Auditable Conformance and Cross-Library Interoperability Testing for ML-KEM and ML-DSA
Abstract
1. Introduction
2. Cryptographic and Engineering Background
2.1. Module-Lattice Foundations and Standardized Algorithms
2.2. Aigis Constructions and Domestic Implementation Context
2.3. Algorithm Families and Engineering Consequences
2.4. Related Benchmarking and Interoperability Evidence
3. Experimental Methodology
3.1. Experimental Scope and Platform
3.2. Correctness Gates
3.3. Adaptive-Batch Timing
3.4. Evidence Provenance and Comparison Rules
3.5. Reproducibility Package
3.6. Native Conformance and Interoperability Architecture
3.7. Vector Selection, Bidirectional Cases, and Mutation Policy
4. Results
4.1. Supporting Broad KEM and Signature Baselines
4.2. ML-KEM Comparison Between Liboqs and PQMagic
4.3. ML-DSA Comparison Between Liboqs and PQMagic
4.4. Supporting Aigis-Enc and Aigis-Sig Measurements
4.5. Supporting SHAKE-to-SM3 Backend Comparison
4.6. Certificate Payload Provenance
4.7. Quantitative Comparison with Abbasi et al.
4.8. Security Targets and Non-Equivalent Scales
4.9. Official Standards-Vector Conformance
4.10. Full-Parameter Bidirectional Interoperability
4.11. Negative Cases and Compatibility Boundaries
4.12. Supporting Same-Commit Cross-Build Replay
5. Deployment Considerations: A Taxonomy and Checklist
5.1. Five Categories of Considerations
5.2. Illustrative Workload Estimates
5.3. Agility and Future Regression Checks
5.4. Scenario Viewpoints
6. Discussion
6.1. Primary Contribution and Supporting Observations
6.2. Single-Session Interpretation and Temporal Sensitivity
6.3. Security and Implementation Risk
6.4. Implementation and Supply-Chain Diversity
6.5. Compatibility Evidence Beyond Performance Benchmarking
7. Threats to Validity
8. Conclusions
Supplementary Materials
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Shor, P.W. Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 1997, 26, 1484–1509. [Google Scholar] [CrossRef] [Scilit]
- Grover, L.K. A fast quantum mechanical algorithm for database search. In Proceedings of the 28th Annual ACM Symposium on Theory of Computing; ACM: New York, NY, USA, 1996; pp. 212–219. [Google Scholar] [CrossRef] [Scilit]
- Chen, L.; Jordan, S.; Liu, Y.-K.; Moody, D.; Peralta, R.; Perlner, R.; Smith-Tone, D. NISTIR 8105: Report on Post-Quantum Cryptography; NIST: Gaithersburg, MD, USA, 2016. [CrossRef] [Scilit]
- Mosca, M. Cybersecurity in an era with quantum computers: Will we be ready? IEEE Secur. Priv. 2018, 16, 38–41. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard; NIST: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- National Institute of Standards and Technology. FIPS 204: Module-Lattice-Based Digital Signature Standard; NIST: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- Abbasi, M.; Cardoso, F.; Vaz, P.; Silva, J.; Martins, P. A practical performance benchmark of post-quantum cryptography across heterogeneous computing environments. Cryptography 2025, 9, 32. [Google Scholar] [CrossRef] [Scilit]
- Souvatzidaki, K.; Limniotis, K. Post-Quantum Key Exchange in TLS 1.3: Further Analysis on Performance of New Cryptographic Standards. Cryptography 2025, 9, 73. [Google Scholar] [CrossRef] [Scilit]
- Raavi, F.; Khan, F.; Wuthier, F.; Chandramouli, P.; Balytskyi, Y.; Chang, S.-Y. Security and Performance Analyses of Post-Quantum Digital Signature Algorithms and Their TLS and PKI Integrations. Cryptography 2025, 9, 38. [Google Scholar] [CrossRef] [Scilit]
