Skip to content

Security Levels

AegisQ supports the three ML-KEM parameter sets defined in FIPS 203. The default is ML-KEM-768 (NIST category 3). Select parameters according to your protocol, threat model, and interoperability requirements; a category is not a certification of this implementation.

LevelEnum ValueNIST LevelPublic KeySecret KeyCapsulePackage Overhead
ML-KEM-512SecurityLevel.ML_KEM_5121800 B1632 B768 B796 B
ML-KEM-768SecurityLevel.ML_KEM_7683 (default)1184 B2400 B1088 B1116 B
ML-KEM-1024SecurityLevel.ML_KEM_102451568 B3168 B1568 B1596 B

One-shot package overhead = capsule + AES nonce (12 B) + AES auth tag (16 B). The total one-shot package size is overhead + plaintext length. Streaming uses a separate header/frame format.

  • Category 1 — Uses exhaustive AES-128 key search as the NIST comparison target.
  • Category 3 — Uses exhaustive AES-192 key search as the comparison target. AegisQ default.
  • Category 5 — Uses exhaustive AES-256 key search as the comparison target.

These are algorithm security categories, not guarantees of a data-retention period or literal bit-security equivalence for every attack. All three hybrid modes still use AES-256-GCM for the payload.

from aegisq import AegisCipher, SecurityLevel
# Default: ML-KEM-768 (NIST Level 3)
cipher = AegisCipher()
# Explicit level selection
cipher_512 = AegisCipher(level=SecurityLevel.ML_KEM_512) # Category 1, smallest keys
cipher_768 = AegisCipher(level=SecurityLevel.ML_KEM_768) # Category 3 (default)
cipher_1024 = AegisCipher(level=SecurityLevel.ML_KEM_1024) # Category 5, largest keys

These are the internal ML-KEM parameters for each security level:

Levelkη₁η₂dᵤdᵥpk sizesk sizect sizess size
ML-KEM-512232104800 B1632 B768 B32 B
ML-KEM-7683221041184 B2400 B1088 B32 B
ML-KEM-10244221151568 B3168 B1568 B32 B

Where:

  • k — Module dimension (number of polynomial vectors)
  • η₁, η₂ — CBD sampling parameters for error terms
  • dᵤ, dᵥ — Compression bit-widths
  • pk — Public key, sk — Secret key, ct — Ciphertext (capsule), ss — Shared secret