Research

Watch · narrated whiteboard episodesL3

ML-KEM, End to End: From LWE to an IND-CCA Key-Encapsulation Mechanism

FIPS 203 is a KEM built by hardening a simple public-key scheme into active security. This series walks the whole construction - the underlying encryption, the KEM game, the Fujisaki-Okamoto transform, the silent decapsulation-failure attacks, and the implementation realities. Grounded in FIPS 203 and the primary papers.

Murali Chillakuru·5 episodes
  1. 17 min Episode 1From LWE to a Public-Key Scheme: Compression, Rounding, and a Secret Hidden in NoiseA moderator and a cryptography expert turn the Learning With Errors assumption into a working public-key scheme — how the public key is an LWE instance, how encryption masks a message with noise, how decryption rounds it back, and why the raw scheme is only passively secure.
  2. 18 min Episode 2KEMs and IND-CCA, Defined: What a Key-Encapsulation Mechanism Must SurviveA moderator and a cryptography expert explain why ML-KEM is a key-encapsulation mechanism rather than plain encryption, what the IND-CCA security game demands, why passive security falls short, and how implicit rejection and key binding make decapsulation robust.
  3. 19 min Episode 3The Fujisaki-Okamoto Transform: From Passive to Active Security by Re-EncryptionA moderator and a cryptography expert unpack the generic transform at the heart of ML-KEM — how derandomization and a re-encryption check turn a malleable, passively-secure scheme into one that withstands chosen-ciphertext attacks, and why the proof rests on the random oracle model.
  4. 19 min Episode 4Decapsulation Failures and Their Consequences: Failure-Boosting AttacksA moderator and a cryptography expert examine why a rare decryption failure in ML-KEM is a security event, not just a correctness bug — how failure-boosting attacks hunt for weak ciphertexts, what a single failure leaks, and the layered defenses that keep it harmless.
  5. 19 min Episode 5Implementation Realities: The NTT, Constant-Time Decapsulation, and the Parameter SetsA moderator and a cryptography expert close the ML-KEM series with the engineering that decides real-world security — the number-theoretic transform for speed, constant-time decapsulation, power and electromagnetic side channels, the parameter sets, and the deployment posture that ties it all together.