pqthreshold_experimental library

Experimental post-quantum threshold APIs.

These APIs are not part of the stable FROST Ed25519 1.0 contract. They may change between releases while the underlying profiles and implementations mature. Do not use them for production key ceremonies without independent review.

Classes

CeremonySession
Drives one participant through Gennaro DKG rounds (C1).
ContinuityProof
Links a new threshold public key to an authorized predecessor.
DealerCeremony
Orchestration for dealer-based VSS (C2).
DkgMessage
Typed wrapper for a canonical DKG protocol envelope.
DkgWireKind
Protocol message kind bytes for DKG (doc/PROTOCOL_MESSAGES.md §3.2).
DkgWireSubKind
Protocol message sub-kind bytes for DKG.
FrostSigningMessage
Typed wrapper for a canonical FROST signing protocol envelope.
FrostWireKind
Protocol message kind bytes for FROST signing.
FrostWireSubKind
Protocol message sub-kind bytes for FROST signing.
MlDsaPublicKey
Joint ML-DSA public key for a threshold ceremony (FIPS 204 encoding).
MlDsaRootCeremony
Orchestration for ML-DSA threshold root generation (C1 beta).
MlDsaShare
Participant share for ML-DSA threshold schemes (v2).
MlDsaSigningMessage
Typed wrapper for ML-DSA threshold signing protocol envelopes.
MlDsaSigningSession
Officer-local ML-DSA signing state between distributed wire rounds.
MlDsaThresholdSigner
Threshold ML-DSA signing (C3) — M2 beta via Mithril bridge.
MlDsaThresholdSigningCeremony
Orchestration for ML-DSA threshold signing (C3 beta).
MlDsaThresholdVerifier
Verifies threshold-produced ML-DSA signatures (FIPS 204 output shape).
MlDsaWireKind
Protocol message kind bytes for ML-DSA threshold signing.
MlDsaWireSubKind
Protocol message sub-kind bytes for ML-DSA threshold signing.
PartialSignature
One signer's FROST round material for a single message.
PqthHeader
Parsed 8-byte PQTH object header.
PublicKey
Joint threshold public key material.
RecoveryCeremony
High-privilege C4 reconstruction — explicit, audited secret export.
RootCeremony
Orchestration for dealer-less root generation (C1).
RotationCeremony
Orchestration for threshold key rotation with continuity evidence (C5).
SchemeCapabilities
Static metadata for each SchemeId (ADR-004).
SecretBuffer
Holds sensitive bytes and wipes them on dispose.
Share
A participant's private share plus verification material.
SigningSession
Officer-local signing state between FROST Round1 and Round2.
ThresholdParams
Describes a threshold instance: quorum size, participant count, and scheme.
ThresholdSigner
FROST threshold signing over Ed25519 (C3).
ThresholdSigningCeremony
Orchestration for FROST threshold signing (C3).
Transcript
Hash-chain transcript of public ceremony data only.
VerifiableSecretSharing
Dealer-based verifiable secret sharing (C2).

Enums

MlDsaThresholdProfile
Maps pqthreshold ML-DSA SchemeId values to pqforge algorithms.
SchemeId
Identifies the cryptographic scheme for a threshold instance.
SchemeMilestone
Production and API readiness for a SchemeId.
ThresholdCeremonyKind
Ceremony types for capability checks.

Extensions

SchemeIdWire on SchemeId
Extension methods for SchemeId wire encoding.

Constants

ceremonyIdLength → const int
Required byte length for a ceremony identifier.
frostEd25519V1MaxParticipants → const int
Hard limit on participants for SchemeId.frostEd25519V1.
pqThresholdSmallSetMaxParticipants → const int
Hard limit on participants for v2 PQ small-set schemes (ADR-004).

Functions

assertMlDsaShareSetConsistent(List<MlDsaShare> shares) → void
Ensures all shares belong to one ceremony and scheme.
assertShareSetConsistent(List<Share> shares) → void
Ensures shares belong to one ceremony and params set.
combineMlDsaFromWire({required MlDsaPublicKey publicKey, required Uint8List message, required Iterable<MlDsaSigningMessage> round2Messages, required Iterable<MlDsaSigningMessage> round3Messages, required List<int> activePartyIdsZeroBased, String? mithrilBridgePath}) → Future<Uint8List>
Combines Round2 + Round3 wire dirs into an ML-DSA signature.
frostRound2WireFromPartial({required PartialSignature partial, required ThresholdParams params}) → FrostSigningMessage
Encodes Round2 wire message from a completed partial.
generateCeremonyId() → Uint8List
Generates a new random ceremony identifier.
loadMlDsaWireMessages(Directory dir) → List<MlDsaSigningMessage>
Loads all ML-DSA wire messages under dir (recursive round subdirs).
mithrilBridgeAvailable({String? overridePath}) → bool
Whether the Mithril bridge binary is available on this machine.
partialsFromRound2Messages({required Iterable<FrostSigningMessage> round1Messages, required Iterable<FrostSigningMessage> round2Messages, required PublicKey publicKey}) → List<PartialSignature>
Builds combine-ready partials from Round1 + Round2 wire messages.
schemeIdFromWireOrdinal(int ordinal) → SchemeId
Parses a wire ordinal into SchemeId.
validateCeremonyId(Uint8List ceremonyId) → void
Validates ceremonyId for use in ceremonies and durable objects.
writeMlDsaWireMessages({required Directory baseDir, required List<MlDsaSigningMessage> messages}) → Future<void>
Writes messages into round-specific subdirs under baseDir.

Exceptions / Errors

CeremonyAborted
A multi-party ceremony aborted (missing participants, complaints, etc.).
InconsistentShares
Shares or verification data are mutually inconsistent.
InsufficientShares
Fewer than ThresholdParams.t shares were supplied.
InvalidParams
ThresholdParams or participant identity failed validation.
InvalidPartialSignature
A partial signature failed validation or combination.
SchemeNotImplemented
SchemeId is registered but ceremony/signing is not implemented yet (v2 M1+).
SerializationError
Binary parse failure or unknown format version/kind/scheme.
ThresholdException
Base type for all recoverable threshold operation failures.
TranscriptMismatch
Transcript hash chain or contents are invalid.
WrongCeremony
Object belongs to a different ceremony or parameter set.