
Esempi di crittografia post-quantistica (PQC) per TLS 1.3 con Apache Camel, utilizzando lo scambio di chiavi ibrido X25519MLKEM768 su JDK 21 (BouncyCastle) e JDK 27 (nativo)
Questa repository contiene tre esempi che dimostrano gli handshake TLS 1.3 con crittografia post-quantistica (PQC) con Apache Camel, utilizzando lo scambio di chiavi ibrido X25519MLKEM768.
X25519MLKEM768 combina il classico X25519 Diffie-Hellman su curva ellittica con ML-KEM-768, un meccanismo di incapsulamento delle chiavi post-quantistico basato su reticoli (NIST FIPS 203). Entrambi gli algoritmi vengono eseguiti insieme, quindi la sicurezza è mantenuta anche se uno dei due viene compromesso.
| Example | JDK | TLS Provider | Approach |
|---|
pqc-ssl-context | JDK 27 | SunJSSE (JDK native) | JEP 527 aggiunge i named group PQC allo stack TLS integrato del JDK |
pqc-kem-jdk24 | JDK 24 | BouncyCastle JSSE 1.83 | BCJSSE per TLS PQC, il JDK dispone di primitive ML-KEM native tramite JEP 496 |
pqc-ssl-context-jdk21 | JDK 21 | BouncyCastle JSSE 1.83 | BCJSSE sostituisce SunJSSE per fornire supporto TLS PQC oggi |
Tutti e tre gli esempi sono configurati interamente tramite le proprietà camel.ssl.* ed eseguono un handshake TLS 1.3 autonomo usando X25519MLKEM768 per lo scambio di chiavi post-quantistico, verificato all'avvio e disponibile su richiesta tramite endpoint REST.
pqc-ssl-context)Utilizza il provider SunJSSE integrato nel JDK, che ottiene il supporto TLS PQC tramite JEP 527 in JDK 27.
camel.ssl.namedGroups=X25519MLKEM768,x25519camel.ssl.selfSigned=true)SSLParameters.setNamedGroups() (API JDK standard)pqc-kem-jdk24)Utilizza il provider JSSE di BouncyCastle (BCJSSE) per portare il supporto TLS PQC su JDK 24. Sebbene JDK 24 includa ML-KEM nativo come primitiva crittografica autonoma (JEP 496), non espone i named group PQC nel suo stack TLS. BCJSSE colma questa lacuna.
camel.ssl.provider=BCJSSE e camel.ssl.namedGroups=X25519MLKEM768,secp256r1camel.ssl.selfSigned=true)/api/verify-kem che dimostra l'API nativa javax.crypto.KEM di JDK 24 con test di interoperabilità tra providerpqc-ssl-context-jdk21)Utilizza il provider JSSE di BouncyCastle (BCJSSE) per portare il supporto TLS PQC su JDK 21, senza aspettare JDK 27.
camel.ssl.provider=BCJSSE e camel.ssl.namedGroups=X25519MLKEM768,secp256r1camel.ssl.selfSigned=true)ECDH da jdk.tls.disabledAlgorithms| Aspetto | JDK 27 nativo | JDK 24 + BouncyCastle | JDK 21 + BouncyCastle |
|---|---|---|---|
| Requisito JDK | JDK 27 EA | JDK 24+ | JDK 21+ |
| Provider TLS | SunJSSE | BCJSSE 1.83 | BCJSSE 1.83 |
| Meccanismo PQC | JEP 527 (integrato) | Libreria TLS BouncyCastle | Libreria TLS BouncyCastle |
| ML-KEM nativo (API KEM) | Sì | Sì (JEP 496) | No |
| Configurazione | Proprietà camel.ssl.* | Proprietà camel.ssl.* | Proprietà camel.ssl.* |
| Gestione certificati | camel.ssl.selfSigned=true | camel.ssl.selfSigned=true | camel.ssl.selfSigned=true |
| Porta REST | 8443 (HTTPS) | 8443 (HTTPS) | 8443 (HTTPS) |
| Dipendenze aggiuntive | Nessuna (JDK nativo) | bcprov, bctls | bcprov, bctls |
cd pqc-ssl-context
sdk use java 27.ea.11-open
mvn clean compile exec:exec
curl -k https://localhost:8443/api/verify-pqc
cd pqc-kem-jdk24
sdk use java 24.0.1-tem
mvn clean compile exec:exec
curl -k https://localhost:8443/api/verify-pqc
curl -k https://localhost:8443/api/verify-kem
cd pqc-ssl-context-jdk21
sdk use java 21.0.10-tem
mvn clean compile exec:exec
curl -k https://localhost:8443/api/verify-pqc
Tutti e tre restituiranno "pqcVerified": true quando l'handshake TLS PQC avrà successo.
| Versione JDK | API KEM ML-KEM | PQC in TLS | Approccio |
|---|---|---|---|
| 21 | No | Sì (tramite BouncyCastle) | pqc-ssl-context-jdk21 - BCJSSE fornisce supporto TLS PQC |
| 24 | Sì (JEP 496) | Sì (tramite BouncyCastle) | pqc-kem-jdk24 - BCJSSE per TLS, il JDK dispone di primitive ML-KEM native |
| 27 | Sì | Sì (nativo) | pqc-ssl-context - JEP 527 aggiunge PQC a SunJSSE |
Se riscontri un problema con Camel o hai qualche feedback, ti preghiamo di contattarci.
Apprezziamo anche i contributori, quindi coinvolgiti :-)
I Camel riders!