Download the PHP package kpqc/kpqc without Composer
On this page you can find all versions of the php package kpqc/kpqc. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Package kpqc
Short Description PHP APIs for AIMer, HAETAE, NTRU+, and SMAUG-T.
License MIT
Homepage https://github.com/KpqC/kpqc-php
Informations about the package kpqc
KpqC
KpqC provides typed, synchronous PHP APIs for AIMer, HAETAE, NTRU+, and SMAUG-T.
Requirements
- PHP 8.1 or newer
- macOS or Linux
- PIE and the standard PHP extension build tools (
phpize,php-config, Autoconf, and Make) - CMake 3.20 or newer and C11/C++17 compilers during installation
Install
Install the extension from Packagist with PIE:
PIE builds, installs, and enables the extension for the selected PHP installation. Confirm that it is loaded with:
Build from a source checkout
For development, the repository can also be built directly with CMake:
To install the compiled module into the extension directory reported by the
selected php-config, run:
The extension directory may require elevated write permission. After
installation, enable the module through php.ini:
Available schemes
| Algorithm | Type | Functions |
|---|---|---|
| AIMer | Signature | aimer128f, aimer128s, aimer192f, aimer192s, aimer256f, aimer256s |
| HAETAE | Signature | haetae2, haetae3, haetae5 |
| NTRU+ | Key encapsulation | ntruplus768, ntruplus864, ntruplus1152 |
| SMAUG‑T | Key encapsulation | smaugt128, smaugt192, smaugt256, timer |
Named functions return immutable algorithm objects:
Signature contexts
AIMer and HAETAE accept an optional context. A context separates signatures created for different application purposes and may contain up to 255 bytes:
Verification fails when the supplied context does not match the one used for signing.
Key encapsulation
A KEM creates a shared secret for a sender and a recipient. The public key may be distributed; the secret key and resulting shared secret must remain private.
Imports
Named algorithm functions can be imported individually:
The shared algorithm classes and value objects are available from the KpqC
namespace:
Data and failures
PHP strings are treated as binary byte strings. Algorithm objects expose an
id and a read-only sizes object. Key pairs and encapsulation results are
read-only objects whose string and debug representations redact secrets.
Parameter sizes
All sizes are in bytes.
Signatures
| Algorithm | Public key | Secret key | Signature |
|---|---|---|---|
aimer128f |
32 | 48 | 6,944 |
aimer128s |
32 | 48 | 4,704 |
aimer192f |
48 | 72 | 15,408 |
aimer192s |
48 | 72 | 10,320 |
aimer256f |
64 | 96 | 31,360 |
aimer256s |
64 | 96 | 20,224 |
haetae2 |
992 | 1,408 | 1,474 |
haetae3 |
1,472 | 2,112 | 2,349 |
haetae5 |
2,080 | 2,752 | 2,948 |
Key encapsulation
| Algorithm | Public key | Secret key | Ciphertext | Shared secret |
|---|---|---|---|---|
ntruplus768 |
1,152 | 2,336 | 1,152 | 32 |
ntruplus864 |
1,296 | 2,624 | 1,296 | 32 |
ntruplus1152 |
1,728 | 3,488 | 1,728 | 32 |
smaugt128 |
672 | 832 | 672 | 32 |
smaugt192 |
1,088 | 1,312 | 992 | 32 |
smaugt256 |
1,440 | 1,728 | 1,376 | 32 |
timer |
672 | 832 | 608 | 32 |
Methods reject values of the wrong size. Signature verification returns
false for an invalid signature. NTRU+ rejects a non-canonical public key or
an invalid ciphertext. SMAUG-T performs implicit rejection and returns a
replacement secret instead; that value does not equal the sender's shared
secret.
Known-answer tests
The bundled implementation is tested through the PHP API against all 1,600 KAT records in KpqC/kpqc-test-vectors at commit 179dcc05ece2. The vector files are not duplicated in this repository.
With kpqc-test-vectors checked out beside kpqc-php, run:
Distribution
kpqc/kpqc is a PIE extension package distributed through Packagist. The same
repository contains the PHP API and all native sources required for a source
build; installation does not download algorithm sources from another
repository. There are no runtime dependencies beyond PHP and the installed
kpqc extension.
Security
The native cores are compiled from the upstream algorithm implementations. This package has not received an independent security audit and does not provide a constant-time execution guarantee. Assess those constraints before using it with sensitive production keys.
Third-party licenses and attributions are listed in THIRD_PARTY_NOTICES.md.