Rust post-quantum crypto library ML-KEM passes independent differential verification
A verification harness called iraca has confirmed that RustCrypto's ml-kem crate, which implements the post-quantum standard ML-KEM (FIPS 203), produces byte-for-byte identical outputs to the official pq-crystals C reference implementation across key generation, encapsulation, and decapsulation. Testing was conducted across 128 random seeds plus a fixed test vector, with no discrepancies found. The harness also confirmed that RustCrypto correctly rejects non-canonical encapsulation keys as required by FIPS 203, verified through both source review and 128 adversarial samples. Developers stress this is a targeted conformance check, not a full security audit, and does not cover side-channel vulnerabilities such as those in the KyberSlash class. The tool is open for reuse by maintainers of other post-quantum implementations seeking independent differential or adversarial verification.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in