pqthreshold 1.0.0
pqthreshold: ^1.0.0 copied to clipboard
High-assurance pure-Dart threshold cryptography and distributed key-management primitives. Provides verifiable secret sharing, distributed key generation (DKG), threshold signatures, and multi-party c [...]
Changelog #
Unreleased #
Operator CLI #
- ✅
dkg participant step— multi-round C1 over--ceremony-dirwithtransport/inbox/outbox. - ✅
sign partial→sign round2→sign combine— disk round-trip for distributed FROST (binding-factor round). - ✅
sign ml-dsa run|verify— ML-DSA-44 threshold sign + optional--wire-direxport (M3 beta). - ✅
sign ml-dsa partial|round2|round3|combine— per-officer distributed ML-DSA wire rounds (M3+).
Tier 1 API #
- ✅
FrostSigningMessagewire codec (doc/PROTOCOL_MESSAGES.md§5). - ✅
MlDsaSigningMessagewire codec (doc/PROTOCOL_MESSAGES.md§6). - ✅
MlDsaSigningSession— three-round ML-DSA with officer-local checkpoint. - ✅
SigningSession— two-round FROST with officer-local checkpoint. - ✅
CeremonySession.exportCheckpoint/fromCheckpoint— DKG dir-transport persistence.
Ceremonies (planned) #
- ❌ C6 proactive share refresh.
- ❌ C4-B re-share without full reconstruct.
Cryptography (v2 PQ — M2 beta) #
- ✅ ADR-004 + profiles +
SchemeIdregistry (M1) - ✅
MlDsaShare/MlDsaPublicKeyPQTH kinds0x07–0x09 - ✅
MlDsaThresholdSigner+MlDsaRootCeremony/MlDsaThresholdSigningCeremony(Tier 2 simulate) - ✅
tool/mithril_bridge— Mithril ML-DSA-44 threshold via threshold-ml-dsa - ✅
MlDsaSigningMessagewire codec +signWithWire/sign ml-dsa run(M3 beta — Mithril coordinator exports rounds) - ✅
MlDsaSigningSession+ distributed CLI (M3+ — deterministic party RNG, officer checkpoints) - ❌ Per-party RSS export without shared ceremony seed (production DKG)
- ❌ Pure Dart ML-DSA-65 lattice MPC (M4)
- ❌ Pedersen VSS (new verification mode).
Integration (planned) #
- ❌ Wrapped share CLI (
*.share.wrapped.json) aligned with pqforge custody. - ❌ Persistent Serverpod relay (beyond in-memory sketch).
1.0.0 #
Stable Tier 1 release — frostEd25519V1 only; PQTH ver=0x01 frozen per doc/API.md §7.
Operator CLI (0.7.0 scope) #
vss split|verify|reconstruct— C2 dealer ceremony on terminal.dkg simulate— in-process C1 DKG with PQTH artifact export (CI/operator).sign run|partial|combine|verify— C3 threshold signing;sign runis the primary path from share files.ceremony run --flow c1|c3|c5|full— orchestrated in-process ceremony workflows.- Tier 1
DealerCeremony(C2) andRecoveryCeremony(C4) helpers.
Distributed integration (0.8.0 scope) #
packages/crypto_shared— relay,OfficerDkgClient,DistributedDkgCoordinator,OfficerSigningClient,DistributedSigningCoordinator, share wrap/unwrap aligned with pqforgePqWrappedKey.example/serverpod_integration/— Serverpod endpoint sketch withThresholdCeremonyService.PublicKey.fromShareSet()— public API for joint key derivation from shares.- Relay-based C3 tests without
SigningSimulator;crypto_sharedtests intool/verify.dart full.
Pre-1.0 hardening (0.9.0 scope) #
- 77 tests in main package + 6 in
crypto_shared;dart run tool/verify.dart fullpasses. - REVIEW_CHECKLIST.md published — independent cryptographic sign-off recommended before high-assurance deployment.
Requires pqforge ^0.4.4.
0.6.0 #
- Feldman VSS — split, verify, reconstruct (C2 dealer-based sharing).
- Gennaro DKG —
CeremonySession, transcripts, wire messages (C1). - FROST threshold signing — Ed25519-compatible aggregate signatures (C3).