- Liu, H.; Chen, L.; Lu, X.; Wang, H.; Bai, L.; Wang, M.; Ren, P. A visual-textual mutual guidance fusion network for remote sensing visual question answering. Pattern Recognit. 2026, 176, 113258. [Google Scholar] [CrossRef] [Scilit]
- Li, X.; Sun, W.; Ji, Y.; Huang, W. A Plot-to-Track Association Framework Based on Graph Representation Learning for Compact HFSWR. IEEE Trans. Aerosp. Electron. Syst. 2026, 62, 12742–12760. [Google Scholar] [CrossRef] [Scilit]
- Dam, D.-T.; Tran, T.-H.; Hoang, V.-P.; Pham, C.-K.; Hoang, T.-T. A Survey of Post-Quantum Cryptography: Start of a New Race. Cryptography 2023, 7, 40. [Google Scholar] [CrossRef] [Scilit]
- Fitzgibbon, G.; Ottaviani, C. Constrained Device Performance Benchmarking with the Implementation of Post-Quantum Cryptography. Cryptography 2024, 8, 21. [Google Scholar] [CrossRef] [Scilit]
- Barker, W.; Polk, W.; Souppaya, M. Getting Ready for Post-Quantum Cryptography: Exploring Challenges Associated with Adopting and Using Post-Quantum Cryptographic Algorithms; NIST Cybersecurity White Paper 15; NIST: Gaithersburg, MD, USA, 2021. [CrossRef] [Scilit]
- Ahmed, N.; Zhang, L.; Gangopadhyay, A. A Survey of Post-Quantum Cryptography Support in Cryptographic Libraries. In Proceedings of the 2025 IEEE International Conference on Quantum Computing and Engineering (QCE); IEEE: New York, NY, USA, 2025; pp. 906–917. [Google Scholar] [CrossRef] [Scilit]
- Paquin, C.; Stebila, D.; Tamvada, G. Benchmarking Post-quantum Cryptography in TLS. In Post-Quantum Cryptography; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2020; pp. 72–91. [Google Scholar] [CrossRef] [Scilit]
- Regev, O. On lattices, learning with errors, random linear codes, and cryptography. In Proceedings of STOC 2005; ACM: New York, NY, USA, 2005; pp. 84–93. [Google Scholar] [CrossRef] [Scilit]
- Lyubashevsky, V.; Peikert, C.; Regev, O. On ideal lattices and learning with errors over rings. In EUROCRYPT 2010; Springer: Berlin, Germany, 2010; pp. 1–23. [Google Scholar] [CrossRef] [Scilit]
- Albrecht, M.R.; Player, R.; Scott, S. On the concrete hardness of learning with errors. J. Math. Cryptol. 2015, 9, 169–203. [Google Scholar] [CrossRef] [Scilit]
- Fujisaki, E.; Okamoto, T. Secure integration of asymmetric and symmetric encryption schemes. In CRYPTO 1999; Springer: Berlin, Germany, 1999; pp. 537–554. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Bos, J.; Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schanck, J.M.; Schwabe, P.; Seiler, G.; Stehle, D. CRYSTALS-Kyber: A CCA-secure module-lattice-based KEM. In 2018 IEEE European Symposium on Security and Privacy; IEEE: Piscataway, NJ, USA, 2018; pp. 353–367. [Google Scholar] [CrossRef] [Scilit]
- Hofheinz, D.; Hovelmanns, K.; Kiltz, E. A modular analysis of the Fujisaki–Okamoto transformation. In TCC 2017; Springer: Cham, Switzerland, 2017; pp. 341–371. [Google Scholar] [CrossRef] [Scilit]
- Jiang, H.; Zhang, Z.; Chen, L.; Wang, H.; Ma, Z. IND-CCA-secure key encapsulation mechanism in the quantum random oracle model, revisited. In CRYPTO 2018; Springer: Cham, Switzerland, 2018; pp. 96–125. [Google Scholar] [CrossRef] [Scilit]
- Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schwabe, P.; Seiler, G.; Stehlé, D. CRYSTALS-Dilithium: A lattice-based digital signature scheme. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2018, 2018, 238–268. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. FIPS 202: SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions; NIST: Gaithersburg, MD, USA, 2015. [CrossRef] [Scilit]
- GB/T 32905-2016; Information Security Technology–SM3 Cryptographic Hash Algorithm. Standards Press of China: Beijing, China, 2016.
