Skip to main content
Applies to:
PKCS#11 (Cryptoki) 3.2DuoKey PKCS#11 Library

The library implements the single-part subset of Cryptoki needed to manage and use keys through the DuoKey Cockpit. Every slot in the function table is a valid pointer: implemented functions do the work, and the rest return a clear error (CKR_FUNCTION_NOT_SUPPORTED or CKR_FUNCTION_NOT_PARALLEL).

Implemented functions​

General purpose​

FunctionBehaviour
C_GetFunctionListReturns the function table (the only exported symbol).
C_InitializeLoads configuration, builds the proxy client, initializes global state.
C_FinalizeTears down global state.
C_GetInfoReports Cryptoki 3.2, library 0.1, manufacturer "DuoKey".

Slot & token management​

FunctionBehaviour
C_GetSlotListPresents exactly one virtual slot (slot_id from config).
C_GetSlotInfoStatic "DKE Cockpit Virtual HSM Slot", flags CKF_TOKEN_PRESENT | CKF_HW_SLOT.
C_GetTokenInfoToken flags and metadata (best-effort from the proxy, with an offline fallback).
C_GetMechanismListReturns the advertised mechanism list (see below).
C_GetMechanismInfoKey-size range and flags per mechanism; OR-s CKF_HW into the flags.

Session management​

FunctionBehaviour
C_OpenSessionSerial sessions only; parallel rejected with CKR_SESSION_PARALLEL_NOT_SUPPORTED.
C_CloseSessionCloses a session.
C_CloseAllSessionsCloses all sessions for the slot.
C_GetSessionInfoDerives the RO/RW × public/user state.
C_LoginMoves the session to the user state. No PIN is transmitted; only CKU_USER / CKU_CONTEXT_SPECIFIC are accepted.
C_LogoutClears the logged-in flag.

Object management​

FunctionBehaviour
C_FindObjectsInit / C_FindObjects / C_FindObjectsFinalQueries the Cockpit with the template filter, interns and pages the results.
C_GetAttributeValueAnswers attributes from the cached descriptor (buffer-length protocol supported).
C_DestroyObjectDeletes the object at the Cockpit and forgets the handle.

Encryption & decryption (single-part)​

FunctionBehaviour
C_EncryptInit / C_EncryptSingle-part encrypt; for AES-GCM the tag is appended to the ciphertext.
C_DecryptInit / C_DecryptSingle-part decrypt.

Signing, verification & digest (single-part)​

FunctionBehaviour
C_SignInit / C_SignSingle-part sign.
C_VerifyInit / C_VerifySingle-part verify; CKR_SIGNATURE_INVALID when the backend reports invalid.
C_DigestInit / C_DigestKeyless single-part digest (computed at the Cockpit).

Key management​

FunctionBehaviour
C_GenerateKeyGenerates a symmetric key (requires login).
C_GenerateKeyPairGenerates an asymmetric key pair (requires login).
C_WrapKeyWraps a key under a wrapping key.
C_UnwrapKeyUnwraps a blob into a new key object.

Random​

FunctionBehaviour
C_GenerateRandomRequests N random bytes from the backend.
C_SeedRandomAccepted and ignored — the backend RNG cannot be seeded by the client.

Not supported​

Return CKR_FUNCTION_NOT_SUPPORTED
  • Token / PIN administration — C_InitToken, C_InitPIN, C_SetPIN
  • Operation state — C_GetOperationState, C_SetOperationState
  • Object create / copy / size / set-attribute — C_CreateObject, C_CopyObject, C_GetObjectSize, C_SetAttributeValue
  • Multi-part encrypt / decrypt — C_EncryptUpdate, C_EncryptFinal, C_DecryptUpdate, C_DecryptFinal
  • Multi-part digest — C_DigestUpdate, C_DigestKey, C_DigestFinal
  • Multi-part / recover sign & verify — C_SignUpdate, C_SignFinal, C_SignRecoverInit, C_SignRecover, C_VerifyUpdate, C_VerifyFinal, C_VerifyRecoverInit, C_VerifyRecover
  • Dual-function — C_DigestEncryptUpdate, C_DecryptDigestUpdate, C_SignEncryptUpdate, C_DecryptVerifyUpdate
  • Key derivation — C_DeriveKey
  • Slot events — C_WaitForSlotEvent
Return CKR_FUNCTION_NOT_PARALLEL

C_GetFunctionStatus, C_CancelFunction (legacy parallel-function management).

