Skip to main content

sgcp-protocol

State Graph Cryptographic Protocol (SGCP) — Python PyPI package.

Implements draft-sgcp-state-graph-cryptographic-protocol-00 in full.

Install

pip install sgcp

Or from source:

cd sgcp-protocol
pip install -e ".[dev]"

Protocol Stack

SGCP
 ├── X.509 Certificates   (§4)  — identity binding via cryptography library
 ├── ECDH / X25519        (§5.4) — shared secret establishment
 ├── HKDF (SHA-256)       (§8)  — Root Secret → Epoch Key → Packet Key
 ├── SGCP State Graph     (§7)  — nodes + hash chain + authenticated edges
 └── Packet Protection    (§5.8/§5.9) — AES-256-GCM + XOR transform

Quick Start

from sgcp.crypto.ecdh import X25519KeyPair, generate_nonce
from sgcp.crypto.kdf  import (
    derive_root_secret_classic, derive_session_id, compute_context_binding
)
from sgcp.packet.data import create_data_packet, receive_data_packet, DataPacket
from sgcp.constants   import Direction

# --- Phase 4: ECDH ---
client_dh = X25519KeyPair()
server_dh = X25519KeyPair()
dh_secret = client_dh.exchange(server_dh.public_bytes)

# --- Phase 4/8.1: Root Secret ---
cn = generate_nonce(32)   # Client_Nonce
sn = generate_nonce(32)   # Server_Nonce
ch = generate_nonce(32)   # Client_Cert_Hash (SHA-256 of client.crt)
sh = generate_nonce(32)   # Server_Cert_Hash

root_secret = derive_root_secret_classic(dh_secret, cn, sn, ch, sh)

# --- Phase 5: Session_ID ---
session_id = derive_session_id(root_secret, cn, sn)

# --- Phase 6: Context Binding ---
ctx = compute_context_binding(1, "client-device-01", 6, 443, 12345,
                               b"socket-cookie-01", session_id)

# --- Phase 8: Send ---
plaintext = b"Hello from SGCP client!"
pkt = create_data_packet(
    plaintext=plaintext, session_id=session_id, root_secret=root_secret,
    epoch=0, sequence=0,
    direction=Direction.CLIENT_TO_SERVER,
    context_binding=ctx,
)
wire = pkt.to_wire()

# --- Phase 9: Receive ---
from sgcp.packet.data import DataPacket
received = DataPacket.from_wire(wire)
recovered, tag = receive_data_packet(received, session_id, root_secret, ctx)
assert recovered == plaintext
print("Decrypted:", recovered)

MP3 Full-Duplex Transfer Example (§14)

from sgcp.media.transfer import segment_file, reassemble_file

# Sender: segment 7 MB MP3
with open("song.mp3", "rb") as f:
    data = f.read()

segments = list(segment_file(data, segment_size=8192))
# → 896 segments, each protected by a unique per-packet key

# Receiver: reassemble (verifies SHA-256 File_Hash automatically)
reassembled = reassemble_file(segments)
assert reassembled == data

Modules

Module Draft section
sgcp.constants §2.2, §6.1, §8.5
sgcp.exceptions throughout
sgcp.x509_integration §4
sgcp.crypto.kdf §8.1–§8.5
sgcp.crypto.aead §5.8/§5.9
sgcp.crypto.ecdh §5.4
sgcp.crypto.transform §9
sgcp.session.replay §5.11
sgcp.session.context §5.2, §5.6, §5.12
sgcp.session.epoch §10
sgcp.session.state §5.5, §5.10, §15
sgcp.graph.node §7.1
sgcp.graph.edge §7.2
sgcp.graph.state_graph §7.3, §7.4
sgcp.packet.header §6.1
sgcp.packet.handshake §5.3, §6.2
sgcp.packet.data §5.8, §5.9, §6.3
sgcp.packet.media §6.3, §14
sgcp.protocol.handshake §5.1–§5.5, §4.5
sgcp.protocol.client §5.1–§5.12
sgcp.protocol.server §5.9–§5.12
sgcp.protocol.transition §11, §5.12
sgcp.protocol.recovery §12
sgcp.media.transfer §14

Run Tests

pip install -e ".[dev]"
pytest tests/ -v

Author

Sripad Karthik sripadkarthik@gmail.com

License

BSD 2-Clause

Metadata

Release files for sgcp 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sgcp 0.1.1
File Size Uploaded
sgcp-0.1.1.tar.gz 57.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sgcp 0.1.1
File Interpreter ABI Platform
sgcp-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 121.5 kB

Release files / sgcp-0.1.1.tar.gz

Download URL sgcp-0.1.1.tar.gz
Size 57.7 kB
Tags Source
SHA-256 checksum
How to use checksums
46c8e040bac7020fc37728c9740fbdfcda423bec4bbb696ffc230ce81da0852e
BLAKE2b-256 checksum
How to use checksums
443ca58af66f8856105e3fee9180b7b9c469abfcde55081ee1f01048288cb8c8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.5

Release files / sgcp-0.1.1-py3-none-any.whl

Download URL sgcp-0.1.1-py3-none-any.whl
Size 63.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8fb0f684d31edc91a8dfd502c1d8c50e00bb63f1562673f4245e3383091d6d99
BLAKE2b-256 checksum
How to use checksums
81518e28b0b6614b6d95b70baaad5f54efc40e0fc65836fa21fc605970082600
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.5

Release history Release notifications | RSS feed

0.1.2

2 release files

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page