- Zhang, J.; Yu, Y.; Fan, S.; Zhang, Z.; Yang, K. Tweaking the asymmetry of asymmetric-key cryptography on lattices: KEMs and signatures of smaller sizes. In Public-Key Cryptography–PKC 2020; Springer: Cham, Switzerland, 2020; pp. 37–65. [Google Scholar] [CrossRef] [Scilit]
- Chen, M.-S.; Chou, T. Classic McEliece on the ARM Cortex-M4. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021, 2021, 125–148. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. FIPS 205: Stateless Hash-Based Digital Signature Standard; NIST: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- Open Quantum Safe. liboqs: C Library for Quantum-Resistant Cryptographic Algorithms. Available online: https://github.com/open-quantum-safe/liboqs (accessed on 16 July 2026).
- PQCrypto. PQMagic: Post-Quantum Cryptographic Algorithm Library. Available online: https://gitee.com/pqcrypto/pqmagic (accessed on 16 July 2026).
- Stebila, D.; Mosca, M. Post-quantum key exchange for the Internet and the Open Quantum Safe project. In Selected Areas in Cryptography–SAC 2016; Springer: Cham, Switzerland, 2017; pp. 14–37. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. Automated Cryptographic Validation Protocol Documentation. Available online: https://pages.nist.gov/ACVP/ (accessed on 9 September 2026).
- Barker, E.; Chen, L.; Cooper, D.; Moody, D.; Regenscheid, A.; Souppaya, M.; Newhouse, W.; Housley, R.; Turner, S.; Barker, W.C.; et al. Considerations for Achieving Crypto Agility: Strategies and Practices; NIST: Gaithersburg, MD, USA, 2025. [CrossRef] [Scilit]














| Evidence Type | Definition | Permitted Inference | Prohibited Inference |
|---|---|---|---|
| Measured | Observed by a stated benchmark with an identified scope | Performance or size under that scope | Universal algorithm ranking |
| Derived | Calculated from measured inputs | Ratios, throughput, and confidence intervals | Independent physical measurement |
| Estimated | Produced by an explicit model | Scenario sizing under stated assumptions | Claim of generated protocol artifacts |
| Theoretical | Obtained from standards or primary literature | Complexity, hardness assumptions, and security categories | Observed runtime or proof of implementation security |
| Scheme/Family | Security Basis | Dominant Software Work | Indicative Complexity | Engineering Implication |
|---|---|---|---|---|
| ML-KEM | Module-LWE with FO-style CCA conversion | NTT, polynomial arithmetic, Keccak | Balanced standardized KEM; moderate artifacts | |
| ML-DSA | Module-LWE and Module-SIS | NTT, rejection sampling, hashing | Expected | Fast verification; signatures larger than ECC |
| Aigis-Enc | AMLWE/AMLWE-R with FO transformation | Compressed module-lattice arithmetic | Domestic implementation path; interoperability must be managed | |
| Aigis-Sig | AMLWE and AMSIS | NTT, decomposition, rejection sampling | Expected | Domestic signature option with implementation-specific evidence |
| Classic McEliece | Binary Goppa-code syndrome decoding | Finite-field operations and decoding | Parameter dependent | Very large public key but small ciphertext |
| FrodoKEM | Plain LWE | Dense matrix arithmetic | Conservative structure with high bandwidth cost | |
