Novolis.Security.SecureText
2026.1.1.52
dotnet add package Novolis.Security.SecureText --version 2026.1.1.52
NuGet\Install-Package Novolis.Security.SecureText -Version 2026.1.1.52
<PackageReference Include="Novolis.Security.SecureText" Version="2026.1.1.52" />
<PackageVersion Include="Novolis.Security.SecureText" Version="2026.1.1.52" />
<PackageReference Include="Novolis.Security.SecureText" />
paket add Novolis.Security.SecureText --version 2026.1.1.52
#r "nuget: Novolis.Security.SecureText, 2026.1.1.52"
#:package Novolis.Security.SecureText@2026.1.1.52
#addin nuget:?package=Novolis.Security.SecureText&version=2026.1.1.52
#tool nuget:?package=Novolis.Security.SecureText&version=2026.1.1.52
Novolis.Security.SecureText
Cryptographic device identities and primitives for the Novolis secure-text v1 protocol.
Install
dotnet add package Novolis.Security.SecureText
Guarantees
- P-256 ECDSA-signed public device bundles.
- P-256 ECDH pairwise key agreement.
- HKDF-SHA-256-derived AES-256-GCM conversation keys.
- A fingerprint that users explicitly compare and pin before accepting a peer.
- Authenticated ciphertext only; plaintext belongs at the endpoints.
Security model
The relay may observe, retain, replay, delay, drop, or alter envelopes. It must not learn message content or successfully alter a valid message. JWTs and transport TLS control relay access; they do not establish peer cryptographic trust.
Before communication, users compare the full bundle fingerprint through an independent trusted
channel and create a SecureTextTrustedPeer. A changed fingerprint blocks delivery until the
users repeat this confirmation.
Secure-text v1 uses static, authenticated pairwise ECDH. It does not claim a ratchet, post-compromise security, group messaging, multi-device synchronization, or forward secrecy. Applications requiring those properties must use an audited ratchet protocol rather than extend this package.
Private-key storage
Private keys are exported only so a host can place them in platform-protected storage through
ISecureTextKeyStore. Do not write them to configuration, logs, backups, source control, or an
ordinary file. Device loss or intentional revocation requires generating a new identity, publishing
a new public bundle, and repeating the fingerprint confirmation.
Quick start
using Novolis.Security.SecureText;
var localIdentity = SecureTextDeviceIdentity.Create();
var localBundle = SecureTextPublicBundle.Create(localIdentity);
// Obtain this through the relay, then compare its fingerprint with the peer out of band.
SecureTextPublicBundle peerBundle = GetPeerBundle();
var trustedPeer = new SecureTextTrustedPeer(peerBundle);
trustedPeer.VerifyBundle(peerBundle);
The transport-neutral envelope and replay policy live in
Novolis.Messaging.SecureText.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- No dependencies.
NuGet packages (3)
Showing the top 3 NuGet packages that depend on Novolis.Security.SecureText:
| Package | Downloads |
|---|---|
|
Novolis.Chat.Directory
Named chat spaces and channels, rosters, devices, and SecureText group membership. |
|
|
Novolis.Chat.Hosting.AspNetCore
ASP.NET Core SignalR orchestration for encrypted chat conversations. |
|
|
Novolis.Messaging.SecureText
Transport-neutral authenticated envelope, replay policy, and sessions for end-to-end secure text. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2026.1.1.52 | 0 | 10/4/2026 |
| 2026.1.1.51 | 35 | 10/4/2026 |
| 2026.1.1.48 | 44 | 10/4/2026 |
| 2026.1.1.47 | 49 | 10/1/2026 |
| 2026.1.1.46 | 82 | 9/30/2026 |