Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
kroxylicious-pqc-filter — A Kroxylicious filter plugin that provides transparent post-quantum (ML-KEM + AES-256-GCM) record-level encryption for Apache Kafka, requiring zero client code changes. | Kitploit
Tools/GitHubGitHub/oscerd/kroxylicious-pqc-filter
Cloud Infrastructure SecurityEncryption/Decryption ToolsCryptographyUtilities & Frameworks
GitHuboscerd/kroxylicious-pqc-filter

kroxylicious-pqc-filter

A Kroxylicious filter plugin that provides transparent post-quantum (ML-KEM + AES-256-GCM) record-level encryption for Apache Kafka, requiring zero client code changes.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
1144 months agoNot yet reviewed
Share

Kroxylicious PQC Record Encryption Filter

A Kroxylicious filter plugin that provides transparent Post-Quantum Cryptography (PQC) record-level encryption for Apache Kafka using ML-KEM (FIPS 203) key encapsulation with AES-256-GCM symmetric encryption.

Kafka producers and consumers require zero code changes. The Kroxylicious proxy intercepts traffic and encrypts on Produce / decrypts on Fetch automatically.

Producer ──plaintext──> Kroxylicious ──encrypted──> Kafka Broker
Consumer <──plaintext── Kroxylicious <──encrypted── Kafka Broker

Why PQC for Kafka?

Classical key establishment algorithms (RSA, ECDH) are vulnerable to future quantum computers. If per-record encryption keys are established using a classical KEM, a quantum adversary could recover those keys from the encapsulations stored alongside the ciphertext on the broker.

This plugin uses ML-KEM (FIPS 203) for quantum-resistant key encapsulation, ensuring that data at rest on the Kafka broker cannot be decrypted even by an adversary with a cryptographically relevant quantum computer.

Note: This filter protects data at rest on the broker, not the TLS channel in transit. See THREAT_MODEL.md for a full analysis of what is and is not defended against.

StandardAlgorithmPurpose in this plugin
FIPS 203ML-KEM (Kyber)Key encapsulation - securely establishes a per-message AES key
N/AAES-256-GCMSymmetric authenticated encryption of the record payload
N/AX25519 ECDHClassical key agreement for hybrid mode defense-in-depth

Features

  • Transparent encryption/decryption - no client-side changes required
  • ML-KEM-512, ML-KEM-768 (default), ML-KEM-1024 parameter sets
  • Hybrid mode (default) - combines ML-KEM + X25519 ECDH so both must be broken
  • Per-record encryption - each record gets a fresh KEM encapsulation + random IV
  • Topic filtering - regex patterns select which topics to encrypt
  • Tamper detection - AES-GCM authenticated encryption rejects modified ciphertext
  • Semantic security - identical plaintexts produce different ciphertexts (IND-CCA2)
  • Key auto-generation - generates and saves ML-KEM keys on first startup if absent
  • x-pqc-encrypted header - marks encrypted records for downstream awareness
  • Pluggable key providers - KeyProvider SPI supports filesystem (default) and HashiCorp Vault backends

Prerequisites

RequirementVersion
JDK17+ (21+ recommended)
Maven3.8+
Kroxylicious0.19.0
Apache Kafka3.9.x

Quick Start

1. Build the plugin

git clone <this-repo>
cd kroxylicious-pqc-filter
mvn clean package -DskipTests

The shaded JAR at target/kroxylicious-pqc-filter-1.0.0-SNAPSHOT.jar bundles Bouncy Castle so it can be dropped into Kroxylicious with no extra dependencies.

To include HashiCorp Vault key provider support, build with the vault profile:

mvn clean package -Pvault -DskipTests

This bundles spring-vault-core and the VaultKeyProvider into the JAR.

2. Generate ML-KEM keys

java -cp target/kroxylicious-pqc-filter-1.0.0-SNAPSHOT.jar \
  io.kroxylicious.filter.pqc.PqcKeyGeneratorCli \
  ML_KEM_768 \
  /etc/kroxylicious/pqc/

Output:

Generating ML-KEM-768 key pair...
Public key:  /etc/kroxylicious/pqc/pqc-public.der
  Size:      1206 bytes
  Format:    X.509
Private key: /etc/kroxylicious/pqc/pqc-private.der
  Size:      2498 bytes
  Format:    PKCS#8

Alternatively, omit the key paths in configuration and the filter will generate keys automatically on first startup.

