Integration Kits · v0.2.0

Stable customer boundaries for qualified multiplatform integration.

Prebuilt libraries, public headers, examples and package evidence support real compile, link and API checks while proprietary implementation details remain private.

01 · Select

Fix the exact package identity

Choose technology, ECC generation where applicable, target platform, architecture, dependency line and runtime-delivery mode.

02 · Integrate

Compile and link from the extracted kit

Use only the delivered public headers, prebuilt libraries and controlled examples. No repository source is required.

03 · Verify

Exercise the packaged boundary

Run integrity, loader, dependency, API, functional and confidentiality checks against the exact delivered binary hashes.

RSA-oriented integration

Advanced Integration Kit v0.2.0 across five dependency variants.

The Advanced Integration Kit is the canonical Core + RSA Advanced customer distribution. Core and RSA remain separate libraries and APIs inside the controlled package.

VariantRuntime boundaryCustomer package
LeanNo OpenSSL, libcrypto or libsslPublic Core/RSA headers, prebuilt libraries, examples and evidence
OpenSSL 3.5.7 ExternalCustomer-provided dynamic libcrypto; no libsslWindows DLL directory must be on PATH
OpenSSL 3.5.7 Self-ContainedApproved libcrypto bundled and checksummedNo external Windows DLL-path step
OpenSSL 4.0.1 ExternalCustomer-provided dynamic libcrypto; no libsslSeparately qualified recent compatibility line
OpenSSL 4.0.1 Self-ContainedApproved architecture-matched runtime bundledRuntime licence, manifest and hashes included
Linux x86-64 glibcLinux x86-64 muslLinux ARM64 glibcLinux ARM64 muslWindows x64Windows ARM64macOS ARM64macOS x86-64

RSA Binary Footprint Integration

Specialized linkable boundaries for constrained and edge assessment.

Binary Footprint Integration Kits complement the full Advanced Integration Kit. They expose a deliberately smaller customer-facing boundary for resource and dependency assessment; they are not presented as the complete Core + RSA Advanced API distribution.

RSA · Embedded Lean Footprint

Embedded Lean Integration Kit

A compact C-facing linkable boundary for constrained targets without OpenSSL.

Workspace
2,176 B at RSA-2048 through 8,704 B at RSA-8192 high-bound
Measured library text
Approximately 507 bytes in the assessed release build
Assessed stack contribution
8–16 bytes within the measured boundary
Dependencies
No OpenSSL, PEM, filesystem, CLI or JSON requirement
RSA · Edge OpenSSL Footprint

Edge OpenSSL Integration Kit

A host-side edge and embedded-Linux boundary for controlled crypto-runtime interoperability.

Runtime
Expected libcrypto dependency; no libssl
Profiles
Qualified OpenSSL 3.5.7 and 4.0.1 runtime lines where applicable
Customer checks
Compile, link, loader, dependency and API-boundary verification
Evidence
Workspace, stack, binary inspection, manifest and checksums

ECC desktop/server integration

ECC v1 and ECC v2: one frozen API, separate fixed-domain products.

Both generations expose the same 17-function Commercial ECC C API v1 and customer ABI. Package identity fixes the generation; public-key blobs are generation-bound and private scalars must not be reused across domains.

ECC Hosted Integration matrix

Lean and OpenSSL 3.5.7/4.0.1, with separate external-runtime and self-contained packages.

For each ECC generation, the desktop/server line retains distinct dependency boundaries across Linux, macOS and Windows. Lean packages have no OpenSSL dependency; OpenSSL-backed packages use either a customer-supplied runtime or the approved bundled runtime.

ECC v1/v2 · Linux

Linux Integration Complete Kits

20 qualified packages per generation.

Lean
4 packages across x86-64/ARM64 and glibc/musl
OpenSSL
16 packages across 3.5.7/4.0.1 and both runtime modes
Customer checks
Compile, link, loader, ABI and examples
ECC v1/v2 · macOS

macOS Integration Complete Kits

10 qualified packages per generation.

Lean
Apple Silicon and Intel packages
OpenSSL
8 packages across both version and runtime lines
Binary form
Controlled dylib install name and architecture
ECC v1/v2 · Windows

Windows Integration Complete Kits

10 qualified packages per generation.

Lean
x64 and ARM64 packages
OpenSSL
8 external/self-contained packages
Binary form
DLL plus matching MSVC import library

ECC embedded integration · Lean only · no OpenSSL

Fixed-capacity static-library kits for six qualified target ABIs.

Embedded Integration Kits are Lean and have no OpenSSL dependency. They contain a sanitized static library, the public embedded C interface, a controlled RNG hook, minimal firmware example, toolchain metadata and target-specific validation evidence.

Cortex-M4 · AAPCS32Cortex-M33 · AAPCS32Cortex-M7 · AAPCS32Cortex-A53 · AAPCS64RV32IMAC · ILP32RV64IMAFDC + Zicsr · LP64D
Shared Embedded Integration contract

The same integration, runtime and qualification boundary applies to ECC v1 and ECC v2.

  • Lean profile with no OpenSSL dependency
  • Public embedded C header and sanitized linkable static archive
  • Separate O2 and Os target packages
  • Fixed-capacity execution, zero heap and platform-provided RNG hook
  • Generation-bound public-key blobs and cross-generation rejection
  • Customer example rebuilt and executed from the supplied kit
  • QEMU execution, package retest, Flash, stack and workspace evidence
  • Manifest, binary-hygiene evidence and SHA-256 checksums
ECC v1 · Embedded Integration

Six target-specific Complete Kits

The first fixed domain is supplied independently across all six target ABIs under the shared Embedded Integration contract.

ECC v2 · Embedded Integration

Six target-specific Complete Kits

The second fixed domain preserves the same public embedded interface and qualification matrix while remaining package- and key-domain separate.

Customer-facing boundaries

Explicit APIs and ownership rules.

Core C API v1

Finite odd-window prime counting and streaming through a stable customer interface.

RSA Advanced C API v1

Separate licensed RSA-oriented operations with configurable policies and optional OpenSSL capabilities.

Commercial ECC C API v1

Exactly 17 functions, opaque handles, Managed Ephemeral and Customer-Provisioned key profiles.

ECC protocol boundary

Validated public keys, ECDH followed by transcript-bound HKDF, role-bound confirmation and explicit clearing.

Release gates

A package name alone is never evidence of qualification.

API/export allowlistABI and loader testsDependency auditNo forbidden RPATHBinary hygieneExamples from archiveConfidentiality scanManifest and checksums

What integration establishes

A testable boundary, not unrestricted implementation disclosure.

Authorized customers can inspect declared dependencies, verify package integrity, compile and link representative applications, exercise the stable API and reproduce supplied non-secret evidence within the agreed scope.

Source access, platform-specific development, production licensing, independent validation and regulated deployment requirements remain separate matters defined through written agreements.

Begin with qualified evidence

Select the Evaluation Kit before fixing the integration boundary.

Review Evaluation KitsDiscuss an integration

Technical brochure

Review the RSA-oriented and ECC-oriented technologies in one concise document.

Download technical brochure