Expand description
Protocol-v2 single-flight authentication framing.
The first client frame carries a clear-text routing prefix and an authenticated encrypted request. It does not add a handshake or round trip. All following control messages on the same TCP connection use independently derived directional keys and monotonically increasing 64-bit counters.
first flight: PBM2 | version | key id | timestamp+salt | counter | len | ciphertext
| | |
| +-> replay/time checks +-> bounded AEAD open
+-> derive directional session keys
continuation: counter(n+1) | len | ciphertext -> same authenticated sessionThis root module coordinates client/server sessions. Frame mechanics, replay admission, log suppression, and protocol tests are isolated in focused child modules.
Structs§
- Client
Header Session - Failure
LogDecision - Server
Header Session - Server
Initial Error - Server
Initial Message - Server
Security - V2Message
Reader - V2Message
Writer