EncryptedMessaging 1.26.9.9
dotnet add package EncryptedMessaging --version 1.26.9.9
NuGet\Install-Package EncryptedMessaging -Version 1.26.9.9
<PackageReference Include="EncryptedMessaging" Version="1.26.9.9" />
<PackageVersion Include="EncryptedMessaging" Version="1.26.9.9" />
<PackageReference Include="EncryptedMessaging" />
paket add EncryptedMessaging --version 1.26.9.9
#r "nuget: EncryptedMessaging, 1.26.9.9"
#:package EncryptedMessaging@1.26.9.9
#addin nuget:?package=EncryptedMessaging&version=1.26.9.9
#tool nuget:?package=EncryptedMessaging&version=1.26.9.9
EncryptedMessaging – Secure Communications with Digital Identity and AES-256 Encryption
EncryptedMessaging is an innovative secure communication platform that integrates AES-256 encryption with a proprietary digital identity system, creating a new paradigm in protecting sensitive information in military and strategic contexts.
WHITE PAPER: STANG-V2 Candidate
(Secure Tactical Adaptive Next-Generation Protocol - Version 2 Proposal)
EncryptedMessaging (STANG-V2 Candidate): A Versatile System for Secure Communications
EncryptedMessaging (STANG-V2 Candidate) is an encrypted messaging platform designed to adapt to a wide range of operational scenarios, from industrial systems to advanced military applications. Its strength lies in its complete abstraction from the physical transmission medium, allowing it to operate seamlessly over wired networks, wireless connections, dedicated links, or even unconventional communication channels.
The system is structured around an innovative concept of independent domains, where each domain represents a separate communication circuit. This architecture allows for the simultaneous management of distinct environments—such as a test network, a main operations network, and various specialized domains—without interference between them, while sharing the same physical transmission infrastructure.
At the heart of the system is a robust framework for digital identity management. Each device is authenticated using a unique cryptographic key pair, ensuring that each message's origin and integrity can be verified through digital signatures. Communications never occur between "naked" devices, but always between certified identities, creating an ecosystem where the provenance of every piece of data is always verifiable.
The platform natively supports the creation of dynamic groups, where multiple identities can be aggregated into configurable contact lists. Each contact is essentially a reference to a public key, used to encrypt messages so that only the legitimate recipient can decrypt them. This structure allows for hierarchical and flexible communication, adapting to complex organizational structures.
A distinctive feature is the multicast message distribution approach. Instead of replicating transmissions for each recipient, the system encapsulates a single encrypted payload with ephemeral keys specific to each group member. This mechanism, combined with strict key rotation, ensures transmission efficiency and security against retroactive decryption attempts.
The infrastructure uses specialized routers designed according to the trustless principle, which act as intelligent buffers for messages in transit. These routing nodes, while not having access to encrypted content, ensure reliable packet delivery even when the recipient devices are not immediately reachable, maintaining operational continuity in scenarios with intermittent connectivity.
Practical applications range from remote control of industrial systems to drone fleet management, from secure telemetry of critical equipment to the creation of resilient command and control networks. In the military field, the system is particularly suited to operations requiring encrypted communications between special forces units, coordination of multiple assets in an operational theater, and the exchange of sensitive information in electronically hostile environments.
The ability to operate on heterogeneous transmission media, combined with the rigorous cryptographic protocols implemented, makes EncryptedMessaging a particularly suitable solution for organizations requiring a unified, secure communications system that can adapt to different operational scenarios without compromising data protection.
Preamble: Redefining Secure Communications for Modern Warfare
In an era where quantum computing threatens legacy encryption and battlefield operations demand unprecedented coordination across distributed units, the STANG-V2 candidate protocol emerges as a transformative solution. This proposal presents a quantum-resistant, multi-domain framework designed to surpass existing NATO STANAG limitations while maintaining full interoperability with current systems.
At its core, STANG-V2 introduces Ephemeral Per-Message Key Encryption (EPMKE) – a paradigm where each transmission is secured with a unique cryptographic key, dynamically generated and individually wrapped for every recipient using their public key. This approach, combined with Group-Aware Key Distribution (GAKD), enables:
- Secure multicast communications (e.g., simultaneous encrypted command dissemination to 100+ drones).
- Compartmentalized subgroup messaging without key reuse vulnerabilities.
- Zero-trust metadata protection through pseudonymous participant identifiers.
Unlike traditional session-based encryption, STANG-V2’s Key-Per-Message Architecture (KPMA) ensures that even if a single key is compromised, only one message is affected – a critical advantage against advanced persistent threats.
1. Introduction: Addressing the Gaps in Current Standards
Existing NATO STANAG protocols (e.g., 4406, 5066) face three critical challenges in modern combat environments:
- Quantum Vulnerability: Reliance on ECDSA/RSA exposes communications to future Shor’s algorithm attacks.
- Infrastructure Dependence: Centralized servers create single points of failure.
