pqtransport logopqtransport

Getting Started

Add pqtransport to a Dart or Flutter project and run the in-memory hybrid handshake the tests use.

Install#

dependencies:
  pqtransport: ^0.1.0
  pqforge: ^0.4.5
  swissarmyknife: ^0.1.0
dart pub get

Import#

Web-safe barrel (no dart:io, no dart:ffi):

import 'package:pqtransport/pqtransport.dart';

VM / mobile / desktop datagrams:

import 'package:pqtransport/pqtransport_io.dart';

First handshake#

The same loop the tests use. No OS sockets, no SecureSocket.

final crypto = PqTransportCrypto();
final identity = PqTlsServerIdentity.generate(crypto);
final (a, b) = MemoryByteSocket.pair();
final client = PqTlsSocket.client(a, crypto: crypto);
final server = PqTlsSocket.server(b, crypto: crypto, identity: identity);
await Future.wait([server.handshake(), client.handshake()]);
final key = client.exporter('app', Uint8List(0), 32);

Encrypted UDP#

final net = MemoryDatagramNetwork();
final kem = crypto.kemKeyGen();
final salt = crypto.randomBytes(16);
final a = PqEncryptedUdpSocket(
  raw: PqUdpSocket(channel: net.bind(epA), throttleWindow: Duration.zero),
  crypto: crypto,
);

Good defaults#

  • Length-filter every share with requireLength before crypto.
  • Treat Result<T, PqTransportError> as the parse/handshake contract. Do not throw on a truncated record or a bad Finished MAC.
  • NIST-curve groups are live via pqforge 0.4.5. SecP384r1MLKEM1024 requires PqForgeProfile.maximum. Profile/group mismatches fail closed (requireGroup) — they do not silently drop the classical share.
  • Default cipher is IANA 0x1302 (SHA-384 AES-GCM). 0x1303 is offered and completes on dart2js (pqforge 0.4.5). Do not put 0x1302 on a SHA-256 schedule.
  • Import pqtransport_io.dart only where you need a real NIC.

Next#