LWE problem

Given A, b = As + e (small e), recover s. Believed hard even for quantum computers.

Advertisement

Kyber (ML-KEM)

Key encapsulation. Public key + ciphertext ~1-1.5 KB. Standardized as NIST FIPS 203 (2024).

Advertisement

Dilithium (ML-DSA)

Signature scheme. Signatures ~2-4 KB. NIST FIPS 204 (2024).

Hybrid deployment

Combine classical (ECDHE) + PQ (Kyber). Only vulnerable if BOTH broken. Chrome + Cloudflare deploying 2024+.