ML-KEM in TLS
by Ostap Cherkashin | - 4:15pm
There is a growing sentiment that quantum computing has been overpromised and underdelivered, leading to skepticism concerning the subject of post-quantum cryptography. As with any kind of risk, evaluating risks posed by quantum computers is not a straightforward “all or nothing” decision. One must consider the value of assets under protection, the cost of mounting an attack, the complexities of the environment, and also the implementation costs. This talk focuses on the latter aspect. As we will see, cryptographers, protocol designers, and engineers made significant progress towards the practicality of defenses [1][2]. We will examine the recently standardized key exchange primitive, ML-KEM [1], see how it works and what underlies its security promises. We will then look at how ML-KEM integrates into TLS [2] and provide practical guidance for configuring web servers.
[1] https://csrc.nist.gov/pubs/fips/203/final
[2] https://datatracker.ietf.org/doc/rfc9954/
About Ostap Cherkashin
Ostap is a cryptography engineer. He recently moved from Zürich to Auckland to pursue a PhD in mathematics at the University of Auckland. His research focuses on mathematical problems underlying cryptographic constructions based on elliptic curves, particularly in the context of post-quantum cryptography (i.e., isogenies). His goal is to enhance the efficiency of these constructions and to establish the groundwork for formally verified implementations. Before relocating to Auckland, Ostap worked on TLS termination, key management, and access control systems for financial services in Switzerland.