Chrome switching to NIST-approved ML-KEM quantum encryption

Share:

Google is updating the post-quantum cryptography used in the Chrome browser to protect against TLS attacks using quantum computers and to mitigate store-now-decrypt-later attacks.

The upcoming change will swap Kyber used in hybrid key exchanges to a newer, and slightly modified version, renamed as Module Lattice Key Encapsulation Mechanism (ML-KEM).

This change comes roughly five months after Google rolled out the post-quantum secure TLS key encapsulation system on Chrome stable for all users, which also caused some problems with TLS exchanges.

The move from Kyber to ML-KEM though is not related to those early problems, that got resolved soon after manifesting. Rather, its a strategic choice to abandon an experimental system for a NIST-approved and fully standardized mechanism.

ML-KEM was fully endorsed by the U.S. National Institute of Standards and Technology (NIST) in mid-August, with the agency publishing the complete technical specifications of the final version at the time.

Google explains that despite the technical changes from Kyber to ML-KEM being minor, the two are essentially incompatible, so a switch had to be made.

“The changes to the final version of ML-KEM make it incompatible with the previously deployed version of Kyber,” explains Google.

“As a result, the codepoint in TLS for hybrid post-quantum key exchange is changing from 0x6399 for Kyber768+X25519, to 0x11EC for ML-KEM768+X25519.”

Abandoning Kyber

Google explains that support for Kyber has to be removed entirely because post-quantum cryptography involves much larger data sizes compared to pre-quantum algorithms.

For instance, a Kyber-based key exchange can take up over 1,000 bytes, and post-quantum signatures like ML-DSA are even bulkier—leading to over 14,000 bytes in a typical handshake.

Should Google decide to maintain support for Kyber in addition to ML-KEM, network performance and efficiency on Chrome would be seriously hurt.

Google notes that server operators could temporarily support both standards to maintain security for a broader set of clients and help make the transition smoother for clients that haven’t upgraded yet, but ML-KEM should be the final target for all stakeholders.

A proposed solution (IETF draft) for the long term is for servers to announce what cryptographic algorithms they support via DNS, so the client uses the appropriate key from the start, avoiding extra round trips during the handshake.

The update is to be implemented in Chrome 131 (current version is 128), scheduled for release on November 6, 2024.

Users of development channels like Chrome Canary, Beta, and Dev, should see ML-KEM support earlier.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:51 pm, Jan 24, 2025
weather icon 8°C
L: 7° | H: 9°
scattered clouds
Humidity: 88 %
Pressure: 1000 mb
Wind: 7 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:49 am
Sunset: 4:35 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
7° | 9°°C 1 mm 100% 7 mph 92 % 1010 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 19 mph 90 % 1000 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 8°°C 0 mm 0% 5 mph 88 % 1000 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 7°°C 0 mm 0% 4 mph 89 % 1000 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 5°°C 1 mm 100% 7 mph 92 % 1001 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 73 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,752.51
0.75%
Ethereum(ETH)
€3,152.46
-0.57%
XRP(XRP)
€2.95
-0.79%
Tether(USDT)
€0.95
-0.02%
Solana(SOL)
€241.53
0.13%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.333256
-0.60%
Shiba Inu(SHIB)
€0.000019
-1.16%
Pepe(PEPE)
€0.000014
-2.72%
Peanut the Squirrel(PNUT)
€0.341611
3.03%
Scroll to Top