{"catalogVersion":"pke-kem-dossier-v3-atomic-contributions","constructions":[{"adaptive_security":null,"api_style":"PKE","associated_data":null,"assumption_family":"code-based","assumption_id":"PKE-ASSUMPTION-DECODING-A-DISGUISED-BINARY-GOPPA-CODE","assumption_name":"decoding a disguised binary Goppa code","authors":["Robert J. McEliece"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["code-based-encryption","post-quantum-lineage"],"ciphertext_security":"historical one-wayness target; not a modern CCA profile","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"code_based","correctness":null,"corruption_model":null,"decapsulation_cost":"secret-code decoding","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"bounded by the selected code/error profile","encapsulation_cost":"not a KEM","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1978-MCELIECE","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"historical research construction","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Public-Key Cryptosystem Based on Algebraic Coding Theory","paper_url":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"public_key_encryption","privacy_model":null,"proof_model":null,"quantum_security":"post-quantum design family; this historical profile is not a current standard","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"code-decoding","security_notion":"historical computational security","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"codeword plus error vector","public_key":"disguised generator matrix","shared_secret":"not applicable"},"statefulness":null,"summary":"The original PKE anchors the code-based family; later CCA-secure KEM specifications require separate records.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"error-vector masking","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1978-MCELIECE","year":1978},{"adaptive_security":null,"api_style":"PKE","associated_data":null,"assumption_family":"factoring","assumption_id":"PKE-ASSUMPTION-RSA-INVERSION","assumption_name":"RSA inversion","authors":["Ronald L. Rivest","Adi Shamir","Leonard M. Adleman"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["public-key-confidentiality-root"],"ciphertext_security":"deterministic; not IND-CPA","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"rsa","correctness":null,"corruption_model":null,"decapsulation_cost":"one private RSA operation","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"none for valid algebraic inputs","encapsulation_cost":"not a KEM","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1978-RSA","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"historical foundation; not secure for deployment by itself","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","paper_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"public_key_encryption","privacy_model":null,"proof_model":null,"quantum_security":"no","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"deterministic trapdoor permutation","security_notion":"not IND-CPA as written","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"one RSA residue","public_key":"modulus and public exponent","shared_secret":"not applicable"},"statefulness":null,"summary":"This card exists to anchor the RSA branch. Randomized encoding is required for modern encryption security.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"none","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1978-RSA","year":1978},{"adaptive_security":null,"api_style":"PKE","associated_data":null,"assumption_family":"discrete logarithm","assumption_id":"PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","assumption_name":"Decisional Diffie–Hellman","authors":["Taher ElGamal"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["randomized-encryption","multiplicative-homomorphism"],"ciphertext_security":"IND-CPA under DDH in an appropriate group; malleable and not CCA secure","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"discrete_log","correctness":null,"corruption_model":null,"decapsulation_cost":"one secret exponentiation plus group operations","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"none for valid group inputs","encapsulation_cost":"not a KEM","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1985-ELGAMAL","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"research foundation","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms","paper_url":"https://doi.org/10.1109/TIT.1985.1057074","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"public_key_encryption","privacy_model":null,"proof_model":null,"quantum_security":"no","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard model in a DDH group","security_notion":"IND-CPA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"two group elements","public_key":"one group element plus group description","shared_secret":"not applicable"},"statefulness":null,"summary":"The multiplicative structure explains both the clean security reduction and the malleability that later CCA-secure designs address.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"ephemeral Diffie–Hellman masking","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1985-ELGAMAL","year":1985},{"adaptive_security":null,"api_style":"transform","associated_data":null,"assumption_family":"RSA / random oracle","assumption_id":"PKE-ASSUMPTION-TRAPDOOR-PERMUTATION-SECURITY-PLUS-RANDOM-ORACLES","assumption_name":"trapdoor permutation security plus random oracles","authors":["Mihir Bellare","Phillip Rogaway"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["randomized-encoding","malformed-ciphertext-rejection"],"ciphertext_security":"randomized-encoding transform with an original random-oracle CCA claim; the generic proof gap and later instantiation-specific results must be kept separate","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"rsa_encoding","correctness":null,"corruption_model":null,"decapsulation_cost":"one inverse permutation plus hash/encoding checks","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"explicit reject on malformed encoding","encapsulation_cost":"not a KEM","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1994-OAEP","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"research transform; RSA-OAEP is profiled by later standards","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Optimal Asymmetric Encryption — How to Encrypt with RSA","paper_url":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"public_key_encryption_transform","privacy_model":null,"proof_model":null,"quantum_security":"no for RSA instantiation","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"random oracle","security_notion":"CCA-oriented security program rather than a generic theorem for every trapdoor permutation","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"one permutation image","public_key":"inherited from trapdoor permutation","shared_secret":"not applicable"},"statefulness":null,"summary":"The security cell is deliberately qualified: it does not merge the original OAEP claim with every later RSA-OAEP proof result.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"OAEP randomized Feistel-style encoding around a trapdoor permutation","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1994-OAEP","year":1994},{"adaptive_security":null,"api_style":"PKE","associated_data":null,"assumption_family":"discrete logarithm","assumption_id":"PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","assumption_name":"Decisional Diffie–Hellman","authors":["Ronald Cramer","Victor Shoup"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["cca2-security","ciphertext-validity-check"],"ciphertext_security":"IND-CCA2","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"discrete_log","correctness":null,"corruption_model":null,"decapsulation_cost":"group exponentiations plus consistency check","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"explicit reject on invalid consistency equation","encapsulation_cost":"not a KEM","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1998-CS","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"research construction","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack","paper_url":"https://crypto.ethz.ch/publications/CraSho98.html","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"public_key_encryption","privacy_model":null,"proof_model":null,"quantum_security":"no","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"public-key","security_model":"standard model","security_notion":"adaptive chosen-ciphertext security","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"four group elements/values","public_key":"several group elements plus hash description","shared_secret":"not applicable"},"statefulness":null,"summary":"Cramer–Shoup is the standard-model CCA landmark in this seed lineage.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"hash-bound consistency check over an ElGamal-like ciphertext","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1998-CS","year":1998},{"adaptive_security":null,"api_style":"transform","associated_data":null,"assumption_family":"generic composition","assumption_id":"PKE-ASSUMPTION-ONE-WAY-CPA-BASE-ENCRYPTION-PLUS-RANDOM-ORACLES","assumption_name":"one-way/CPA base encryption plus random oracles","authors":["Eiichiro Fujisaki","Tatsuaki Okamoto"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["cca-transform","hybrid-composition","reencryption-validation-lineage"],"ciphertext_security":"chosen-ciphertext secure in the specified random-oracle treatment","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"generic_transform","correctness":null,"corruption_model":null,"decapsulation_cost":"base decryption plus validation/re-encryption","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"inherited from base primitive plus explicit reject/re-encrypt check","encapsulation_cost":"base encryption plus hashing/symmetric work","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-1999-FO","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"research transform; many later KEMs use FO-family variants","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","paper_url":"https://doi.org/10.1007/3-540-48405-1_34","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"hybrid_pke_transform","privacy_model":null,"proof_model":null,"quantum_security":"depends on the base primitive and proof model","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"hybrid public-key","security_model":"random oracle","security_notion":"IND-CCA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"base ciphertext plus symmetric component","public_key":"inherited","shared_secret":"derived by hashing"},"statefulness":null,"summary":"Later KEMs use multiple FO variants; those variants must not be assumed identical without a construction-specific record.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"Fujisaki–Okamoto message-dependent hashing, re-encryption validation, and symmetric integration","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-1999-FO","year":1999},{"adaptive_security":null,"api_style":"KEM","associated_data":null,"assumption_family":"lattice","assumption_id":"PKE-ASSUMPTION-MODULE-LWE","assumption_name":"Module-LWE","authors":["Joppe Bos","Léo Ducas","Eike Kiltz","Tancrède Lepoint","Vadim Lyubashevsky","John M. Schanck","Peter Schwabe","Gregor Seiler","Damien Stehlé"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["post-quantum-kem","implicit-rejection","module-lattice-arithmetic"],"ciphertext_security":"IND-CCA KEM in the stated random-oracle treatment","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"module_lattice","correctness":null,"corruption_model":null,"decapsulation_cost":"module polynomial arithmetic plus validation/implicit rejection","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"negligible but nonzero; parameter-bound","encapsulation_cost":"module polynomial arithmetic plus hashing","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-2017-KYBER","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"research/NIST submission design; superseded normatively by ML-KEM","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM","paper_url":"https://eprint.iacr.org/2017/634","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"key_encapsulation_mechanism","privacy_model":null,"proof_model":null,"quantum_security":"post-quantum candidate lineage","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"key encapsulation","security_model":"ROM/QROM analyses by version","security_notion":"IND-CCA","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"parameter-set dependent","public_key":"parameter-set dependent","shared_secret":"fixed derived byte string"},"statefulness":null,"summary":"This row follows the 2020-10-14 full revision of ePrint 2017/634. Round-three Kyber and FIPS 203 ML-KEM are separate configurations and must not inherit byte-level claims from this row.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"FO-family transform over module-LWE/module-LWR-style PKE","update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"PKE-PAPER-2017-KYBER","year":2017},{"adaptive_security":null,"api_style":"hybrid framework","associated_data":null,"assumption_family":"composition","assumption_id":"PKE-ASSUMPTION-SUITE-DEPENDENT-KEM","assumption_name":"suite-dependent KEM","authors":["Richard Barnes","Karthikeyan Bhargavan","Benjamin Lipp","Christopher A. Wood"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["kem-dem-composition","sender-authentication-modes","associated-data"],"ciphertext_security":"suite- and mode-dependent; base, PSK, authenticated, and authenticated-PSK modes are distinct","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"kem_kdf_aead_composition","correctness":null,"corruption_model":null,"decapsulation_cost":"selected KEM decapsulation plus key schedule and AEAD open","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"KEM/AEAD rejection; suite-dependent","encapsulation_cost":"selected KEM encapsulation plus key schedule and AEAD seal","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-2022-HPKE","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"IETF RFC 9180","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Hybrid Public Key Encryption","paper_url":"https://www.rfc-editor.org/rfc/rfc9180.html","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"hybrid_public_key_encryption","privacy_model":null,"proof_model":null,"quantum_security":"RFC 9180 base KEM registry is classical","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"multi-mode hybrid PKE","security_model":"component composition","security_notion":"hybrid encryption security by mode","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"encapsulated key plus AEAD ciphertext/tag","public_key":"selected KEM public key","shared_secret":"KDF-derived context secret"},"statefulness":null,"summary":"HPKE is a framework rather than one algorithm; suite-dependent values remain explicitly unresolved in this row.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"KEM + labeled KDF + AEAD key schedule","update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"PKE-PAPER-2022-HPKE","year":2022},{"adaptive_security":null,"api_style":"KEM","associated_data":null,"assumption_family":"lattice","assumption_id":"PKE-ASSUMPTION-MODULE-LWE","assumption_name":"Module-LWE","authors":["National Institute of Standards and Technology"],"base_signature":null,"block_size":null,"bootstrapping":null,"capabilities":["post-quantum-kem","implicit-rejection","three-parameter-sets"],"ciphertext_security":"IND-CCA-oriented standardized KEM","circuit_class":null,"client_storage":null,"communication":null,"construction_family":"module_lattice","correctness":null,"corruption_model":null,"decapsulation_cost":"parameter-set-specific NTT/module arithmetic plus implicit rejection","decrypt_cost":{},"decrypt_pairings":"","decryption_failure":"negligible and parameter-set dependent","encapsulation_cost":"parameter-set-specific NTT/module arithmetic plus hashing","exactness":null,"ggm_file":null,"id":"PKE-CONSTRUCTION-2024-MLKEM","identifiable_abort":null,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":"FIPS 203","object_type":null,"online":null,"output_compatibility":null,"packing":null,"paper_title":"Module-Lattice-Based Key-Encapsulation Mechanism Standard","paper_url":"https://csrc.nist.gov/pubs/fips/203/final","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"key_encapsulation_mechanism","privacy_model":null,"proof_model":null,"quantum_security":"NIST post-quantum standard","query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"key encapsulation","security_model":"module-lattice plus hash-function idealizations in analyses","security_notion":"IND-CCA KEM target","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"ciphertext":"768 / 1088 / 1568 bytes","public_key":"800 / 1184 / 1568 bytes","shared_secret":"32 bytes"},"statefulness":null,"summary":"Sizes list ML-KEM-512, ML-KEM-768, and ML-KEM-1024 in that order, as fixed by the initial 2024 final FIPS 203. The NIST publication record flags potential updates, so conformance evidence should retain the exact revision identity.","supported_gates":null,"tag_size":null,"threshold_policy":null,"transform":"normative round-three-Kyber-derived implicit-rejection KEM transform with FIPS-specific input-output rules","update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"PKE-PAPER-2024-FIPS203","year":2024}],"edges":[{"evidenceLocator":"Cramer–Shoup paper, security theorem and proof","evidenceUrl":"https://crypto.ethz.ch/publications/CraSho98.html","id":"PKE-REL-06FD2F8D8214EE","note":"The paper proves the consistency-checked construction adaptively CCA secure in the standard model under its stated