Hi In the case we move forward with pkcs11-kdf-ecdh as proposed by Mike, then pkcs11-ckm-ecdh-aes-key-wrap proposal would need to be updated to avoid usage of CKM_ECDH1_DERIVE . Attached is an update to the pkcs11-ckm-ecdh-aes-key-wrap document to illustrate how it may look like, in such a case. However, I am not updating the ecdh proposal yet, until a decision is made on the pkcs11-kdf-ecdh . Doron