pqthreshold_experimental library
Experimental post-quantum threshold APIs.
These APIs are not part of the stable FROST Ed25519 1.0 contract. They may change between releases while the underlying profiles and implementations mature. Do not use them for production key ceremonies without independent review.
Classes
- CeremonySession
- Drives one participant through Gennaro DKG rounds (C1).
- ContinuityProof
- Links a new threshold public key to an authorized predecessor.
- DealerCeremony
- Orchestration for dealer-based VSS (C2).
- DkgMessage
- Typed wrapper for a canonical DKG protocol envelope.
- DkgWireKind
-
Protocol message kind bytes for DKG (
doc/PROTOCOL_MESSAGES.md§3.2). - DkgWireSubKind
- Protocol message sub-kind bytes for DKG.
- FrostSigningMessage
- Typed wrapper for a canonical FROST signing protocol envelope.
- FrostWireKind
- Protocol message kind bytes for FROST signing.
- FrostWireSubKind
- Protocol message sub-kind bytes for FROST signing.
- MlDsaPublicKey
- Joint ML-DSA public key for a threshold ceremony (FIPS 204 encoding).
- MlDsaRootCeremony
- Orchestration for ML-DSA threshold root generation (C1 beta).
- Participant share for ML-DSA threshold schemes (v2).
- MlDsaSigningMessage
- Typed wrapper for ML-DSA threshold signing protocol envelopes.
- MlDsaSigningSession
- Officer-local ML-DSA signing state between distributed wire rounds.
- MlDsaThresholdSigner
- Threshold ML-DSA signing (C3) — M2 beta via Mithril bridge.
- MlDsaThresholdSigningCeremony
- Orchestration for ML-DSA threshold signing (C3 beta).
- MlDsaThresholdVerifier
- Verifies threshold-produced ML-DSA signatures (FIPS 204 output shape).
- MlDsaWireKind
- Protocol message kind bytes for ML-DSA threshold signing.
- MlDsaWireSubKind
- Protocol message sub-kind bytes for ML-DSA threshold signing.
- PartialSignature
- One signer's FROST round material for a single message.
- PqthHeader
- Parsed 8-byte PQTH object header.
- PublicKey
- Joint threshold public key material.
- RecoveryCeremony
- High-privilege C4 reconstruction — explicit, audited secret export.
- RootCeremony
- Orchestration for dealer-less root generation (C1).
- RotationCeremony
- Orchestration for threshold key rotation with continuity evidence (C5).
- SchemeCapabilities
- Static metadata for each SchemeId (ADR-004).
- SecretBuffer
- Holds sensitive bytes and wipes them on dispose.
- A participant's private share plus verification material.
- SigningSession
- Officer-local signing state between FROST Round1 and Round2.
- ThresholdParams
- Describes a threshold instance: quorum size, participant count, and scheme.
- ThresholdSigner
- FROST threshold signing over Ed25519 (C3).
- ThresholdSigningCeremony
- Orchestration for FROST threshold signing (C3).
- Transcript
- Hash-chain transcript of public ceremony data only.
- VerifiableSecretSharing
- Dealer-based verifiable secret sharing (C2).
Enums
- MlDsaThresholdProfile
- Maps pqthreshold ML-DSA SchemeId values to pqforge algorithms.
- SchemeId
- Identifies the cryptographic scheme for a threshold instance.
- SchemeMilestone
- Production and API readiness for a SchemeId.
- ThresholdCeremonyKind
- Ceremony types for capability checks.
Extensions
- SchemeIdWire on SchemeId
- Extension methods for SchemeId wire encoding.
Constants
- ceremonyIdLength → const int
- Required byte length for a ceremony identifier.
- frostEd25519V1MaxParticipants → const int
- Hard limit on participants for SchemeId.frostEd25519V1.
- pqThresholdSmallSetMaxParticipants → const int
- Hard limit on participants for v2 PQ small-set schemes (ADR-004).
Functions
-
Ensures all
sharesbelong to one ceremony and scheme. -
Ensures
sharesbelong to one ceremony and params set. -
combineMlDsaFromWire(
{required MlDsaPublicKey publicKey, required Uint8List message, required Iterable< MlDsaSigningMessage> round2Messages, required Iterable<MlDsaSigningMessage> round3Messages, required List<int> activePartyIdsZeroBased, String? mithrilBridgePath}) → Future<Uint8List> - Combines Round2 + Round3 wire dirs into an ML-DSA signature.
-
frostRound2WireFromPartial(
{required PartialSignature partial, required ThresholdParams params}) → FrostSigningMessage - Encodes Round2 wire message from a completed partial.
-
generateCeremonyId(
) → Uint8List - Generates a new random ceremony identifier.
-
loadMlDsaWireMessages(
Directory dir) → List< MlDsaSigningMessage> -
Loads all ML-DSA wire messages under
dir(recursive round subdirs). -
mithrilBridgeAvailable(
{String? overridePath}) → bool - Whether the Mithril bridge binary is available on this machine.
-
partialsFromRound2Messages(
{required Iterable< FrostSigningMessage> round1Messages, required Iterable<FrostSigningMessage> round2Messages, required PublicKey publicKey}) → List<PartialSignature> - Builds combine-ready partials from Round1 + Round2 wire messages.
-
schemeIdFromWireOrdinal(
int ordinal) → SchemeId - Parses a wire ordinal into SchemeId.
-
validateCeremonyId(
Uint8List ceremonyId) → void -
Validates
ceremonyIdfor use in ceremonies and durable objects. -
writeMlDsaWireMessages(
{required Directory baseDir, required List< MlDsaSigningMessage> messages}) → Future<void> -
Writes
messagesinto round-specific subdirs underbaseDir.
Exceptions / Errors
- CeremonyAborted
- A multi-party ceremony aborted (missing participants, complaints, etc.).
- Shares or verification data are mutually inconsistent.
- Fewer than ThresholdParams.t shares were supplied.
- InvalidParams
- ThresholdParams or participant identity failed validation.
- InvalidPartialSignature
- A partial signature failed validation or combination.
- SchemeNotImplemented
- SchemeId is registered but ceremony/signing is not implemented yet (v2 M1+).
- SerializationError
- Binary parse failure or unknown format version/kind/scheme.
- ThresholdException
- Base type for all recoverable threshold operation failures.
- TranscriptMismatch
- Transcript hash chain or contents are invalid.
- WrongCeremony
- Object belongs to a different ceremony or parameter set.