QianHeng乾珩 PQC Docs Hub量子文档 ✦ Ask AI✦ 问问文档 ⚐ Scan⚐ 扫一扫

HSMs & Crypto Machines

Hardware security modules, cloud key-management services, and Chinese 密码机 (crypto machines) are where post-quantum keys actually live in production. Through 2025-2026 the major HSM vendors shipped native ML-KEM/ML-DSA/SLH-DSA firmware, the big clouds turned on PQC signing and hybrid TLS, and Chinese vendors fielded full anti-quantum 密码机 lines. This page snapshots confirmed products, the standards that bind them, and where validation is still pending.

Western HSMs

Vendor / productWhatDate
Thales Luna v7.9Native ML-KEM/ML-DSA/SLH-DSA; v7.9.1 enhancements; FIPS 140-3 L3 PQC in process2025-06; 2025-09
Entrust nShield 5 firmware v13.8PQC firmware, FPGA-accelerated; NIST CAVP for ML-DSA/ML-KEM/SLH-DSA; FIPS 140-3 CMVP pending2025-08; CAVP 2025-09
Utimaco "Quantum Protect" (u.trust GP HSM Se-Series)Field-activatable PQC app: ML-KEM/ML-DSA/LMS-HSS/XMSSLaunched 2025-04; CAVP 2025-10
Marvell LiquidSecurityCAVP for ML-KEM/ML-DSA/SLH-DSA; powers Azure Cloud HSM2025-2026
Securosys Primus CyberVaultPQC-ready2025-03
Crypto4A QxHSMML-KEM/ML-DSA/SLH-DSA, CAVP2025-2026

The pattern across Western HSMs is consistent: algorithm support arrived first via firmware, CAVP algorithm testing followed, and full FIPS 140-3 module validation is the slow last step. Thales Luna and Entrust nShield 5 added the full lattice + hash trio natively; Utimaco's "Quantum Protect" is notable for being field-activatable on existing Se-Series hardware, so deployed fleets can gain PQC without a hardware swap, including the stateful LMS-HSS/XMSS schemes. Marvell's LiquidSecurity is the engine behind Azure's Cloud HSM, blurring the line between on-prem HSM and cloud KMS below. A clear distinction matters: CAVP is algorithm-implementation validation, while CMVP / FIPS 140-3 is full cryptographic-module certification; a "CAVP" mark in the table means the algorithm implementation passed testing, not that the whole HSM has achieved FIPS 140-3 PQC module certification.

Cloud KMS

Vendor / productWhatDate
AWS KMSML-DSA signatures GA; ML-KEM hybrid TLS across KMS/ACM/Secrets Manager; CloudHSM ML-DSA previewGA 2025-06
Google Cloud KMSML-DSA-65 + SLH-DSA-128s for software keys, plus ML-KEM; Cloud HSM hardware PQC (roadmap)2025-02
MicrosoftSymCrypt ML-KEM/ML-DSA, GA on Windows; Azure Managed HSM PQC via vendors (tracking)GA 2025-11

The clouds split PQC into two tiers. Software keys get post-quantum signing and hybrid key exchange fastest — AWS made ML-DSA signatures generally available and rolled ML-KEM hybrid TLS through KMS, ACM, and Secrets Manager, while Google Cloud KMS offers ML-DSA-65 and SLH-DSA-128s for software-backed keys. Microsoft pushed PQC into the SymCrypt engine that underpins Windows. Hardware-backed cloud HSM PQC lags: AWS CloudHSM ML-DSA is in preview, Google Cloud HSM hardware PQC is on the roadmap, and Azure Managed HSM relies on the underlying vendor module (Marvell). Plan migrations around what is GA in your key-protection tier, not just the headline announcement.

Standards binding HSMs & KMS

OASIS PKCS#11 v3.2 (2025) standardizes ML-DSA, SLH-DSA, and ML-KEM mechanisms, giving applications a portable API instead of vendor-specific extensions — a quiet but important enabler for crypto-agility. On the compliance clock, US FIPS 140-2 certificates stop counting for federal procurement after 2026-09-21, which is pushing the FIPS 140-3 + PQC validation backlog noted above. Stateful hash signatures (LMS/XMSS) deserve special care: their security depends on never reusing a one-time key, so state must be managed inside the HSM and never duplicated across replicas or backups — see xmss-lms.html.