assumptions.","resultId":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","target":"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","type":"ESTABLISHES_SECURITY"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-0CD0A63BACEBCA","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1978-RSA","target":"PKE-ASSUMPTION-RSA-INVERSION","type":"RELIES_ON"},{"evidenceLocator":"OAEP paper, construction and RSA instantiation","evidenceUrl":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","id":"PKE-REL-12F584DF249B57","note":"OAEP randomizes and validates a trapdoor-permutation input rather than applying textbook RSA directly to the message.","resultId":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","target":"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM","type":"HARDENS"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-154D74B06E9D8D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-2017-KYBER","target":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-16D1FCD5F62875","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1976-DH","target":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","type":"HAS_RESULT"},{"evidenceLocator":"Kyber paper, Sections 4–5 and CCA-transform discussion","evidenceUrl":"https://eprint.iacr.org/2017/634","id":"PKE-REL-1A1D0575B57282","note":"Kyber applies an FO-family validation and key-derivation transform to its module-lattice encryption component.","resultId":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","target":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-1EC106C0B0D395","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1978-RSA","target":"PKE-PAPER-1978-RSA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-1F30BA7BE268AF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1994-OAEP","target":"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-269ED363BC1699","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-2024-MLKEM","target":"PKE-ASSUMPTION-MODULE-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-27CF395AD2E213","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1999-FO","target":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-27EA999B829DF3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-2017-KYBER","target":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-2DA7D1EC588823","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1998-CS","target":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-3AD36931574760","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-2022-HPKE","target":"PKE-ASSUMPTION-SUITE-DEPENDENT-KEM","type":"RELIES_ON"},{"evidenceLocator":"Diffie–Hellman paper, Sections II–III","evidenceUrl":"https://doi.org/10.1109/TIT.1976.1055638","id":"PKE-REL-3FB1FFFAABA86E","note":"The exponential exchange gives one concrete shared-secret capability inside the broader public-key program, without becoming noninteractive PKE.","resultId":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","target":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","type":"INSTANTIATES_CAPABILITY"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-49FA016645B07D","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1998-CS","target":"PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","type":"RELIES_ON"},{"evidenceLocator":"Kyber paper, transition from Section 3 PKE to Sections 4–5 KEM","evidenceUrl":"https://eprint.iacr.org/2017/634","id":"PKE-REL-4CDA73B5401264","note":"The full Kyber KEM wraps the paper's CPA module-lattice encryption component in its FO-family CCA transform.","resultId":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","reviewStatus":"primary_source_checked","source":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","target":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","type":"TRANSFORMS"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-5DBE0E99099FC1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-2022-HPKE","target":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-5F59068C2D5112","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1978-MCELIECE","target":"PKE-PAPER-1978-MCELIECE","type":"DESCRIBED_IN"},{"evidenceLocator":"ElGamal paper, encryption-system construction","evidenceUrl":"https://doi.org/10.1109/TIT.1985.1057074","id":"PKE-REL-5F881C065FA055","note":"ElGamal uses an ephemeral Diffie–Hellman-style shared group element to mask a plaintext for a recipient public key.","resultId":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","target":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","type":"USES_PRIMITIVE"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-610636EB31EA0E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1985-ELGAMAL","target":"PKE-PAPER-1985-ELGAMAL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-6124AA5666ECEA","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1985-ELGAMAL","target":"PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-68CA3E01E81507","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-2022-HPKE","target":"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES","type":"HAS_RESULT"},{"evidenceLocator":"RFC 9180 Sections 4 and 7.1","evidenceUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","id":"PKE-REL-758295EB083000","note":"HPKE defines DHKEM suites that package Diffie–Hellman shared-secret derivation behind a KEM interface and labeled key schedule.","resultId":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","target":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","type":"COMPOSES"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-775F6519C3AA6C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-2017-KYBER","target":"PKE-PAPER-2017-KYBER","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-779AAF1B2351D2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1998-CS","target":"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"RSA paper, Abstract and enciphering/deciphering discussion","evidenceUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","id":"PKE-REL-7F5210CDBCDC9C","note":"RSA supplies a concrete noninteractive enciphering and deciphering relation for the public/private-key interface that Diffie and Hellman had posed as a cryptographic program.","resultId":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","target":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","type":"INSTANTIATES_CAPABILITY"},{"evidenceLocator":"FIPS 203 Introduction and Appendix C","evidenceUrl":"https://csrc.nist.gov/pubs/fips/203/final","id":"PKE-REL-8C26475E3B86A2","note":"FIPS 203 specifies a Kyber-derived KEM as ML-KEM with fixed algorithms, encodings, validation, and three parameter sets.","resultId":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","reviewStatus":"primary_source_checked","source":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","target":"PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD","type":"STANDARDIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-9F7DC9AF47E79A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1976-DH","target":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-A01EFD0AC19356","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-2024-MLKEM","target":"PKE-PAPER-2024-FIPS203","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-A90C4C18335257","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1998-CS","target":"PKE-PAPER-1998-CS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-AC2236759C74E5","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1994-OAEP","target":"PKE-PAPER-1994-OAEP","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-B514635976616E","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1994-OAEP","target":"PKE-ASSUMPTION-TRAPDOOR-PERMUTATION-SECURITY-PLUS-RANDOM-ORACLES","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-B795A5002DF998","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1978-MCELIECE","target":"PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"RFC 9180 Section 5","evidenceUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","id":"PKE-REL-C0CF05C9DE9703","note":"HPKE reuses the same suite and context framework while binding sender authentication and/or PSK inputs in additional setup modes.","resultId":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","reviewStatus":"primary_source_checked","source":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","target":"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES","type":"EXTENDS_SETTINGS"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-C4AA6BBF65C936","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1985-ELGAMAL","target":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-C713E465D16F74","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-1978-RSA","target":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-D653F0B9B1F0E2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-PAPER-2024-FIPS203","target":"PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-E1F42ECD1EB1B5","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1978-MCELIECE","target":"PKE-ASSUMPTION-DECODING-A-DISGUISED-BINARY-GOPPA-CODE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-E59B47AA9813D9","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-2017-KYBER","target":"PKE-ASSUMPTION-MODULE-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-EC98DE312E2696","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"PKE-CONSTRUCTION-1999-FO","target":"PKE-ASSUMPTION-ONE-WAY-CPA-BASE-ENCRYPTION-PLUS-RANDOM-ORACLES","type":"RELIES_ON"},{"evidenceLocator":"Cramer–Shoup paper, Introduction and cryptosystem definition","evidenceUrl":"https://crypto.ethz.ch/publications/CraSho98.html","id":"PKE-REL-F2F3E1F24935F3","note":"Cramer–Shoup augments an ElGamal-like ciphertext with hash-bound components and a rejection equation to block adaptive malleation.","resultId":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","reviewStatus":"primary_source_checked","source":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","target":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","type":"HARDENS"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-F56CD34E30A9E6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-1999-FO","target":"PKE-PAPER-1999-FO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PKE-REL-F5D0CBA1337981","note":"","resultId":null,"reviewStatus":"source_declared","source":"PKE-CONSTRUCTION-2022-HPKE","target":"PKE-PAPER-2022-HPKE","type":"DESCRIBED_IN"}],"nodes":[{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","keywords":["discrete logarithm"],"metadata":{"family":"discrete logarithm","name":"Decisional Diffie–Hellman"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete logarithm","summary":"Assumption used by one or more PKE/KEM construction records: Decisional Diffie–Hellman.","title":"Decisional Diffie–Hellman","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-DECODING-A-DISGUISED-BINARY-GOPPA-CODE","keywords":["code-based"],"metadata":{"family":"code-based","name":"decoding a disguised binary Goppa code"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"code-based","summary":"Assumption used by one or more PKE/KEM construction records: decoding a disguised binary Goppa code.","title":"decoding a disguised binary Goppa code","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-DECODING-A-DISGUISED-BINARY-GOPPA-CODE"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-MODULE-LWE","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more PKE/KEM construction records: Module-LWE.","title":"Module-LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-MODULE-LWE"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-ONE-WAY-CPA-BASE-ENCRYPTION-PLUS-RANDOM-ORACLES","keywords":["generic composition"],"metadata":{"family":"generic composition","name":"one-way/CPA base encryption plus random oracles"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"generic composition","summary":"Assumption used by one or more PKE/KEM construction records: one-way/CPA base encryption plus random oracles.","title":"one-way/CPA base encryption plus random oracles","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-ONE-WAY-CPA-BASE-ENCRYPTION-PLUS-RANDOM-ORACLES"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-RSA-INVERSION","keywords":["factoring"],"metadata":{"family":"factoring","name":"RSA inversion"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"factoring","summary":"Assumption used by one or more PKE/KEM construction records: RSA inversion.","title":"RSA inversion","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-RSA-INVERSION"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-SUITE-DEPENDENT-KEM","keywords":["composition"],"metadata":{"KDF":null,"and AEAD security":null,"family":"composition","name":"suite-dependent KEM"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"composition","summary":"Assumption used by one or more PKE/KEM construction records: suite-dependent KEM.","title":"suite-dependent KEM","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-SUITE-DEPENDENT-KEM"},{"evidence":"scheme_declared","id":"PKE-ASSUMPTION-TRAPDOOR-PERMUTATION-SECURITY-PLUS-RANDOM-ORACLES","keywords":["RSA / random oracle"],"metadata":{"family":"RSA / random oracle","name":"trapdoor permutation security plus random oracles"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"RSA / random oracle","summary":"Assumption used by one or more PKE/KEM construction records: trapdoor permutation security plus random oracles.","title":"trapdoor permutation security plus random oracles","type":"assumption","venue":null,"year":null,"sourcePath":"data/pke-kem-catalog.json#PKE-ASSUMPTION-TRAPDOOR-PERMUTATION-SECURITY-PLUS-RANDOM-ORACLES"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1978-MCELIECE","keywords":["public_key_encryption","code_based","code-based-encryption","post-quantum-lineage"],"metadata":{"api_style":"PKE","assumption":{"family":"code-based","name":"decoding a disguised binary Goppa code"},"capabilities":["code-based-encryption","post-quantum-lineage"],"ciphertext_security":"historical one-wayness target; not a modern CCA profile","construction_family":"code_based","decapsulation_cost":"secret-code decoding","decryption_failure":"bounded by the selected code/error profile","dossier_type":"construction","encapsulation_cost":"not a KEM","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1978-MCELIECE","name":"Original McEliece encryption","normative_status":"historical research construction","primitive":"public_key_encryption","quantum_security":"post-quantum design family; this historical profile is not a current standard","security":{"mode":"public-key","model":"code-decoding","notion":"historical computational security"},"sizes":{"ciphertext":"codeword plus error vector","public_key":"disguised generator matrix","shared_secret":"not applicable"},"status":"historical","title":"Original McEliece encryption","transform":"error-vector masking","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1978-MCELIECE","year":1978},"primaryUrl":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","sections":[{"content":"The original PKE anchors the code-based family; later CCA-secure KEM specifications require separate records.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"public_key_encryption · 1978","summary":"The original PKE anchors the code-based family; later CCA-secure KEM specifications require separate records.","title":"Original McEliece encryption","type":"construction","venue":"DSN Progress Report 42-44","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1978-MCELIECE"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1978-RSA","keywords":["public_key_encryption","rsa","public-key-confidentiality-root"],"metadata":{"api_style":"PKE","assumption":{"family":"factoring","name":"RSA inversion"},"capabilities":["public-key-confidentiality-root"],"ciphertext_security":"deterministic; not IND-CPA","construction_family":"rsa","decapsulation_cost":"one private RSA operation","decryption_failure":"none for valid algebraic inputs","dossier_type":"construction","encapsulation_cost":"not a KEM","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1978-RSA","name":"Textbook RSA encryption relation","normative_status":"historical foundation; not secure for deployment by itself","primitive":"public_key_encryption","quantum_security":"no","security":{"mode":"public-key","model":"deterministic trapdoor permutation","notion":"not IND-CPA as written"},"sizes":{"ciphertext":"one RSA residue","public_key":"modulus and public exponent","shared_secret":"not applicable"},"status":"historical","title":"Textbook RSA encryption relation","transform":"none","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1978-RSA","year":1978},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[{"content":"This card exists to anchor the RSA branch. Randomized encoding is required for modern encryption security.