c2pa_crypto 0.1.0-dev.1 copy "c2pa_crypto: ^0.1.0-dev.1" to clipboard
c2pa_crypto: ^0.1.0-dev.1 copied to clipboard

Cryptographic, PKI, timestamp, and revocation support for C2PA.

c2pa_crypto #

Cryptographic building blocks for C2PA: SHA-2 hashing, COSE signing and verification adapters, X.509 path/profile validation, trust lists, RFC 3161 timestamps, OCSP, CRLs, and asset hashing.

Platforms #

The package supports Dart VM, Flutter, and web. Backend and algorithm availability can vary by runtime; browser deployments depend on available WebCrypto behavior.

import 'package:c2pa_crypto/c2pa_crypto.dart';

final digest = await HashAlgorithm.sha256.digest([1, 2, 3]);
print(digest.length); // 32

See example/c2pa_crypto.dart.

Security and defaults #

This package never fetches certificates, trust lists, timestamps, OCSP, or CRLs by itself. Trust anchors, intermediates, validation time, revocation material, and signing callbacks are caller supplied. A valid signature is not equivalent to a trusted signer. Keep private keys in a platform keystore, HSM, or external service rather than application memory where practical.

Package relationships #

c2pa_crypto depends on c2pa_codec and c2pa_io. The high-level c2pa package uses it for claim signatures, hard bindings, trust, and revocation.

Compatibility and limitations #

The compatibility target is c2pa-rs c2pa-v0.90.22. Supported C2PA algorithms include SHA-256/384/512, ES256/384/512, PS256/384/512, and Ed25519, subject to backend support. This package does not provide an operating-system trust-store policy or network transport.

Licensed under the MIT License (LICENSE). As an alternative, you may instead use this package under the Apache License, Version 2.0 (LICENSE-APACHE), so the package is offered as MIT OR Apache-2.0, at your option. Copyright is held by contributors to c2pa_dart.

0
likes
160
points
0
downloads

Documentation

API reference

Publisher

verified publisherabrah.am

Weekly Downloads

Cryptographic, PKI, timestamp, and revocation support for C2PA.

Repository (GitHub)
View/report issues

Topics

#c2pa #cryptography #pki #timestamps #x509

License

MIT (license)

Dependencies

c2pa_codec, c2pa_io, cryptography, pointycastle

More

Packages that depend on c2pa_crypto