AntOS Library — crypto (reference)

The crypto library's design and native core — Ed25519 signing, HMAC-SHA256, and the TLS CA trust store. Split out of the P4 data library so data stays pure encoding/hashing/JSON. The script-facing API is luau_crypto.

What it is

Three related capabilities: public-key signatures (Ed25519 — deterministic keygen from a 32-byte seed, sign, verify), message authentication (HMAC-SHA256), and the TLS certificate-authority trust store that net uses to validate HTTPS.

Why it's separate from data

On the ESP32-P4 these lived as data.crypto.* and data.ca.*. They are pulled into their own library because they are a different concern from encoding: data is byte-shuffling (JSON, base64, hex, checksums) that any script reaches for freely; crypto is security-critical — key material, signatures, and the trust anchors for TLS. Keeping them apart makes the security surface easy to see, and lets data stay dependency-light. Plain hashing (sha256/crc32) stays in data, since it's used constantly and isn't a secret.

Design notes

  • The signature scheme is Ed25519, and a node's identity on the gossip mesh is its Ed25519 public key — so crypto.keygen/sign/verify and gossip share one key model.
  • CA validity is clock-dependent — not_before/not_after are only meaningful once the system clock is set, so the CA store interacts with the RTC/NTP ordering the same way HTTPS does.
  • Keys and MACs are raw bytes; the binding never widens or narrows them — a 32-byte seed, 64-byte secret, 32-byte public key, 64-byte signature, 32-byte MAC, checked at the boundary.

Native core — libantos_crypto

The crypto and CA code from the P4 sys_data core — Ed25519 (x25519-named in the source), HMAC-SHA256, and the mbedTLS-backed certificate store — plain C, no Luau. The same core backs net's TLS and gossip's signed packets.

Related

Important: The Ant64 family of home computers are at early design/prototype stage, everything you see here is subject to change.