| Falcon/FN-DSA | NTRU lattices | FFT-like sampling | Compact signature but demanding constant-time implementation |
| Item | Configuration | Evidence Role |
|---|---|---|
| Host | Windows 10, x86_64, Intel Family 6 Model 141 | Single host; Microsoft/Redmond WA and Intel/Santa Clara CA, USA |
| Python | 3.13.0; PSF (Beaverton, OR, USA) | Benchmark orchestration only |
| PQMagic build | PQMagic/PQCrypto 9613aa3c; Release; Clang 20.1.2; x86_64 | LLVM/llvm.org; Kitware/Clifton Park NY, USA; SHAKE/SM3 builds |
| liboqs runtime | liboqs/OQS 0.15.0 (97f6b86b); 29 KEMs and 221 signature mechanisms | OQS/openquantumsafe.org; common ML-KEM/ML-DSA baseline |
| Instruction availability | SSE2/SSE4, AES, PCLMULQDQ, AVX/AVX2/AVX-512, SHA reported available | Capability metadata; not proof of per-path instruction use |
| Repeated observations | 50 adaptive batches per operation after 10 warm-ups | Repeated batches within the primary session |
| Batch target | Approximately 20 ms per timed batch | Reduces timer and Python-call granularity |
| Stage | KEM Gate | Signature Gate | Recorded Output |
|---|---|---|---|
| Positive correctness | Encapsulated and decapsulated secrets must match | Valid signature must verify | Pass/fail status |
| Negative correctness | Not applicable to the selected API gate | Modified message must be rejected | Return code and rejection status |
| Warm-up | 10 untimed calls | 10 untimed calls | Warm-up count |
| Calibration | Batch size doubled to about 20 ms | Same procedure | Selected batch size |
| Measurement | 50 per-operation batch means | 50 per-operation batch means | Mean, median, sample SD, min, max, P95, CI |
| Independent check | Representative native executable | Representative native executable | Eight program return codes |
| Layer | Executed Evidence | Required Result | Failure Classification |
|---|---|---|---|
| Build contract | Pinned commits, binary hashes, 33 PQMagic symbols | Exact descriptor and symbol closure | Infrastructure failure |
| Official vectors | FIPS 203/204 ACVP projections | Exact bytes or expected verification result | VECTOR_MISMATCH |
| Positive interoperability | Two KEM and two signature directions | Shared-secret equality or successful verification | INTEROP_FAILURE |
| Negative cases | Deterministic one-bit mutations | Rejection; stable ML-KEM implicit-rejection secret | INTEROP_FAILURE |
| Supporting same-commit replay | Archived/clean builds of one commit; producer–consumer subprocesses | Recorded artifact remains consumable for the tested build pair | BUILD_REPLAY_FAILURE |
| Primitive/Algorithm | KeyGen Mean ± h0.95 (ms) | Public/Peer Operation Mean (ms) | Private Operation Mean (ms) | Public Key (B) | Peer Artifact (B) |
|---|---|---|---|---|---|
| X25519 | 0.2991 ± 0.4549 | 0.0308 ± 0.0024 | 0.0292 ± 0.0002 | 32 | 32 |
| ECDH-P256 | 0.0419 ± 0.0115 | 0.0588 ± 0.0019 | 0.0580 ± 0.0022 | 91 | 91 |
| RSA-2048 | 42.1939 ± 6.2774 | 0.0782 ± 0.0131 | 0.6681 ± 0.0217 | 294 | 256 |
| RSA-3072 | 144.6304 ± 25.3711 | 0.0957 ± 0.0037 | 1.4027 ± 0.0210 | 422 | 384 |
| RSA-4096 | 447.0856 ± 77.7060 | 0.1321 ± 0.0095 | 2.5197 ± 0.0294 | 550 | 512 |
