KpqC 0.1.1
dotnet add package KpqC --version 0.1.1
NuGet\Install-Package KpqC -Version 0.1.1
<PackageReference Include="KpqC" Version="0.1.1" />
<PackageVersion Include="KpqC" Version="0.1.1" />
<PackageReference Include="KpqC" />
paket add KpqC --version 0.1.1
#r "nuget: KpqC, 0.1.1"
#:package KpqC@0.1.1
#addin nuget:?package=KpqC&version=0.1.1
#tool nuget:?package=KpqC&version=0.1.1
KpqC
KpqC provides safe, synchronous .NET APIs for AIMer, HAETAE, NTRU+, and SMAUG-T.
Runtime support
- .NET 8 or newer
- Windows x64
- Linux x64 or Arm64
- macOS x64 or Apple silicon
Install
dotnet add package KpqC
Available schemes
| Algorithm | Type | Exports |
|---|---|---|
| AIMer | Signature | Aimer128F, Aimer128S, Aimer192F, Aimer192S, Aimer256F, Aimer256S |
| HAETAE | Signature | Haetae2, Haetae3, Haetae5 |
| NTRU+ | Key encapsulation | NtruPlus768, NtruPlus864, NtruPlus1152 |
| SMAUG‑T | Key encapsulation | SmaugT128, SmaugT192, SmaugT256, Timer |
Importing an algorithm family keeps the entry point focused:
using KpqC;
ReadOnlySpan<byte> payload = "release-manifest:v3"u8;
using KeyPair keys = Aimer.Aimer128F.GenerateKeyPair();
byte[] proof = Aimer.Aimer128F.Sign(payload, keys.SecretKey);
if (!Aimer.Aimer128F.Verify(payload, proof, keys.PublicKey))
{
throw new InvalidOperationException("Signature verification failed");
}
Signature contexts
AIMer and HAETAE accept an optional context. A context separates signatures created for different application purposes and may contain up to 255 bytes.
using KpqC;
ReadOnlySpan<byte> payload = "account=42"u8;
ReadOnlySpan<byte> context = "audit-record"u8;
using KeyPair keys = Haetae.Haetae3.GenerateKeyPair();
byte[] signature = Haetae.Haetae3.Sign(payload, keys.SecretKey, context);
bool valid = Haetae.Haetae3.Verify(
payload,
signature,
keys.PublicKey,
context);
Console.WriteLine(valid); // True
Verification fails when the supplied context does not match the one used for signing.
Key encapsulation
A KEM creates a shared secret for a sender and a recipient. The public key may be distributed; the secret key and resulting shared secret must remain private.
using KpqC;
using KeyPair recipient = SmaugT.SmaugT192.GenerateKeyPair();
using EncapsulatedSecret outbound =
SmaugT.SmaugT192.Encapsulate(recipient.PublicKey);
// Send outbound.Ciphertext to the recipient.
byte[] inboundSecret = SmaugT.SmaugT192.Decapsulate(
outbound.Ciphertext,
recipient.SecretKey);
Console.WriteLine(
inboundSecret.AsSpan().SequenceEqual(outbound.SharedSecret)); // True
The caller is responsible for clearing the array returned by Decapsulate
when it is no longer needed.
Imports
Each family has a dedicated static class:
using KpqC;
SignatureAlgorithm signer = Aimer.Aimer256S;
SignatureAlgorithm anotherSigner = Haetae.Haetae5;
KeyEncapsulationAlgorithm keyExchange = NtruPlus.NtruPlus1152;
KeyEncapsulationAlgorithm anotherKeyExchange = SmaugT.Timer;
All named algorithms are also available from Algorithms:
using KpqC;
SignatureAlgorithm signer = Algorithms.Aimer192F;
KeyEncapsulationAlgorithm keyExchange = Algorithms.NtruPlus864;
Data and failures
Inputs are ReadOnlySpan<byte> values and outputs are byte[] values. Each
algorithm exposes an Id and a Sizes value.
Parameter sizes
All sizes are in bytes.
Signatures
| Algorithm | Public key | Secret key | Signature |
|---|---|---|---|
Aimer128F |
32 | 48 | 5,888 |
Aimer128S |
32 | 48 | 4,160 |
Aimer192F |
48 | 72 | 13,056 |
Aimer192S |
48 | 72 | 9,120 |
Aimer256F |
64 | 96 | 25,120 |
Aimer256S |
64 | 96 | 17,056 |
Haetae2 |
992 | 1,408 | 1,474 |
Haetae3 |
1,472 | 2,112 | 2,349 |
Haetae5 |
2,080 | 2,752 | 2,948 |
Key encapsulation
| Algorithm | Public key | Secret key | Ciphertext | Shared secret |
|---|---|---|---|---|
NtruPlus768 |
1,152 | 2,336 | 1,152 | 32 |
NtruPlus864 |
1,296 | 2,624 | 1,296 | 32 |
NtruPlus1152 |
1,728 | 3,488 | 1,728 | 32 |
SmaugT128 |
672 | 832 | 672 | 32 |
SmaugT192 |
1,088 | 1,312 | 992 | 32 |
SmaugT256 |
1,440 | 1,728 | 1,376 | 32 |
Timer |
672 | 832 | 608 | 32 |
Methods reject values of the wrong size. Signature verification returns
false for an invalid signature. NTRU+ rejects an invalid ciphertext.
SMAUG-T performs implicit rejection and returns a replacement secret instead;
that value will not equal the sender's shared secret.
Distribution
The published package includes the managed .NET assembly and native libraries for each supported runtime identifier. It has no runtime package dependencies.
KeyPair and EncapsulatedSecret implement IDisposable. Their secret-key and
shared-secret arrays are wiped on disposal on a best-effort basis.
Building from source
A C11 compiler, CMake 3.20 or newer, and the .NET 8 SDK are required. Build and stage the native library for the current platform before running the managed tests or packing:
./scripts/build-native.sh osx-arm64
dotnet test tests/KpqC.Tests/KpqC.Tests.csproj -c Release -r osx-arm64
dotnet pack src/KpqC/KpqC.csproj -c Release -p:AllowPartialRuntimePack=true
Use the matching RID on other supported platforms. Windows builds can use
scripts/build-native.ps1. A release package requires all supported RID
assets; AllowPartialRuntimePack is intended only for local validation.
Security
The native cores are compiled from the upstream algorithm implementations. This package has not received an independent security audit and does not provide a constant-time execution guarantee. Assess those constraints before using it with sensitive production keys.
Third-party licenses and attributions are listed in THIRD_PARTY_NOTICES.md.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.