Skip to content

Glossary

TermDefinition
KEMKey Encapsulation Mechanism — establishes a shared secret using asymmetric cryptography. ML-KEM is the quantum-safe KEM used here.
DEMData Encapsulation Mechanism — symmetric encryption for the actual payload. AES-256-GCM is the DEM used here.
AEADAuthenticated Encryption with Associated Data — provides both confidentiality and integrity. AES-GCM is an AEAD scheme.
AADAdditional Authenticated Data — input to the AES-GCM tag computation that is not encrypted but is authenticated. In AegisQ streaming, AAD is the 4-byte big-endian chunk index.
M-LWEModule Learning With Errors — the hard lattice problem underlying ML-KEM’s quantum resistance.
NTTNumber Theoretic Transform — FFT over finite fields for O(n log n) polynomial multiplication.
CBDCentered Binomial Distribution — used to sample small error terms in ML-KEM key generation.
Implicit RejectionML-KEM Decaps returns a pseudorandom key for invalid contents of a correctly sized capsule, rather than a validity error. Structural size errors remain distinct.
Transit PackageThe complete byte array sent over the network: [Capsule | Nonce | Tag | Ciphertext].
ZeroizationSecurely overwriting sensitive memory (keys, secrets) with zeros before deallocation.
Auth TagAES-GCM’s 16-byte authentication tag. Verification can fail due to tampering, a wrong key, or an invalid capsule; it does not prove sender identity.
Forward SecrecyCompromise of a long-term secret does not compromise past session keys. EphemeralSession manages session keys but does not alone guarantee this protocol property or secure erasure.
TermDefinition
HeaderFirst chunk of a stream-mode Transit Package: [capsule | base_nonce (12 B) | chunk_size (4 B BE u32)].
FrameOne chunk’s envelope in a stream-mode Transit Package: [length (4 B BE u32) | ciphertext | tag (16 B)].
base_nonceThe 12-byte random nonce stored in the stream header. Per-chunk nonces are derived from this.
chunk_sizeMaximum ciphertext size per yielded chunk (1..=16 MiB; default 64 KiB). Encoded in the header.
EOF MarkerSpecial frame with length = 0 and a tag over empty plaintext. Closes the stream.
Chunk Index0-based position of a frame in the stream (uint32). Used in nonce derivation and AAD.
TermDefinition
PEMPrivacy-Enhanced Mail envelope: ASCII-armored key with -----BEGIN ... ----- / -----END ... ----- headers. AegisQ uses an adapted form (RFC 7468).
JSON KeySelf-describing key format with algorithm, level, and public_key fields. Useful when the level cannot be conveyed out of band.
Base64 URL-safeBase64 variant that uses - and _ instead of + and /, and omits = padding. Suitable for HTTP headers, URLs, and env vars.
HKDFHMAC-based Key Derivation Function (RFC 5869). AegisQ uses HKDF-SHA3-256 for key wrapping. It is not a password-hardening function; use high-entropy secret input.
Key WrapEncrypting a key under another key. AegisQ uses AES-256-GCM with a key derived from high-entropy secret input by HKDF-SHA3-256; the API argument is named password.
FingerprintTruncated public-key identifier: first 8 bytes of SHA3-256(public_key) in hex. Used by KeyPair.__repr__; not identity authentication, and it enables log correlation.
MagicInternal byte sequence marking an AegisQ encrypted key blob. Validated on load to catch format mismatch.
DocumentURL
FIPS 203 (ML-KEM)https://csrc.nist.gov/pubs/fips/203/final
NIST SP 800-38D (AES-GCM)https://csrc.nist.gov/pubs/sp/800/38/d/final
RFC 5869 (HKDF)https://www.rfc-editor.org/rfc/rfc5869
RFC 4648 (Base64)https://www.rfc-editor.org/rfc/rfc4648
RFC 7468 (PEM)https://www.rfc-editor.org/rfc/rfc7468
CRYSTALS-Kyber spec v3.02https://pq-crystals.org/kyber/
aes-gcm Rust cratehttps://docs.rs/aes-gcm
zeroize Rust cratehttps://docs.rs/zeroize
subtle Rust cratehttps://docs.rs/subtle
PyO3 User Guidehttps://pyo3.rs/latest/
Maturin Documentationhttps://www.maturin.rs/
Starlight Documentationhttps://starlight.astro.build/