iraca verifies RustCrypto ml-kem byte-for-byte against pq-crystals reference
The iraca project ran an independent differential check of the RustCrypto ml-kem crate (ML-KEM / FIPS 203): keys, ciphertexts and shared secrets matched the pq-crystals C reference byte-for-byte across 128 seeds. The crate also correctly rejects non-canonical keys as FIPS 203 requires. It is a conformance spot-check, not a full audit, and does not cover side channels.
- ML-KEM-768 matched pq-crystals across 128 seeds and a fixed vector
- RustCrypto rejects non-canonical keys with coefficients ≥ q per FIPS 203
- ML-DSA-87 also matched the dilithium reference byte-for-byte
- Side channels and the KyberSlash class were not tested
Read next
Security