Handshake Simulator
Walk a QVTP/1 tunnel establishment message by message. The client offers an ephemeral ML-KEM-1024 key, the server encapsulates a shared secret against it, and both sides prove identity with ML-DSA-87 before any record is encrypted. The ephemeral key is destroyed once the session keys are derived.
Target
Demonstration only. No packet is sent to the named host and no key material is
generated. The session ID is derived from the target so a given host always
demonstrates the same session.
ESTABLISHED
- Session ID
- Tenant
- Protocol
- Cipher Suite
- Key Encapsulation
- Authentication
- Record Encryption
- Key Derivation
✓
Forward secrecy confirmed
Ephemeral ML-KEM-1024 key discarded after key derivation.
✓
HNDL protection confirmed
A captured transcript stays closed to a future quantum adversary.
✓
Mutual authentication
Both endpoints proved identity with ML-DSA-87 signatures.