Closed ounsworth closed 1 month ago
TODO: as per https://www.enisa.europa.eu/publications/post-quantum-cryptography-integration-study section 4.2, might need to specify behaviour in light of KEMs with a non-zero failure probability.
We probably need to at least mention that decapsulation failure is a possible result of calling CompositeML-KEM.decaps(). Borrow language from, or reference, draft-ietf-lamps-cms-kyber ?
draft-ietf-lamps-cms-kyber