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"public_key_encryption · 1978","summary":"This card exists to anchor the RSA branch. Randomized encoding is required for modern encryption security.","title":"Textbook RSA encryption relation","type":"construction","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1978-RSA"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1985-ELGAMAL","keywords":["public_key_encryption","discrete_log","randomized-encryption","multiplicative-homomorphism"],"metadata":{"api_style":"PKE","assumption":{"family":"discrete logarithm","name":"Decisional Diffie–Hellman"},"capabilities":["randomized-encryption","multiplicative-homomorphism"],"ciphertext_security":"IND-CPA under DDH in an appropriate group; malleable and not CCA secure","construction_family":"discrete_log","decapsulation_cost":"one secret exponentiation plus group operations","decryption_failure":"none for valid group inputs","dossier_type":"construction","encapsulation_cost":"not a KEM","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1985-ELGAMAL","name":"ElGamal public-key encryption","normative_status":"research foundation","primitive":"public_key_encryption","quantum_security":"no","security":{"mode":"public-key","model":"standard model in a DDH group","notion":"IND-CPA"},"sizes":{"ciphertext":"two group elements","public_key":"one group element plus group description","shared_secret":"not applicable"},"status":"published","title":"ElGamal public-key encryption","transform":"ephemeral Diffie–Hellman masking","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1985-ELGAMAL","year":1985},"primaryUrl":"https://doi.org/10.1109/TIT.1985.1057074","sections":[{"content":"The multiplicative structure explains both the clean security reduction and the malleability that later CCA-secure designs address.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"public_key_encryption · 1985","summary":"The multiplicative structure explains both the clean security reduction and the malleability that later CCA-secure designs address.","title":"ElGamal public-key encryption","type":"construction","venue":"IEEE Transactions on Information Theory 31(4)","year":1985,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1985-ELGAMAL"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1994-OAEP","keywords":["public_key_encryption_transform","rsa_encoding","randomized-encoding","malformed-ciphertext-rejection"],"metadata":{"api_style":"transform","assumption":{"family":"RSA / random oracle","name":"trapdoor permutation security plus random oracles"},"capabilities":["randomized-encoding","malformed-ciphertext-rejection"],"ciphertext_security":"randomized-encoding transform with an original random-oracle CCA claim; the generic proof gap and later instantiation-specific results must be kept separate","construction_family":"rsa_encoding","decapsulation_cost":"one inverse permutation plus hash/encoding checks","decryption_failure":"explicit reject on malformed encoding","dossier_type":"construction","encapsulation_cost":"not a KEM","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1994-OAEP","name":"OAEP encoding transform","normative_status":"research transform; RSA-OAEP is profiled by later standards","primitive":"public_key_encryption_transform","quantum_security":"no for RSA instantiation","security":{"mode":"public-key","model":"random oracle","notion":"CCA-oriented security program rather than a generic theorem for every trapdoor permutation"},"sizes":{"ciphertext":"one permutation image","public_key":"inherited from trapdoor permutation","shared_secret":"not applicable"},"status":"published","title":"OAEP encoding transform","transform":"OAEP randomized Feistel-style encoding around a trapdoor permutation","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1994-OAEP","year":1994},"primaryUrl":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","sections":[{"content":"The security cell is deliberately qualified: it does not merge the original OAEP claim with every later RSA-OAEP proof result.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"public_key_encryption_transform · 1994","summary":"The security cell is deliberately qualified: it does not merge the original OAEP claim with every later RSA-OAEP proof result.","title":"OAEP encoding transform","type":"construction","venue":"EUROCRYPT 1994","year":1994,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1994-OAEP"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1998-CS","keywords":["public_key_encryption","discrete_log","cca2-security","ciphertext-validity-check"],"metadata":{"api_style":"PKE","assumption":{"family":"discrete logarithm","name":"Decisional Diffie–Hellman"},"capabilities":["cca2-security","ciphertext-validity-check"],"ciphertext_security":"IND-CCA2","construction_family":"discrete_log","decapsulation_cost":"group exponentiations plus consistency check","decryption_failure":"explicit reject on invalid consistency equation","dossier_type":"construction","encapsulation_cost":"not a KEM","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1998-CS","name":"Cramer–Shoup encryption","normative_status":"research construction","primitive":"public_key_encryption","quantum_security":"no","security":{"mode":"public-key","model":"standard model","notion":"adaptive chosen-ciphertext security"},"sizes":{"ciphertext":"four group elements/values","public_key":"several group elements plus hash description","shared_secret":"not applicable"},"status":"published","title":"Cramer–Shoup encryption","transform":"hash-bound consistency check over an ElGamal-like ciphertext","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1998-CS","year":1998},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho98.html","sections":[{"content":"Cramer–Shoup is the standard-model CCA landmark in this seed lineage.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"public_key_encryption · 1998","summary":"Cramer–Shoup is the standard-model CCA landmark in this seed lineage.","title":"Cramer–Shoup encryption","type":"construction","venue":"CRYPTO 1998","year":1998,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1998-CS"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-1999-FO","keywords":["hybrid_pke_transform","generic_transform","cca-transform","hybrid-composition","reencryption-validation-lineage"],"metadata":{"api_style":"transform","assumption":{"family":"generic composition","name":"one-way/CPA base encryption plus random oracles"},"capabilities":["cca-transform","hybrid-composition","reencryption-validation-lineage"],"ciphertext_security":"chosen-ciphertext secure in the specified random-oracle treatment","construction_family":"generic_transform","decapsulation_cost":"base decryption plus validation/re-encryption","decryption_failure":"inherited from base primitive plus explicit reject/re-encrypt check","dossier_type":"construction","encapsulation_cost":"base encryption plus hashing/symmetric work","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-1999-FO","name":"Fujisaki–Okamoto hybrid transform","normative_status":"research transform; many later KEMs use FO-family variants","primitive":"hybrid_pke_transform","quantum_security":"depends on the base primitive and proof model","security":{"mode":"hybrid public-key","model":"random oracle","notion":"IND-CCA"},"sizes":{"ciphertext":"base ciphertext plus symmetric component","public_key":"inherited","shared_secret":"derived by hashing"},"status":"published","title":"Fujisaki–Okamoto hybrid transform","transform":"Fujisaki–Okamoto message-dependent hashing, re-encryption validation, and symmetric integration","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-1999-FO","year":1999},"primaryUrl":"https://doi.org/10.1007/3-540-48405-1_34","sections":[{"content":"Later KEMs use multiple FO variants; those variants must not be assumed identical without a construction-specific record.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"hybrid_pke_transform · 1999","summary":"Later KEMs use multiple FO variants; those variants must not be assumed identical without a construction-specific record.","title":"Fujisaki–Okamoto hybrid transform","type":"construction","venue":"CRYPTO 1999","year":1999,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-1999-FO"},{"evidence":"primary_source_reviewed","id":"PKE-CONSTRUCTION-2017-KYBER","keywords":["key_encapsulation_mechanism","module_lattice","post-quantum-kem","implicit-rejection","module-lattice-arithmetic"],"metadata":{"api_style":"KEM","assumption":{"family":"lattice","name":"Module-LWE"},"capabilities":["post-quantum-kem","implicit-rejection","module-lattice-arithmetic"],"ciphertext_security":"IND-CCA KEM in the stated random-oracle treatment","construction_family":"module_lattice","decapsulation_cost":"module polynomial arithmetic plus validation/implicit rejection","decryption_failure":"negligible but nonzero; parameter-bound","dossier_type":"construction","encapsulation_cost":"module polynomial arithmetic plus hashing","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-2017-KYBER","name":"CRYSTALS-Kyber KEM","normative_status":"research/NIST submission design; superseded normatively by ML-KEM","primitive":"key_encapsulation_mechanism","quantum_security":"post-quantum candidate lineage","security":{"mode":"key encapsulation","model":"ROM/QROM analyses by version","notion":"IND-CCA"},"sizes":{"ciphertext":"parameter-set dependent","public_key":"parameter-set dependent","shared_secret":"fixed derived byte string"},"status":"published","title":"CRYSTALS-Kyber KEM","transform":"FO-family transform over module-LWE/module-LWR-style PKE","verification":{"status":"primary_source_reviewed"},"work_id":"PKE-PAPER-2017-KYBER","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/634","sections":[{"content":"This row follows the 2020-10-14 full revision of ePrint 2017/634. Round-three Kyber and FIPS 203 ML-KEM are separate configurations and must not inherit byte-level claims from this row.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"key_encapsulation_mechanism · 2017","summary":"This row follows the 2020-10-14 full revision of ePrint 2017/634. Round-three Kyber and FIPS 203 ML-KEM are separate configurations and must not inherit byte-level claims from this row.","title":"CRYSTALS-Kyber KEM","type":"construction","venue":"IEEE European Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-2017-KYBER"},{"evidence":"normative_source_reviewed","id":"PKE-CONSTRUCTION-2022-HPKE","keywords":["hybrid_public_key_encryption","kem_kdf_aead_composition","kem-dem-composition","sender-authentication-modes","associated-data"],"metadata":{"api_style":"hybrid framework","assumption":{"KDF":null,"and AEAD security":null,"family":"composition","name":"suite-dependent KEM"},"capabilities":["kem-dem-composition","sender-authentication-modes","associated-data"],"ciphertext_security":"suite- and mode-dependent; base, PSK, authenticated, and authenticated-PSK modes are distinct","construction_family":"kem_kdf_aead_composition","decapsulation_cost":"selected KEM decapsulation plus key schedule and AEAD open","decryption_failure":"KEM/AEAD rejection; suite-dependent","dossier_type":"construction","encapsulation_cost":"selected KEM encapsulation plus key schedule and AEAD seal","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-2022-HPKE","name":"RFC 9180 HPKE framework","normative_status":"IETF RFC 9180","primitive":"hybrid_public_key_encryption","quantum_security":"RFC 9180 base KEM registry is classical","security":{"mode":"multi-mode hybrid PKE","model":"component composition","notion":"hybrid encryption security by mode"},"sizes":{"ciphertext":"encapsulated key plus AEAD ciphertext/tag","public_key":"selected KEM public key","shared_secret":"KDF-derived context secret"},"status":"standard","title":"RFC 9180 HPKE framework","transform":"KEM + labeled KDF + AEAD key schedule","verification":{"status":"normative_source_reviewed"},"work_id":"PKE-PAPER-2022-HPKE","year":2022},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","sections":[{"content":"HPKE is a framework rather than one algorithm; suite-dependent values remain explicitly unresolved in this row.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"hybrid_public_key_encryption · 2022","summary":"HPKE is a framework rather than one algorithm; suite-dependent values remain explicitly unresolved in this row.","title":"RFC 9180 HPKE framework","type":"construction","venue":"RFC 9180","year":2022,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-2022-HPKE"},{"evidence":"normative_source_reviewed","id":"PKE-CONSTRUCTION-2024-MLKEM","keywords":["key_encapsulation_mechanism","module_lattice","post-quantum-kem","implicit-rejection","three-parameter-sets"],"metadata":{"api_style":"KEM","assumption":{"family":"lattice","name":"Module-LWE"},"capabilities":["post-quantum-kem","implicit-rejection","three-parameter-sets"],"ciphertext_security":"IND-CCA-oriented standardized KEM","construction_family":"module_lattice","decapsulation_cost":"parameter-set-specific NTT/module arithmetic plus implicit rejection","decryption_failure":"negligible and parameter-set dependent","dossier_type":"construction","encapsulation_cost":"parameter-set-specific NTT/module arithmetic plus hashing","evidence":"primary_source_checked","id":"PKE-CONSTRUCTION-2024-MLKEM","name":"ML-KEM","normative_status":"FIPS 203","primitive":"key_encapsulation_mechanism","quantum_security":"NIST post-quantum standard","security":{"mode":"key encapsulation","model":"module-lattice plus hash-function idealizations in analyses","notion":"IND-CCA KEM target"},"sizes":{"ciphertext":"768 / 1088 / 1568 bytes","public_key":"800 / 1184 / 1568 bytes","shared_secret":"32 bytes"},"status":"standard","title":"ML-KEM","transform":"normative round-three-Kyber-derived implicit-rejection KEM transform with FIPS-specific input-output rules","verification":{"status":"normative_source_reviewed"},"work_id":"PKE-PAPER-2024-FIPS203","year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/203/final","sections":[{"content":"Sizes list ML-KEM-512, ML-KEM-768, and ML-KEM-1024 in that order, as fixed by the initial 2024 final FIPS 203. The NIST publication record flags potential updates, so conformance evidence should retain the exact revision identity.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"key_encapsulation_mechanism · 2024","summary":"Sizes list ML-KEM-512, ML-KEM-768, and ML-KEM-1024 in that order, as fixed by the initial 2024 final FIPS 203. The NIST publication record flags potential updates, so conformance evidence should retain the exact revision identity.","title":"ML-KEM","type":"construction","venue":"FIPS 203","year":2024,"sourcePath":"data/pke-kem-catalog.json#PKE-CONSTRUCTION-2024-MLKEM"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1976-DH","keywords":["foundations","diffie-hellman","discrete-log"],"metadata":{"authors":["Whitfield Diffie","Martin E. Hellman"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1976-DH","keywords":["foundations","diffie-hellman","discrete-log"],"primary_url":"https://doi.org/10.1109/TIT.1976.1055638","status":"published","title":"New Directions in Cryptography","venue":"IEEE Transactions on Information Theory 22(6)","year":1976},"primaryUrl":"https://doi.org/10.1109/TIT.1976.1055638","sections":[{"content":"Introduces public-key cryptography and a public-channel key-agreement method. The card does not relabel key agreement itself as a complete authenticated encryption protocol.","heading":"Atomic claims"},{"content":"Abstract and Sections II–III of the IEEE paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Whitfield Diffie, Martin E. Hellman · 1976","summary":"Introduces public-key cryptography and a public-channel key-agreement method. The card does not relabel key agreement itself as a complete authenticated encryption protocol.","title":"New Directions in Cryptography","type":"paper","venue":"IEEE Transactions on Information Theory 22(6)","year":1976,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1976-DH"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1978-MCELIECE","keywords":["foundations","mceliece","code-based","post-quantum"],"metadata":{"authors":["Robert J. McEliece"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1978-MCELIECE","keywords":["foundations","mceliece","code-based","post-quantum"],"primary_url":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","status":"published","title":"A Public-Key Cryptosystem Based on Algebraic Coding Theory","venue":"DSN Progress Report 42-44","year":1978},"primaryUrl":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","sections":[{"content":"Constructs public-key encryption by hiding an efficiently decodable algebraic code behind a public generator matrix and adding a bounded error vector.","heading":"Atomic claims"},{"content":"Opening construction and encryption/decryption description in the JPL report.","heading":"Evidence locator"}],"status":"published","subtitle":"Robert J. McEliece · 1978","summary":"Constructs public-key encryption by hiding an efficiently decodable algebraic code behind a public generator matrix and adding a bounded error vector.","title":"A Public-Key Cryptosystem Based on Algebraic Coding Theory","type":"paper","venue":"DSN Progress Report 42-44","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1978-MCELIECE"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1978-RSA","keywords":["foundations","rsa","factoring","trapdoor-permutation"],"metadata":{"authors":["Ronald L. Rivest","Adi Shamir","Leonard M. Adleman"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1978-RSA","keywords":["foundations","rsa","factoring","trapdoor-permutation"],"primary_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","status":"published","title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","venue":"Communications of the ACM 21(2)","year":1978},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[{"content":"Gives the RSA trapdoor-permutation approach to public-key encryption. Textbook RSA is retained only as a historical construction root, not as a modern secure encryption encoding.","heading":"Atomic claims"},{"content":"Abstract and the enciphering/deciphering discussion in the author-hosted CACM paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Ronald L. Rivest, Adi Shamir, Leonard M. Adleman · 1978","summary":"Gives the RSA trapdoor-permutation approach to public-key encryption. Textbook RSA is retained only as a historical construction root, not as a modern secure encryption encoding.","title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","type":"paper","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1978-RSA"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1985-ELGAMAL","keywords":["elgamal","discrete-log","randomized-encryption"],"metadata":{"authors":["Taher