From Algebraic Correctness to Zero Trust Deployment: An Assurance Framework for ML-KEM
William Edwards, Miroslav Vukovic, Jeffrey WallaceThe transition from post-quantum cryptographic standardization to operational deployment requires more than the selection of a quantum-resistant algorithm. It requires traceability from the mathematical assumptions of the primitive to implementation requirements, protocol composition, migration controls, and runtime governance. This paper develops a cross-layer assurance framework for deploying the NIST-standardized Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) within crypto-agile Zero Trust architectures. The paper presents a simplified algebraic model of the public-key encryption operations underlying ML-KEM, emphasizing quotient-ring arithmetic, module operations, controlled noise, and cancellation of the principal bilinear term. It then distinguishes this explanatory model from the complete mechanism specified in FIPS 203, including standardized sampling, encoding, compression, hashing, key derivation, ciphertext consistency checking through re-encryption and comparison, implicit rejection, and prescribed decapsulation behavior. The principal contribution is an assurance framework connecting three levels: algebraic assurance, implementation assurance, and cryptographic governance. A deployment architecture, threat model, crypto-agility lifecycle, and bounded AI-assisted monitoring model are presented to show how ML-KEM profiles can be inventoried, approved, negotiated, observed, migrated, rolled back, and audited without altering the underlying cryptographic guarantees. The resulting framework provides a technically grounded bridge between ML-KEM mathematics and practical post-quantum migration in Zero Trust systems.