How ML-KEM works
Encrypting data is the easy part. Fast ciphers like AES-256 do it well, and they hold up against quantum computers. The hard part is getting the same secret key to both sides without anyone in the middle learning it. That job is called key establishment, and it’s the only thing ML-KEM does.
- The recipient makes a key pair: a public encapsulation key they can hand to anyone, and a private decapsulation key they keep.
- The sender encapsulates: using the public key, it creates a fresh 32-byte shared secret plus a ciphertext that wraps it.
- The recipient decapsulates: the private key opens the ciphertext and yields the same 32-byte secret. Both sides now encrypt with a fast cipher using that secret.
Its security rests on a math problem called Module Learning With Errors: recovering hidden values from equations that have had small random errors mixed in. No known algorithm, classical or quantum, solves it efficiently at these sizes. RSA and elliptic-curve keys rest on factoring and discrete logarithms, which a large quantum computer running Shor’s algorithm could solve.
| Parameter set | NIST category | About as hard to break as | Public key | Ciphertext |
|---|---|---|---|---|
| ML-KEM-512 | 1 | AES-128 | 800 bytes | 768 bytes |
| ML-KEM-768 | 3 | AES-192 | 1,184 bytes | 1,088 bytes |
| ML-KEM-1024 | 5 | AES-256 | 1,568 bytes | 1,568 bytes |
The main cost is size: keys and ciphertexts are tens of times larger than elliptic-curve ones. The math itself is fast.
Why ML-KEM matters
Anything protected by today’s key exchange can be recorded now and opened later, once a large enough quantum computer exists. That is the harvest now, decrypt later threat. Switching the key exchange to ML-KEM closes it for everything sent after the switch.
Deadlines are already set. NIST’s draft transition plan proposes deprecating quantum-vulnerable algorithms like RSA and elliptic-curve key exchange after 2030 and disallowing them after 2035, with ML-KEM as the replacement for key establishment.2 Most real deployments run ML-KEM next to a classical algorithm such as X25519, a setup called hybrid encryption, so a flaw in either one alone isn’t enough to break the connection.
Where you’ll see ML-KEM
- Your browser. Chrome moved to the hybrid X25519MLKEM768 key exchange by default in Chrome 131, released in November 2024.3 The IETF standardized that hybrid for TLS 1.3 in RFC 10024.4 Cloudflare reported in April 2026 that over 65% of human traffic to its network was post-quantum encrypted.5
- SSH. OpenSSH 10.0 made mlkem768x25519-sha256 its default key exchange in April 2025.6
- Messaging. Apple’s iMessage PQ3 protocol uses Kyber,7 and Signal added ML-KEM-768 to its protocol with the Sparse Post-Quantum Ratchet in October 2025.8
ML-KEM in Secria
Secria uses the strongest of the three sets, ML-KEM-1024, paired with X25519. Secria Mail seals every message in your mailbox with it on every plan, free included, with nothing to turn on. Secria VPN mixes an ML-KEM-1024 protected key into every WireGuard session. More on post-quantum email and the post-quantum VPN.
Related terms
Sources
- NIST, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (August 2024).
- NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
- Google Security Blog, A new path for Kyber on the web (September 2024).
- IETF, RFC 10024: Post-quantum traditional hybrid key agreement for TLS 1.3.
- Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).
- OpenSSH, Post-quantum cryptography.
- Apple Security Research, iMessage with PQ3 (February 2024).
- Signal, Signal protocol and post-quantum ratchets (October 2025).
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.