| ML-KEM-512 | 0.2138 ± 0.0124 | 0.2069 ± 0.0044 | 0.0292 ± 0.0004 | 800 | 768 |
| ML-KEM-768 | 0.2161 ± 0.0051 | 0.2159 ± 0.0036 | 0.0413 ± 0.0006 | 1184 | 1088 |
| ML-KEM-1024 | 0.2368 ± 0.0063 | 0.2413 ± 0.0084 | 0.0581 ± 0.0005 | 1568 | 1568 |
| Classic-McEliece-348864 | 194.3801 ± 43.4381 | 0.5462 ± 0.0999 | 13.9493 ± 0.1800 | 261,120 | 96 |
| FrodoKEM-640-AES | 0.5002 ± 0.0385 | 0.6093 ± 0.0318 | 0.3526 ± 0.0027 | 9616 | 9720 |
| Algorithm | KeyGen Mean ± h0.95 (ms) | Sign Mean ± h0.95 (ms) | Verify Mean ± h0.95 (ms) | Public Key (B) | Signature (B) |
|---|---|---|---|---|---|
| ECDSA-P256 | 0.0174 ± 0.0018 | 0.0394 ± 0.0140 | 0.0666 ± 0.0011 | 91 | 71 |
| Ed25519 | 0.0334 ± 0.0010 | 0.0334 ± 0.0013 | 0.0936 ± 0.0020 | 32 | 64 |
| RSA-2048 | 38.5568 ± 6.2677 | 0.6528 ± 0.0126 | 0.0437 ± 0.0042 | 294 | 256 |
| RSA-3072 | 128.1143 ± 18.8101 | 1.4169 ± 0.0114 | 0.0632 ± 0.0007 | 422 | 384 |
| RSA-4096 | 451.9183 ± 86.2340 | 2.5784 ± 0.0340 | 0.0990 ± 0.0031 | 550 | 512 |
| ML-DSA-44 | 0.2783 ± 0.0119 | 0.4685 ± 0.0496 | 0.0773 ± 0.0020 | 1312 | 2420 |
| ML-DSA-65 | 0.3345 ± 0.0135 | 0.5804 ± 0.0705 | 0.1220 ± 0.0050 | 1952 | 3309 |
| ML-DSA-87 | 0.3964 ± 0.0126 | 0.6984 ± 0.0781 | 0.1910 ± 0.0051 | 2592 | 4627 |
| Falcon-512 | 4.9984 ± 0.4213 | 0.6247 ± 0.0234 | 0.0497 ± 0.0043 | 897 | 656 |
| Falcon-1024 | 14.9868 ± 1.4783 | 0.8937 ± 0.0686 | 0.0886 ± 0.0086 | 1793 | 1270 |
| Algorithm | Operation | Liboqs (ms) | PQMagic-SHAKE (ms) | PQMagic/Liboqs |
|---|---|---|---|---|
| ML-KEM-1024 | Decaps | 0.0599 ± 0.0017 | 0.0727 ± 0.0018 | 1.213 |
| ML-KEM-1024 | Encaps | 0.2804 ± 0.0076 | 0.2465 ± 0.0112 | 0.879 |
| ML-KEM-1024 | KeyGen | 0.3101 ± 0.0097 | 0.3507 ± 0.0161 | 1.131 |
| ML-KEM-512 | Decaps | 0.0279 ± 0.0007 | 0.0364 ± 0.0010 | 1.306 |
| ML-KEM-512 | Encaps | 0.2118 ± 0.0047 | 0.2902 ± 0.0216 | 1.370 |
| ML-KEM-512 | KeyGen | 0.2370 ± 0.0082 | 0.2548 ± 0.0126 | 1.075 |
| ML-KEM-768 | Decaps | 0.0417 ± 0.0013 | 0.0515 ± 0.0009 | 1.235 |
| ML-KEM-768 | Encaps | 0.2687 ± 0.0073 | 0.2917 ± 0.0139 | 1.086 |
| ML-KEM-768 | KeyGen | 0.2867 ± 0.0108 | 0.3938 ± 0.0198 | 1.374 |
| Algorithm | Operation | Liboqs (ms) | PQMagic-SHAKE (ms) | PQMagic/Liboqs |
|---|---|---|---|---|
| ML-DSA-44 | KeyGen | 0.3306 ± 0.0115 | 0.2593 ± 0.0128 | 0.784 |
| ML-DSA-44 | Sign | 0.5342 ± 0.0109 | 0.1004 ± 0.0020 | 0.188 |
| ML-DSA-44 | Verify | 0.0762 ± 0.0011 | 0.0606 ± 0.0011 | 0.795 |
| ML-DSA-65 | KeyGen | 0.3130 ± 0.0109 | 0.3158 ± 0.0146 | 1.009 |
| ML-DSA-65 | Sign | 0.6857 ± 0.0248 | 0.1616 ± 0.0039 | 0.236 |
| ML-DSA-65 | Verify | 0.1197 ± 0.0026 | 0.1032 ± 0.0025 | 0.862 |
| ML-DSA-87 | KeyGen | 0.4340 ± 0.0134 | 0.3416 ± 0.0071 | 0.787 |
| ML-DSA-87 | Sign | 0.8039 ± 0.0306 | 0.3315 ± 0.0054 | 0.412 |
| ML-DSA-87 | Verify | 0.1925 ± 0.0046 | 0.1689 ± 0.0039 | 0.877 |
| Algorithm | Operation Means ± h0.95 (ms) | Public Key (B) | Ciphertext/Signature (B) | Three-Operation Sum (ms) |
|---|---|---|---|---|
| Aigis-Enc-1 | KeyGen 0.2179 ± 0.0089; Encaps 0.2549 ± 0.0107; Decaps 0.0410 ± 0.0010 | 672 | 736 | 0.5138 |
| Aigis-Enc-2 | KeyGen 0.2178 ± 0.0082; Encaps 0.3109 ± 0.0112; Decaps 0.0562 ± 0.0017 | 896 | 992 | 0.5850 |
| Aigis-Enc-3 | KeyGen 0.2017 ± 0.0065; Encaps 0.2994 ± 0.0110; Decaps 0.0555 ± 0.0014 | 992 | 1056 | 0.5567 |
