2.3 KiB
Aere Quantum
Self-hosted post-quantum infrastructure from Aere Network. Three components, each a few files with no dependencies:
Node.js 24 and the OpenSSL 3.5 it ships with (node:crypto), nothing from a package registry.
| component | what it does |
|---|---|
pq-gateway/ |
a TLS 1.3 terminating proxy in front of any HTTP service, with the hybrid key exchange X25519MLKEM768: hybrid-only refuses a classical client at the handshake, hybrid-preferred keeps it working; optional client authentication with ML-DSA certificates |
pq-kms/ |
a transit-style key management service where every key is hybrid: X25519 + ML-KEM-768 for encryption, Ed25519 + ML-DSA-65 for signatures (both halves required); versions, rotation, rewrap, data keys, a chained audit log; the root key from the environment or sealed by an HSM through PKCS#11 |
pq-pki/ |
a private certificate authority for ML-DSA (X.509 v3, RFC 9881): root and issuing CAs, leaf certificates, revocation lists, and a strict chain verifier compared against OpenSSL |
Each component's README says what it is not and what is not measured. No third party has reviewed any of them.
How each is checked
Every component ships its test suite and a negative control: the control plants a real defect in a copy of the code, one at a time, and requires the named test to fail for the named reason; a planting that cannot be applied, or that breaks the build instead of the test, counts as a failure of the control. Results measured on 2026-09-29 (Node.js 24.14.1, OpenSSL 3.5.5):
| component | tests | negative control |
|---|---|---|
| pq-gateway | 33/33 (node proba-pq-gateway.mjs) |
33/33 (bash proba-pq-gateway-control-negativ.sh) |
| pq-kms | 62/62 (node test/proba.mjs); HSM root on SoftHSM2 + OpenSC 20/20 (test/proba-hsm.mjs, Linux); sealed-file trust rules 7/7 (test/proba-hsm-incredere.mjs) |
16/16 (node test/control-negativ.mjs); sealed-file rules 2/2 in this repository (test/control-negativ-hsm-incredere.mjs) |
| pq-pki | 27/27 (node test/proba.mjs), each verdict compared with OpenSSL 3.5 |
22/22 (node test/control-negativ.mjs) |
Test names and control messages are in Romanian; identifiers, error codes, messages and documentation are in English.
Licence
MIT, see LICENSE. Files: 24 (pq-gateway 6, pq-kms 10, pq-pki 6).