CRYPTOGRAPHY
ZP-1
An experimental Rust signed-envelope protocol focused on canonical wire formats, provider boundaries and reproducible verification.
- Current state
- Protocol prototype
- Discipline
- Cryptography
- Built with
- Rust / SHA-384 / HMAC / AES-256-GCM-SIV / Cargo / Provider traits
The idea
Study protocol composition through deterministic wire formats, separated cryptographic providers and repeatable verification, while keeping experimental assumptions visible.
How it works
The reference library separates KEM and signature provider traits from object encoding, KDF, sealing, opening and Merkle logic. The target suite specifies ML-KEM-1024 and ML-DSA-87, HMAC-SHA384 and AES-256-GCM-SIV. Deterministic test providers exercise protocol mechanics while remaining explicitly non-cryptographic.
What’s implemented
- Canonical binary object encoding
- Recipient stanzas and key commitment
- Signed public manifests
- Authenticated chunks bound by a domain-separated SHA-384 Merkle tree
- Protocol limit checks and tamper rejection
- Frozen reference vectors, negative corpus and mutation-test scaffolding
PROJECT STATUS / PROTOCOL PROTOTYPE
Where it stands
Experimental unaudited protocol reference implementation.
- The default crate has no production PQC provider.
- Tests-only deterministic provider is not cryptographically secure.
- Archival SLH-DSA structures are defined but operation requires a real provider.
- No independent cryptographic review or formal security proof.
Source & resources
Documentation behind this project page
Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.