ID  Algorithm  Requirement  Definition 

TBD  MLKEM512+ECDHNISTP256  MAY 

TBD  MLKEM768+ECDHNISTP384  MAY 

TBD  MLKEM1024+ECDHNISTP384  MAY 

TBD  MLKEM768+ECDHbrainpoolP256r1  MAY 

TBD  MLKEM1024+ECDHbrainpoolP384r1  MAY 

TBD  MLDSA44+ECDSANISTP256  MAY 

TBD  MLDSA65+ECDSANISTP384  MAY 

TBD  MLDSA87+ECDSANISTP384  MAY 

TBD  MLDSA65+ECDSAbrainpoolP256r1  MAY 

TBD  MLDSA87+ECDSAbrainpoolP384r1  MAY 

NIST P256  NIST P384  

Algorithm ID reference  TBD (MLKEM512+ECDHNISTP256)  TBD (MLKEM768+ECDHNISTP384, MLKEM1024+ECDHNISTP384, ) 
Field size  32 octets  48 octets 
ECCKEM  ecdhKem ( 
ecdhKem ( 
ECDH public key  65 octets of SEC1encoded public point  97 octets of SEC1encoded public point 
ECDH secret key  32 octets bigendian encoded secret scalar  48 octets bigendian encoded secret scalar 
ECDH ephemeral  65 octets of SEC1encoded ephemeral point  97 octets of SEC1encoded ephemeral point 
ECDH share  65 octets of SEC1encoded shared point  97 octets of SEC1encoded shared point 
Key share  32 octets  64 octets 
Hash  SHA3256  SHA3512 
brainpoolP256r1  brainpoolP384r1  

Algorithm ID reference  TBD (MLKEM768+ECDHbrainpoolP256r1)  TBD (MLKEM1024+ECDHbrainpoolP384r1) 
Field size  32 octets  48 octets 
ECCKEM  ecdhKem ( 
ecdhKem ( 
ECDH public key  65 octets of SEC1encoded public point  97 octets of SEC1encoded public point 
ECDH secret key  32 octets bigendian encoded secret scalar  48 octets bigendian encoded secret scalar 
ECDH ephemeral  65 octets of SEC1encoded ephemeral point  97 octets of SEC1encoded ephemeral point 
ECDH share  65 octets of SEC1encoded shared point  97 octets of SEC1encoded shared point 
Key share  32 octets  64 octets 
Hash  SHA3256  SHA3512 
Algorithm ID reference  MLKEM  Public key  Secret key  Ciphertext  Key share 

TBD  MLKEM512  800  1632  768  32 
TBD  MLKEM768  1184  2400  1088  32 
TBD  MLKEM1024  1568  3168  1568  32 
Algorithm ID reference  MLKEM  ECCKEM  ECCKEM curve 

TBD (MLKEM512+ECDHNISTP256)  MLKEM512  ecdhKem  NIST P256 
TBD (MLKEM768+ECDHNISTP384)  MLKEM768  ecdhKem  NIST P384 
TBD (MLKEM1024+ECDHNISTP384)  MLKEM1024  ecdhKem  NIST P384 
TBD (MLKEM768+ECDHbrainpoolP256r1)  MLKEM768  ecdhKem  brainpoolP256r1 
TBD (MLKEM1024+ECDHbrainpoolP384r1)  MLKEM1024  ecdhKem  brainpoolP384r1 
Algorithm ID reference  Curve  Field size  Public key  Secret key  Signature value R  Signature value S 

TBD (MLDSA44+ECDSANISTP256)  NIST P256  32  65  32  32  32 
TBD (MLDSA65+ECDSANISTP384,MLDSA87+ECDSANISTP384)  NIST P384  48  97  48  48  48 
TBD (MLDSA65+ECDSAbrainpoolP256r1)  brainpoolP256r1  32  65  32  32  32 
TBD (MLDSA87+ECDSAbrainpoolP384r1)  brainpoolP384r1  48  97  48  48  48 
Algorithm ID reference  MLDSA  Public key  Secret key  Signature value 

TBD  MLDSA44  1312  2528  2420 
TBD  MLDSA65  1952  4032  3293 
TBD  MLDSA87  2592  4896  4595 
Algorithm ID reference  Hash function  Hash function ID reference 

TBD (MLDSA44 IDs)  SHA3256  12 
TBD (MLDSA65 IDs)  SHA3512  14 
TBD (MLDSA87 IDs)  SHA3512  14 
ID  Algorithm  Public Key Format  Secret Key Format  Signature Format  PKESK Format  Reference 

TBD  MLDSA65+TBD  TBD octets TBD public key , TBD octets MLDSA65 public key ( 
TBD octets TBD secret key , TBD octets MLDSA65 secret ( 
TBD octets TBD signature , TBD octets MLDSA65 signature ( 
N/A 
