crypto_shared library

Shared integration helpers for pqthreshold + pqforge consumers.

Use from Flutter officer apps and Serverpod coordinators. See example/serverpod_integration/ for a Serverpod wiring sketch.

Classes

CeremonyMessageRelay
Relays canonical DKG wire bytes between participants.
CeremonySession
Drives one participant through Gennaro DKG rounds (C1).
ContinuityProof
Links a new threshold public key to an authorized predecessor.
DealerCeremony
Orchestration for dealer-based VSS (C2).
DirectoryCeremonyRelay
Persists DKG wire bytes under rootDir/messages/ for sneakernet workflows.
DistributedDkgCoordinator
Runs C1 with officers communicating only through relay.
DistributedSigningCoordinator
Runs threshold signing with officers submitting partials to a coordinator.
DkgMessage
Typed wrapper for a canonical DKG protocol envelope.
DkgWireKind
Protocol message kind bytes for DKG (doc/PROTOCOL_MESSAGES.md §3.2).
DkgWireSubKind
Protocol message sub-kind bytes for DKG.
FrostSigningMessage
Typed wrapper for a canonical FROST signing protocol envelope.
FrostWireKind
Protocol message kind bytes for FROST signing.
FrostWireSubKind
Protocol message sub-kind bytes for FROST signing.
InMemoryCeremonyRelay
In-memory relay for tests and local multi-process prototypes.
OfficerDkgClient
Drives CeremonySession rounds via a relay (Flutter ↔ Serverpod pattern).
OfficerSigningClient
Officer-side C3 helper when partials are collected by a coordinator service.
PartialSignature
One signer's FROST round material for a single message.
PqBytes
PqClassical
Process-wide registry for the active PqClassicalProvider.
PqRandom
Process-wide source of cryptographic randomness.
PqthHeader
Parsed 8-byte PQTH object header.
PublicKey
Joint threshold public key material.
RecoveryCeremony
High-privilege C4 reconstruction — explicit, audited secret export.
RootCeremony
Orchestration for dealer-less root generation (C1).
RotationCeremony
Orchestration for threshold key rotation with continuity evidence (C5).
SecretBuffer
Holds sensitive bytes and wipes them on dispose.
Share
A participant's private share plus verification material.
SigningJobCoordinator
Collects partial signatures until quorum, then combines.
SigningSession
Officer-local signing state between FROST Round1 and Round2.
ThresholdCeremonyService
Coordinator-side API (no share custody).
ThresholdParams
Describes a threshold instance: quorum size, participant count, and scheme.
ThresholdSigner
FROST threshold signing over Ed25519 (C3).
ThresholdSigningCeremony
Orchestration for FROST threshold signing (C3).
Transcript
Hash-chain transcript of public ceremony data only.
VerifiableSecretSharing
Dealer-based verifiable secret sharing (C2).

Enums

SchemeId
Identifies the cryptographic scheme for a threshold instance.

Extensions

SchemeIdWire on SchemeId
Extension methods for SchemeId wire encoding.

Constants

ceremonyIdLength → const int
Required byte length for a ceremony identifier.
frostEd25519V1MaxParticipants → const int
Hard limit on participants for SchemeId.frostEd25519V1.
pqThresholdSmallSetMaxParticipants → const int
Hard limit on participants for v2 PQ small-set schemes (ADR-004).
thresholdShareAlgorithmId → const String
pqforge PqExportedKey.algorithmId for PQTH Share bytes.
thresholdShareKeyKind → const String
pqforge PqExportedKey.kind for wrapped threshold shares.

Functions

assertShareSetConsistent(List<Share> shares) → void
Ensures shares belong to one ceremony and params set.
bytesToHex(Uint8List bytes) → String
Lowercase hex without 0x prefix (TEST_VECTORS.md §3).
ceremonyIdFromHex(String hex) → Uint8List
Parses a 16-byte ceremony id from hex.
ceremonyIdToHex(Uint8List ceremonyId) → String
Ceremony id as hex (32 chars).
createOfficerDkgClient({required ThresholdParams params, required Uint8List ceremonyId, required String ceremonyIdHex, required String participantId, required int participantIndex, required CeremonyMessageRelay relay, List<String>? participantIds}) → OfficerDkgClient
Factory for a new officer client.
frostRound2WireFromPartial({required PartialSignature partial, required ThresholdParams params}) → FrostSigningMessage
Encodes Round2 wire message from a completed partial.
generateCeremonyId() → Uint8List
Generates a new random ceremony identifier.
hexToBytes(String hex) → Uint8List
Parses hex (even length) into bytes.
partialsFromRound2Messages({required Iterable<FrostSigningMessage> round1Messages, required Iterable<FrostSigningMessage> round2Messages, required PublicKey publicKey}) → List<PartialSignature>
Builds combine-ready partials from Round1 + Round2 wire messages.
readWrappedShareFile(String path) → Future<PqWrappedKey>
Reads wrapped share JSON from disk.
schemeIdFromWireOrdinal(int ordinal) → SchemeId
Parses a wire ordinal into SchemeId.
unwrapShareWithPassphrase({required PqWrappedKey wrapped, required String passphrase}) → Share
Restores Share from a pqforge wrapped envelope.
validateCeremonyId(Uint8List ceremonyId) → void
Validates ceremonyId for use in ceremonies and durable objects.
wrapShareWithPassphrase({required Share share, required String passphrase, String? keyId}) → PqWrappedKey
Wraps share with pqforge Argon2id + AES-GCM (same model as device keys).
writeCeremonyManifest({required Directory rootDir, required String ceremonyIdHex, required Map<String, Object?> manifest}) → Future<void>
JSON metadata written alongside dir-transport ceremonies.
writeWrappedShareFile({required String path, required PqWrappedKey wrapped}) → Future<void>
Writes *.share.wrapped.json (TERMINAL.md §6).

Exceptions / Errors

CeremonyAborted
A multi-party ceremony aborted (missing participants, complaints, etc.).
InconsistentShares
Shares or verification data are mutually inconsistent.
InsufficientShares
Fewer than ThresholdParams.t shares were supplied.
InvalidParams
ThresholdParams or participant identity failed validation.
InvalidPartialSignature
A partial signature failed validation or combination.
SchemeNotImplemented
SchemeId is registered but ceremony/signing is not implemented yet (v2 M1+).
SerializationError
Binary parse failure or unknown format version/kind/scheme.
ThresholdException
Base type for all recoverable threshold operation failures.
TranscriptMismatch
Transcript hash chain or contents are invalid.
WrongCeremony
Object belongs to a different ceremony or parameter set.