Self-hosted post-quantum infrastructure: TLS 1.3 gateway with X25519MLKEM768, hybrid KMS (ML-KEM-768/ML-DSA-65), ML-DSA private CA. Zero dependencies, Node.js 24.
Go to file
2026-09-29 17:46:20 +03:00
crypto-inventory Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
pq-gateway Aere Quantum: a post-quantum TLS 1.3 gateway (X25519MLKEM768, optional ML-DSA client authentication), a hybrid KMS (X25519 + ML-KEM-768, Ed25519 + ML-DSA-65; root key from the environment or sealed by an HSM through PKCS#11) and an ML-DSA private CA (X.509 v3, RFC 9881). Zero dependencies, Node.js 24 with OpenSSL 3.5. Each with its test suite and a negative control. 2026-09-29 16:24:04 +03:00
pq-kms Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
pq-pki Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
LICENSE Aere Quantum: a post-quantum TLS 1.3 gateway (X25519MLKEM768, optional ML-DSA client authentication), a hybrid KMS (X25519 + ML-KEM-768, Ed25519 + ML-DSA-65; root key from the environment or sealed by an HSM through PKCS#11) and an ML-DSA private CA (X.509 v3, RFC 9881). Zero dependencies, Node.js 24 with OpenSSL 3.5. Each with its test suite and a negative control. 2026-09-29 16:24:04 +03:00
README.md README: say exactly which parts are in English 2026-09-29 17:46:20 +03:00

Aere Quantum

Self-hosted post-quantum infrastructure from Aere Network. Four components, each a few files with no dependencies: Node.js 24 and the OpenSSL 3.5 it ships with (node:crypto), nothing from a package registry.

component what it does
pq-gateway/ a TLS 1.3 terminating proxy in front of any HTTP service, with the hybrid key exchange X25519MLKEM768: hybrid-only refuses a classical client at the handshake, hybrid-preferred keeps it working; optional client authentication with ML-DSA certificates
pq-kms/ a transit-style key management service where every key is hybrid: X25519 + ML-KEM-768 for encryption, Ed25519 + ML-DSA-65 for signatures (both halves required); versions, rotation, rewrap, data keys, a chained audit log; the root key from the environment or sealed by an HSM through PKCS#11
pq-pki/ a private certificate authority for ML-DSA (X.509 v3, RFC 9881): root and issuing CAs, leaf certificates, revocation lists, and a strict chain verifier compared against OpenSSL
crypto-inventory/ a cryptographic inventory of source code (JavaScript/TypeScript, Python, Java, Go, PEM blocks, dependency manifests): every use classified by its exposure to a quantum computer, with a migration target, written as a CycloneDX 1.6 CBOM; nothing from the scanned tree is executed, and its cost stays linear on input built to be slow

Each component's README says what it is not and what is not measured. No third party has reviewed any of them.

How each is checked

Every component ships its test suite and a negative control: the control plants a real defect in a copy of the code, one at a time, and requires the named test to fail for the named reason; a planting that cannot be applied, or that breaks the build instead of the test, counts as a failure of the control. Results measured on 2026-09-29 (Node.js 24.14.1, OpenSSL 3.5.5):

component tests negative control
pq-gateway 33/33 (node proba-pq-gateway.mjs) 33/33 (bash proba-pq-gateway-control-negativ.sh)
pq-kms 62/62 (node test/proba.mjs); HSM root on SoftHSM2 + OpenSC 20/20 (test/proba-hsm.mjs, Linux); sealed-file trust rules 7/7 (test/proba-hsm-incredere.mjs) 16/16 (node test/control-negativ.mjs); sealed-file rules 2/2 in this repository (test/control-negativ-hsm-incredere.mjs)
pq-pki 27/27 (node test/proba.mjs), each verdict compared with OpenSSL 3.5 22/22 (node test/control-negativ.mjs)
crypto-inventory 37/37 (node test/proba.mjs); cost on hostile input 8/8 linear (node test/proba-timp.mjs) 18/18 (node test/control-negativ.mjs); cost 3/3 in this repository (node test/control-negativ-timp.mjs; its fourth case compares with version 0.1.0 from the development history and is skipped here)

Code comments, most function and variable names (also many exported between the files of a component), test names and control messages are in Romanian, and so are the two command words of the KMS HSM tool (explained in its README). Error codes, error messages, the HTTP APIs, the inventory's module interface (scan, buildCbom, renderSummary, ...) and the documentation are in English.

Licence

MIT, see LICENSE. Files: 66 (pq-gateway 6, pq-kms 10, pq-pki 6, crypto-inventory 42).