Comment by westurner
16 hours ago
Is this the thing with ML-KEM, then:
> [With AuthKEM,] you would replace the ~2.4 KB ML-DSA signature with a ~1 KB ML-KEM ciphertext.
16 hours ago
Is this the thing with ML-KEM, then:
> [With AuthKEM,] you would replace the ~2.4 KB ML-DSA signature with a ~1 KB ML-KEM ciphertext.
What "the thing"? AuthKEM isn't being deployed anywhere.
How much more complex is the difference than 2.4 KB w/ ML-DSA or ~1 KB w/ ML-KEM?