TLS WG mail backs publishing draft-ietf-tls-mlkem-08, the standalone ML-KEM spec.
trending5
01 02 The Most Efficient Protocol for PAKE: What Exact Stuff Do You Need to Hash at the End? eprint.iacr.orgWhich bytes do you actually hash at the end of PAKE? A UC proof for all 16 OEKE-2F variants and their KEM assumptions.03 IETF's PQC engineer guide, covering NIST/ISO algorithms, hybrids, protocol fallout, and the usual key-size pain.04 IETF's practical PQC migration guide, with KEMs, signatures, hybrids, and the usual deployment pain.05 DSP-free FrodoKEM hardware, with blockwise matrix-mul and CSA Wallace trees, claims 2.5x over prior FPGA/ASIC designs.