ElGamal"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1985-ELGAMAL","keywords":["elgamal","discrete-log","randomized-encryption"],"primary_url":"https://doi.org/10.1109/TIT.1985.1057074","status":"published","title":"A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms","venue":"IEEE Transactions on Information Theory 31(4)","year":1985},"primaryUrl":"https://doi.org/10.1109/TIT.1985.1057074","sections":[{"content":"Defines randomized public-key encryption in a finite cyclic group using an ephemeral exponent and a Diffie–Hellman-style shared group element.","heading":"Atomic claims"},{"content":"Encryption-system section of the IEEE paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Taher ElGamal · 1985","summary":"Defines randomized public-key encryption in a finite cyclic group using an ephemeral exponent and a Diffie–Hellman-style shared group element.","title":"A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms","type":"paper","venue":"IEEE Transactions on Information Theory 31(4)","year":1985,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1985-ELGAMAL"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1994-OAEP","keywords":["oaep","rsa","transform","random-oracle"],"metadata":{"authors":["Mihir Bellare","Phillip Rogaway"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1994-OAEP","keywords":["oaep","rsa","transform","random-oracle"],"primary_url":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","status":"published","title":"Optimal Asymmetric Encryption — How to Encrypt with RSA","venue":"EUROCRYPT 1994","year":1994},"primaryUrl":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","sections":[{"content":"Introduces OAEP as a randomized encoding transform for trapdoor permutations, with an explicit ciphertext-security program in the random-oracle model.","heading":"Atomic claims"},{"content":"Author-hosted abstract and linked full paper; construction and security sections.","heading":"Evidence locator"}],"status":"published","subtitle":"Mihir Bellare, Phillip Rogaway · 1994","summary":"Introduces OAEP as a randomized encoding transform for trapdoor permutations, with an explicit ciphertext-security program in the random-oracle model.","title":"Optimal Asymmetric Encryption — How to Encrypt with RSA","type":"paper","venue":"EUROCRYPT 1994","year":1994,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1994-OAEP"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1998-CS","keywords":["cramer-shoup","discrete-log","cca2","standard-model"],"metadata":{"authors":["Ronald Cramer","Victor Shoup"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1998-CS","keywords":["cramer-shoup","discrete-log","cca2","standard-model"],"primary_url":"https://crypto.ethz.ch/publications/CraSho98.html","status":"published","title":"A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack","venue":"CRYPTO 1998","year":1998},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho98.html","sections":[{"content":"Gives a practical public-key encryption scheme proved secure against adaptive chosen-ciphertext attack in the standard model under standard intractability assumptions.","heading":"Atomic claims"},{"content":"ETH publication abstract and the paper introduction/construction.","heading":"Evidence locator"}],"status":"published","subtitle":"Ronald Cramer, Victor Shoup · 1998","summary":"Gives a practical public-key encryption scheme proved secure against adaptive chosen-ciphertext attack in the standard model under standard intractability assumptions.","title":"A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack","type":"paper","venue":"CRYPTO 1998","year":1998,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1998-CS"},{"evidence":"primary_source_checked","id":"PKE-PAPER-1999-FO","keywords":["fujisaki-okamoto","transform","hybrid-encryption","cca"],"metadata":{"authors":["Eiichiro Fujisaki","Tatsuaki Okamoto"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-1999-FO","keywords":["fujisaki-okamoto","transform","hybrid-encryption","cca"],"primary_url":"https://doi.org/10.1007/3-540-48405-1_34","status":"published","title":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","venue":"CRYPTO 1999","year":1999},"primaryUrl":"https://doi.org/10.1007/3-540-48405-1_34","sections":[{"content":"Develops a generic integration of asymmetric and symmetric encryption that upgrades a weak public-key primitive toward chosen-ciphertext security in a random-oracle setting.","heading":"Atomic claims"},{"content":"Springer abstract and transform/security sections of the CRYPTO paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Eiichiro Fujisaki, Tatsuaki Okamoto · 1999","summary":"Develops a generic integration of asymmetric and symmetric encryption that upgrades a weak public-key primitive toward chosen-ciphertext security in a random-oracle setting.","title":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","type":"paper","venue":"CRYPTO 1999","year":1999,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-1999-FO"},{"evidence":"primary_source_checked","id":"PKE-PAPER-2017-KYBER","keywords":["kyber","module-lattice","post-quantum","kem"],"metadata":{"authors":["Joppe Bos","Léo Ducas","Eike Kiltz","Tancrède Lepoint","Vadim Lyubashevsky","John M. Schanck","Peter Schwabe","Gregor Seiler","Damien Stehlé"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-2017-KYBER","keywords":["kyber","module-lattice","post-quantum","kem"],"primary_url":"https://eprint.iacr.org/2017/634","status":"published","title":"CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM","venue":"IEEE European Symposium on Security and Privacy 2018","versions":[{"date":"2017-06-27","label":"Initial ePrint submission","url":"https://eprint.iacr.org/2017/634"},{"date":"2020-10-14","label":"Full ePrint revision used for section-level review","url":"https://eprint.iacr.org/2017/634"}],"year":2017},"primaryUrl":"https://eprint.iacr.org/2017/634","sections":[{"content":"Presents a module-lattice KEM designed for chosen-ciphertext security with compact arithmetic and an explicit decryption-failure analysis.","heading":"Atomic claims"},{"content":"IACR ePrint 2017/634, full revision dated 2020-10-14, abstract and Sections 3–5. This identity remains separate from round-three Kyber and FIPS 203 ML-KEM.","heading":"Evidence locator"}],"status":"published","subtitle":"Joppe Bos, Léo Ducas, Eike Kiltz et al. · 2017","summary":"Presents a module-lattice KEM designed for chosen-ciphertext security with compact arithmetic and an explicit decryption-failure analysis.","title":"CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM","type":"paper","venue":"IEEE European Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-2017-KYBER"},{"evidence":"primary_source_checked","id":"PKE-PAPER-2022-HPKE","keywords":["hpke","standard","hybrid-encryption","kem","aead"],"metadata":{"authors":["Richard Barnes","Karthikeyan Bhargavan","Benjamin Lipp","Christopher A. Wood"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-2022-HPKE","keywords":["hpke","standard","hybrid-encryption","kem","aead"],"primary_url":"https://www.rfc-editor.org/rfc/rfc9180.html","status":"published","title":"Hybrid Public Key Encryption","venue":"RFC 9180","year":2022},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","sections":[{"content":"Specifies a hybrid public-key encryption framework that composes a KEM, KDF, and AEAD across base, authenticated, pre-shared-key, and authenticated-PSK modes.","heading":"Atomic claims"},{"content":"RFC 9180 Sections 1, 4, and 5.","heading":"Evidence locator"}],"status":"published","subtitle":"Richard Barnes, Karthikeyan Bhargavan, Benjamin Lipp et al. · 2022","summary":"Specifies a hybrid public-key encryption framework that composes a KEM, KDF, and AEAD across base, authenticated, pre-shared-key, and authenticated-PSK modes.","title":"Hybrid Public Key Encryption","type":"paper","venue":"RFC 9180","year":2022,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-2022-HPKE"},{"evidence":"primary_source_checked","id":"PKE-PAPER-2024-FIPS203","keywords":["nist","standard","ml-kem","module-lattice","post-quantum"],"metadata":{"authors":["National Institute of Standards and Technology"],"citation_key":"NIST24/FIPS203","dossier_type":"paper","evidence":"primary_source_checked","id":"PKE-PAPER-2024-FIPS203","keywords":["nist","standard","ml-kem","module-lattice","post-quantum"],"primary_url":"https://csrc.nist.gov/pubs/fips/203/final","status":"published","title":"Module-Lattice-Based Key-Encapsulation Mechanism Standard","venue":"FIPS 203","year":2024},"primaryUrl":"https://csrc.nist.gov/pubs/fips/203/final","sections":[{"content":"Standardizes ML-KEM, a module-lattice KEM derived from the selected Kyber design, with three parameter sets and normative encodings and algorithms.","heading":"Atomic claims"},{"content":"FIPS 203 Introduction, Sections 6–7, and parameter-set tables.","heading":"Evidence locator"}],"status":"published","subtitle":"National Institute of Standards and Technology · 2024","summary":"Standardizes ML-KEM, a module-lattice KEM derived from the selected Kyber design, with three parameter sets and normative encodings and algorithms.","title":"Module-Lattice-Based Key-Encapsulation Mechanism Standard","type":"paper","venue":"FIPS 203","year":2024,"sourcePath":"data/pke-kem-catalog.json#PKE-PAPER-2024-FIPS203"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","keywords":["atomic-result","foundations","diffie-hellman","discrete-log","public_key_roots","public_key_capability","hybrid_composition","capability_result"],"metadata":{"claim_slug":"interactive-public-channel-key-agreement","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["public_key_capability","hybrid_composition"],"technical_thread":["public_key_roots"]},"historical_context":{"narrative":"The public-key concept still needed a concrete way for strangers to establish shared key material. Diffie and Hellman supplied an interactive exchange: each participant publishes an exponentiation, then combines the received value with a private exponent to reach the same group element. The protocol became a durable primitive for session-key establishment and later underlay ElGamal and DHKEM constructions. It is intentionally not called PKE in this atlas. Both parties contribute messages, and the original exchange does not by itself authenticate their identities or encrypt an arbitrary plaintext for an offline recipient.","prior_boundary":"Parties without a pre-shared secret lacked a public-channel procedure for deriving fresh common key material from independently chosen private values.","significance_at_publication":"The protocol became a foundation for later ElGamal masking and DH-based KEM suites, but key agreement itself remained distinct from noninteractive public-key encryption.","technical_delta":"The exponential key exchange let both participants compute the same group element from public messages and their own secret exponent."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","keywords":["foundations","diffie-hellman","discrete-log","public_key_roots","public_key_capability","hybrid_composition","capability_result"],"limitations":["Key agreement is not a complete PKE, KEM ciphertext interface, or authenticated channel."],"paper_id":"PKE-PAPER-1976-DH","qualifiers":["Interactive unauthenticated key agreement in the paper's cyclic-group setting."],"source_locator":{"dossier_section":"PKE-PAPER-1976-DH § Atomic claims and Evidence locator","primary_source":"Sections II–III of the IEEE paper, exponential key-exchange protocol.","primary_source_url":"https://doi.org/10.1109/TIT.1976.1055638","status":"section_checked"},"statement":"Diffie and Hellman give an interactive protocol in which two parties exchange exponentials and derive a common group element without sending that element directly.","statement_status":"source_normalized_statement","status":"published","title":"Interactive Diffie–Hellman key agreement over a public channel","work_id":"PKE-PAPER-1976-DH"},"primaryUrl":"https://doi.org/10.1109/TIT.1976.1055638","sections":[],"status":"published","subtitle":"New Directions in Cryptography","summary":"Diffie and Hellman give an interactive protocol in which two parties exchange exponentials and derive a common group element without sending that element directly.","title":"Interactive Diffie–Hellman key agreement over a public channel","type":"result","venue":"IEEE Transactions on Information Theory 22(6)","year":1976,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","keywords":["atomic-result","foundations","diffie-hellman","discrete-log","public_key_roots","public_key_capability","definition"],"metadata":{"claim_slug":"public-key-cryptography-concept","contribution_kind":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["public_key_capability"],"technical_thread":["public_key_roots"]},"historical_context":{"narrative":"Before 1976, encryption generally began with a secret that sender and receiver had somehow exchanged securely. Diffie and Hellman proposed a different architecture: some keying information could be published without disclosing the private capability needed to reverse or authenticate an operation. That change defined the public-key research program and made open distribution of enciphering material a legitimate cryptographic interface. It was a concept and feasibility agenda, not yet a complete public-key encryption algorithm; RSA, ElGamal, and code-based constructions later supplied distinct concrete realizations.","prior_boundary":"Conventional cryptography assumed that communicating parties first shared the same secret, making key distribution part of the trusted channel problem.","significance_at_publication":"This conceptual separation created the research program for public-key encryption and signatures, while leaving concrete trapdoor constructions as an explicit open direction.","technical_delta":"The paper proposed an asymmetric interface with publicly distributable information and separately held secret information."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","keywords":["foundations","diffie-hellman","discrete-log","public_key_roots","public_key_capability","definition"],"limitations":["The contribution does not by itself instantiate secure PKE, a KEM, or an authenticated protocol."],"paper_id":"PKE-PAPER-1976-DH","qualifiers":["Conceptual public-key interface rather than one concrete encryption algorithm."],"source_locator":{"dossier_section":"PKE-PAPER-1976-DH § Atomic claims and Evidence locator","primary_source":"Abstract and Sections I–II of the IEEE paper.","primary_source_url":"https://doi.org/10.1109/TIT.1976.1055638","status":"section_checked"},"statement":"Diffie and Hellman formulate public-key cryptography as systems in which publishing enciphering information need not reveal the private information required to reverse or authenticate an operation.","statement_status":"source_normalized_statement","status":"published","title":"Public-key cryptography separates public enciphering information from a private secret","work_id":"PKE-PAPER-1976-DH"},"primaryUrl":"https://doi.org/10.1109/TIT.1976.1055638","sections":[],"status":"published","subtitle":"New Directions in Cryptography","summary":"Diffie and Hellman formulate public-key cryptography as systems in which publishing enciphering information need not reveal the private information required to reverse or authenticate an operation.","title":"Public-key cryptography separates public enciphering information from a private secret","type":"result","venue":"IEEE Transactions on Information Theory 22(6)","year":1976,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION","keywords":["atomic-result","foundations","mceliece","code-based","post-quantum","code_based_encryption","post_quantum_transition","construction"],"metadata":{"claim_slug":"code-based-public-key-encryption","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_transition"],"technical_thread":["code_based_encryption"]},"historical_context":{"narrative":"RSA and Diffie–Hellman made public-key cryptography concrete through number theory, but they did not exhaust the possible hardness foundations. McEliece instead published a disguised generator matrix and encrypted a codeword after injecting a correctable error. The secret algebraic code made decryption efficient while generic decoding remained hard. This was a complete PKE construction rather than a key-agreement protocol, and its source of asymmetry was qualitatively different from modular inversion or discrete logarithms. The historical scheme is not automatically a modern CCA KEM; any later profile needs its own transform, parameters, security statement, and evidence.","prior_boundary":"The first public-key agenda was dominated by number-theoretic trapdoors and did not establish that error-correcting codes could support an asymmetric encryption interface.","significance_at_publication":"The construction established that public-key encryption could rest on hard decoding rather than a number-theoretic trapdoor, opening an independent construction branch.","technical_delta":"McEliece hid an efficiently decodable algebraic code behind public linear transformations and used intentional decoding errors as ciphertext randomization."