Swapping the Movement: Post-Distribution Parameter Tampering in Post-Quantum Cryptography
FIPS 203 defines three ML-KEM parameter sets with fixed constants. This paper examines a deployment question: after a conformant implementation has been built and distributed, which parts of the execution stack detect a modified artifact before it performs cryptographic operations? The study consolidates nine target rows from five implementation families (liboqs, wolfSSL, AWS-LC, SymCrypt, NVIDIA cuPQC), Windows CNG, and GPU execution on Google Colab and Kaggle. The recorded probes distinguish three integrity states: no runtime verification (State 0), platform-enforced verification (State 1), and module integrity self-test (State 2). Seven of nine targets are State 0 by default. The analytical model shows that eta1=0 is the only modeled parameter change that preserves both ciphertext size (768 bytes) and same-build roundtrip behavior, making it invisible to smoke checks but detectable by canonical KATs and byte-level integrity controls. The study does not claim a runtime vulnerability in any library. Companion materials include a reproducible Jupyter notebook, CSV data tables, and GPU smoke-test reports from two independent environments.
Authors
- Everton Melo
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-08-25
- DOI
- https://doi.org/10.5281/zenodo.22097773
- Primary Topic
- Cryptographic Implementations and Security
- Type
- preprint