A new federal standard now defines how computers agree on secret keys in a way that quantum computers cannot break. Published by the National Institute of Standards and Technology as FIPS 203 in August 2024, ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism, grew out of an algorithm called CRYSTALS-Kyber and is already being built into browsers, messaging apps, and secure shells. The stakes are not abstract: encrypted traffic captured today could be decrypted years from now, once sufficiently powerful quantum machines exist.
Encryption itself is not the hard problem here. Fast, reliable ciphers such as AES-256 already resist quantum attacks. The real difficulty lies in getting two parties, say a browser and a website, to agree on the same secret key without an eavesdropper intercepting it along the way. That process, known as key establishment, is the single task ML-KEM performs. It works in three steps: the recipient generates a public encapsulation key and a private decapsulation key; the sender uses the public key to create a fresh 32-byte shared secret along with a ciphertext that wraps it; and the recipient's private key unwraps that ciphertext to recover the identical secret. From there, both sides switch to conventional fast encryption. People securing remote connections should also understand the protective layers around the tunnel itself, including how to turn the kill switch on, since a dropped connection without one can expose traffic even when the underlying cryptography is sound.
ML-KEM's security rests on a mathematical puzzle called Module Learning With Errors, which involves recovering hidden values from equations deliberately scrambled with small random errors. No known method, classical or quantum, solves this efficiently at the sizes used in practice. That stands in contrast to RSA and elliptic-curve cryptography, which depend on factoring large numbers and solving discrete logarithms, both of which a sufficiently large quantum computer running Shor's algorithm could crack. The trade-off is size: ML-KEM's keys and ciphertexts run tens of times larger than elliptic-curve equivalents, though the underlying computations remain fast.
A Deadline Already on the Calendar
The urgency stems from what security researchers call the harvest-now-decrypt-later threat. Adversaries can record encrypted traffic today and simply wait for quantum decryption to mature. Switching key exchange to ML-KEM closes that window for anything transmitted after the switch, but it does nothing to protect data already intercepted under older systems. NIST's draft transition plan calls for deprecating quantum-vulnerable algorithms like RSA and elliptic-curve key exchange after 2030 and disallowing them entirely after 2035. In the meantime, most real-world deployments run ML-KEM alongside a classical algorithm such as X25519, a hybrid approach that ensures a weakness in either method alone cannot compromise the connection.
Already Woven Into Everyday Tools
The rollout is further along than most users realize. Chrome adopted the hybrid X25519MLKEM768 key exchange by default starting with version 131 in late 2024, and the IETF has since standardized that same hybrid approach for TLS 1.3. OpenSSH made a similar hybrid its default key exchange in 2025. Apple's iMessage uses Kyber within its PQ3 protocol, and Signal added ML-KEM-768 to its encryption scheme through what it calls the Sparse Post-Quantum Ratchet. Each of these deployments quietly shifts a piece of daily internet traffic out of reach of future quantum decryption, without requiring any action from the people using them.