Chapter 5ML-KEM

The Parameter Sets

August 25, 20264 min readbeginner

| | ML-KEM-512 | ML-KEM-768 | ML-KEM-1024 | | --- | --- | --- | --- | | NIST security level | 1 | 3 | 5 | | module rank k | 2 | 3 | 4 | | _1 | 3 | 2 | 2 | | _2 | 2 | 2 | 2 | | d_u…

01.What is fixed and what varies

ML-KEM-512ML-KEM-768ML-KEM-1024
NIST security level135
module rank kk234
η1\eta_1322
η2\eta_2222
dud_u101011
dvd_v445
public key800 B1184 B1568 B
ciphertext768 B1088 B1568 B

Fixed across all three: n=256n = 256 and q=3329q = 3329.

That those two never change is the design decision from Module-LWE doing its work. One transform length, one modulus, one set of twiddle tables, one arithmetic datapath, three security levels. A hardware implementation supports all three by changing a loop bound.

02.Reading the table

kk, the module rank. How many polynomials are in the secret vector. The effective lattice dimension is k⋅256k \cdot 256, which is where the names come from: ML-KEM-768 works over a lattice of dimension 768768. This is the main security knob.

η1\eta_1 and η2\eta_2, the noise widths. The centred binomial parameters from Chapter 3. η1\eta_1 governs the secret and the main error, η2\eta_2 the smaller errors added during encryption. A larger η\eta means noisier samples, which is harder for an attacker and also harder for the legitimate recipient.

Notice that ML-KEM-512 uses η1=3\eta_1 = 3 while the larger parameter sets use 22. That looks backwards, since the lowest security level has the most noise. It is not a mistake. At k=2k = 2 the lattice dimension is only 512512, which is the least comfortable margin of the three, so extra noise compensates. At k=3k = 3 and above the dimension is doing enough work that the noise can be reduced, which improves the failure probability and shrinks nothing else.

dud_u and dvd_v, the compression widths. How many bits each ciphertext coefficient is squeezed into before transmission. Compression and Ciphertext Size covers these.

03.What the NIST levels mean

The security levels are defined by comparison with symmetric primitives rather than in absolute bits.

Level 1 means breaking the scheme should be at least as hard as recovering a 128-bit AES key by brute force. Level 3 corresponds to AES-192, and level 5 to AES-256.

The comparison is deliberate. It sidesteps arguments about exactly how many operations a given lattice attack costs, by anchoring to a problem whose difficulty everyone already agrees on.

ML-KEM-768 is the recommended default. NIST's guidance, and the choice made by most deploying software including the major browsers, is level 3 rather than level 1. The reasoning is that the cost difference between 768 and 512 is a few hundred bytes and a small number of extra ring multiplications, while the margin against future improvements in lattice attacks is meaningfully larger. Lattice cryptanalysis is a younger field than factoring, and estimates have moved before.

04.Sizes in context

Worth putting next to what is being replaced.

An X25519 elliptic-curve public key is 32 bytes and its ciphertext equivalent is 32 bytes. ML-KEM-768 is 1184 and 1088. So the move to post-quantum costs roughly a factor of thirty-five in handshake bytes.

That sounds severe and turns out to be tolerable. A TLS handshake already carries a certificate chain of several kilobytes, so adding one kilobyte is a modest proportional increase. It is not free, and it is the reason the deployed configurations are hybrid, sending both an X25519 and an ML-KEM share, which costs the sum of both but keeps the connection secure if either primitive fails.

The rest of the chapter fixes ML-KEM-768 for every worked description: k=3k = 3, η1=η2=2\eta_1 = \eta_2 = 2, du=10d_u = 10, dv=4d_v = 4.

FeedbackBook mode
post-quantum-cryptographycryptographymathematics