Skip to content

FIPS 203 Compliance

AegisQ was developed in phases. The tables below describe implemented components and historical releases, not certification or a current test-run result. Published versions are listed on PyPI; checkout versions live in the package manifests, and release history is recorded in CHANGELOG.md.

v1.0–v1.2 — Core FIPS 203 ML-KEM + Hybrid KEM-DEM

Section titled “v1.0–v1.2 — Core FIPS 203 ML-KEM + Hybrid KEM-DEM”
PhaseComponentReferenceStatus
1Field arithmetic (Zq) & Barrett reductionFIPS 203 §4.2✅
2NTT & inverse NTTFIPS 203 §4.3✅
3Polynomial operationsFIPS 203 §4.1✅
4Compress / DecompressFIPS 203 §4.2.1✅
5Parameters moduleFIPS 203 §5✅
6CBD sampling & XOFFIPS 203 §4.1, §4.2.2✅
7KeyGen (Algorithm 15)FIPS 203 Alg. 15✅
8Encaps (Algorithm 16)FIPS 203 Alg. 16✅
9Decaps with implicit rejectionFIPS 203 Alg. 17✅
10Public KEM API (kem.rs)—✅
11AES-256-GCM Hybrid (hybrid.rs)NIST SP 800-38D✅
12FFI error types—✅
13PyO3 types (KeyPair, SecurityLevel)—✅
14PyO3 KEM bindings—✅
15PyO3 Hybrid bindings—✅
16PyO3 module registration—✅
17Python exceptions—✅
18Python type stubsPEP 561✅
19Python KEM API (MlKem)—✅
20Python high-level API (AegisCipher)—✅
21Python package exports—✅
22KEM bridge tests—✅
23Hybrid bridge tests—✅
24AegisCipher end-to-end tests—✅
25KEM API tests + NIST KAT vectors—✅
26GitHub Actions CI/CD—✅
27NIST ACVP KAT vector JSON filesNIST vectors✅
27bKAT vector verification testsNIST vectors✅
28EphemeralSession (session keypair lifecycle)—✅
29Async support (encrypt_async, decrypt_async)—✅

v1.3.0 — KDF, Key Wrap, and Key Serialization

Section titled “v1.3.0 — KDF, Key Wrap, and Key Serialization”
PhaseComponentReferenceStatus
30HKDF-SHA3-256 + AES-256-GCM key wrap (kdf.rs, key_wrap.rs)RFC 5869, NIST SP 800-38D✅
31Key serialization: PEM, JSON, encrypted PEM (key_io_bindings.rs, aegisq/keys.py)RFC 7468 (adapted)✅

v1.4.0 — Safe Repr, Context Manager, Implicit-Rejection Coverage

Section titled “v1.4.0 — Safe Repr, Context Manager, Implicit-Rejection Coverage”
PhaseComponentReferenceStatus
32KeyPair.__repr__ fingerprint + AegisCipher context manager + 25-case __repr__ regression suite + 25-case implicit-rejection regression suite (FIPS 203 §7.3)FIPS 203 §7.3✅
PhaseComponentReferenceStatus
33aStreaming encrypt/decrypt (stream.rs, stream_bindings.rs, encrypt_stream / decrypt_stream)AES-GCM primitive: SP 800-38D; framing: AegisQ-specific✅
33bCriterion benchmarks for NTT and KEM (benches/ntt.rs, benches/kem.rs)—✅
StandardDescription
FIPS 203ML-KEM — Module-Lattice-Based Key-Encapsulation Mechanism (NIST, 2024)
NIST SP 800-38DAES-GCM — Galois/Counter Mode specification
RFC 5869HMAC-based Extract-and-Expand Key Derivation Function (HKDF)
RFC 4648Base16, Base32, Base64 data encodings (used for PEM bodies and Base64 URL-safe keys)
RFC 7468Textual Encodings of PKIX, PKCS, and CMS Structures (PEM format adapted for ML-KEM)
PEP 561Distributing and Packaging Type Information (AegisQ ships py.typed + .pyi stubs)

Versions are current manifest requirements, not exact lockfile resolutions or a historical v1.5.0 inventory. Workspace declarations live in Cargo.toml; PyO3 and Criterion are declared in the bridge/core manifests. Cargo.lock records resolved versions.

CrateVersionPurposeno_std
aes-gcm0.11AES-256-GCM authenticated encryption (hardware AES-NI)✅
sha30.12SHA3-256/512 for ML-KEM✅
shake0.1XOF variants moved out of sha3 upstream (RustCrypto/XOFs split)✅
zeroize1.9Secure memory erasure of secrets✅
subtle2.6Constant-time comparisons✅
getrandom0.4OS-level CSPRNG (OsRng) for nonces and keygen✅
base640.23PEM body encoding✅
thiserror2.0Error type definitions✅
pyo30.29Rust-Python FFI bindings (abi3-py311)—
criterion (dev)0.5Benchmarks for NTT and KEM operations—

All cryptographic crates are no_std compatible. pyo3 and criterion are excluded — they are used only at the FFI and dev-dependency layers respectively.

AegisQ verifies its ML-KEM implementation against the official NIST ACVP (Automated Cryptographic Validation Program) test vectors:

  • KeyGen — tests/python/json-files/ML-KEM-keyGen-FIPS203/
  • Encap/Decap — tests/python/json-files/ML-KEM-encapDecap-FIPS203/

tests/python/test_kat_vectors.py explicitly compares expected KeyGen and encapsulation outputs byte-for-byte. It does not invoke decapsulation or assert the expected decapsulation/rejection outputs from the combined corpus. Roundtrips are checked separately in tests/python/test_kem_api.py; tests/python/test_implicit_rejection.py covers invalid capsule contents. Those tests do not replace decapsulation known-answer tests.

Passing these tests is correctness evidence for the checked inputs, not a proof of security, exhaustive vector coverage, or official certification. A pass claim must refer to an actual run against the matching source and native extension.