Algorithms
What is FrodoKEM?
Plain Learning-with-Errors KEM without the algebraic structure of ML-KEM. Larger but conservative — selected by BSI (German government) for high-assurance applications.
Deep dive
FrodoKEM on QNSP
Plain Learning With Errors (LWE) KEM — same lattice family as ML-KEM but without the additional ring or module structure. Larger keys and ciphertexts but built on the most conservative lattice assumption.
For parameter sets, key and signature sizes, NIST ACVP conformance status, and when to use it, see the full FrodoKEM algorithm reference.
FAQ
Common questions
What is FrodoKEM?
Plain Learning-with-Errors KEM without the algebraic structure of ML-KEM. Larger but conservative — selected by BSI (German government) for high-assurance applications.
More