Paper 2025/1241
Public Key Linting for ML-KEM and ML-DSA
Abstract
With the advancing standardization of post-quantum cryptographic schemes, the need for preparing the IT security infrastructure for integrating post-quantum schemes increases. The focus of this work is a specific part of the IT security infrastructure, namely public key infrastructures. For public certification authorities, it is crucial to guarantee the quality of public keys certified by them. To this end, linting is deployed, which describes the process of analyzing the content of a certificate with respect to predefined rules, the so-called lints. In this work, we initiate the study of lints for post-quantum cryptography. As a starting point, we choose lattice-based schemes and analyze the public keys of the NIST standards ML-KEM and ML-DSA. We base our analyses on the NIST FIPS standards and IETF documents. We formally describe the identified lints and classify them with respect to the property of the public key that the lint checks. We implement the lints for a common X.509 certificate linter and provide an open-source tool.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Major revision. SPIQE 2025
- Keywords
- ML-KEMML-DSAPQCX.509Linting
- Contact author(s)
-
evangelos karatsiolis @ mtg de
franziskus @ cryspen com
juliane kraemer @ ur de
maximiliane weishaeupl @ ur de - History
- 2025-07-11: approved
- 2025-07-04: received
- See all versions
- Short URL
- https://ia.cr/2025/1241
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1241,
author = {Evangelos Karatsiolis and Franziskus Kiefer and Juliane Krämer and Mirjam Loiero and Christian Tobias and Maximiliane Weishäupl},
title = {Public Key Linting for {ML}-{KEM} and {ML}-{DSA}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1241},
year = {2025},
url = {https://eprint.iacr.org/2025/1241}
}