Paper 2026/1117
On the Secrecy of the Encapsulation Coin in ML-KEM
Abstract
ML-KEM (FIPS 203) draws a fresh 32-byte coin at each encapsulation. The shared secret is a deterministic function of the public key and this coin, so a known coin is a recovered key. This is elementary. We ask instead how well the coin's secrecy is protected in practice, and we answer by experiment. On six unmodified libraries (OpenSSL 3.5, wolfSSL 5.9, AWS-LC, Go 1.26, Bouncy Castle 1.83, and CIRCL), and a from-scratch reference, the coin-recovery is reachable in every one; what differs is the guard, from a test-walled package in Go to an ordinary production call in wolfSSL. A second path needs no injection function at all: substituting the generator at build time makes the ordinary encapsulation predictable, while the public re-seed interface correctly refuses to. Outside the validated FIPS-140-3 configuration that most deployments do not yet use, the coin's secrecy rests on convention, not construction. The predictability this permits is externally invisible and parameter-controlled, of the class shown once before in Dual_EC_DRBG. We claim no backdoor; we claim only that the door is reachable, and say so while it is still being closed.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- ML-KEMFIPS 203randomnessencapsulation coin
- Contact author(s)
-
madjid tehrani @ napier ac uk
B Buchanan @ napier ac uk
M Lemoudden @ napier ac uk - History
- 2026-06-02: approved
- 2026-05-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1117
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1117,
author = {Madjid G. Tehrani and William J Buchanan and Mouad Lemoudden},
title = {On the Secrecy of the Encapsulation Coin in {ML}-{KEM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1117},
year = {2026},
url = {https://eprint.iacr.org/2026/1117}
}