QNSP

Algorithms

What is FrodoKEM?

Plain Learning-with-Errors KEM without the algebraic structure of ML-KEM. Larger but conservative — selected by BSI (German government) for high-assurance applications.

FrodoKEM algorithm reference →

Deep dive

FrodoKEM on QNSP

Plain Learning With Errors (LWE) KEM — same lattice family as ML-KEM but without the additional ring or module structure. Larger keys and ciphertexts but built on the most conservative lattice assumption.

For parameter sets, key and signature sizes, NIST ACVP conformance status, and when to use it, see the full FrodoKEM algorithm reference.

FAQ

Common questions

What is FrodoKEM?

Plain Learning-with-Errors KEM without the algebraic structure of ML-KEM. Larger but conservative — selected by BSI (German government) for high-assurance applications.

More

Keep exploring