#./fio-stl/156 mlkem.h
17 public symbols.
#Macros
#FIO_MLKEM768_PUBLICKEYBYTES
#define FIO_MLKEM768_PUBLICKEYBYTES 1184ML-KEM-768 constants
Symbol type: macro
#FIO_MLKEM768_SECRETKEYBYTES
#define FIO_MLKEM768_SECRETKEYBYTES 2400Symbol type: macro
#FIO_MLKEM768_CIPHERTEXTBYTES
#define FIO_MLKEM768_CIPHERTEXTBYTES 1088Symbol type: macro
#FIO_MLKEM768_SSBYTES
#define FIO_MLKEM768_SSBYTES 32Symbol type: macro
#FIO_MLKEM768_SYMBYTES
#define FIO_MLKEM768_SYMBYTES 32Symbol type: macro
#FIO_X25519MLKEM768_PUBLICKEYBYTES
#define FIO_X25519MLKEM768_PUBLICKEYBYTES (32 + 1184) /* 1216 */X25519MLKEM768 hybrid constants
Symbol type: macro
#FIO_X25519MLKEM768_SECRETKEYBYTES
#define FIO_X25519MLKEM768_SECRETKEYBYTES (32 + 2400) /* 2432 */Symbol type: macro
#FIO_X25519MLKEM768_CIPHERTEXTBYTES
#define FIO_X25519MLKEM768_CIPHERTEXTBYTES (32 + 1088) /* 1120 */Symbol type: macro
#FIO_X25519MLKEM768_SSBYTES
#define FIO_X25519MLKEM768_SSBYTES 64Symbol type: macro
#Functions
#fio_mlkem768_keypair
int fio_mlkem768_keypair(uint8_t pk[1184], uint8_t sk[2400])Generate ML-KEM-768 keypair.
Generates a random keypair using the system CSPRNG. Returns 0 on success, -1 on failure.
Symbol type: function
#fio_mlkem768_keypair_derand
int fio_mlkem768_keypair_derand(uint8_t pk[1184], uint8_t sk[2400], const uint8_t coins[64])Generate ML-KEM-768 keypair from deterministic seed.
The coins buffer must be exactly 64 bytes (d || z). Returns 0 on success, -1 on failure.
Symbol type: function
#fio_mlkem768_encaps
int fio_mlkem768_encaps(uint8_t ct[1088], uint8_t ss[32], const uint8_t pk[1184])Encapsulate: generate ciphertext and shared secret from public key.
Uses system CSPRNG for randomness. Returns 0 on success, -1 on failure.
Symbol type: function
#fio_mlkem768_encaps_derand
int fio_mlkem768_encaps_derand(uint8_t ct[1088], uint8_t ss[32], const uint8_t pk[1184], const uint8_t coins[32])Encapsulate with deterministic randomness.
The coins buffer must be exactly 32 bytes. Returns 0 on success, -1 on failure.
Symbol type: function
#fio_mlkem768_decaps
int fio_mlkem768_decaps(uint8_t ss[32], const uint8_t ct[1088], const uint8_t sk[2400])Decapsulate: recover shared secret from ciphertext and secret key.
Uses implicit rejection: if the ciphertext is invalid, a pseudorandom shared secret is returned (derived from the secret key and ciphertext) rather than an error, preventing chosen-ciphertext attacks.
Returns 0 on success (always succeeds for well-formed inputs).
Symbol type: function
#fio_x25519mlkem768_keypair
int fio_x25519mlkem768_keypair(uint8_t pk[1216], uint8_t sk[2432])Generate X25519MLKEM768 hybrid keypair.
Generates both X25519 and ML-KEM-768 keypairs using system CSPRNG. The public key is ML-KEM-768_ek (1184) || X25519_pk (32) = 1216 bytes. The secret key is ML-KEM-768_dk (2400) || X25519_sk (32) = 2432 bytes.
Returns 0 on success, -1 on failure.
Symbol type: function
#fio_x25519mlkem768_encaps
int fio_x25519mlkem768_encaps(uint8_t ct[1120], uint8_t ss[64], const uint8_t pk[1216])X25519MLKEM768 hybrid encapsulation.
Performs both X25519 key exchange and ML-KEM-768 encapsulation. The ciphertext is ML-KEM-768_ct (1088) || X25519_ephemeral_pk (32) = 1120 bytes. The shared secret is ML-KEM-768_ss (32) || X25519_ss (32) = 64 bytes.
Returns 0 on success, -1 on failure.
Symbol type: function
#fio_x25519mlkem768_decaps
int fio_x25519mlkem768_decaps(uint8_t ss[64], const uint8_t ct[1120], const uint8_t sk[2432])X25519MLKEM768 hybrid decapsulation.
Performs both X25519 shared secret derivation and ML-KEM-768 decapsulation. The shared secret is ML-KEM-768_ss (32) || X25519_ss (32) = 64 bytes.
Returns 0 on success, -1 if X25519 shared secret computation fails (low-order point). ML-KEM-768 uses implicit rejection for invalid ciphertexts.
Symbol type: function