Skip to main content

USMP - Unified Secure Multi-transport Protocol

Secure, encrypted communication for ESP32, Arduino, and IoT devices.

USMP sits between raw sockets (no security) and full TLS/DTLS (too heavy for microcontrollers) - giving any constrained device a fully encrypted, mutually authenticated session in three function calls.

pip install usmp

What it gives you

  • Mutual authentication - both device and server verify each other via HMAC-SHA256 + PSK
  • Forward secrecy - X25519 ephemeral key exchange, new keys every session
  • Encryption - AES-256-GCM, mandatory, no plaintext mode
  • Replay protection - monotonic sequence numbers
  • Multiple Transports - Production-ready support for both TCP and UDP streams.

Quickstart

Server

import asyncio
from usmp import USMPServer, USMPSession, USMPProtocol, ConnectionClosedError

# Initialize server
server = USMPServer(host="0.0.0.0", port=9000, psk=b"your-psk-here", protocol=USMPProtocol.TCP)

@server.on_session
async def handle(session: USMPSession):
    print(f"Device connected: {session.device_id}")
    try:
        while True:
            data = await session.recv()
            print(f"RX: {data}")
            await session.send(b"got it")
    except ConnectionClosedError:
        print(f"Device disconnected: {session.device_id}")

async def main():
    await server.serve()

if __name__ == "__main__":
    asyncio.run(main())

Client (Python)

import asyncio
from usmp import USMPClient, USMPProtocol

async def main():
    # Initialize client
    client = USMPClient(host="127.0.0.1", port=9000, psk=b"your-psk-here", protocol=USMPProtocol.TCP)
    await client.connect()
    
    await client.send(b"hello")
    reply = await client.recv()
    print(f"RX: {reply}")
    
    await client.disconnect()

if __name__ == "__main__":
    asyncio.run(main())

Client (Arduino ESP32)

#include <USMP.h>

USMPClient usmp("your-psk-here");

void setup() {
    // Connect using TCP or UDP
    usmp.begin(USMP::TCP("192.168.1.100").wifi("SSID", "password"));
    usmp.send("hello from esp32");
}

void loop() {
    usmp.maintain(); // keepalive + reconnect

    if (usmp.available()) {
        Serial.println(usmp.read());
    }
}

Protocol overview

Device                        Server
  |                              |
  |-- HELLO (device_id, pub_C) -->|
  |<- CHALLENGE (nonce, pub_S) ---|
  |-- HELLO_ACK (HMAC) ---------->|
  |<- SESSION_OK (session_id) ----|
  |                              |
  |== AES-256-GCM encrypted ======|

4-step handshake, then every frame is AES-256-GCM encrypted with a session key derived via X25519 + HKDF-SHA256.

Installation

pip install usmp

Requires Python 3.11+.

ESP32 / Arduino library

The Arduino library and ESP-IDF component are available directly through their respective package registries:

  • ESP-IDF Component: Add as a dependency by running idf.py add-dependency "metaloomlabs/usmp" in your project directory.
  • Arduino Library: Import the packaged release ZIP archive usmp-1.0.1-arduino.zip via Sketch ➔ Include Library ➔ Add .ZIP Library...

USMP™ • Developed by Metaloom

Release files for usmp 1.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for usmp 1.2.0
File Size Uploaded
usmp-1.2.0.tar.gz 25.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for usmp 1.2.0
File Interpreter ABI Platform
usmp-1.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 55.9 kB

Release files / usmp-1.2.0.tar.gz

Download URL usmp-1.2.0.tar.gz
Size 25.0 kB
Tags Source
SHA-256 checksum
How to use checksums
1d42b64bec484e4547534fdb89e6b94892a1b66d227975da8febc1869f91b7ec
BLAKE2b-256 checksum
How to use checksums
37e114c18d9e12592ddc5d44cd883bdc55006be1fbeb22dc8bf56dd7f94dd342
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.5.21

Release files / usmp-1.2.0-py3-none-any.whl

Download URL usmp-1.2.0-py3-none-any.whl
Size 30.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
40a5772e029be3647b4bf920b8a8ce4874ed62a0ae4a3800d944ba57d2fbe05b
BLAKE2b-256 checksum
How to use checksums
03b8467d2c8a8da1f2eb5f49cd4e8941d236a95bf7e9d79beed8cc8321579568
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.5.21

Release history Release notifications | RSS feed

1.2.2

2 release files

1.2.1

2 release files

This release

1.2.0 This release

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.5.1

2 release files

0.4.7

2 release files

0.4.4

2 release files

0.4.2

2 release files

0.4.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page