- Ceremony helpers —
RootCeremony,RotationCeremony,ContinuityProof(C5). - Tier 2 simulators in
package:pqthreshold/testing.dart. - Acceptance vectors under
test/vectors/;dart run tool/verify.dart fullpasses. - Requires pqforge ^0.4.4 (
PqBytes.sha512for FROST profile hashes). - Independent cryptographic review checklist:
doc/REVIEW_CHECKLIST.md(recommended before production). - Phase 5 ceremony helpers: C1/C3/C5 orchestration per
doc/API.md§4.4. RootCeremony.startSession/simulate,ThresholdSigningCeremony.simulate,RotationCeremony.simulate.ContinuityProoftype with PQTH wire codec (doc/SERIALIZATION.md§4.6).- Example app runs C1 → C3 → C5 via Tier 2 simulators.
- FROST SHA-512 via
PqBytes.sha512from pqforge 0.4.4 (no directcryptodependency). - Six ceremony tests in
test/ceremony/ceremony_test.dart;dart run tool/verify.dart fullpasses.
0.5.0 #
- Phase 4 FROST threshold signing: Ed25519-compatible aggregate signatures (C3).
ThresholdSigner.signPartial,combine,verifyperdoc/API.md§4.3.PartialSignaturetype with PQTH wire codec (doc/SERIALIZATION.md§4.4).- FROST core under
lib/src/scheme/frost/(binding factors, group commitment, Lagrange shares). - Challenge hash uses RFC 8032 FROST-Ed25519 H2 so
PqClassical.provider.ed25519Verifysucceeds. - FROST acceptance vector in
test/vectors/frost/;tool/generate_frost_vectors.dartfor regeneration. - Five signing tests in
test/signing/frost_test.dart;dart run tool/verify.dart fullpasses.
0.4.0 #
- Phase 3 distributed key generation: Gennaro DKG over Ed25519 (C1).
CeremonySessionwith swissarmyknifeStateMachineperdoc/PROTOCOL_MESSAGES.md§3.1.- DKG wire messages (
DkgMessage) for Round1/Round2 packages. Transcripthash-chain append, seal, verify, and PQTH wire codec.- Tier 2
DkgSimulatorinpackage:pqthreshold/testing.dart. - DKG acceptance vectors in
test/vectors/dkg/;tool/generate_dkg_vectors.dartfor regeneration. - Five integration tests in
test/dkg/dkg_simulation_test.dart;dart run tool/verify.dart fullpasses.
0.3.0 #
- Phase 2 verifiable secret sharing: Feldman VSS over Ed25519.
VerifiableSecretSharing.split,verifyShare,reconstructperdoc/API.md§4.2.ShareandPublicKeytypes with PQTH wire codecs (doc/SERIALIZATION.md§4.2–4.3).- In-tree Ed25519 curve/field ops under
lib/src/scheme/feldman/(pqforge has no group API). - Feldman acceptance vectors in
test/vectors/feldman/;tool/generate_feldman_vectors.dartfor regeneration. - Six unit tests in
test/sharing/feldman_test.dart;dart run tool/verify.dart fullpasses.
0.2.0 #
- Phase 1 foundation: params, errors, PQTH serialization, and util modules.
ThresholdParams/SchemeIdwith swissarmyknifeValidatorand canonical 16-byte wire format.- Sealed
ThresholdExceptionhierarchy; internalResultbridged at public API boundary. PqthHeader,ThresholdParamsCodec,BinaryReader/BinaryWriterperdoc/SERIALIZATION.md.SecretBuffer(Disposable wipe),validateCeremonyId/generateCeremonyId.- Phase 1 CLI (
pqthreshold params,pqthreshold inspect) perdoc/TERMINAL.md. - 32+ unit tests across params, serialization, util, CLI, and package smoke;
dart run tool/verify.dart fullpasses.
0.1.0 #
- Planning release: formative architecture, security, ceremony, and integration docs.
- Locked v1 scheme stack (FROST Ed25519, Feldman VSS, Gennaro DKG) in
doc/SCHEMES.md. - Added implementer index (
doc/INDEX.md), protocol specs, params, test vector plan, implementation guide, tooling, release checklist. - CI (
.github/workflows/ci.yml) andtool/verify.dartrelease gate. - ADRs for scheme selection, runtime dependencies, and serialization format.
- Implementation scaffold only; no cryptographic functionality yet.