Skip to content

Class: HybridKEM ​

Defined in: kem.ts:97

Hybrid classical + post-quantum KEM. Default: X25519+ML-KEM-768, byte-compatible with quantum-safe-py's HybridKEM. Also accepts X-Wing (TypeScript-only, interoperable with other X-Wing implementations, not readable by quantum-safe-py).

Example ​

ts
await init(); // no-op on Node.js
const kem = new HybridKEM();
using pair = kem.generateKeyPair();
const { ciphertext, sharedSecret } = kem.encapsulate(pair.publicKey);
using recovered = kem.decapsulate(pair.secretKey, ciphertext);

Extends ​

  • BaseKem

Constructors ​

Constructor ​

new HybridKEM(algorithm?): HybridKEM

Defined in: kem.ts:98

Parameters ​

algorithm? ​

KemAlgorithm = DEFAULT_KEM

Returns ​

HybridKEM

Overrides ​

BaseKem.constructor

Properties ​

algorithm ​

readonly algorithm: KemAlgorithm

Defined in: kem.ts:28

Canonical algorithm string.

Inherited from ​

BaseKem.algorithm


info ​

readonly info: SuiteInfo

Defined in: kem.ts:30

Suite metadata (NIST level, CNSA 2.0 status, …).

Inherited from ​

BaseKem.info

Methods ​

decapsulate() ​

decapsulate(secretKey, ciphertext): SecretBytes

Defined in: kem.ts:70

Recovers the shared secret from ciphertext.

ML-KEM uses implicit rejection (FIPS 203): a ciphertext that was not produced for this key yields a pseudorandom secret rather than an error, so a wrong ciphertext is detected downstream (for example by AEAD authentication), not here.

Parameters ​

secretKey ​

SecretKey

ciphertext ​

Uint8Array

Returns ​

SecretBytes

Throws ​

if the ciphertext has the wrong structure or length.

Inherited from ​

BaseKem.decapsulate


encapsulate() ​

encapsulate(publicKey): Encapsulation

Defined in: kem.ts:47

Encapsulates a fresh shared secret to publicKey.

Parameters ​

publicKey ​

PublicKey

Returns ​

Encapsulation

Throws ​

if the key belongs to a different algorithm.

Throws ​

if the key bytes are invalid.

Inherited from ​

BaseKem.encapsulate


generateKeyPair() ​

generateKeyPair(): KeyPair

Defined in: kem.ts:38

Generates a key pair. Free it (or use using) when done.

Returns ​

KeyPair

Inherited from ​

BaseKem.generateKeyPair

Apache-2.0.