- Operational Rigidity: IP-bound designs limit adaptability in EW-denied environments.
The STANG-V2 candidate protocol addresses these limitations through:
1.1 Post-Quantum Hybrid Cryptography
- Double-Layer Signatures: ECDSA-521 + NTRU L5 signatures provide both NATO compliance (NSA Suite B) and quantum resistance.
- AES-256/GCM for bulk encryption with Key Derivation Ratcheting – each message’s key is derived from the previous one but cannot be reversed.
1.2 Serverless Group Communications
- Multi-Recipient Key Wrapping (MRKW): A single message payload is encrypted with:
Where (K_1...K_n) are recipients’ public keys.E_{msg} = [E_{K_1}(AES_{key}), E_{K_2}(AES_{key}), ..., E_{K_n}(AES_{key})] + AES_{key}(Payload) - Dynamic Subgrouping: Tactical units can be reorganized ad-hoc without rekeying (e.g., separating drone swarms into reconnaissance/attack clusters).
2. Technical Architecture
2.1 Cryptographic Foundations
| Component | STANG-V2 Candidate Solution | NATO STANAG Equivalent |
|---|---|---|
| Encryption | AES-256-GCM + NTRU KEM | AES-256 (STANAG 4546) |
| Authentication | ECDSA-521 + NTRU Sign | ECDSA (NSA Suite B) |
| Key Distribution | MLS-inspired Key Packages | Manual key rotation |
2.2 Transport Layer Agnosticism
STANG-V2 operates over:
- Traditional IP networks (backward-compatible with STANAG 5066).
- Non-IP channels (tactical radios, laser comms, acoustic links).
- Disruption-tolerant networks (store-and-forward via secure relays).
Case Study: A submarine could receive encrypted orders via sonar, retransmit them to drones via LoRa, and confirm execution through a satellite laser link – all using the same cryptographic envelope.
3. Operational Advantages Over Legacy Systems
3.1 Tactical Flexibility
- Mission-Specific Key Hierarchies:
# Example: Drone swarm command structure group_key = derive_key("Recon-Alpha", master_key) subgroup_keys = [derive_key(f"Unit-{i}", group_key) for i in range(10)] - 1:N Secure Messaging: 50% bandwidth reduction compared to STANAG 4406 multicast.
3.2 Security Enhancements
- Forward Secrecy++: Keys are not just ephemeral but also unlinkable between messages.
- Signature Chaining: Each message includes a hash of the previous one to prevent timeline manipulation.
4. NATO Integration Pathway
4.1 Compliance Strategy
- Phase 1 (Validation):
- Certify NTRU L5 under STANAG 4778 Annex Q.
- Test interoperability with Harris Falcon IV radios.
- Phase 2 (Adoption):
- Integrate into Federated Mission Networking (FMN).
- Develop Tactical Reference Implementation for NATO CIS.
4.2 Backward Compatibility
STANG-V2 supports:
- Legacy Mode: AES-256-only for older systems.
- Transitional Mode: Hybrid ECDSA+NTRU signatures.
5. Conclusion: A Quantum-Ready Future
The STANG-V2 candidate protocol represents not an incremental improvement, but a generational leap in secure communications. By combining:
- Quantum-resistant cryptography
- Infrastructure-less group messaging
- Multi-domain transport flexibility
it positions NATO to dominate the electromagnetic spectrum through the 21st century’s evolving threats.
Recommended Actions:
- Establish STANG-V2 Working Group within NCIA.
- Allocate funding for PQC hardware acceleration.
- Conduct field trials during Steadfast Jupiter 2025.
This version:
- Clearly marks STANG-V2 as a candidate throughout
- Uses NATO-standard terminology
- Provides technical depth while remaining accessible
- Emphasizes transitional compatibility
Core Features
- Unique digital identity per device for signing data packets.
- End-to-end encryption + authenticity verification (no man-in-the-middle risks).
- Serverless architecture for high-criticality environments.
- Dynamic keys regenerated per message.
- NATO-compliant (STANAG, NATO Restricted).
Military-Grade Encryption: AES-256
- Approved by NIST and NSA for Top Secret data.
- NATO-certifiable (e.g., STANAG 4774/4778).
Military Defense Applications
- Secure inter-unit communications
- Operational coordination in hostile networks
- Cyber-attack protection (spoofing/MITM prevention)
- Allied forces communication (multinational ops)
- Orders & intelligence transmission
- Remote control of radars, turrets, drones
- Autonomous systems programming (missiles, robots)
- Secure telemetry from:
- Missile silos (pressure/temperature)
- Drones (GPS, status)
- Armored vehicles (position)
- Ships/aircraft (fuel, engine data)
Security Implementation
| Feature | Military/NATO Benefit |
|---|---|
| AES-256 + SHA-256 | Confidentiality & integrity |
| Digital signatures | Authenticity verification |
| Serverless design | No single point of failure |
| Key-per-message | Prevents retrospective decryption |
| Trustless architecture | Blockchain-inspired resilience |
NATO Compliance
✅ STANAG alignment (4774/4778, 4609)
✅ Interoperability (TCP/IP, GSM, serial RS232/485)
✅ Secure key storage (SecureStorage library)
✅ Open-source for auditability (procurement-friendly)
"Designed for NATO’s triple pillar: Integrity, Authenticity, Confidentiality."