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION","keywords":["foundations","mceliece","code-based","post-quantum","code_based_encryption","post_quantum_transition","construction"],"limitations":["The original construction is not a modern CCA-secure KEM or a current normative profile."],"paper_id":"PKE-PAPER-1978-MCELIECE","qualifiers":["Historical PKE under the paper's code and error parameters."],"source_locator":{"dossier_section":"PKE-PAPER-1978-MCELIECE § Atomic claims and Evidence locator","primary_source":"Opening construction and encryption/decryption description in the JPL report.","primary_source_url":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","status":"section_checked"},"statement":"McEliece encrypts by encoding under a disguised public generator matrix and adding a bounded error vector that only the secret code structure efficiently corrects.","statement_status":"source_normalized_statement","status":"published","title":"Code-based public-key encryption from disguised decoding structure","work_id":"PKE-PAPER-1978-MCELIECE"},"primaryUrl":"https://ipnpr.jpl.nasa.gov/progress_report2/42-44/44N.PDF","sections":[],"status":"published","subtitle":"A Public-Key Cryptosystem Based on Algebraic Coding Theory","summary":"McEliece encrypts by encoding under a disguised public generator matrix and adding a bounded error vector that only the secret code structure efficiently corrects.","title":"Code-based public-key encryption from disguised decoding structure","type":"result","venue":"DSN Progress Report 42-44","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","keywords":["atomic-result","foundations","rsa","factoring","trapdoor-permutation","public_key_roots","public_key_capability","construction"],"metadata":{"claim_slug":"rsa-public-key-encryption-relation","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["public_key_capability"],"technical_thread":["public_key_roots"]},"historical_context":{"narrative":"The public-key agenda required an algorithm that anyone could apply in the forward direction while only one key holder could efficiently reverse it. RSA provided that algebraic relation through modular exponentiation and a secret inverse exponent derived from the modulus factors. A sender could now encrypt for an offline recipient using only published material. The root is historically decisive but cryptographically narrow: textbook RSA is deterministic and structurally malleable, so it does not satisfy modern indistinguishability notions. OAEP belongs later in the lineage precisely because secure deployment requires randomized encoding and rejection behavior around this permutation.","prior_boundary":"Diffie and Hellman had articulated public-key cryptography while leaving an efficient general trapdoor construction as a central unresolved problem.","significance_at_publication":"The result made noninteractive public-key encryption concrete and created the trapdoor-permutation branch later wrapped by randomized encodings such as OAEP.","technical_delta":"RSA instantiated that interface with modular exponentiation whose inverse is efficiently available to the holder of the factorization-derived secret exponent."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","keywords":["foundations","rsa","factoring","trapdoor-permutation","public_key_roots","public_key_capability","construction"],"limitations":["Textbook RSA is deterministic and not IND-CPA or CCA secure."],"paper_id":"PKE-PAPER-1978-RSA","qualifiers":["Historical trapdoor-permutation relation."],"source_locator":{"dossier_section":"PKE-PAPER-1978-RSA § Atomic claims and Evidence locator","primary_source":"Abstract and the enciphering/deciphering discussion in the author-hosted CACM paper.","primary_source_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","status":"section_checked"},"statement":"RSA uses public modular exponentiation for enciphering and the private inverse exponent for deciphering, giving a concrete trapdoor-permutation PKE relation.","statement_status":"source_normalized_statement","status":"published","title":"RSA trapdoor permutation as a public-key encryption relation","work_id":"PKE-PAPER-1978-RSA"},"primaryUrl":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","sections":[],"status":"published","subtitle":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","summary":"RSA uses public modular exponentiation for enciphering and the private inverse exponent for deciphering, giving a concrete trapdoor-permutation PKE relation.","title":"RSA trapdoor permutation as a public-key encryption relation","type":"result","venue":"Communications of the ACM 21(2)","year":1978,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","keywords":["atomic-result","elgamal","discrete-log","randomized-encryption","public_key_roots","public_key_capability","construction"],"metadata":{"claim_slug":"randomized-discrete-log-encryption","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["public_key_capability"],"technical_thread":["public_key_roots"]},"historical_context":{"narrative":"Diffie–Hellman let two active participants derive a common group element, but it was not an offline-recipient encryption algorithm. ElGamal turned the same ephemeral-exponent idea into PKE: the ciphertext carries a fresh public group element and uses the corresponding shared value to mask the message under a long-term recipient key. Randomization distinguished it from textbook RSA and supported a clean CPA-security account in suitable groups. Its multiplicative structure also made ciphertexts malleable, so the construction remains the starting point—not the endpoint—for the later standard-model CCA design of Cramer and Shoup.","prior_boundary":"Diffie–Hellman established interactive shared-secret derivation, while RSA supplied deterministic noninteractive encryption through a trapdoor permutation.","significance_at_publication":"The construction became the standard discrete-log PKE baseline whose algebraic malleability later Cramer–Shoup hardened against adaptive ciphertext attacks.","technical_delta":"ElGamal converted the ephemeral shared group value into randomized noninteractive encryption under a recipient's long-term public key."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","keywords":["elgamal","discrete-log","randomized-encryption","public_key_roots","public_key_capability","construction"],"limitations":["ElGamal is malleable and does not provide chosen-ciphertext security."],"paper_id":"PKE-PAPER-1985-ELGAMAL","qualifiers":["Randomized PKE in an appropriate cyclic group."],"source_locator":{"dossier_section":"PKE-PAPER-1985-ELGAMAL § Atomic claims and Evidence locator","primary_source":"Encryption-system section of the IEEE paper.","primary_source_url":"https://doi.org/10.1109/TIT.1985.1057074","status":"section_checked"},"statement":"ElGamal PKE samples an ephemeral exponent, publishes its group element, and masks the plaintext with a Diffie–Hellman-style shared group element.","statement_status":"source_normalized_statement","status":"published","title":"Randomized ElGamal encryption from an ephemeral Diffie–Hellman secret","work_id":"PKE-PAPER-1985-ELGAMAL"},"primaryUrl":"https://doi.org/10.1109/TIT.1985.1057074","sections":[],"status":"published","subtitle":"A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms","summary":"ElGamal PKE samples an ephemeral exponent, publishes its group element, and masks the plaintext with a Diffie–Hellman-style shared group element.","title":"Randomized ElGamal encryption from an ephemeral Diffie–Hellman secret","type":"result","venue":"IEEE Transactions on Information Theory 31(4)","year":1985,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM","keywords":["atomic-result","oaep","rsa","transform","random-oracle","cca_transforms","chosen_ciphertext_security"],"metadata":{"claim_slug":"oaep-randomized-encoding-transform","contribution_kind":"transform","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["chosen_ciphertext_security"],"technical_thread":["cca_transforms"]},"historical_context":{"narrative":"RSA's trapdoor relation made public-key encryption possible, but applying it directly to a message leaked equality and preserved unwanted algebraic structure. OAEP inserted a randomized two-hash encoding before the permutation and required structured recovery during decoding. That design made encoding and rejection part of the cryptographic construction rather than application folklore. The 1994 paper claimed strong random-oracle security for the enhanced scheme, but later work exposed a gap in the generic proof and established narrower results for particular instantiations such as RSA-OAEP. This node therefore records the transform and its security program, not a blanket IND-CCA theorem for every trapdoor permutation.","prior_boundary":"Raw trapdoor-permutation encryption was deterministic and exposed algebraic structure, preventing it from meeting modern ciphertext-security goals.","significance_at_publication":"The transform established a practical randomized-encoding program around trapdoor permutations, but the original generic chosen-ciphertext claim was not the final security boundary for every instantiation.","technical_delta":"OAEP added randomized masking, redundancy, and a decoding validity boundary around the permutation input."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM","keywords":["oaep","rsa","transform","random-oracle","cca_transforms","chosen_ciphertext_security"],"limitations":["The original generic proof does not by itself establish IND-CCA security for every trapdoor-permutation instantiation; this caveat is checked against Shoup, OAEP Reconsidered, Abstract and Sections 1–2 (IACR ePrint 2000/060)."],"paper_id":"PKE-PAPER-1994-OAEP","qualifiers":["Random-oracle transform for a trapdoor permutation; theorem scope is instantiation-sensitive."],"source_locator":{"dossier_section":"PKE-PAPER-1994-OAEP § Atomic claims and Evidence locator","primary_source":"Author-hosted full paper, OAEP construction and security sections.","primary_source_url":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","status":"section_checked"},"statement":"OAEP uses a two-hash Feistel-style encoding to randomize and structure a message before applying a trapdoor permutation such as RSA.","statement_status":"source_normalized_statement","status":"published","title":"OAEP randomized encoding around a trapdoor permutation","work_id":"PKE-PAPER-1994-OAEP"},"primaryUrl":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","sections":[],"status":"published","subtitle":"Optimal Asymmetric Encryption — How to Encrypt with RSA","summary":"OAEP uses a two-hash Feistel-style encoding to randomize and structure a message before applying a trapdoor permutation such as RSA.","title":"OAEP randomized encoding around a trapdoor permutation","type":"result","venue":"EUROCRYPT 1994","year":1994,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","keywords":["atomic-result","cramer-shoup","discrete-log","cca2","standard-model","cca_transforms","chosen_ciphertext_security","construction"],"metadata":{"claim_slug":"hash-bound-elgamal-ciphertext-consistency","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["chosen_ciphertext_security"],"technical_thread":["cca_transforms"]},"historical_context":{"narrative":"ElGamal ciphertexts could be modified algebraically, so a decryption oracle gave an attacker leverage unavailable in the CPA game. Cramer and Shoup changed the ciphertext structure by adding group components and hashing them into a consistency exponent checked during decryption. A malformed or recombined ciphertext would normally fail before revealing a plaintext. This construction mechanism is recorded separately from its security theorem: the equation explains how the design works, while the companion node states the adaptive CCA guarantee and assumptions that make the hardening claim meaningful.","prior_boundary":"ElGamal achieved randomized CPA encryption but allowed algebraic ciphertext modifications that an adaptive decryption oracle could expose.","significance_at_publication":"This architecture supplied a practical standard-model route to CCA security rather than relying only on generic random-oracle encodings.","technical_delta":"The construction bound ciphertext components together through a target-collision-resistant hash and rejected values failing the consistency relation."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","keywords":["cramer-shoup","discrete-log","cca2","standard-model","cca_transforms","chosen_ciphertext_security","construction"],"limitations":["The consistency mechanism alone is not a generic compiler for arbitrary PKE."],"paper_id":"PKE-PAPER-1998-CS","qualifiers":["ElGamal-like discrete-log construction with an explicit rejection check."],"source_locator":{"dossier_section":"PKE-PAPER-1998-CS § Atomic claims and Evidence locator","primary_source":"Cramer–Shoup paper, Introduction and cryptosystem definition.","primary_source_url":"https://crypto.ethz.ch/publications/CraSho98.html","status":"section_checked"},"statement":"Cramer–Shoup augments an ElGamal-like ciphertext with extra group elements and a hash-bound consistency equation that decryption verifies before releasing a message.","statement_status":"source_normalized_statement","status":"published","title":"Hash-bound consistency checks harden an ElGamal-like ciphertext","work_id":"PKE-PAPER-1998-CS"},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho98.html","sections":[],"status":"published","subtitle":"A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack","summary":"Cramer–Shoup augments an ElGamal-like ciphertext with extra group elements and a hash-bound consistency equation that decryption verifies before releasing a message.","title":"Hash-bound consistency checks harden an ElGamal-like ciphertext","type":"result","venue":"CRYPTO 1998","year":1998,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","keywords":["atomic-result","cramer-shoup","discrete-log","cca2","standard-model","cca_transforms","chosen_ciphertext_security","security_result"],"metadata":{"claim_slug":"standard-model-adaptive-cca-encryption","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["chosen_ciphertext_security"],"technical_thread":["cca_transforms"]},"historical_context":{"narrative":"Chosen-ciphertext security had been an important target, but efficient constructions commonly relied on random-oracle encodings or remained vulnerable to adaptive decryption queries. Cramer and Shoup proved that their consistency-checked discrete-log scheme reaches the stronger game in the standard model under the paper's exact assumptions. The result changed the accepted feasibility boundary for practical PKE. It is kept apart from the ciphertext architecture because a construction diagram is not a theorem: the security node owns the adversary model and reduction, while the companion node owns the algebraic checking mechanism.","prior_boundary":"Earlier practical PKE either stopped at chosen-plaintext security or obtained stronger guarantees through idealized random-oracle encodings.","significance_at_publication":"The theorem established a landmark standard-model CCA point and made proof model a first-class coordinate in comparing hardened public-key encryption.","technical_delta":"The proof showed that the hash-bound ciphertext consistency design resists adaptive decryption queries without programming a random oracle."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","keywords":["cramer-shoup","discrete-log","cca2","standard-model","cca_transforms","chosen_ciphertext_security","security_result"],"limitations":["The theorem applies to the exact Cramer–Shoup construction and assumptions, not all ElGamal variants."],"paper_id":"PKE-PAPER-1998-CS","qualifiers":["Adaptive CCA security in the paper's standard-model group setting."],"source_locator":{"dossier_section":"PKE-PAPER-1998-CS § Atomic claims and Evidence locator","primary_source":"Cramer–Shoup paper, security theorem and proof following the cryptosystem definition.","primary_source_url":"https://crypto.ethz.ch/publications/CraSho98.html","status":"section_checked"},"statement":"Cramer–Shoup proves its public-key encryption construction secure against adaptive chosen-ciphertext attack in the standard model under its stated discrete-log-group assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Adaptive chosen-ciphertext security for practical PKE in the standard model","work_id":"PKE-PAPER-1998-CS"},"primaryUrl":"https://crypto.ethz.ch/publications/CraSho98.html","sections":[],"status":"published","subtitle":"A Practical Public Key Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack","summary":"Cramer–Shoup proves its public-key encryption construction secure against adaptive chosen-ciphertext attack in the standard model under its stated discrete-log-group assumptions.","title":"Adaptive chosen-ciphertext security for practical PKE in the standard model","type":"result","venue":"CRYPTO 1998","year":1998,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION"},{"evidence":"primary_source_checked","id":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","keywords":["atomic-result","fujisaki-okamoto","transform","hybrid-encryption","cca","cca_transforms","chosen_ciphertext_security","hybrid_composition"],"metadata":{"claim_slug":"fujisaki-okamoto-cca-transform","contribution_kind":"transform","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["chosen_ciphertext_security","hybrid_composition"],"technical_thread":["cca_transforms"]},"historical_context":{"narrative":"Hybrid encryption was efficient, but simply placing a symmetric ciphertext beside a public-key ciphertext did not guarantee security against active decryption queries. Fujisaki and Okamoto tied the components together by hashing message-dependent values into encryption coins and key material, then checking the recovered value by re-encryption. This yielded an IND-CCA hybrid construction under the paper's random-oracle conditions. Kyber later adapted the validation pattern to a KEM, but that later interface should not be projected backward onto the 1999 scheme. The name “FO” now covers several descendants with different rejection rules, assumptions, and quantum-random-oracle analyses.","prior_boundary":"Efficient hybrid encryption needed a principled way to combine a weaker asymmetric primitive with fast symmetric processing without losing security against active ciphertext attacks.","significance_at_publication":"FO created the reusable CCA-hardening lineage later instantiated in module-lattice KEMs, while leaving exact variants and proof models construction-specific.","technical_delta":"The transform coupled asymmetric encryption and symmetric protection through message-dependent hashing and a re-encryption consistency check."