Map
โ†‘Post-Quantum Cryptography

ML-KEM

Wiki conceptcryptographyquantum-computing โ†ณ show in map Markdown
title
ML-KEM
type
concept
summary
Module-Lattice KEM (FIPS 203, ex-Kyber): post-quantum key exchange replacing ECDH
tags
cryptography, quantum-computing
created
2026-04-07
updated
2026-04-07

Module-Lattice Key Encapsulation Mechanism (FIPS 203), formerly known as Kyber. The NIST-standardized post-quantum replacement for ECDH and RSA key exchange.

ML-KEM is a KEM (Key Encapsulation Mechanism), not a NIKE (Non-Interactive Key Exchange). The distinction matters: KEMs require a round trip (one party encapsulates a shared secret to the other's public key, the other decapsulates), while NIKEs let both parties derive a shared secret from each other's public keys without interaction. Protocols that depend on NIKEs (some messaging protocols) need architectural changes to use ML-KEM.

How it works

Based on the Module Learning With Errors (MLWE) problem. The sender generates a ciphertext that encapsulates a shared secret using the recipient's public key. The recipient decapsulates with their private key. An eavesdropper would need to solve MLWE โ€” finding a short vector in a noisy lattice โ€” which no known quantum algorithm can do efficiently.

Three security levels:

  • ML-KEM-512 โ€” roughly equivalent to AES-128 security
  • ML-KEM-768 โ€” roughly equivalent to AES-192 security (recommended default)
  • ML-KEM-1024 โ€” roughly equivalent to AES-256 security

Deployment status

Chrome and other browsers already ship ML-KEM in hybrid mode (X25519 + ML-KEM-768) for TLS 1.3 key exchange. Two years of deployment (starting as Kyber) has built significant confidence in the algorithm's correctness and the underlying math.

Per crqc-timeline, any non-PQ key exchange should now be treated as a potential active compromise vector.