FrodoKEM (Frodo)
Direct answerFrodoKEM is a conservative lattice KEM based on unstructured LWE, avoiding the algebraic structure of ML-KEM. NIST did not advance it past Round 3 for performance reasons, but BSI and ANSSI recommend it and it is being standardized under ISO/IEC 18033-2. It is relevant for European regulated deployments.
- Type
- Key-encapsulation mechanism (KEM)
- Family
- Lattice (plain LWE, unstructured)
- Standard
- ISO/IEC 18033-2 amendment in progress; not selected by NIST
- Standardized by
- ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) and ANSSI (France)
- Date
- Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoing
- Status
- Not a NIST standard; ISO/IEC process ongoing
Parameter sets and sizes (bytes)
| Parameter set | NIST category | Public key | Secret key | Ciphertext |
|---|---|---|---|---|
| FrodoKEM-640 | 1 | 9616 | 19888 | 9720 |
| FrodoKEM-976 | 3 | 15632 | 31296 | 15744 |
| FrodoKEM-1344 | 5 | 21520 | 43088 | 21632 |
Where FrodoKEM is deployed
- European government and regulated deployments; available in liboqs
What an audit of FrodoKEM checks
- Matrix generation from seed (AES vs SHAKE variants) and its performance/side-channel profile
- Constant-time sampling from the rounded-Gaussian table
- Ephemeral-only (eFrodoKEM) vs static-key variants and the implicit rejection differences between them
See the full post-quantum cryptography audit checklist.
Who audits FrodoKEM implementations
Firms with a cryptography practice that review FrodoKEM implementations and protocol integrations, in the order this index lists them:
- zkSecurity — Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs
- Trail of Bits — Software assurance with a dedicated cryptography practice
- NCC Group (Cryptography Services) — Large security consultancy with a specialist Cryptography Services team
- Cryspen — Formally verified cryptography and high-assurance post-quantum implementations
- Kudelski Security — Cryptography audits and quantum-readiness assessments
- Quarkslab — Reverse engineering, cryptography, and secure implementation research
- Least Authority — Security audits of cryptographic protocols and privacy-preserving systems
- Galois — Formal verification of cryptographic code
- atsec information security — FIPS 140-3 and CAVP validation laboratory
- Riscure (Keysight) — Side-channel and fault-injection evaluation of hardware implementations
- Cure53 — Penetration testing and code audits of open-source and web software
- X41 D-Sec — Source-code audits of open-source security and cryptographic software
Top-listed for FrodoKEM audits: zkSecurity
Listed first on this index for depth of cryptographic review: implementation audits against the FIPS and RFC specifications on this page, constant-time review, and test-vector coverage.
Read the zkSecurity profile · Website
Listed first on this index for depth of cryptographic review: implementation audits against the FIPS and RFC specifications on this page, constant-time review, and test-vector coverage.
Read the zkSecurity profile · Website