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","keywords":["fujisaki-okamoto","transform","hybrid-encryption","cca","cca_transforms","chosen_ciphertext_security","hybrid_composition"],"limitations":["Later FO-family KEM transforms differ in validation, rejection, assumptions, and proof model."],"paper_id":"PKE-PAPER-1999-FO","qualifiers":["Generic hybrid transform in the paper's random-oracle treatment."],"source_locator":{"dossier_section":"PKE-PAPER-1999-FO § Atomic claims and Evidence locator","primary_source":"Springer full paper, transform definition and security theorem sections.","primary_source_url":"https://doi.org/10.1007/3-540-48405-1_34","status":"section_checked"},"statement":"Fujisaki and Okamoto give a random-oracle transform that derives asymmetric encryption coins and symmetric keying material from message-dependent hashes, then validates decryption by recomputing the asymmetric ciphertext.","statement_status":"source_normalized_statement","status":"published","title":"Fujisaki–Okamoto random-oracle transform for CCA-secure hybrid encryption","work_id":"PKE-PAPER-1999-FO"},"primaryUrl":"https://doi.org/10.1007/3-540-48405-1_34","sections":[],"status":"published","subtitle":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","summary":"Fujisaki and Okamoto give a random-oracle transform that derives asymmetric encryption coins and symmetric keying material from message-dependent hashes, then validates decryption by recomputing the asymmetric ciphertext.","title":"Fujisaki–Okamoto random-oracle transform for CCA-secure hybrid encryption","type":"result","venue":"CRYPTO 1999","year":1999,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM"},{"evidence":"primary_source_checked","id":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","keywords":["atomic-result","kyber","module-lattice","post-quantum","kem","lattice_kems","chosen_ciphertext_security","post_quantum_transition","construction"],"metadata":{"claim_slug":"module-lattice-cca-secure-kem","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["chosen_ciphertext_security","post_quantum_transition"],"technical_thread":["lattice_kems"]},"historical_context":{"narrative":"The Kyber base encryption scheme provided compact module-lattice arithmetic, but a network-facing KEM needed to withstand attacker-chosen ciphertexts and return stable key material. The full construction wrapped that component in an FO-family transform, coupling ciphertext generation, hashing, validation, and shared-secret derivation. This produced the paper's CCA-oriented encapsulation interface and made Kyber a leading post-quantum KEM design. The node remains a research construction: parameter choices, encodings, and some algorithm details changed before FIPS 203 fixed ML-KEM, so the two identities must not be collapsed.","prior_boundary":"Module-lattice CPA encryption supplied efficient public-key operations but did not expose the robust encapsulation/decapsulation interface required against active ciphertext attackers.","significance_at_publication":"The KEM combined compact module arithmetic with CCA hardening and became the research construction from which the later ML-KEM normative profile was derived.","technical_delta":"Kyber derived encryption coins and shared-secret material through hashing and rejected or replaced invalid decapsulation results according to its transform design."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","keywords":["kyber","module-lattice","post-quantum","kem","lattice_kems","chosen_ciphertext_security","post_quantum_transition","construction"],"limitations":["Kyber and standardized ML-KEM are related but not identical configurations."],"paper_id":"PKE-PAPER-2017-KYBER","qualifiers":["Research-version Kyber KEM; the normalized ROM/QROM claim follows the 2020-10-14 full revision of ePrint 2017/634, not round-three Kyber or ML-KEM."],"source_locator":{"dossier_section":"PKE-PAPER-2017-KYBER § Atomic claims and Evidence locator","primary_source":"Kyber ePrint 2017/634 full revision dated 2020-10-14, Sections 4–5 and CCA-transform discussion.","primary_source_url":"https://eprint.iacr.org/2017/634","status":"section_checked"},"statement":"Kyber applies an FO-family transform and implicit validation logic to its module-lattice encryption component to obtain a chosen-ciphertext-secure key-encapsulation mechanism.","statement_status":"source_normalized_statement","status":"published","title":"Kyber's FO-transformed module-lattice CCA KEM","work_id":"PKE-PAPER-2017-KYBER"},"primaryUrl":"https://eprint.iacr.org/2017/634","sections":[],"status":"published","subtitle":"CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM","summary":"Kyber applies an FO-family transform and implicit validation logic to its module-lattice encryption component to obtain a chosen-ciphertext-secure key-encapsulation mechanism.","title":"Kyber's FO-transformed module-lattice CCA KEM","type":"result","venue":"IEEE European Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM"},{"evidence":"primary_source_checked","id":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","keywords":["atomic-result","kyber","module-lattice","post-quantum","kem","lattice_kems","post_quantum_transition","mechanism"],"metadata":{"claim_slug":"module-lattice-cpa-encryption-component","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_transition"],"technical_thread":["lattice_kems"]},"historical_context":{"narrative":"Lattice encryption offered post-quantum assumptions, yet a deployable KEM still needed a compact base scheme with efficient arithmetic and controlled decoding errors. Kyber's inner encryption layer used module-lattice matrices and polynomial vectors, compressed public and ciphertext values, and analyzed the remaining probability of decryption failure. That object is not itself the complete CCA KEM. It is the CPA component that makes the later transform concrete, so the map keeps it as a reviewed-related mechanism node beside—but not merged with—the primary Kyber encapsulation result.","prior_boundary":"Post-quantum KEM design needed a practical base encryption layer balancing lattice structure, bandwidth, arithmetic cost, and correctness failure.","significance_at_publication":"This component provided the concrete encryption substrate to which an FO-family transform could add CCA-secure key encapsulation.","technical_delta":"The Kyber CPA component instantiated module-LWE-style matrix and polynomial operations with compression and an explicit failure analysis."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","keywords":["kyber","module-lattice","post-quantum","kem","lattice_kems","post_quantum_transition","mechanism"],"limitations":["The component alone is not the CCA-secure Kyber KEM or the ML-KEM standard."],"paper_id":"PKE-PAPER-2017-KYBER","qualifiers":["CPA encryption component with parameter-dependent nonzero failure probability."],"source_locator":{"dossier_section":"PKE-PAPER-2017-KYBER § Atomic claims and Evidence locator","primary_source":"Kyber ePrint 2017/634 full revision dated 2020-10-14, Section 3 and decryption-failure analysis.","primary_source_url":"https://eprint.iacr.org/2017/634","status":"section_checked"},"statement":"Kyber defines a compact public-key encryption component over module lattices using structured polynomial arithmetic, compressed ciphertext components, and a quantified decryption-failure probability.","statement_status":"source_normalized_statement","status":"published","title":"Module-lattice CPA encryption component underlying Kyber","work_id":"PKE-PAPER-2017-KYBER"},"primaryUrl":"https://eprint.iacr.org/2017/634","sections":[],"status":"published","subtitle":"CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM","summary":"Kyber defines a compact public-key encryption component over module lattices using structured polynomial arithmetic, compressed ciphertext components, and a quantified decryption-failure probability.","title":"Module-lattice CPA encryption component underlying Kyber","type":"result","venue":"IEEE European Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT"},{"evidence":"primary_source_checked","id":"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES","keywords":["atomic-result","hpke","standard","hybrid-encryption","kem","aead","hybrid_protocols","hybrid_composition","capability_result"],"metadata":{"claim_slug":"authenticated-and-psk-modes","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["hybrid_composition"],"technical_thread":["hybrid_protocols"]},"historical_context":{"narrative":"Once the base HPKE stack was defined, applications still differed in how they authenticated the sender or incorporated an existing shared secret. RFC 9180 addressed that variation through four setup modes: base, PSK, authenticated, and authenticated-PSK. Each mode feeds different credential material into the same labeled schedule and therefore changes the protocol's trust contract. This is a separate capability contribution from the generic KEM-KDF-AEAD composition. An authenticated mode relies on the selected KEM's authentication interface and does not replace application-level identity validation or make every HPKE suite equivalent.","prior_boundary":"A basic KEM-to-AEAD composition establishes recipient confidentiality but does not cover every application requirement for sender authentication or pre-shared context.","significance_at_publication":"These modes expanded the framework's trust and authentication settings without turning HPKE into a single authenticated public-key encryption algorithm.","technical_delta":"HPKE added mode-specific inputs and setup procedures while retaining one suite and encrypted-message framework."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES","keywords":["hpke","standard","hybrid-encryption","kem","aead","hybrid_protocols","hybrid_composition","capability_result"],"limitations":["HPKE authentication modes do not by themselves validate application identities or certificates."],"paper_id":"PKE-PAPER-2022-HPKE","qualifiers":["Four protocol modes with distinct credential and PSK inputs."],"source_locator":{"dossier_section":"PKE-PAPER-2022-HPKE § Atomic claims and Evidence locator","primary_source":"RFC 9180 Section 5, mode definitions and setup inputs.","primary_source_url":"https://www.rfc-editor.org/rfc/rfc9180.html","status":"section_checked"},"statement":"RFC 9180 defines base, PSK, authenticated, and authenticated-PSK setup modes that alter which sender credentials and pre-shared inputs are bound into the HPKE key schedule.","statement_status":"source_normalized_statement","status":"published","title":"HPKE authenticated and pre-shared-key modes extend the base hybrid context","work_id":"PKE-PAPER-2022-HPKE"},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","sections":[],"status":"published","subtitle":"Hybrid Public Key Encryption","summary":"RFC 9180 defines base, PSK, authenticated, and authenticated-PSK setup modes that alter which sender credentials and pre-shared inputs are bound into the HPKE key schedule.","title":"HPKE authenticated and pre-shared-key modes extend the base hybrid context","type":"result","venue":"RFC 9180","year":2022,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES"},{"evidence":"primary_source_checked","id":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","keywords":["atomic-result","hpke","standard","hybrid-encryption","kem","aead","hybrid_protocols","hybrid_composition","capability_result"],"metadata":{"claim_slug":"kem-kdf-aead-hybrid-framework","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["hybrid_composition"],"technical_thread":["hybrid_protocols"]},"historical_context":{"narrative":"Hybrid public-key encryption is a stack rather than one algorithm: an asymmetric mechanism establishes secret material, a KDF binds context, and an AEAD protects payloads. RFC 9180 standardized how those pieces fit together through labeled extraction, suite identifiers, setup functions, and sender/receiver contexts. This eliminated a class of incompatible ad hoc compositions while allowing several registered component choices. HPKE is therefore represented as a protocol framework, not a KEM row. Its guarantees remain suite- and mode-dependent, and the classical DHKEM registry in the RFC does not make the framework inherently post-quantum.","prior_boundary":"Applications had many ad hoc ways to combine public-key key establishment with symmetric encryption, creating incompatible context binding, key schedules, and ciphertext formats.","significance_at_publication":"The framework made hybrid composition interoperable across suites without defining one new KEM or claiming that all component combinations have identical security.","technical_delta":"HPKE standardized component interfaces, suite identifiers, labeled derivation, setup APIs, and encrypted-message contexts around KEM, KDF, and AEAD choices."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","keywords":["hpke","standard","hybrid-encryption","kem","aead","hybrid_protocols","hybrid_composition","capability_result"],"limitations":["HPKE is not one KEM, one concrete ciphertext format across all suites, or inherently post-quantum."],"paper_id":"PKE-PAPER-2022-HPKE","qualifiers":["Suite-parameterized protocol framework; component security remains explicit."],"source_locator":{"dossier_section":"PKE-PAPER-2022-HPKE § Atomic claims and Evidence locator","primary_source":"RFC 9180 Sections 3–4 and 6–7.","primary_source_url":"https://www.rfc-editor.org/rfc/rfc9180.html","status":"section_checked"},"statement":"RFC 9180 defines HPKE as a suite-parameterized hybrid protocol that combines a KEM-produced shared secret with a labeled key schedule and an AEAD encryption context.","statement_status":"source_normalized_statement","status":"published","title":"HPKE framework composes a selected KEM, KDF, and AEAD suite","work_id":"PKE-PAPER-2022-HPKE"},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc9180.html","sections":[],"status":"published","subtitle":"Hybrid Public Key Encryption","summary":"RFC 9180 defines HPKE as a suite-parameterized hybrid protocol that combines a KEM-produced shared secret with a labeled key schedule and an AEAD encryption context.","title":"HPKE framework composes a selected KEM, KDF, and AEAD suite","type":"result","venue":"RFC 9180","year":2022,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK"},{"evidence":"primary_source_checked","id":"PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD","keywords":["atomic-result","nist","standard","ml-kem","module-lattice","post-quantum","migration_standards","post_quantum_transition","hybrid_composition","standardization_result"],"metadata":{"claim_slug":"ml-kem-normative-standard","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_transition","hybrid_composition"],"technical_thread":["migration_standards"]},"historical_context":{"narrative":"Selection of Kyber identified a post-quantum design family, but implementations still needed one permanent algorithm and wire-level contract. FIPS 203 supplied that contract under the ML-KEM name, deriving its algorithms from round-three CRYSTALS-KYBER while fixing three parameter sets, encodings, checks, encapsulation, decapsulation, and implicit rejection. Appendix C records input-output differences from the submission lineage. The publication therefore marks normative adoption rather than invention of module-lattice encryption or the FO family. A historical Kyber implementation is not automatically ML-KEM conformant, and paper-level claims do not silently transfer to every detail of the standard.","prior_boundary":"Kyber had been selected as a post-quantum KEM design, but interoperable deployment still required a stable federal name, parameter set, byte encoding, and conformance contract.","significance_at_publication":"The standard moved module-lattice encapsulation from a research submission lineage into a deployable profile without claiming that the FIPS document invented Kyber's architecture.","technical_delta":"FIPS 203 fixed a round-three-Kyber-derived variant as ML-KEM-512, ML-KEM-768, and ML-KEM-1024, including normative interfaces, byte encodings, input checks, and transform details."