Skip to main content
Glama

CipherHUB Cryptography Toolkit

hybrid_kex

[pqc_kem] 执行 X25519 + ML-KEM-768 混合密钥交换全流程演示。 【设计灵感】参考 IETF X-Wing 草案(draft-connolly-cfrg-xwing-kem)的思路,本工具实现的是通用拼接组合器(ecdh_ss || ml_kem_ss → HKDF-SHA256),并非 X-Wing 规范本身的组合器。 【参数】所有密钥参数均可选:

  • alice_x25519_private_key_pem / bob_x25519_private_key_pem:X25519 PEM 私钥

  • alice_ml_kem_public_key_base64 / bob_ml_kem_public_key_base64:ML-KEM-768 公钥,支持 raw 或 SPKI DER Base64

  • alice_ml_kem_secret_key_base64 / bob_ml_kem_secret_key_base64:ML-KEM-768 私钥,支持 raw 或 PKCS#8 DER Base64

  • ML-KEM 公钥和私钥必须同时提供;留空则服务端使用 CSPRNG 随机生成 raw keypair 【流程】

  1. Alice 和 Bob 各持有 X25519 + ML-KEM-768 密钥对

  2. Alice 用 Bob 公钥做 X25519 ECDH + ML-KEM Encap

  3. Bob 用自己私钥做 X25519 ECDH + ML-KEM Decap

  4. 双方将 ecdh_ss || ml_kem_ss 通过 HKDF-SHA256 派生 32 字节最终密钥 【输出】双方中间值 + 最终密钥 + keys_match(bool)验证一致性。 【安全等级】组合后达到 NIST Level 3(ML-KEM-768)+ Level 1(X25519),抵抗经典和量子攻击。

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bob_x25519_public_key_pemNo
bob_x25519_private_key_pemNoBob 侧 X25519 私钥的 PEM 文本
alice_x25519_public_key_pemNo
alice_x25519_private_key_pemNoAlice 侧 X25519 私钥的 PEM 文本
bob_ml_kem_public_key_base64NoBob 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)
bob_ml_kem_secret_key_base64NoBob 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)
alice_ml_kem_public_key_base64NoAlice 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)
alice_ml_kem_secret_key_base64NoAlice 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changed
    • addedInput schema / properties / alice_ml_kem_public_key_base64 / description
      Added value: +"Alice 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)"
    • addedInput schema / properties / alice_ml_kem_secret_key_base64 / description
      Added value: +"Alice 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)"
    • addedInput schema / properties / alice_x25519_private_key_pem / description
      Added value: +"Alice 侧 X25519 私钥的 PEM 文本"
    • addedInput schema / properties / bob_ml_kem_public_key_base64 / description
      Added value: +"Bob 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)"
    • addedInput schema / properties / bob_ml_kem_secret_key_base64 / description
      Added value: +"Bob 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)"
    • addedInput schema / properties / bob_x25519_private_key_pem / description
      Added value: +"Bob 侧 X25519 私钥的 PEM 文本"
  2. Changed1 schema field changed
    • changedInput schema / description
      Previous value: -"X25519 + ML-KEM-768 混合密钥交换请求。\n\n所有密钥字段均可选:\n- 若留空,服务端随机生成\n- 若传入,服务端使用传入的密钥对进行协商\n\nAlice 侧字段:\n- alice_x25519_private_key_pem: Alice X25519 私钥 (PEM)\n- alice_x25519_public_key_pem:  Alice X25519 公钥 (PEM)\n- alice_ml_kem_public_key_base64: Alice ML-KEM 公钥 (Base64)\n- alice_ml_kem_secret_key_base64: Alice ML-KEM 私钥 (Base64)\n\nBob 侧字段同理。"New value: +"X25519 + ML-KEM-768 混合密钥交换请求。\n\n所有密钥字段均可选:\n- 若留空,服务端随机生成\n- 若传入,服务端使用传入的密钥对进行协商\n\nAlice 侧字段:\n- alice_x25519_private_key_pem: Alice X25519 私钥 (PEM)\n- alice_x25519_public_key_pem:  Alice X25519 公钥 (PEM,仅展示/回填)\n- alice_ml_kem_public_key_base64: Alice ML-KEM 公钥 (raw 或 SPKI DER Base64)\n- alice_ml_kem_secret_key_base64: Alice ML-KEM 私钥 (raw 或 PKCS#8 DER Base64)\n\nBob 侧字段同理。若传入 ML-KEM key,公钥和私钥必须同时提供;响应保持 raw key Base64 以兼容演示流程。"
  3. First observed

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden, and it does so thoroughly: it discloses that blank keys are generated via CSPRNG, that ML-KEM public and private keys must be provided together, accepted encodings, the HKDF-SHA256 derivation flow, output including keys_match, and the claimed security level. It even warns that this is not the X-Wing combiner itself, preventing misuse.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured with clear sections: summary, design note, parameters, flow, output, and security level. It front-loads the purpose and keeps each section dense and relevant; the X-Wing caveat and security statement earn their place for a cryptographic demo tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex 8-parameter tool with no output schema, the description covers the flow, input optionality, key-format constraints, derivation process, and result verification through keys_match. It is slightly vague about exactly which 'intermediate values' are returned, but overall an agent has enough context to invoke the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The description adds meaning by organizing the eight parameters by Alice/Bob side, explaining raw vs SPKI/PKCS#8 Base64 formats, and emphasizing the paired public/private key requirement. Much of this is already present in the schema description, so the added value is mostly consolidation and clearer framing rather than entirely new semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states a specific verb and resource: '执行 X25519 + ML-KEM-768 混合密钥交换全流程演示'. It distinguishes itself from sibling single-algorithm tools like ml_kem_encap, ml_kem_decap, and ecc_key_exchange by describing a hybrid full-flow demo. It also clarifies that it implements a generic concatenation combiner rather than the X-Wing specification.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description strongly implies usage as a full hybrid key-exchange demo and explains the flow, but it never explicitly states when to prefer this tool over siblings such as ml_kem_encap/ml_kem_decap or ecc_key_exchange. It includes setup conditions, like 'all parameters optional' and 'keys generated randomly if blank', but lacks explicit when-to-use/when-not-to-use guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.