| Aigis-Enc-4 | KeyGen 0.2652 ± 0.0113; Encaps 0.3055 ± 0.0092; Decaps 0.0844 ± 0.0026 | 1440 | 1568 | 0.6552 |
| Aigis-Sig-1 | KeyGen 0.2304 0.0104; Sign 0.4046 0.0045; Verify 0.0558 0.0014 | 1056 | 1852 | 0.6908 |
| Aigis-Sig-2 | KeyGen 0.2823 ± 0.0064; Sign 0.2967 ± 0.0059; Verify 0.0794 ± 0.0013 | 1312 | 2445 | 0.6585 |
| Aigis-Sig-3 | KeyGen 0.2903 ± 0.0094; Sign 0.4258 ± 0.0113; Verify 0.1087 ± 0.0033 | 1568 | 3046 | 0.8248 |
| Family | Mean Ratio | Median Ratio | Minimum | Maximum |
|---|---|---|---|---|
| Aigis-Enc | 1.344 | 1.251 | 0.935 | 1.853 |
| Aigis-Sig | 1.968 | 1.800 | 0.799 | 2.931 |
| ML-DSA | 2.881 | 2.394 | 1.377 | 7.481 |
| ML-KEM | 1.198 | 1.022 | 0.741 | 1.693 |
| Algorithm | Size (B) | Evidence | Method |
|---|---|---|---|
| RSA-2048 | 891 | Measured | DER certificate generated locally |
| RSA-3072 | 1147 | Measured | DER certificate generated locally |
| RSA-4096 | 1403 | Measured | DER certificate generated locally |
| ML-DSA-44 | 4032 | Estimated | public key + signature + 300 B fixed structural allowance |
| ML-DSA-65 | 5561 | Estimated | public key + signature + 300 B fixed structural allowance |
| ML-DSA-87 | 7519 | Estimated | public key + signature + 300 B fixed structural allowance |
| Falcon-512 | 1848 | Estimated | public key + signature + 300 B fixed structural allowance |
| Falcon-1024 | 3360 | Estimated | public key + signature + 300 B fixed structural allowance |
| Algorithm | Operation | This Work: Local Liboqs (ms) | Abbasi Laptop E2 (ms) | Local/External | External Source |
|---|---|---|---|---|---|
| ML-KEM-768 | KeyGen | 0.2867 ± 0.0108 | 0.280 | 1.024 | Table 4 |
| ML-KEM-768 | Encaps | 0.2687 ± 0.0073 | 0.220 | 1.221 | Table 4 |
| ML-KEM-768 | Decaps | 0.0417 ± 0.0013 | 0.250 | 0.167 | Table 4 |
| ML-DSA-65 | KeyGen | 0.3130 ± 0.0109 | 0.360 | 0.870 | Table 4 |
| ML-DSA-65 | Sign | 0.6857 ± 0.0248 | 0.420 | 1.633 | Table 4 |
| ML-DSA-65 | Verify | 0.1197 ± 0.0026 | 0.250 | 0.479 | Table 4 |
| Algorithm/Parameter Set | Family | Reported Target | Underlying Problem | Interpretation |
|---|---|---|---|---|
| RSA-2048 | Classical | 112 estimated classical bits | integer factorization | Classical estimate; not post-quantum secure |
| RSA-3072 | Classical | 128 estimated classical bits | integer factorization | Classical estimate; not post-quantum secure |
| ECDH/ECDSA P-256 | Classical | 128 estimated classical bits | elliptic-curve discrete logarithm | Classical estimate; not post-quantum secure |
| X25519/Ed25519 | Classical | 128 estimated classical bits | elliptic-curve discrete logarithm | Classical estimate; not post-quantum secure |
| ML-KEM-512/ML-DSA-44 | Lattice | NIST Category 1 | Module-LWE/Module-SIS | NIST category; not a continuous bit-equivalent scale |
| ML-KEM-768/ML-DSA-65 | Lattice | NIST Category 3 | Module-LWE/Module-SIS | NIST category; not a continuous bit-equivalent scale |
| ML-KEM-1024/ML-DSA-87 | Lattice | NIST Category 5 | Module-LWE/Module-SIS | NIST category; not a continuous bit-equivalent scale |
| Falcon-512/FN-DSA | Lattice signature | NIST Category 1 | NTRU lattice problems | Category claim subject to the FN-DSA standardization status |