},"historical_context_status":"curator_synthesis","id":"PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD","keywords":["nist","standard","ml-kem","module-lattice","post-quantum","migration_standards","post_quantum_transition","hybrid_composition","standardization_result"],"limitations":["FIPS 203 standardizes a Kyber-derived configuration; it does not make all Kyber versions byte-compatible with ML-KEM.","This card identifies the initial 2024 final publication; the NIST CSRC record currently flags potential updates, so a conformance claim should name the exact FIPS revision used."],"paper_id":"PKE-PAPER-2024-FIPS203","qualifiers":["Normative ML-KEM profile with three fixed parameter sets."],"source_locator":{"dossier_section":"PKE-PAPER-2024-FIPS203 § Atomic claims and Evidence locator","primary_source":"FIPS 203 Introduction, Sections 6–7, Appendix C, and parameter-set tables.","primary_source_url":"https://csrc.nist.gov/pubs/fips/203/final","status":"section_checked"},"statement":"FIPS 203 normatively specifies ML-KEM with three parameter sets, exact algorithms, encodings, input checks, and implicit-rejection behavior.","statement_status":"source_normalized_statement","status":"published","title":"NIST standardization of the Kyber-derived ML-KEM profile","work_id":"PKE-PAPER-2024-FIPS203"},"primaryUrl":"https://csrc.nist.gov/pubs/fips/203/final","sections":[],"status":"published","subtitle":"Module-Lattice-Based Key-Encapsulation Mechanism Standard","summary":"FIPS 203 normatively specifies ML-KEM with three parameter sets, exact algorithms, encodings, input checks, and implicit-rejection behavior.","title":"NIST standardization of the Kyber-derived ML-KEM profile","type":"result","venue":"FIPS 203","year":2024,"sourcePath":"data/pke-kem-catalog.json#PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD"}],"propertyAssertions":[{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-034A36325E7657","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"parameter-set-specific NTT/module arithmetic plus hashing"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-050D48A6322169","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"negligible but nonzero; parameter-bound"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-0B5F4661A6434B","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"malformed-ciphertext-rejection"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-0DE60457B52A50","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"negligible and parameter-set dependent"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-0E1FD3579C315B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"one private RSA operation"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-120CE47AD60568","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"module_lattice"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-12728BDA4857DB","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"reencryption-validation-lineage"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-12BF1AE1259EC4","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"module_lattice"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-16CA14AF412814","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"randomized-encryption"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-172C9DF808F7C3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"FO-family transform over module-LWE/module-LWR-style PKE"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-1795DCA2AA1247","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"OAEP randomized Feistel-style encoding around a trapdoor permutation"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-1C12E9055D4303","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"KEM + labeled KDF + AEAD key schedule"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-1CC1758413FC09","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"rsa"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-1E38116A17421F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"no"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-1E94AE7C4A5354","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"RFC 9180 base KEM registry is classical"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-2142622DC07018","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"hash-bound consistency check over an ElGamal-like ciphertext"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-232475725306F7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"historical research construction"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-277C267070299F","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"public-key-confidentiality-root"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-278EC449AE7304","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"public_key_encryption_transform"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-281169FC967F3E","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"module-lattice-arithmetic"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-28AF1E53A6204F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"parameter-set-specific NTT/module arithmetic plus implicit rejection"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-2A05156E21F0AE","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"module polynomial arithmetic plus validation/implicit rejection"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-2DD7E9E3BD7EAD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"public_key_encryption"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-2F1E8BE27FE0EB","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"post-quantum-kem"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-2F305A8B4214AC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"not a KEM"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-30F035F39B82D7","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"kem_kdf_aead_composition"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-3A0EFA526E6E71","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"hybrid framework"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-3AE076022DE5C3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"public_key_encryption"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-3D437149C8D357","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"code_based"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-3DF312ECD16B12","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"research foundation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-3EEABBA1102564","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"research construction"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-3FC23CC5D79E4C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"no"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-423BC4EBC0627A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"not a KEM"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-42F1438960E87D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"FIPS 203"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-43B3AE5FA3921B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"KEM"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-497780CFC79867","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"associated-data"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-4B1BC243301A4C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"PKE"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-4B333F38F14CB2","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"cca2-security"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-552D9B8B140C0A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"PKE"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-55595C967D4F45","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"group exponentiations plus consistency check"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-5622E52C05BAB9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"not a KEM"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-5BC654AC846B9F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"KEM"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-5FFF252D6D956A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"explicit reject on invalid consistency equation"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-64A8C99B66651F","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"code-based-encryption"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-6B55CEE2C0B5ED","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"post-quantum-lineage"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-6C39AF914CF282","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"implicit-rejection"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-73F9619BDC4D53","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"none"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-74B5BD2F478069","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"hybrid_public_key_encryption"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-765A19A3AFFD4E","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"multiplicative-homomorphism"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-773CD7C9D6DA6A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"KEM/AEAD rejection; suite-dependent"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-7A6B00F9612BD0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"research transform; RSA-OAEP is profiled by later standards"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-7B9A076FD992F2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"post-quantum candidate lineage"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-7C1F80DE80548E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"research/NIST submission design; superseded normatively by ML-KEM"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-7C5B8AEC30EB00","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"PKE"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-7D4FC0647A3F6A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"bounded by the selected code/error profile"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-7E4E39FE8CC4C0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"none for valid algebraic inputs"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-8055102B24A12F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"base encryption plus hashing/symmetric work"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-832988B39B79C9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"historical foundation; not secure for deployment by itself"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-84742C237D5808","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"cca-transform"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-85DFB047E72A5B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"transform"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-897729E7D81A7A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"hybrid_pke_transform"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-8BF2D5E42E6A57","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"ephemeral Diffie–Hellman masking"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-911B1C24683674","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"research transform; many later KEMs use FO-family variants"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-93BF4FFB83ACA1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"selected KEM decapsulation plus key schedule and AEAD open"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-943E48BCAD2AED","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"error-vector masking"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-94EBDDA987248F","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"post-quantum-kem"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-94FE76264793B9","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"sender-authentication-modes"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-972884697256CB","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"implicit-rejection"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-9BCBA7E5848255","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"ciphertext-validity-check"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-9CC93FAD4C55C8","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"IETF RFC 9180"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-A0172A9579800F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"public_key_encryption"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-A09754388AA9F1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"normative round-three-Kyber-derived implicit-rejection KEM transform with FIPS-specific input-output rules"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-A5BFC9BC75AF4B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"no for RSA instantiation"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-A9714FF4913759","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"selected KEM encapsulation plus key schedule and AEAD seal"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-AA0780096DAB0C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"key_encapsulation_mechanism"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-AA40564D23677C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"PKE"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-AA431D55D220AB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"base decryption plus validation/re-encryption"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-AD6848E77BB1E7","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"NIST post-quantum standard"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-AF331F8FC99B04","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"secret-code decoding"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-B190E4AF8E3658","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"suite- and mode-dependent; base, PSK, authenticated, and authenticated-PSK modes are distinct"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-B27F665EE24C2E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"not a KEM"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-B329F07BB53E54","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"chosen-ciphertext secure in the specified random-oracle treatment"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-B7471DC347DD54","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"three-parameter-sets"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-B955CBBE86B0A3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"one inverse permutation plus hash/encoding checks"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-B998EF2C8C35C1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"none for valid group inputs"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-B9DB0AE3BEA197","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"generic_transform"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-BBEC0B53C7AAF8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"depends on the base primitive and proof model"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-C078592CE11551","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"historical one-wayness target; not a modern CCA profile"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-C285FEDBDC10D9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"public_key_encryption"},{"dimension":"decapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-C413C9C399D98E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"one secret exponentiation plus group operations"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-C45D0088786315","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"deterministic; not IND-CPA"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-C9E534756E4320","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"rsa_encoding"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-CFF7AB3F8AAE68","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"IND-CCA-oriented standardized KEM"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-D14FB2FBC56789","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"randomized-encoding"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-MCELIECE.md","id":"PKE-PROP-D32259B387CBB1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-MCELIECE","value":"post-quantum design family; this historical profile is not a current standard"},{"dimension":"api_style","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-D343C03D6B2A66","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"transform"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-D3D5F0A10945A8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"inherited from base primitive plus explicit reject/re-encrypt check"},{"dimension":"quantum_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1978-RSA.md","id":"PKE-PROP-D5D2F9D0F6BACF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1978-RSA","value":"no"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-DEAA8773316B2B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"IND-CCA2"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2024-MLKEM.md","id":"PKE-PROP-DF8EBF78973902","review_status":"normative_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2024-MLKEM","value":"key_encapsulation_mechanism"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-E0E162EAA53932","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"module polynomial arithmetic plus hashing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2022-HPKE.md","id":"PKE-PROP-E1B3008FC42F49","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-2022-HPKE","value":"kem-dem-composition"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1998-CS.md","id":"PKE-PROP-E3A1B5B703F6FF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1998-CS","value":"discrete_log"},{"dimension":"transform","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-E423B1CECBA8C6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"Fujisaki–Okamoto message-dependent hashing, re-encryption validation, and symmetric integration"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-E8DAE8A18E1E55","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"discrete_log"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-2017-KYBER.md","id":"PKE-PROP-E91C152A2D24C1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-2017-KYBER","value":"IND-CCA KEM in the stated random-oracle treatment"},{"dimension":"encapsulation_cost","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-F27D0D46E9D55A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"not a