Novolis.Security.SecureText 2026.1.1.48

There is a newer version of this package available.
See the version list below for details.
dotnet add package Novolis.Security.SecureText --version 2026.1.1.48
                    
NuGet\Install-Package Novolis.Security.SecureText -Version 2026.1.1.48
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Novolis.Security.SecureText" Version="2026.1.1.48" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Novolis.Security.SecureText" Version="2026.1.1.48" />
                    
Directory.Packages.props
<PackageReference Include="Novolis.Security.SecureText" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Novolis.Security.SecureText --version 2026.1.1.48
                    
#r "nuget: Novolis.Security.SecureText, 2026.1.1.48"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Novolis.Security.SecureText@2026.1.1.48
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Novolis.Security.SecureText&version=2026.1.1.48
                    
Install as a Cake Addin
#tool nuget:?package=Novolis.Security.SecureText&version=2026.1.1.48
                    
Install as a Cake Tool

Novolis

Novolis · Docs · Source

Novolis.Security.SecureText

Cryptographic device identities and primitives for the Novolis secure-text v1 protocol.

Install

dotnet add package Novolis.Security.SecureText

Guarantees

  • P-256 ECDSA-signed public device bundles.
  • P-256 ECDH pairwise key agreement.
  • HKDF-SHA-256-derived AES-256-GCM conversation keys.
  • A fingerprint that users explicitly compare and pin before accepting a peer.
  • Authenticated ciphertext only; plaintext belongs at the endpoints.

Security model

The relay may observe, retain, replay, delay, drop, or alter envelopes. It must not learn message content or successfully alter a valid message. JWTs and transport TLS control relay access; they do not establish peer cryptographic trust.

Before communication, users compare the full bundle fingerprint through an independent trusted channel and create a SecureTextTrustedPeer. A changed fingerprint blocks delivery until the users repeat this confirmation.

Secure-text v1 uses static, authenticated pairwise ECDH. It does not claim a ratchet, post-compromise security, group messaging, multi-device synchronization, or forward secrecy. Applications requiring those properties must use an audited ratchet protocol rather than extend this package.

Private-key storage

Private keys are exported only so a host can place them in platform-protected storage through ISecureTextKeyStore. Do not write them to configuration, logs, backups, source control, or an ordinary file. Device loss or intentional revocation requires generating a new identity, publishing a new public bundle, and repeating the fingerprint confirmation.

Quick start

using Novolis.Security.SecureText;

var localIdentity = SecureTextDeviceIdentity.Create();
var localBundle = SecureTextPublicBundle.Create(localIdentity);

// Obtain this through the relay, then compare its fingerprint with the peer out of band.
SecureTextPublicBundle peerBundle = GetPeerBundle();
var trustedPeer = new SecureTextTrustedPeer(peerBundle);
trustedPeer.VerifyBundle(peerBundle);

The transport-neutral envelope and replay policy live in Novolis.Messaging.SecureText.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.

NuGet packages (3)

Showing the top 3 NuGet packages that depend on Novolis.Security.SecureText:

Package Downloads
Novolis.Messaging.SecureText

Transport-neutral authenticated envelope, replay policy, and sessions for end-to-end secure text.

Novolis.Chat.Directory

Named chat spaces and channels, rosters, devices, and SecureText group membership.

Novolis.Chat.Hosting.AspNetCore

ASP.NET Core SignalR orchestration for encrypted chat conversations.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2026.1.1.52 43 10/4/2026
2026.1.1.51 41 10/4/2026
2026.1.1.48 47 10/4/2026
2026.1.1.47 52 10/1/2026
2026.1.1.46 85 9/30/2026