China: anti-quantum 密码机

Vendor / productWhatDate
三未信安 (Sansec)Full anti-quantum line — 抗量子密码机/密码卡/UKey/网关/CA/KMS supporting ML-KEM/ML-DSA/SLH-DSA + Falcon + domestic Aigis/LAC; 14.85M RMB anti-quantum R&D disclosed2024-09; R&D 2025-04
问天量子 + HUSTChip-level PQC card (PQC SoC + quantum-RNG)2025-07
openHiTLSOpen-sourced ML-KEM/ML-DSA/SLH-DSA2025-04
吉大正元 (Jit)元密一体机 — quantum-key + PQC integrated appliance2025-2026
信雅达 (Sunyard)PQC-for-finance "量子安全 + 商用密码"2025-10

Chinese 密码机 vendors pair internationally standardized PQC with domestic SM compatibility and frequently with QKD-supplied keys. Sansec fields the broadest anti-quantum line — crypto machines, cards, UKeys, gateways, CA, and KMS — and supports both NIST algorithms and domestic candidates (Aigis-enc/sig, LAC), with a disclosed 14.85M RMB R&D commitment. 问天量子's HUST chip-level card and the openHiTLS open-source project (offering ML-KEM/ML-DSA/SLH-DSA) broaden the supply chain, while Jit's 元密一体机 and Sunyard's finance-targeted "量子安全 + 商用密码" show PQC packaged for specific verticals. For the wider vendor and case-study picture, see cn-vendors.html; for the chips beneath these machines, see pqc-hardware.html.

One caveat on completeness: many other 国密 密码机 vendors — 江南天安, 渔翁, 卫士通, 格尔, 数字认证, 信安世纪 and others — are publicly pursuing PQC, but at this snapshot we could not confirm individually dated, shipping PQC products from each. Treat their PQC status as "in progress" rather than delivered until a dated product confirmation appears.

Standards & references

Note
Snapshot as of June 2026; vendor claims are their own; FIPS 140-3 hardware+PQC validations are largely still in process.

HSM 与密码机

硬件安全模块、云密钥管理服务以及国产密码机,才是后量子密钥在生产环境中真正存放的地方。2025 至 2026 年间,主流 HSM 厂商交付了原生支持 ML-KEM/ML-DSA/SLH-DSA 的固件,各大云开启了 PQC 签名与混合 TLS,国产厂商也推出了完整的抗量子密码机产品线。本页梳理已确认的产品、约束它们的标准,以及认证仍在进行中的环节。

西方 HSM

厂商 / 产品能力时间
Thales Luna v7.9原生 ML-KEM/ML-DSA/SLH-DSAv7.9.1 增强;FIPS 140-3 L3 PQC 认证进行中2025-06;2025-09
Entrust nShield 5 固件 v13.8PQC 固件,FPGA 加速;ML-DSA/ML-KEM/SLH-DSA 通过 NIST CAVP;FIPS 140-3 CMVP 待定2025-08;CAVP 2025-09
Utimaco "Quantum Protect"(u.trust GP HSM Se 系列)可现场激活的 PQC 应用:ML-KEM/ML-DSA/LMS-HSS/XMSS2025-04 发布;CAVP 2025-10
Marvell LiquidSecurityML-KEM/ML-DSA/SLH-DSA 通过 CAVP;为 Azure Cloud HSM 提供底层2025-2026
Securosys Primus CyberVaultPQC-ready2025-03
Crypto4A QxHSMML-KEM/ML-DSA/SLH-DSA,CAVP2025-2026

西方 HSM 的节奏高度一致:算法支持先通过固件到位,CAVP 算法测试随后跟进,完整的 FIPS 140-3 模块认证则是最慢的收尾环节。Thales Luna 与 Entrust nShield 5 原生加入了完整的格基 + 哈希三件套;Utimaco 的 "Quantum Protect" 尤为突出之处在于可在既有 Se 系列硬件上现场激活,让已部署的设备无需换机即可获得 PQC,包括有状态的 LMS-HSS/XMSS 方案。Marvell 的 LiquidSecurity 则是 Azure Cloud HSM 背后的引擎,模糊了本地 HSM 与下文云 KMS 的界线。需明确区分:CAVP 是算法实现验证,而 CMVP / FIPS 140-3 是完整密码模块认证;表中标注的"通过 CAVP"仅表示算法实现已通过测试,不等于 HSM 整机已通过 FIPS 140-3 PQC 模块认证。

