Paper 2025/1241

Public Key Linting for ML-KEM and ML-DSA

Evangelos Karatsiolis, MTG
Franziskus Kiefer, Cryspen
Juliane Krämer, University of Regensburg
Mirjam Loiero, MTG
Christian Tobias, MTG
Maximiliane Weishäupl, University of Regensburg
Abstract

With the advancing standardization of post-quantum cryptographic schemes, the need for preparing the IT security infrastructure for integrating post-quantum schemes increases. The focus of this work is a specific part of the IT security infrastructure, namely public key infrastructures. For public certification authorities, it is crucial to guarantee the quality of public keys certified by them. To this end, linting is deployed, which describes the process of analyzing the content of a certificate with respect to predefined rules, the so-called lints. In this work, we initiate the study of lints for post-quantum cryptography. As a starting point, we choose lattice-based schemes and analyze the public keys of the NIST standards ML-KEM and ML-DSA. We base our analyses on the NIST FIPS standards and IETF documents. We formally describe the identified lints and classify them with respect to the property of the public key that the lint checks. We implement the lints for a common X.509 certificate linter and provide an open-source tool.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Major revision. SPIQE 2025
Keywords
ML-KEMML-DSAPQCX.509Linting
Contact author(s)
evangelos karatsiolis @ mtg de
franziskus @ cryspen com
juliane kraemer @ ur de
maximiliane weishaeupl @ ur de
History
2025-07-11: approved
2025-07-04: received
See all versions
Short URL
https://ia.cr/2025/1241
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1241,
      author = {Evangelos Karatsiolis and Franziskus Kiefer and Juliane Krämer and Mirjam Loiero and Christian Tobias and Maximiliane Weishäupl},
      title = {Public Key Linting for {ML}-{KEM} and {ML}-{DSA}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1241},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1241}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.