Documentation · Pairwise protection
  1. Documentation overview
  2. Core concepts
  3. Protocol Line
  4. Foundation
  5. Identity
  6. Pairwise protection
  7. Messaging & reliability
  8. HTTPS transport
  9. Groups & federation
  10. Verification
  11. Governance & license

Pairwise protection: one indivisible profile

stable-core binds paired one-time prekeys, dual authentication, hybrid establishment, confirmation, and a bounded classic Double Ratchet.

Exact construction

The active stable-core profile combines X25519 and ML-KEM-768 for establishment, Ed25519 and ML-DSA-65 for dual Endpoint authentication, HKDF-SHA-256, full HMAC-SHA-256 for SessionAccept, and IETF ChaCha20-Poly1305 for confirmation and protected records.

No algorithm menu. Profile components cannot be independently selected, negotiated, downgraded, or replaced by aliases.

Paired one-time prekeys

One responder-issued X25519 and ML-KEM-768 pair shares one globally monotonic sequence and one atomic redemption. Missing either component is terminal. The pair cannot be reserved, reused, or consumed partially.

Transcript and confirmation

Establishment authenticates the exact Protocol Line and profile identities, Endpoint and sibling authority-state digests, signing-key references, the signed paired prekey, and hybrid ephemeral inputs. Unknown or mismatched content rejects before state advance.

Bounded record state

Established traffic uses a bounded classic X25519 Double Ratchet. Atomic persistence, rollback detection, deletion rules, skipped-key limits, and resource bounds are part of the protocol definition rather than implementation suggestions.