LWE problem

Given A, b = As + e (small e), recover s. Believed hard even for quantum computers.

Advertisement

Kyber (ML-KEM)

Key encapsulation. Public key + ciphertext ~1-1.5 KB. Standardized as NIST FIPS 203 (2024).

Advertisement

Dilithium (ML-DSA)

Signature scheme. Signatures ~2-4 KB. NIST FIPS 204 (2024).