The Parameter Sets
August 25, 20264 min readbeginner
| | ML-KEM-512 | ML-KEM-768 | ML-KEM-1024 | | --- | --- | --- | --- | | NIST security level | 1 | 3 | 5 | | module rank k | 2 | 3 | 4 | | _1 | 3 | 2 | 2 | | _2 | 2 | 2 | 2 | | d_u…
01.What is fixed and what varies
| ML-KEM-512 | ML-KEM-768 | ML-KEM-1024 | |
|---|---|---|---|
| NIST security level | 1 | 3 | 5 |
| module rank | 2 | 3 | 4 |
| 3 | 2 | 2 | |
| 2 | 2 | 2 | |
| 10 | 10 | 11 | |
| 4 | 4 | 5 | |
| public key | 800 B | 1184 B | 1568 B |
| ciphertext | 768 B | 1088 B | 1568 B |
Fixed across all three: and .
That those two never change is the design decision from Module-LWE doing its work. One transform length, one modulus, one set of twiddle tables, one arithmetic datapath, three security levels. A hardware implementation supports all three by changing a loop bound.
02.Reading the table
, the module rank. How many polynomials are in the secret vector. The effective lattice dimension is , which is where the names come from: ML-KEM-768 works over a lattice of dimension . This is the main security knob.
and , the noise widths. The centred binomial parameters from Chapter 3. governs the secret and the main error, the smaller errors added during encryption. A larger means noisier samples, which is harder for an attacker and also harder for the legitimate recipient.
Notice that ML-KEM-512 uses while the larger parameter sets use . That looks backwards, since the lowest security level has the most noise. It is not a mistake. At the lattice dimension is only , which is the least comfortable margin of the three, so extra noise compensates. At and above the dimension is doing enough work that the noise can be reduced, which improves the failure probability and shrinks nothing else.
and , the compression widths. How many bits each ciphertext coefficient is squeezed into before transmission. Compression and Ciphertext Size covers these.
03.What the NIST levels mean
The security levels are defined by comparison with symmetric primitives rather than in absolute bits.
Level 1 means breaking the scheme should be at least as hard as recovering a 128-bit AES key by brute force. Level 3 corresponds to AES-192, and level 5 to AES-256.
The comparison is deliberate. It sidesteps arguments about exactly how many operations a given lattice attack costs, by anchoring to a problem whose difficulty everyone already agrees on.
ML-KEM-768 is the recommended default. NIST's guidance, and the choice made by most deploying software including the major browsers, is level 3 rather than level 1. The reasoning is that the cost difference between 768 and 512 is a few hundred bytes and a small number of extra ring multiplications, while the margin against future improvements in lattice attacks is meaningfully larger. Lattice cryptanalysis is a younger field than factoring, and estimates have moved before.
04.Sizes in context
Worth putting next to what is being replaced.
An X25519 elliptic-curve public key is 32 bytes and its ciphertext equivalent is 32 bytes. ML-KEM-768 is 1184 and 1088. So the move to post-quantum costs roughly a factor of thirty-five in handshake bytes.
That sounds severe and turns out to be tolerable. A TLS handshake already carries a certificate chain of several kilobytes, so adding one kilobyte is a modest proportional increase. It is not free, and it is the reason the deployed configurations are hybrid, sending both an X25519 and an ML-KEM share, which costs the sum of both but keeps the connection secure if either primitive fails.
The rest of the chapter fixes ML-KEM-768 for every worked description: , , , .