CRYSTALS-Kyber (ML-KEM)
Encryption for the quantum era. CRYSTALS-Kyber, now NIST's ML-KEM standard, exchanges secret keys using lattice math that quantum computers cannot easily break.
- Term
- CRYSTALS-Kyber (ML-KEM)
- Is
- A post-quantum key-encapsulation mechanism
- Standard
- NIST FIPS 203, finalized 2024
- Resists
- Future quantum-computer attacks
Parts of speech & senses
- CRYSTALS-Kyber, standardized by NIST as ML-KEM in FIPS 203, is a post-quantum key-encapsulation mechanism designed to resist attacks from future quantum computers. "They moved their TLS handshakes to CRYSTALS-Kyber to be quantum-safe."
What CRYSTALS-Kyber is
CRYSTALS-Kyber is an encryption algorithm built to stay secure even against a future quantum computer. Its job is key encapsulation: when two parties want a private conversation, they need to agree on a secret key that no eavesdropper can recover. In a key-encapsulation mechanism, one party publishes a public key, the other uses it to wrap up a freshly generated shared secret, and the first party unwraps it — both ends arrive at the same secret without ever sending it in the clear. Kyber does this using lattice-based mathematics, specifically a hard problem called Module Learning With Errors. The security rests on the fact that recovering the secret would require solving that lattice problem, which is believed to be hard even for quantum computers — unlike the factoring and discrete-log problems that today's RSA and elliptic-curve cryptography rely on.
The reason Kyber exists is the looming threat that a sufficiently powerful quantum computer would break the public-key cryptography securing the internet today. Shor's algorithm, run on such a machine, could crack RSA and elliptic-curve key exchange, which protect everything from web traffic to financial transactions. That machine does not exist yet, but the danger is real now because of "harvest now, decrypt later" — adversaries can record encrypted data today and decrypt it once quantum hardware arrives. Post-quantum cryptography replaces the vulnerable algorithms with ones believed to resist quantum attack, and Kyber is the front-runner for the key-exchange piece. The United States National Institute of Standards and Technology ran a multi-year competition to select such algorithms, and Kyber emerged as the chosen standard for general key encapsulation.
CRYSTALS-Kyber as the NIST ML-KEM standard
In August 2024, NIST finalized CRYSTALS-Kyber as an official standard, publishing it as FIPS 203 under the name ML-KEM, which stands for Module-Lattice-Based Key-Encapsulation Mechanism. "CRYSTALS-Kyber" was the name of the original submission to NIST's competition; "ML-KEM" is the standardized version, and the two refer to essentially the same algorithm at different stages. It was announced alongside FIPS 204 (a digital-signature standard derived from CRYSTALS-Dilithium) and FIPS 205 (a hash-based signature standard). ML-KEM comes in three parameter sets — ML-KEM-512, ML-KEM-768, and ML-KEM-1024 — trading speed against security strength, with ML-KEM-768 recommended as the default for most uses including TLS. Being a NIST standard matters because it signals vetted security and drives adoption across government and industry.
Kyber is distinct from the other post-quantum standards in what it does. ML-KEM (Kyber) handles key encapsulation — establishing a shared secret — and is the intended replacement for the Diffie-Hellman and elliptic-curve key exchanges used in protocols like TLS. The signature standards, ML-DSA (Dilithium) and SLH-DSA (the hash-based scheme), instead handle digital signatures, which prove authenticity and integrity rather than establishing a secret. They solve different halves of the cryptography problem, and a fully quantum-safe system needs both. Real deployment is already underway: Google Chrome enabled a hybrid key exchange combining classical X25519 with ML-KEM-768 by default in late 2024, and Cloudflare and OpenSSL added support, with hybrids favored so a flaw in either component still leaves the other protecting the connection.
Why CRYSTALS-Kyber matters
CRYSTALS-Kyber matters to anyone responsible for data that must stay confidential for years, which includes most businesses handling customer information. The "harvest now, decrypt later" threat means data encrypted today with classical algorithms could be quietly recorded and exposed once quantum computers mature, so the migration to post-quantum cryptography is a forward-looking security decision, not a reaction to a present breach. For a marketing or data organization, the practical relevance is indirect but real: the platforms, browsers, and cloud services you depend on are adopting ML-KEM to protect connections, and your security and compliance posture increasingly references post-quantum readiness. Knowing what Kyber is helps you read vendor security claims and understand why "quantum-safe" is appearing in the tools you use.
The discipline here is to treat post-quantum migration as a gradual, standards-led process rather than a panic. Hybrid schemes that pair Kyber with a classical algorithm are the sensible path during the transition, because they stay secure even if one component later proves flawed. The failure modes are at the extremes: dismissing the threat as far-off science fiction and leaving long-lived secrets exposed to harvesting, or overreacting by ripping out proven cryptography for unproven implementations of a new standard. Kyber, as the vetted NIST choice, is the credible middle path — adopt it deliberately, in hybrid form, as the ecosystem does, and let the standard rather than the hype set the pace. None of this is legal or compliance advice, only a description of the technology.
Synonyms & antonyms
Synonyms
Antonyms
Origin & history
CRYSTALS-Kyber, from the CRYSTALS cryptographic suite, was standardized by NIST as ML-KEM in FIPS 203 in 2024 as the post-quantum replacement for classical key exchange.
Etymology: source.
Usage trends
Search interest for this term over the last five years:
Common questions
- What is CRYSTALS-Kyber?
- A post-quantum key-encapsulation mechanism, standardized by NIST as ML-KEM in FIPS 203 in 2024. It uses lattice-based math to let two parties agree on a secret key in a way believed to resist attacks from future quantum computers.
- Why is CRYSTALS-Kyber needed?
- A powerful quantum computer could break the RSA and elliptic-curve cryptography securing the internet. Even before one exists, "harvest now, decrypt later" lets adversaries record encrypted data today to decrypt later, so quantum-safe key exchange is needed now.
- What is the difference between Kyber and ML-KEM?
- They are essentially the same algorithm. CRYSTALS-Kyber was the original name submitted to NIST's competition; ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism, is the standardized version published as FIPS 203 in 2024.
Resources & people to follow
- referenceRGM analysis — definitions, senses, and usage verified per term
Curated, non-competitor resources verified per term.
Related training
Disciplines
Areas of marketing where crystals-kyber (ml-kem) is a core concern: