
`ML-DSA` parameter sets via `@ParameterizedTest`.
- Add tests to `BaseTestPQCKeys`. Expand alias coverage to include case
variants, OID aliases, and bare OID strings. Added tests for
`getAlgorithm()` family-name correctness for all ML-DSA and ML-KEM
aliases
- Add tests to `BaseTestPQCSignature` for generic `ML-DSA` sign/verify
tests to all three parameter sets.

Fixes: IBM#1567

Back-ported from: IBM#1667

Signed-off-by: Jason Katonica <katonica@us.ibm.com>
@jasonkatonica
jasonkatonica force-pushed the katonica/issue1567/genericmldsa-java17 branch from 616151e to 214a9e2 Compare September 9, 2026 20:29
Signed-off-by: Jason Katonica <katonica@us.ibm.com>
@jasonkatonica
jasonkatonica force-pushed the katonica/issue1567/genericmldsa-java17 branch from 214a9e2 to a9ec3f7 Compare September 9, 2026 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant