Documentation · Pairwise protection
Pairwise protection: one indivisible profile
stable-core binds paired one-time prekeys, dual authentication, hybrid establishment, confirmation, and a bounded classic Double Ratchet.
Exact construction
The active stable-core profile combines X25519 and ML-KEM-768 for establishment, Ed25519 and ML-DSA-65 for dual Endpoint authentication, HKDF-SHA-256, full HMAC-SHA-256 for SessionAccept, and IETF ChaCha20-Poly1305 for confirmation and protected records.
No algorithm menu. Profile components cannot be independently selected, negotiated, downgraded, or replaced by aliases.
Paired one-time prekeys
One responder-issued X25519 and ML-KEM-768 pair shares one globally monotonic sequence and one atomic redemption. Missing either component is terminal. The pair cannot be reserved, reused, or consumed partially.
Transcript and confirmation
Establishment authenticates the exact Protocol Line and profile identities, Endpoint and sibling authority-state digests, signing-key references, the signed paired prekey, and hybrid ephemeral inputs. Unknown or mismatched content rejects before state advance.
Bounded record state
Established traffic uses a bounded classic X25519 Double Ratchet. Atomic persistence, rollback detection, deletion rules, skipped-key limits, and resource bounds are part of the protocol definition rather than implementation suggestions.