云 KMS

厂商 / 产品能力时间
AWS KMSML-DSA 签名 GA;ML-KEM 混合 TLS 覆盖 KMS/ACM/Secrets Manager;CloudHSM ML-DSA 预览GA 2025-06
Google Cloud KMS软件密钥支持 ML-DSA-65 + SLH-DSA-128sML-KEM;Cloud HSM 硬件 PQC(规划)2025-02
MicrosoftSymCrypt ML-KEM/ML-DSA,在 Windows 上 GA;Azure Managed HSM 经由厂商提供 PQC(跟踪中)GA 2025-11

各大云把 PQC 分成两个层级。软件密钥最先获得后量子签名与混合密钥交换——AWS 将 ML-DSA 签名正式商用,并把 ML-KEM 混合 TLS 推向 KMS、ACM 与 Secrets Manager;Google Cloud KMS 为软件密钥提供 ML-DSA-65SLH-DSA-128s;微软则把 PQC 做进支撑 Windows 的 SymCrypt 引擎。硬件托管的云 HSM PQC 则相对滞后:AWS CloudHSM ML-DSA 仍在预览,Google Cloud HSM 硬件 PQC 仍在规划,Azure Managed HSM 依赖底层厂商模块(Marvell)。制定迁移计划时,应以你所在密钥保护层级中真正 GA 的能力为准,而非仅看头条公告。

约束 HSM 与 KMS 的标准

OASIS PKCS#11 v3.2(2025)标准化了 ML-DSASLH-DSAML-KEM 机制,让应用获得可移植 API 而非厂商私有扩展——这是推动密码敏捷性的一项低调却重要的使能。在合规时间线上,美国 FIPS 140-2 证书在 2026-09-21 之后不再计入联邦采购,这正在加剧上文提到的 FIPS 140-3 + PQC 认证积压。有状态哈希签名(LMS/XMSS)需要特别谨慎:其安全性依赖于一次性密钥绝不重用,因此状态必须在 HSM 内部管理,绝不能在副本或备份之间复制——参见 xmss-lms.html

中国抗量子密码机

厂商 / 产品能力时间
三未信安 (Sansec)完整抗量子产品线——抗量子密码机/密码卡/UKey/网关/CA/KMS,支持 ML-KEM/ML-DSA/SLH-DSA + Falcon + 国产 Aigis/LAC;披露抗量子研发投入 1485 万元2024-09;研发 2025-04
问天量子 + 华中科技大学芯片级 PQC 密码卡(PQC SoC + 量子随机数)2025-07
openHiTLS开源 ML-KEM/ML-DSA/SLH-DSA2025-04
吉大正元 (Jit)元密一体机——量子密钥 + PQC 一体机2025-2026
信雅达 (Sunyard)面向金融的 PQC "量子安全 + 商用密码"2025-10

国产密码机厂商普遍将国际标准化的 PQC 与国产 SM 兼容性结合,并常常配合 QKD 提供的密钥。三未信安拥有最广的抗量子产品线——密码机、密码卡、UKey、网关、CA 与 KMS——既支持 NIST 算法也支持国产候选(Aigis-enc/sig、LAC),并披露了 1485 万元的研发投入。问天量子与华中科技大学的芯片级密码卡,以及 openHiTLS 开源项目(提供 ML-KEM/ML-DSA/SLH-DSA)拓宽了供应链;吉大正元的元密一体机与信雅达面向金融的 "量子安全 + 商用密码" 则展示了 PQC 针对特定行业的打包形态。更完整的厂商与案例图景参见 cn-vendors.html;这些机器内部的芯片参见 pqc-hardware.html

关于完整性需要一点说明:还有许多其他国密密码机厂商——江南天安、渔翁、卫士通、格尔、数字认证、信安世纪等——都在公开推进 PQC,但在本次快照时点,我们无法逐一确认每家都有带明确时间、已发货的 PQC 产品。在出现带日期的产品确认之前,应把它们的 PQC 状态视为"进行中"而非"已交付"。

标准与参考

注意
本文为 2026 年 6 月的快照;厂商能力为其自行声明;FIPS 140-3 硬件加 PQC 的认证大多仍在进行中。
⚑ Report an error⚑ 纠错与校正