Skip to main content

Module secure

Module secure 

Source
Expand description

Protocol-v2 single-flight authentication framing.

The first client frame carries a clear-text routing prefix and an authenticated encrypted request. It does not add a handshake or round trip. All following control messages on the same TCP connection use independently derived directional keys and monotonically increasing 64-bit counters.

first flight: PBM2 | version | key id | timestamp+salt | counter | len | ciphertext
                        |           |                         |
                        |           +-> replay/time checks    +-> bounded AEAD open
                        +-> derive directional session keys

continuation: counter(n+1) | len | ciphertext -> same authenticated session

This root module coordinates client/server sessions. Frame mechanics, replay admission, log suppression, and protocol tests are isolated in focused child modules.

Structs§

ClientHeaderSession
FailureLogDecision
ServerHeaderSession
ServerInitialError
ServerInitialMessage
ServerSecurity
V2MessageReader
V2MessageWriter

Enums§

HeaderMessageReader
HeaderMessageWriter
HeaderProtocol

Constants§

PROTOCOL_V2_MAGIC
PROTOCOL_V2_VERSION