3. Configure Kroxylicious

Add the filter to your Kroxylicious proxy YAML configuration:

filterDefinitions:
  - name: pqc-encryption
    type: PqcRecordEncryptionFilterFactory
    config:
      kemAlgorithm: ML_KEM_768
      hybridMode: true
      publicKeyPath: /etc/kroxylicious/pqc/pqc-public.der
      privateKeyPath: /etc/kroxylicious/pqc/pqc-private.der
      topicPatterns:
        - "sensitive-.*"
        - "pii-.*"

defaultFilters:
  - pqc-encryption

4. Deploy

Place the JAR in a directory accessible to Kroxylicious and add it to the classpath via the KROXYLICIOUS_CLASSPATH environment variable:

export KROXYLICIOUS_CLASSPATH="/opt/kroxylicious/plugins/*"

When using Docker, set it in your container environment:

environment:
  KROXYLICIOUS_CLASSPATH: /opt/kroxylicious/plugins/*

Then start the proxy. Producers and consumers connect to the proxy port instead of the broker directly.

Configuration Reference

PropertyTypeRequiredDefaultDescription
kemAlgorithmenumNoML_KEM_768ML-KEM parameter set. One of ML_KEM_512, ML_KEM_768, ML_KEM_1024.
hybridModebooleanNotrueCombine ML-KEM with X25519 ECDH for defense-in-depth.
publicKeyPathstringFilesystem only-Filesystem path to the ML-KEM public key (X.509 DER encoded).
privateKeyPathstringFilesystem only-Filesystem path to the ML-KEM private key (PKCS#8 DER encoded).
topicPatternslist<string>No[".*"]Java regex patterns. Only records in matching topics are encrypted/decrypted.
keyProviderTypestringNofilesystemKey storage backend. One of filesystem, vault.
keyProviderConfigmap<string, string>Vault only{}Backend-specific configuration (see Vault section below).

Key Providers

Filesystem (keyProviderType: filesystem, default): Loads ML-KEM keys from DER files on disk. If the files do not exist, generates a fresh key pair and saves them. Requires publicKeyPath and privateKeyPath.

HashiCorp Vault (keyProviderType: vault, requires -Pvault build): Fetches ML-KEM keys from a Vault KV v2 secrets engine. Keys are stored as base64-encoded DER in publicKey and privateKey fields. Vault secret versions map to key IDs for key rotation support.

Vault keyProviderConfig properties:

PropertyRequiredDefaultDescription
vaultAddressYesVAULT_ADDR envVault server URL (e.g., http://vault:8200)
vaultTokenFor token authVAULT_TOKEN envVault authentication token
secretPathYes--Path within the secrets engine (e.g., kroxylicious/pqc)
secretEngineNosecretKV v2 secrets engine mount name
authMethodNotokenAuth method: token, approle, or kubernetes
roleIdFor approle--AppRole role ID
secretIdFor approle--AppRole secret ID
kubeRoleFor kubernetes--Kubernetes auth role name
kubeTokenPathNo/var/run/secrets/.../tokenService account token file path

Example Vault configuration:

filterDefinitions:
  - name: pqc-encryption
    type: PqcRecordEncryptionFilterFactory
    config:
      kemAlgorithm: ML_KEM_768
      hybridMode: false
      keyProviderType: vault
      keyProviderConfig:
        vaultAddress: http://vault:8200
        vaultToken: my-token
        secretPath: kroxylicious/pqc
      topicPatterns:
        - "sensitive-.*"

ML-KEM Parameter Sets

AlgorithmSecurity LevelPublic KeyPrivate KeyCiphertext OverheadUse Case
ML-KEM-512128-bit822 B1,730 B~854 BLightweight, IoT
ML-KEM-768192-bit1,206 B2,498 B~1,174 BRecommended default
ML-KEM-1024256-bit1,590 B3,266 B~1,654 BClassified / long-lived data

Encryption Modes

Download Tool