▲ | throw0101a 4 days ago | |
> * ML-KEM is NIST approved and AFAIK NIST is on record saying that hybrid KEMs are fine.* See perhaps §3.2, PQC-Classical Hybrid Protocols from interim report "Transition to Post-Quantum Cryptography Standards" (draft): * https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.p... No algorithm explicitly mentioned, but the general idea/technique discussed. |