What is ML-KEM?

ML-KEM is the US standard for post-quantum key exchange. Published by NIST in August 2024 as FIPS 203, it lets two parties agree on a shared secret key over an open network in a way that is designed to resist quantum computers. It replaces RSA encryption and elliptic-curve key exchange (ECDH) for that job.

What does "ML-KEM" stand for?

Module-Lattice-based Key-Encapsulation Mechanism. It is the standardised version of CRYSTALS-Kyber, which won NIST's post-quantum competition for key establishment. Its security rests on a lattice problem (Module Learning With Errors) that neither ordinary nor quantum computers are known to solve efficiently.

How does a key-encapsulation mechanism work?

Instead of both sides contributing to a key, as in Diffie-Hellman, one side publishes an encapsulation (public) key. The other side uses it to produce two things: a random shared secret, and a ciphertext that wraps it. Only the holder of the matching private key can unwrap the ciphertext and recover the same secret. Both sides then use that secret with ordinary symmetric encryption such as AES-256.

Which ML-KEM parameter set should I use?

There are three: ML-KEM-512, ML-KEM-768 and ML-KEM-1024, in increasing strength. ML-KEM-768 is the common default and is what major browsers and content-delivery networks use. ML-KEM-1024 is used where the highest strength category is required, for example under the NSA's CNSA 2.0.

How big are ML-KEM keys?

Larger than elliptic-curve keys, but small enough for everyday use. For ML-KEM-768 the public key is 1,184 bytes and the ciphertext 1,088 bytes, compared with 32 bytes each for X25519. It is also fast: key generation, encapsulation and decapsulation are typically quicker than RSA.

What is hybrid ML-KEM?

A hybrid combines ML-KEM with a classical key exchange — most often X25519 — and derives the session key from both. If either algorithm holds, the connection stays secure. This is how post-quantum key exchange is being rolled out on the web today: Chrome and Cloudflare, among others, already use a hybrid of X25519 and ML-KEM-768 for TLS.

Does ML-KEM replace digital signatures too?

No. ML-KEM only establishes keys. Signatures (for certificates, code signing, login tokens) move to ML-DSA (FIPS 204) or SLH-DSA (FIPS 205).

How can I use ML-KEM?

Recent versions of mainstream libraries include it — OpenSSL 3.5, for example. Qopanza offers ML-KEM, ML-DSA and SLH-DSA through one API and SDKs in nine languages, including hybrid mode, and finds the RSA and elliptic-curve code in your systems that ML-KEM should replace. See the developer docs or how to migrate.