| Classic McEliece-348864 | Code-based | NIST Category 1 | syndrome decoding | NIST category; not a continuous bit-equivalent scale |
| Operation | Implementation | Cases | Pass | Comparison Contract |
|---|---|---|---|---|
| kem-keygen | liboqs | 75 | 75 | Exact bytes |
| kem-keygen | pqmagic | 75 | 75 | Exact bytes |
| kem-encaps | liboqs | 75 | 75 | Exact bytes |
| kem-encaps | pqmagic | 75 | 75 | Exact bytes |
| kem-decaps | liboqs | 30 | 30 | Exact bytes |
| kem-decaps | pqmagic | 30 | 30 | Exact bytes |
| sig-keygen | liboqs | 75 | 75 | Exact bytes |
| sig-keygen | pqmagic | 75 | 75 | Exact bytes |
| sig-sign | liboqs | 45 | 45 | Exact bytes |
| sig-sign | pqmagic | 45 | 45 | Exact bytes |
| sig-verify | liboqs | 45 | 45 | Expected Boolean result |
| sig-verify | pqmagic | 45 | 45 | Expected Boolean result |
| Parameter Set | Cross-Implementation Test Path | Executed Cases | Passed Cases |
|---|---|---|---|
| ML-KEM-512 | PQMagic KeyGen → liboqs Encaps → PQMagic Decaps | 100 | 100 |
| ML-KEM-512 | liboqs KeyGen → PQMagic Encaps → liboqs Decaps | 100 | 100 |
| ML-KEM-768 | PQMagic KeyGen → liboqs Encaps → PQMagic Decaps | 100 | 100 |
| ML-KEM-768 | liboqs KeyGen → PQMagic Encaps → liboqs Decaps | 100 | 100 |
| ML-KEM-1024 | PQMagic KeyGen → liboqs Encaps → PQMagic Decaps | 100 | 100 |
| ML-KEM-1024 | liboqs KeyGen → PQMagic Encaps → liboqs Decaps | 100 | 100 |
| ML-DSA-44 | PQMagic Sign → liboqs Verify | 100 | 100 |
| ML-DSA-44 | liboqs Sign → PQMagic Verify | 100 | 100 |
| ML-DSA-65 | PQMagic Sign → liboqs Verify | 100 | 100 |
| ML-DSA-65 | liboqs Sign → PQMagic Verify | 100 | 100 |
| ML-DSA-87 | PQMagic Sign → liboqs Verify | 100 | 100 |
| ML-DSA-87 | liboqs Sign → PQMagic Verify | 100 | 100 |
| Configuration | Mutation or Boundary | Rows | Result |
|---|---|---|---|
| liboqs | ciphertext | 9 | 9 |
| pqmagic | ciphertext | 9 | 9 |
| liboqs | message | 9 | 9 |
| liboqs | signature | 9 | 9 |
| liboqs | public_key | 9 | 9 |
| liboqs | context | 9 | 9 |
| pqmagic | message | 9 | 9 |
| pqmagic | signature | 9 | 9 |
| pqmagic | public_key | 9 | 9 |
| pqmagic | context | 9 | 9 |
| PQMagic-SM3/Aigis | Compatibility boundary | 13 | NOT_APPLICABLE |
| Parameter Set | Build Direction | Pass | Producer Hash Prefix | Consumer Hash Prefix |
|---|---|---|---|---|
| ML-KEM-512 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-KEM-512 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| ML-KEM-768 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-KEM-768 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| ML-KEM-1024 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-KEM-1024 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| ML-DSA-44 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-DSA-44 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| ML-DSA-65 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-DSA-65 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| ML-DSA-87 | Baseline → Current | 1 | 381842658b42 | c99f1eb5ec28 |
| ML-DSA-87 | Current → Baseline | 1 | c99f1eb5ec28 | 381842658b42 |
| Dimension | Primary Evidence | Checklist Question | Evidence Boundary/Further Work |
|---|---|---|---|
