Skip to content

Class: KEM ​

Defined in: kem.ts:107

Pure ML-KEM (ML-KEM-512/768/1024), matching quantum-safe-py's KEM. Not recommended for new deployments during the transition period; prefer HybridKEM.

Extends ​

  • BaseKem

Constructors ​

Constructor ​

new KEM(algorithm?): KEM

Defined in: kem.ts:108

Parameters ​

algorithm? ​

"ML-KEM-512" | "ML-KEM-768" | "ML-KEM-1024"

Returns ​

KEM

Overrides ​

BaseKem.constructor

Properties ​

algorithm ​

readonly algorithm: KemAlgorithm

Defined in: kem.ts:28

Canonical algorithm string.

Inherited from ​

BaseKem.algorithm


info ​

readonly info: SuiteInfo

Defined in: kem.ts:30

Suite metadata (NIST level, CNSA 2.0 status, …).

Inherited from ​

BaseKem.info

Methods ​

decapsulate() ​

decapsulate(secretKey, ciphertext): SecretBytes

Defined in: kem.ts:70

Recovers the shared secret from ciphertext.

ML-KEM uses implicit rejection (FIPS 203): a ciphertext that was not produced for this key yields a pseudorandom secret rather than an error, so a wrong ciphertext is detected downstream (for example by AEAD authentication), not here.

Parameters ​

secretKey ​

SecretKey

ciphertext ​

Uint8Array

Returns ​

SecretBytes

Throws ​

if the ciphertext has the wrong structure or length.

Inherited from ​

BaseKem.decapsulate


encapsulate() ​

encapsulate(publicKey): Encapsulation

Defined in: kem.ts:47

Encapsulates a fresh shared secret to publicKey.

Parameters ​

publicKey ​

PublicKey

Returns ​

Encapsulation

Throws ​

if the key belongs to a different algorithm.

Throws ​

if the key bytes are invalid.

Inherited from ​

BaseKem.encapsulate


generateKeyPair() ​

generateKeyPair(): KeyPair

Defined in: kem.ts:38

Generates a key pair. Free it (or use using) when done.

Returns ​

KeyPair

Inherited from ​

BaseKem.generateKeyPair

Apache-2.0.