Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

Registry/DGV Live/DGV-TC-041
DGV-TC-041L1: Compute SubstrateGER-343: Post-Quantum Key Exchange Not AvailableVersion: 1.0.0

ML-KEM-768 Key Encapsulation

Verifies that the Only OS key establishment layer performs real ML-KEM-768 (NIST FIPS 203 Module-Lattice-Based Key-Encapsulation Mechanism) encapsulation and decapsulation. An honest encapsulation-decapsulation cycle must produce identical shared secrets. The implicit rejection property ensures that a tampered ciphertext cannot yield the sender's shared secret, providing CCA2 security.

Operational Purpose & Scope

Real FIPS 203 ML-KEM-768: only-gate generates a fresh keypair using the ml-kem 0.3.2 RustCrypto crate, encapsulates to produce (ciphertext, shared_secret_sender), decapsulates to produce shared_secret_receiver, and confirms both secrets are identical.

Verification Context

  • Target Scope:Only OS key establishment path; Agent-to-agent session key negotiation; DGV Level 3 post-quantum KEM
  • Audit Strategy:exact-match
  • Verification Metrics:kem_algorithmfips_203_compliantsecurity_levelshared_secrets_matchshared_key_size_bytesimplicit_rejection_propertyreal_kem
  • Framework Origin:DGV v0.5.0 Expansion
  • Mandatory:Yes — must pass for certification

Governance Risk & Penalty

Post-quantum key encapsulation failure leaves key establishment vulnerable to future quantum decryption.

Expected Outcome

  • pass:true
  • gate_status:"OPEN"
  • kem_algorithm:"ML-KEM-768"
  • fips_203_compliant:true
  • shared_secrets_match:true
  • real_kem:true

Explore this card in 3D

Open DGV-TC-041 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.

Open DGV Live →