| Computation | Measured operation time and theoretical arithmetic | Can the workload meet latency/throughput targets? | Specify operation mix; no aggregate decision score is validated |
| Storage | Measured key and output sizes | Can endpoints and key stores hold the material? | API sizes only; measure native workspace and storage overhead separately |
| Time | Mean, P95, CI, and cross-session sensitivity | Is the timing baseline repeatable enough for regression use? | Snapshot only; replicate sessions before setting regression thresholds |
| Network | Public key plus ciphertext/signature bytes | Will handshakes, certificates, or updates fragment? | Payload estimates only; measure protocol traces and fragmentation |
| Deployment | Standards status, backend, implementation source, correctness gates | What additional evidence is needed for integration and release migration? | Require protocol and cross-version tests; same-commit replay is insufficient |
| Scenario | Illustrative Starting Point | Why | Condition or Caveat |
|---|---|---|---|
| Interoperable Internet-facing key establishment | ML-KEM-768 in a standards-oriented stack | Standard status and balanced size/performance | Protocol and certificate behavior still require real integration tests |
| Controlled domestic infrastructure | PQMagic ML-KEM/ML-DSA or Aigis with optional SM3 | Domestic maintenance path and SM3 compatibility | Enable SM3 selectively because overhead is operation dependent |
| High-volume signing service | Benchmark ML-DSA implementation and parameter set against actual sign/verify mix | PQMagic-SHAKE signing was faster locally | Key protection and side-channel controls dominate production acceptance |
| Firmware verification | ML-DSA or compact-signature alternative | Verification and artifact size matter more than key generation | Long-lived verifier updates must support algorithm replacement |
| Constrained links | Prefer moderate artifacts; avoid unmodeled certificate expansion | Fragmentation can dominate primitive latency | Use measured protocol traces before deployment |
| Algorithm-diversity requirement | Hybrid or dual-track implementation | Reduces dependence on one mathematical family or supplier | Composition, negotiation, downgrade resistance, and lifecycle management must be specified |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Xie, S.; Lu, X.; Wang, H.; Zhao, H. Auditable Conformance and Cross-Library Interoperability Testing for ML-KEM and ML-DSA. Computers 2026, 15, 642. https://doi.org/10.3390/computers15100642
Xie S, Lu X, Wang H, Zhao H. Auditable Conformance and Cross-Library Interoperability Testing for ML-KEM and ML-DSA. Computers. 2026; 15(10):642. https://doi.org/10.3390/computers15100642
Chicago/Turabian StyleXie, Sijiang, Xingyu Lu, Haida Wang, and Hong Zhao. 2026. "Auditable Conformance and Cross-Library Interoperability Testing for ML-KEM and ML-DSA" Computers 15, no. 10: 642. https://doi.org/10.3390/computers15100642
APA StyleXie, S., Lu, X., Wang, H., & Zhao, H. (2026). Auditable Conformance and Cross-Library Interoperability Testing for ML-KEM and ML-DSA. Computers, 15(10), 642. https://doi.org/10.3390/computers15100642

