pqtransport 0.1.0 copy "pqtransport: ^0.1.0" to clipboard
pqtransport: ^0.1.0 copied to clipboard

Pure-Dart post-quantum transport: UDP, TLS 1.3 hybrid (X25519MLKEM768 / SecP256r1MLKEM768 / SecP384r1MLKEM1024), DNS/DoH/DoT, mDNS, QUIC, HTTP/1.1–3.

pqtransport #

Work In Progress: Pure-Dart post-quantum transport: UDP, TLS 1.3 hybrid key exchange(RFC 10024), DNS/DoH/DoT, mDNS, QUIC, and HTTP/1.1–3.

Project signals #

pub.dev version API GitHub Pages Wiki license Dart SDK stars

Protocol surface #

RFC 10024 X25519MLKEM768 NIST groups AEAD schedule runtime tests

Automation and discovery #

CI Publish Release CodeQL Pages workflow Wiki sync OpenSSF Scorecard llms.txt

Claim boundary #

CMVP OpenSSL encoding pqforge swissarmyknife pqcrypto

Cryptography is exclusively package:pqforge. Infrastructure is exclusively package:swissarmyknife. There is no dart:ffi and no platform TLS (SecureSocket) on the PQ path.

This is not a FIPS 140 module. Side-channel resistance and zeroization in Dart are best-effort. ML-KEM/ML-DSA evidence lives in package:pqcrypto (via pqforge).

Documentation (architecture, features, bugs, tracker, roadmap): doc/INDEX.md. Site (Jaspr, same engine as swissarmyknife): turkananation.github.io/pqtransport. Wiki: github.com/turkananation/pqtransport/wiki. How the site is built: doc/SITE.md.

Hybrid groups (RFC 10024) #

Group Codepoint Client Server Shared secret Order
X25519MLKEM768 0x11EC 1216 1120 64 ML-KEM then X25519
SecP256r1MLKEM768 0x11EB 1249 1153 64 ECDHE then ML-KEM
SecP384r1MLKEM1024 0x11ED 1665 1665 80 ECDHE then ML-KEM

Live handshake (KEM + classical ECDH + ML-DSA + AES-256-GCM records) is implemented for all three RFC 10024 groups. SecP384r1MLKEM1024 requires PqForgeProfile.maximum. Profile/group mismatches are refused (requireGroup) rather than silently dropping the classical share.

TLS record protection defaults to AES-256-GCM with HKDF-SHA-384 (IANA TLS_AES_256_GCM_SHA384, 0x1302). The client also offers TLS_CHACHA20_POLY1305_SHA256 (0x1303), which completes on VM, dart2wasm, and dart2js via pqforge 0.4.5. Private-use 0xFF00 is retired. Concatenation is RFC 10024-aligned and unit-tested — this release does not claim OpenSSL interop.

Install #

dependencies:
  pqtransport: ^0.1.0
  pqforge: ^0.4.5
  swissarmyknife: ^0.1.0
import 'package:pqtransport/pqtransport.dart';

IO datagrams / multicast: import 'package:pqtransport/pqtransport_io.dart';

Consume #

In-memory TLS 1.3 hybrid handshake (the same path the tests use):

final crypto = PqTransportCrypto();
final identity = PqTlsServerIdentity.generate(crypto);
final (a, b) = MemoryByteSocket.pair();
final client = PqTlsSocket.client(a, crypto: crypto);
final server = PqTlsSocket.server(b, crypto: crypto, identity: identity);
await Future.wait([server.handshake(), client.handshake()]);
final key = client.exporter('app', Uint8List(0), 32);

Encrypted UDP session:

final net = MemoryDatagramNetwork();
final kem = crypto.kemKeyGen();
final salt = crypto.randomBytes(16);
final a = PqEncryptedUdpSocket(
  raw: PqUdpSocket(channel: net.bind(epA), throttleWindow: Duration.zero),
  crypto: crypto,
);
final flight = await a.initiate(
  peerKemPublicKey: kem.publicKey,
  deploymentSalt: salt,
);

Tests #

dart test
bash tool/check_invariants.sh .

dart analyze is clean. 153 tests, 90.7% line coverage of lib/. Gates: hybrid concat (all three groups), AEAD round-trip, replay-before-open, TLS state machines, live RFC 10024 handshakes (X25519, P-256, P-384), IANA 0x1302 / 0x1303 suites, requireGroup refuse, checkEncapsulationKey on a bad modulus, HTTP/1.1 GET over PqTlsSocket, DNS circuit-breaker + TTL cache, mDNS probe/announce/browse, ML-DSA-65 TXT, QUIC CRYPTO frames carrying the 1216-byte share, dart:io UDP.

Documentation #

Canonical root: doc/INDEX.md.

Document Purpose
doc/ACHIEVEMENTS.md What 0.1.0 shipped, with evidence
doc/ARCHITECTURE.md Layout, concat, TLS/UDP data flow
doc/FEATURES.md Done / partial / fail-closed / not started
doc/API.md Public types and consume examples
doc/BUGS.md OPEN / BLK / LIM / FIX
doc/TRACKER.md Canonical tracker
doc/ROADMAP.md 0.2 → 0.5, order is not optional
doc/PQFORGE_EXPORTS.md Consumed vs not-wired pqforge 0.4.5 APIs
doc/CLAIM_BOUNDARY.md Allowed vs forbidden wording

Sister packages #

Package Role
pqcrypto ML-KEM / ML-DSA / SLH-DSA primitives and KATs
pqforge Hybrid crypto workflows this package consumes
swissarmyknife Result, StateMachine, CircuitBreaker, Cache

License #

MIT. See LICENSE.

4
likes
160
points
90
downloads

Documentation

Documentation
API reference

Publisher

verified publisheryardenah.com

Weekly Downloads

Pure-Dart post-quantum transport: UDP, TLS 1.3 hybrid (X25519MLKEM768 / SecP256r1MLKEM768 / SecP384r1MLKEM1024), DNS/DoH/DoT, mDNS, QUIC, HTTP/1.1–3.

Homepage
Repository (GitHub)
View/report issues
Contributing

Topics

#cryptography #tls #quic #network #flutter

License

MIT (license)

Dependencies

pqforge, swissarmyknife, zeroize

More

Packages that depend on pqtransport