KEM"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1985-ELGAMAL.md","id":"PKE-PROP-F28F8E0A1CB33D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1985-ELGAMAL","value":"IND-CPA under DDH in an appropriate group; malleable and not CCA secure"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1999-FO.md","id":"PKE-PROP-F6391CE5B1FEE6","review_status":"scheme_declared","scope":"construction","subject_id":"PKE-CONSTRUCTION-1999-FO","value":"hybrid-composition"},{"dimension":"decryption_failure","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-F7E00C17DA9865","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"explicit reject on malformed encoding"},{"dimension":"ciphertext_security","evidence_ref":"knowledge/primitives/pke-kem/schemes/PKE-CONSTRUCTION-1994-OAEP.md","id":"PKE-PROP-FEF5179654A7AA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"PKE-CONSTRUCTION-1994-OAEP","value":"randomized-encoding transform with an original random-oracle CCA claim; the generic proof gap and later instantiation-specific results must be kept separate"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT":{"anchor_roles":[],"group":"construction","label":"Interactive DH key agreement","lane_rationale":"Gives the interactive exponential key-agreement protocol, an unauthenticated construction rather than the general public-key notion.","lenses":["public_key_capability","hybrid_composition"],"selection_rationale":"This adjacent node prevents “public-key cryptography” from being read as synonymous with PKE; it records an interactive, unauthenticated key-establishment capability later reused by ElGamal and HPKE's DHKEM suites.","thread":"public_key_roots","visibility":"reviewed_related"},"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT":{"anchor_roles":["model_definition"],"group":"foundation","label":"Public-key cryptography concept","lane_rationale":"Introduces the public/private cryptographic interface independently of any particular PKE or key-agreement algorithm.","lenses":["public_key_capability"],"primary":true,"selection_rationale":"Omitting this definition would make the map begin with a particular formula and hide the earlier conceptual shift from shared-secret distribution to a public/private interface.","thread":"public_key_roots","visibility":"backbone"},"PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"McEliece code-based PKE","lane_rationale":"Constructs encryption from a disguised decodable code and bounded errors; its historical role does not turn the algorithm into a model definition.","lenses":["post_quantum_transition"],"primary":true,"selection_rationale":"McEliece is the seed's independent code-decoding PKE root; without it, the early map would incorrectly suggest that public-key encryption developed only from number-theoretic trapdoors.","thread":"code_based_encryption","visibility":"backbone"},"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Textbook RSA encryption root","lane_rationale":"Gives the concrete RSA trapdoor-permutation encryption relation, without attributing IND-CPA or CCA security to textbook RSA.","lenses":["public_key_capability"],"primary":true,"selection_rationale":"RSA supplies the concrete noninteractive trapdoor-permutation root needed to understand both the feasibility of offline-recipient PKE and why OAEP later wraps the deterministic textbook relation.","thread":"public_key_roots","visibility":"backbone"},"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Randomized ElGamal PKE","lane_rationale":"Constructs randomized recipient-key encryption from an ephemeral Diffie-Hellman mask, with malleability retained as a limitation.","lenses":["public_key_capability"],"primary":true,"selection_rationale":"ElGamal connects interactive Diffie–Hellman agreement to randomized recipient-key encryption and provides the malleable algebraic baseline that Cramer–Shoup later hardens.","thread":"public_key_roots","visibility":"backbone"},"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"OAEP randomized encoding","lane_rationale":"Provides the randomized two-hash encoding around a trapdoor permutation; its instantiation-sensitive security scope is not a generic CCA theorem.","lenses":["chosen_ciphertext_security"],"primary":true,"selection_rationale":"OAEP marks the move from raw trapdoor permutations to randomized, validity-checked encoding; its inclusion also makes the random-oracle and proof-scope caveat visible instead of treating RSA-OAEP as a generic CCA theorem.","thread":"cca_transforms","visibility":"backbone"},"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY":{"anchor_roles":[],"group":"construction","label":"Hash-bound Cramer–Shoup ciphertexts","lane_rationale":"Defines the concrete hash-bound ciphertext consistency and rejection mechanism of Cramer-Shoup encryption.","lenses":["chosen_ciphertext_security"],"selection_rationale":"This mechanism node shows how Cramer–Shoup blocks algebraic ciphertext modification through a hash-bound rejection equation, rather than leaving the standard-model CCA theorem unexplained.","thread":"cca_transforms","visibility":"reviewed_related"},"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION":{"anchor_roles":["capability_boundary"],"group":"foundation","label":"Standard-model adaptive CCA PKE","lane_rationale":"This exact node owns the independently significant standard-model adaptive-CCA theorem, while the companion node owns the concrete consistency-check construction.","lenses":["chosen_ciphertext_security"],"primary":true,"selection_rationale":"The theorem is the seed's standard-model adaptive-CCA boundary; separating it from the ciphertext mechanism preserves the adversary model and assumptions that make the construction significant.","thread":"cca_transforms","visibility":"backbone"},"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Fujisaki–Okamoto CCA transform","lane_rationale":"Provides the reusable random-oracle hybrid-encryption transform with recomputation validation, not every later FO-family KEM variant.","lenses":["chosen_ciphertext_security","hybrid_composition"],"primary":true,"selection_rationale":"Fujisaki–Okamoto is the reusable random-oracle hybrid-encryption hardening step later adapted by Kyber; omitting it would make Kyber's re-encryption validation appear construction-specific and historically unmotivated.","thread":"cca_transforms","visibility":"backbone"},"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Kyber module-lattice CCA KEM","lane_rationale":"Constructs the research-version CCA KEM by wrapping its module-lattice CPA component in an FO-family transform, with the reviewed revision named.","lenses":["chosen_ciphertext_security","post_quantum_transition"],"primary":true,"selection_rationale":"Kyber is the module-lattice, FO-transformed research KEM that connects the post-quantum construction line to later standardization; it remains distinct because its 2017 configuration is not FIPS 203 ML-KEM.","thread":"lattice_kems","visibility":"backbone"},"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT":{"anchor_roles":[],"group":"construction","label":"Kyber CPA encryption component","lane_rationale":"Defines the module-lattice CPA encryption substrate with compression and decryption failures as a component distinct from the full CCA KEM.","lenses":["post_quantum_transition"],"selection_rationale":"This reviewed-related node exposes the CPA encryption substrate, compression, and failure contract underneath Kyber so readers do not mistake the base component for the complete CCA KEM.","thread":"lattice_kems","visibility":"reviewed_related"},"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES":{"anchor_roles":[],"group":"construction","label":"HPKE authentication and PSK modes","lane_rationale":"Specifies protocol setup variants binding sender credentials and PSKs into the hybrid key schedule; it does not introduce a new KEM or validate application identities.","lenses":["hybrid_composition"],"selection_rationale":"The additional modes are reviewed separately because sender credentials and PSK inputs change HPKE's trust contract while reusing the same framework; they are not new KEM constructions.","thread":"hybrid_protocols","visibility":"reviewed_related"},"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK":{"anchor_roles":["capability_boundary"],"group":"construction","label":"HPKE KEM-KDF-AEAD framework","lane_rationale":"The RFC-backed claim specifies a concrete suite-parameterized KEM-KDF-AEAD protocol composition, not merely an adoption milestone.","lenses":["hybrid_composition"],"primary":true,"selection_rationale":"HPKE changes the comparison object from one KEM to a suite-parameterized KEM–KDF–AEAD protocol interface; without it, the map would conflate encapsulation with complete hybrid message protection.","thread":"hybrid_protocols","visibility":"backbone"}},"overview_reading_path":["PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK"],"problems":[{"id":"public_key_capability","label":"Public-key capability","question":"Which interfaces make confidentiality possible without a pre-shared secret?","reading_path":["PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION"]},{"id":"chosen_ciphertext_security","label":"Chosen-ciphertext security","question":"How did public-key encryption and KEMs move from malleable CPA security to robust CCA security?","reading_path":["PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM","PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION","PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM"]},{"id":"post_quantum_transition","label":"Post-quantum transition","question":"Which construction families and standards replace classical public-key assumptions?","reading_path":["PKE-RESULT-1978-MCELIECE-CODE-BASED-PUBLIC-KEY-ENCRYPTION","PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM"]},{"id":"hybrid_composition","label":"Hybrid composition","question":"How should a KEM compose with key derivation and authenticated encryption in a deployable protocol?","reading_path":["PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK"]}],"relations":[{"change_dimensions":["functionality","model"],"evidence_locator":"Diffie–Hellman paper, Sections II–III","evidence_url":"https://doi.org/10.1109/TIT.1976.1055638","id":"lineage-4a8d241d71c1c7a8","map_relation":"lineage","predecessor":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","relation_basis":"model_relation","relation_type":"INSTANTIATES_CAPABILITY","review_status":"primary_source_checked","statement":"The exponential exchange gives one concrete shared-secret capability inside the broader public-key program, without becoming noninteractive PKE.","successor":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT"},{"change_dimensions":["functionality"],"evidence_locator":"RSA paper, Abstract and enciphering/deciphering discussion","evidence_url":"https://people.csail.mit.edu/rivest/Rsapaper.pdf","id":"lineage-eeb8c3653397b4cc","map_relation":"lineage","predecessor":"PKE-RESULT-1976-DH-PUBLIC-KEY-CRYPTOGRAPHY-CONCEPT","relation_basis":"model_relation","relation_type":"INSTANTIATES_CAPABILITY","review_status":"primary_source_checked","statement":"RSA supplies a concrete noninteractive enciphering and deciphering relation for the public/private-key interface that Diffie and Hellman had posed as a cryptographic program.","successor":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"ElGamal paper, encryption-system construction","evidence_url":"https://doi.org/10.1109/TIT.1985.1057074","id":"lineage-aea5dc9f2b614ce4","map_relation":"lineage","predecessor":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","relation_basis":"technical_dependency","relation_type":"USES_PRIMITIVE","review_status":"primary_source_checked","statement":"ElGamal uses an ephemeral Diffie–Hellman-style shared group element to mask a plaintext for a recipient public key.","successor":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION"},{"change_dimensions":["mechanism"],"evidence_locator":"OAEP paper, construction and RSA instantiation","evidence_url":"https://www.cs.ucdavis.edu/~rogaway/papers/oaep-abstract.html","id":"lineage-34e8bf1644d6a8a5","map_relation":"lineage","predecessor":"PKE-RESULT-1978-RSA-RSA-PUBLIC-KEY-ENCRYPTION-RELATION","relation_basis":"technical_dependency","relation_type":"HARDENS","review_status":"primary_source_checked","statement":"OAEP randomizes and validates a trapdoor-permutation input rather than applying textbook RSA directly to the message.","successor":"PKE-RESULT-1994-OAEP-OAEP-RANDOMIZED-ENCODING-TRANSFORM"},{"change_dimensions":["mechanism","security"],"evidence_locator":"Cramer–Shoup paper, Introduction and cryptosystem definition","evidence_url":"https://crypto.ethz.ch/publications/CraSho98.html","id":"lineage-afbaed8759e5df02","map_relation":"lineage","predecessor":"PKE-RESULT-1985-ELGAMAL-RANDOMIZED-DISCRETE-LOG-ENCRYPTION","relation_basis":"technical_dependency","relation_type":"HARDENS","review_status":"primary_source_checked","statement":"Cramer–Shoup augments an ElGamal-like ciphertext with hash-bound components and a rejection equation to block adaptive malleation.","successor":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY"},{"change_dimensions":["security"],"evidence_locator":"Cramer–Shoup paper, security theorem and proof","evidence_url":"https://crypto.ethz.ch/publications/CraSho98.html","id":"lineage-1b1e9a64eb2c2f28","map_relation":"lineage","predecessor":"PKE-RESULT-1998-CS-HASH-BOUND-ELGAMAL-CIPHERTEXT-CONSISTENCY","relation_basis":"analysis","relation_type":"ESTABLISHES_SECURITY","review_status":"primary_source_checked","statement":"The paper proves the consistency-checked construction adaptively CCA secure in the standard model under its stated assumptions.","successor":"PKE-RESULT-1998-CS-STANDARD-MODEL-ADAPTIVE-CCA-ENCRYPTION"},{"change_dimensions":["mechanism","security"],"evidence_locator":"Kyber paper, Sections 4–5 and CCA-transform discussion","evidence_url":"https://eprint.iacr.org/2017/634","id":"lineage-88e5baa7786987d0","map_relation":"lineage","predecessor":"PKE-RESULT-1999-FO-FUJISAKI-OKAMOTO-CCA-TRANSFORM","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"Kyber applies an FO-family validation and key-derivation transform to its module-lattice encryption component.","successor":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM"},{"change_dimensions":["mechanism","security","functionality"],"evidence_locator":"Kyber paper, transition from Section 3 PKE to Sections 4–5 KEM","evidence_url":"https://eprint.iacr.org/2017/634","id":"lineage-d4b8fd43b42c7ccc","map_relation":"lineage","predecessor":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CPA-ENCRYPTION-COMPONENT","relation_basis":"technical_dependency","relation_type":"TRANSFORMS","review_status":"primary_source_checked","statement":"The full Kyber KEM wraps the paper's CPA module-lattice encryption component in its FO-family CCA transform.","successor":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"RFC 9180 Sections 4 and 7.1","evidence_url":"https://www.rfc-editor.org/rfc/rfc9180.html","id":"lineage-b7f17627456c68ab","map_relation":"lineage","predecessor":"PKE-RESULT-1976-DH-INTERACTIVE-PUBLIC-CHANNEL-KEY-AGREEMENT","relation_basis":"technical_dependency","relation_type":"COMPOSES","review_status":"primary_source_checked","statement":"HPKE defines DHKEM suites that package Diffie–Hellman shared-secret derivation behind a KEM interface and labeled key schedule.","successor":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK"},{"change_dimensions":["functionality","model","security"],"evidence_locator":"RFC 9180 Section 5","evidence_url":"https://www.rfc-editor.org/rfc/rfc9180.html","id":"lineage-696c72f5958ccf10","map_relation":"lineage","predecessor":"PKE-RESULT-2022-HPKE-KEM-KDF-AEAD-HYBRID-FRAMEWORK","relation_basis":"technical_dependency","relation_type":"EXTENDS_SETTINGS","review_status":"primary_source_checked","statement":"HPKE reuses the same suite and context framework while binding sender authentication and/or PSK inputs in additional setup modes.","successor":"PKE-RESULT-2022-HPKE-AUTHENTICATED-AND-PSK-MODES"},{"change_dimensions":["implementation"],"evidence_locator":"FIPS 203 Introduction and Appendix C","evidence_url":"https://csrc.nist.gov/pubs/fips/203/final","id":"lineage-bcd7b37b444f33dd","map_relation":"reference","predecessor":"PKE-RESULT-2017-KYBER-MODULE-LATTICE-CCA-SECURE-KEM","relation_basis":"technical_dependency","relation_type":"STANDARDIZES","review_status":"primary_source_checked","statement":"FIPS 203 specifies a Kyber-derived KEM as ML-KEM with fixed algorithms, encodings, validation, and three parameter sets.","successor":"PKE-RESULT-2024-FIPS203-ML-KEM-NORMATIVE-STANDARD"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"Trapdoor and Diffie–Hellman foundations for public-key confidentiality.","id":"public_key_roots","label":"Public-key roots"},{"color":"#4f7b60","description":"Error-correcting-code constructions and their post-quantum lineage.","id":"code_based_encryption","label":"Code-based encryption"},{"color":"#b65358","description":"Encodings and generic transformations that harden encryption or KEMs.","id":"cca_transforms","label":"CCA transforms"},{"color":"#73549a","description":"Module-lattice KEM constructions and their standardized profiles.","id":"lattice_kems","label":"Lattice KEMs"},{"color":"#2f718e","description":"KEM, KDF, and AEAD composition at the protocol interface.","id":"hybrid_protocols","label":"Hybrid protocols"},{"color":"#9a6c2d","description":"Normative profiles and interoperability transitions.","id":"migration_standards","label":"Migration and standards"}]},"stats":{"constructions":9,"countsByType":{"assumption":7,"construction":9,"paper":10,"result":14},"entities":40,"lineageRelationships":10,"propertyAssertions":111,"relationships":43,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}