Install#
dependencies:
pqtransport: ^0.1.0
pqforge: ^0.4.5
swissarmyknife: ^0.1.0
dart pub get
Import#
Web-safe barrel (no dart:io, no dart:ffi):
import 'package:pqtransport/pqtransport.dart';
VM / mobile / desktop datagrams:
import 'package:pqtransport/pqtransport_io.dart';
First handshake#
The same loop the tests use. No OS sockets, no SecureSocket.
final crypto = PqTransportCrypto();
final identity = PqTlsServerIdentity.generate(crypto);
final (a, b) = MemoryByteSocket.pair();
final client = PqTlsSocket.client(a, crypto: crypto);
final server = PqTlsSocket.server(b, crypto: crypto, identity: identity);
await Future.wait([server.handshake(), client.handshake()]);
final key = client.exporter('app', Uint8List(0), 32);
Encrypted UDP#
final net = MemoryDatagramNetwork();
final kem = crypto.kemKeyGen();
final salt = crypto.randomBytes(16);
final a = PqEncryptedUdpSocket(
raw: PqUdpSocket(channel: net.bind(epA), throttleWindow: Duration.zero),
crypto: crypto,
);
Good defaults#
- Length-filter every share with
requireLengthbefore crypto. -
Treat
Result<T, PqTransportError>as the parse/handshake contract. Do notthrowon a truncated record or a bad Finished MAC. -
NIST-curve groups are live via pqforge 0.4.5. SecP384r1MLKEM1024
requires
PqForgeProfile.maximum. Profile/group mismatches fail closed (requireGroup) — they do not silently drop the classical share. -
Default cipher is IANA
0x1302(SHA-384 AES-GCM).0x1303is offered and completes on dart2js (pqforge 0.4.5). Do not put0x1302on a SHA-256 schedule. - Import
pqtransport_io.dartonly where you need a real NIC.
Next#
- Architecture — barrels, data flow, concat formulas.
- Hybrid Groups — why order is group-dependent.
- Cookbook — common patterns.
- Claim Boundary — wording that is allowed.