These operations are not used by the supported key workflows, which are single-part by construction.

Mechanisms​

C_GetMechanismList advertises the mechanisms below. C_GetMechanismInfo returns the key-size range and flags and also sets CKF_HW. Key-size units follow the mechanism: AES in bytes, RSA/EC in bits.

MechanismMinMaxOperations
CKM_AES_KEY_GEN1632generate
CKM_AES_CBC, CKM_AES_CBC_PAD1632encrypt, decrypt, wrap, unwrap
CKM_AES_GCM1632encrypt, decrypt
CKM_AES_KEY_WRAP, CKM_AES_KEY_WRAP_PAD1632wrap, unwrap
CKM_GENERIC_SECRET_KEY_GEN1512generate
CKM_RSA_PKCS_KEY_PAIR_GEN20484096generate key pair
CKM_RSA_PKCS20484096encrypt, decrypt, sign, verify, wrap, unwrap
CKM_RSA_PKCS_OAEP20484096encrypt, decrypt, wrap, unwrap
CKM_RSA_PKCS_PSS, CKM_SHA256_RSA_PKCS, CKM_SHA384_RSA_PKCS, CKM_SHA512_RSA_PKCS20484096sign, verify
CKM_EC_KEY_PAIR_GEN256521generate key pair
CKM_ECDSA, CKM_ECDSA_SHA256, CKM_ECDSA_SHA384256521sign, verify
CKM_SHA_1, CKM_SHA256, CKM_SHA384, CKM_SHA512——digest
CKM_SHA256_HMAC, CKM_SHA384_HMAC, CKM_SHA512_HMAC1512sign, verify
CKM_ML_DSA_KEY_PAIR_GEN, CKM_SLH_DSA_KEY_PAIR_GEN, CKM_ML_KEM_KEY_PAIR_GEN——generate key pair
CKM_ML_DSA, CKM_SLH_DSA——sign, verify
Post-quantum

The concrete parameter set (e.g. ML-DSA-65, SLH-DSA-128s) is selected per key via CKA_PARAMETER_SET, not a bit-length key size, so these mechanisms report no min/max key size. CKM_ML_KEM_KEY_PAIR_GEN generates a key pair only — the v3.2 encapsulation mechanism itself is not yet advertised.

Digest mechanisms

Digest is computed at the Cockpit and currently supports SHA-256 / 384 / 512. CKM_SHA_1 is advertised but a SHA-1 digest is rejected by the backend (CKR_MECHANISM_INVALID).

Objects & attributes​

Object classes: CKO_DATA, CKO_CERTIFICATE, CKO_PUBLIC_KEY, CKO_PRIVATE_KEY, CKO_SECRET_KEY, CKO_DOMAIN_PARAMETERS.

Key types: CKK_AES, CKK_RSA, CKK_EC, CKK_GENERIC_SECRET, CKK_DSA, CKK_DH, CKK_SHA256_HMAC, CKK_SHA384_HMAC, CKK_SHA512_HMAC, CKK_ML_DSA, CKK_SLH_DSA, CKK_ML_KEM.

C_GetAttributeValue returns, from the cached descriptor: CKA_CLASS, CKA_KEY_TYPE, CKA_LABEL, CKA_ID, CKA_VALUE_LEN, CKA_MODULUS, CKA_PUBLIC_EXPONENT, CKA_MODULUS_BITS, CKA_EC_PARAMS, CKA_EC_POINT, and the boolean capability flags (CKA_TOKEN, CKA_PRIVATE, CKA_SENSITIVE, CKA_EXTRACTABLE, CKA_ENCRYPT, CKA_DECRYPT, CKA_WRAP, CKA_UNWRAP, CKA_SIGN, CKA_VERIFY, CKA_DERIVE, …).

CKA_VALUE is sensitive

CKA_VALUE always returns CKR_ATTRIBUTE_SENSITIVE — raw key material lives only in the backend and never crosses the PKCS#11 boundary. Keys report CKA_EXTRACTABLE = false, CKA_SENSITIVE = true, CKA_NEVER_EXTRACTABLE = true. Any unrecognized attribute type returns CKR_ATTRIBUTE_TYPE_INVALID.