Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Presentation

ML-KEM is Great! What’s Missing?

February 25, 2025

Presenters

John Preuß Mattsson - Ericsson

Description

Post-Quantum Cryptography (PQC) has made significant progress with the standardization of ML-KEM, ML-DSA, and SLH-DSA, paving the way for widespread adoption. However, since many adopters lack expertise in cryptography,
it is crucial for specifications and guidance to be concise, accessible, and focused on recommending only secure implementations of PQC and related primitives to minimize the risk of vulnerabilities. Moreover, ML-KEM may not be suitable for all applications, and backup algorithms are needed for cryptographic agility. To address this, we propose several suggestions for NIST’s specifications and guidance, including the use of ephemeral keys, hybridization strategies, key combiners, key derivation functions, additional key encapsulation mechanisms, and best practices for asymmetric keying. The transition to quantum-resistant cryptography offers an excellent opportunity to reassess outdated algorithms and practices that no longer provide acceptable security.

Presented at

NIST Workshop on Guidance for KEMs
February 25-26, 2025 (Virtual)

Downloads

Event Details

Location

    Virtual

Related Topics

Security and Privacy: key management, post-quantum cryptography

Created February 26, 2025, Updated April 28, 2025