top of page

What Is ML-KEM-768? A Plain-English Guide to the New Post-Quantum Standard

12 minutes ago
4 min read

ML-KEM-768 is a post-quantum key-establishment algorithm standardized by the U.S. National Institute of Standards and Technology in FIPS 203. Its purpose is to allow two systems to establish the same secret key over a public network, even when an attacker can observe the messages exchanged between them.


The shared secret produced by ML-KEM-768 is then used with symmetric encryption, such as AES-GCM, to encrypt and authenticate data. ML-KEM-768 does not encrypt a database, file, or network stream by itself. It establishes the secret material that symmetric encryption uses afterward.


ML-KEM stands for Module-Lattice-Based Key-Encapsulation Mechanism. It is based on a mathematical problem called Module Learning With Errors. The security of the algorithm depends on the difficulty of recovering a hidden value from structured mathematical data containing carefully controlled noise. This problem is believed to remain difficult for both conventional and quantum computers.


ML-KEM is the standardized successor to the algorithm previously known as CRYSTALS-Kyber. The names are related but should not be treated as interchangeable. ML-KEM is the final NIST-standardized specification. Older Kyber implementations may not be interoperable with software that implements FIPS 203 ML-KEM.


A key-encapsulation mechanism has three operations: key generation, encapsulation, and decapsulation. The receiving system generates a public encapsulation key and a private decapsulation key. It shares the public key and keeps the private key secret. A sending system uses the public key to generate a new shared secret and an associated ciphertext. It sends the ciphertext to the receiving system. The receiving system uses its private key to recover the same shared secret.


The public encapsulation key and ciphertext can cross an untrusted network. The private decapsulation key and resulting shared secret must remain protected. If an attacker obtains the private decapsulation key, they may be able to recover shared secrets from ciphertexts created for that key. If an attacker obtains a live shared secret, they may be able to derive the symmetric keys used to protect the associated data.


ML-KEM-768 is the middle of the three parameter sets defined by FIPS 203. The parameter sets offer different tradeoffs between security strength, bandwidth, storage, and computational cost.


Parameter set

NIST security category

Public key

Private key

Ciphertext

Shared secret

ML-KEM-512

1

800 bytes

1,632 bytes

768 bytes

32 bytes

ML-KEM-768

3

1,184 bytes

2,400 bytes

1,088 bytes

32 bytes

ML-KEM-1024

5

1,568 bytes

3,168 bytes

1,568 bytes

32 bytes


ML-KEM-768 is designed to provide security comparable to NIST Category 3, which is associated with the difficulty of exhaustive key search against AES-192. NIST recommends ML-KEM-768 as the default parameter set because it provides a substantial security margin without the larger bandwidth and computation requirements of ML-KEM-1024.


The name “768” does not mean that ML-KEM-768 produces a 768-bit key. The final shared secret is 32 bytes, or 256 bits. The name identifies a standardized parameter set with specific internal parameters and a defined security-performance profile.


ML-KEM-768 uses larger public keys and ciphertexts than commonly deployed elliptic-curve key exchange. An X25519 public key is 32 bytes, while an ML-KEM-768 public key is 1,184 bytes. An ML-KEM-768 ciphertext is 1,088 bytes. This increase affects TLS handshakes, VPN negotiation, constrained devices, high-frequency connection establishment, and protocols with strict packet-size limits.


The larger message size does not mean that ML-KEM-768 encrypts application data inefficiently. ML-KEM-768 is used once during key establishment. The resulting 32-byte shared secret is then used to derive ordinary symmetric traffic keys. Bulk data is still encrypted with efficient symmetric algorithms such as AES-GCM or ChaCha20-Poly1305.


ML-KEM-768 is intended to address the quantum threat to classical public-key cryptography. A sufficiently capable quantum computer could use Shor’s algorithm to break RSA, finite-field Diffie-Hellman, and elliptic-curve Diffie-Hellman. These algorithms are widely used to establish encryption keys in TLS, VPNs, SSH, messaging systems, and other secure protocols. ML-KEM-768 uses a different mathematical basis for which no practical quantum attack is currently known.


ML-KEM-768 is a key-establishment algorithm, not a digital-signature algorithm. It cannot sign software, authenticate a certificate, verify a firmware update, or prove the identity of a server by itself. Post-quantum signatures require separate algorithms, such as ML-DSA or SLH-DSA.


A post-quantum TLS deployment may use ML-KEM-768 alongside a classical key-exchange algorithm during a transition period. This is called hybrid key establishment. The system generates a classical shared secret and a post-quantum shared secret, then combines them through a key-derivation function. The resulting traffic keys depend on both contributions. This approach retains protection from the classical component against ordinary attackers while adding protection from the ML-KEM component against a future quantum attacker.


ML-KEM-768 requires correct implementation. The algorithm depends on high-quality randomness during key generation and encapsulation, correct validation of inputs, constant-time handling of sensitive operations, protection of the decapsulation key, and secure deletion of temporary secrets when they are no longer required. A system using ML-KEM-768 can still be compromised through weak access controls, memory exposure, flawed key management, vulnerable software, insecure firmware, or implementation errors.


ML-KEM-768 is therefore a replacement for one specific part of a cryptographic system: establishing a shared secret over an untrusted channel. It does not replace symmetric encryption, digital signatures, certificate management, authentication, access control, or secure key storage. Its role is to prevent a future quantum computer from breaking the public-key mechanism used to establish the secret that protects encrypted communication.

Recent Posts

See All

Comments


bottom of page