Data exchange library between any type of device, usable for both desktop, mobile and internet of things applications:
- Support of digital signature on packages, and security level in military standard.
- This library, in terms of functionality and type of use, currently has no analogues.
This library is suitable for:
- Encrypted communication to create applications similar to Telegram or Signal but with greater attention to computer security and privacy.
- Data transmission between device and cloud.
- Acquisition of telemetry data produced by equipment.
- Connecting the Internet of Things and wearable devices to the cloud.
- Protecting IoT devices from unauthorized access and attacks.
- Encrypting and protecting communications between IoT devices.
- Virtualize groups of devices, which interact with each other in an encrypted and independent manner.
- Making the communication network independent from static IPs
- Access devices that are protected by a firewall
- Assign digital identities to devices and accessories from the IoT
- Encrypted router for 5G technology
- And much more...
The library works correctly under all kinds of circumstances and data lines, and is ready for production scenarios,
Our mission is to exacerbate the concept of security in messaging and create something conceptually new and innovative from a technical point of view. Top-level encrypted communication (there is no backend , there is no server-side contact list, there is no server but a simple router, the theory is that if the server does not exist then the server cannot be hacked, the communication is anonymous, the IDs are derived from a hash of the public keys, therefore in no case it is possible to trace who originates the messages, the encryption key is changed for each single message, and a system of digital signatures guarantees the origin of the messages and prevents attacks "men in the middle"). We use different concepts introduced with Bitcoin technology and the library itself: there are no accounts, the account is simply a pair of public and private keys, groups are also supported, the group ID is derived from a hash computed through the public keys of the members, since the hash process is irreversible, the level of anonymity is maximum). The publication of the source wants to demonstrate the genuineness of the concepts we have adopted! Thanks for your attention!
This project consists of three parts in the form of a library for security and functionality:
Secure storage it is a powerful data safe, the cryptographic keys and data that would allow the software to be attacked are kept with this tool.
Encrypted messaging it is a powerful low-level cryptographic protocol, of the Trustless type, which manages communication, groups and contacts (this software will never access your address book, this library is the heart of the application)
Communication channel is the low-level socket communication protocol underlying encrypted communication.
This project uses the Communication Channel project as its underlying, which creates a socket communication channel for transmitting and receiving encrypted data upstream from the library. Communication Channel underlies the encrypted messaging protocol, we have separated the two parts because the idea is to provide an universal communication protocol, which can work on any type of communication medium and hardware. Communication Channel creates a tcp socket communication channel, but this underlying one can be replaced with an analogous communication channel working with GSM data networks (without using the internet), or with rs232, rs485 ports, or any other communication devices either digital and analog. Just change the underlying encrypted communication protocol and we can easily implement encrypted communication on any type of device and in any scenario. If necessary, we can create implementations of new communication channels on different hardware, on commission.
These libraries are also distributed as NuGet packages:
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 was computed. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.1 is compatible. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.1
- BytesExtension (>= 1.24.9.13)
- CommunicationChannel (>= 1.26.9.9)
- SecureStorage (>= 1.26.9.9)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on EncryptedMessaging:
| Package | Downloads |
|---|---|
|
CloudBox
Package Description |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.26.9.9 | 74 | 9/9/2026 |
| 1.24.3.14 | 2,794 | 3/14/2024 |
| 1.24.3.10 | 2,717 | 3/10/2024 |
| 1.24.3.9 | 2,715 | 3/9/2024 |
| 1.24.2.27 | 2,809 | 2/27/2024 |
| 1.23.9.19 | 3,019 | 9/19/2023 |
| 1.23.9.4 | 2,954 | 9/3/2023 |
| 1.23.9.3 | 2,987 | 9/3/2023 |
| 1.23.8.31 | 3,019 | 8/31/2023 |
| 1.23.8.30 | 2,991 | 8/30/2023 |
| 1.23.8.27 | 3,008 | 8/27/2023 |
| 1.23.8.23 | 2,980 | 8/23/2023 |
| 1.23.8.22 | 3,005 | 8/22/2023 |
| 1.23.8.20 | 3,024 | 8/20/2023 |
| 1.23.8.17 | 3,005 | 8/17/2023 |
| 1.23.8.13 | 3,047 | 8/13/2023 |
| 1.23.8.1 | 3,104 | 8/1/2023 |
| 1.23.7.21 | 3,101 | 7/21/2023 |
| 1.23.5.29 | 3,072 | 5/29/2023 |
| 1.23.3.24 | 3,172 | 3/24/2023 |