<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>QERYX Research</title>
    <link>https://qeryx.com/research</link>
    <atom:link href="https://qeryx.com/research/rss.xml" rel="self" type="application/rss+xml"/>
    <description>Versioned publications distilled from the QERYX protocol specification — updated dates derived from real changelogs.</description>
    <language>en</language>
    <item>
      <title>Entanglement-Anchored Key Agreement</title>
      <link>https://qeryx.com/research/entanglement-anchored-key-agreement</link>
      <guid isPermaLink="false">qeryx:entanglement-anchored-key-agreement:v0.1</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <category>white-paper</category>
      <description>Q-Entangle-Witness: folding Bell-certified public randomness — from a loophole-free Bell-test beacon or an operator-run CHSH device-behaviour witness — into session-key input material as an additive public co-factor strictly under a hybrid X25519 + ML-KEM-1024 secret. Auditable freshness that can never weaken the post-quantum floor, with the honest limits stated in full.</description>
    </item>
    <item>
      <title>CNSA 2.0 and FIPS Conformance Posture</title>
      <link>https://qeryx.com/research/cnsa-fips-mapping</link>
      <guid isPermaLink="false">qeryx:cnsa-fips-mapping:v1.2</guid>
      <pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate>
      <category>conformance</category>
      <description>Every QERYX primitive mapped to its CNSA 2.0 line item and FIPS standard, with honest per-line markers — COMPLIANT, PARTIAL, DEVIATES — and the justification for each deviation. Includes the FIPS 140-3 module lifecycle, the self-test KAT set, and the two-build model for NSS-targeted deployments.</description>
    </item>
    <item>
      <title>Cryptographic Primitives and Parameter Sets</title>
      <link>https://qeryx.com/research/primitives</link>
      <guid isPermaLink="false">qeryx:primitives:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>The master table of every primitive QERYX instantiates — parameter sets, byte sizes, backend pinning, and the source citation for each. Covers the FIPS 204 §5.2 context-framing discipline, the labeled-HKDF catalog, Argon2id at m=512 MiB, and what is deliberately absent from the build.</description>
    </item>
    <item>
      <title>FSOR: Cryptographic Erasure of Server-Held Ciphertext</title>
      <link>https://qeryx.com/research/fsor-server-erasure</link>
      <guid isPermaLink="false">qeryx:fsor-server-erasure:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>Forward-Secrecy Output Reset wraps every server-stored ciphertext in a per-conversation envelope whose key lives only in process memory. On destroy, the epoch advances and the old key is zeroized — bytes left in any backup, WAL, or replica become envelope-locked under a key that no longer exists. With the honest limits stated.</description>
    </item>
    <item>
      <title>Group Messaging: Sender Keys with Post-Quantum Rotation</title>
      <link>https://qeryx.com/research/group-messaging</link>
      <guid isPermaLink="false">qeryx:group-messaging:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>One sender key per member, ratcheted forward every message, re-encapsulated to the current member set via ML-KEM-1024 every 100 messages and on every membership change. Every group message individually signed under ML-DSA-87. Removed members cannot decrypt what comes next; new joiners cannot decrypt what came before.</description>
    </item>
    <item>
      <title>Identity and Key Transparency: Serpent ID, Profile ID, and the KTS Log</title>
      <link>https://qeryx.com/research/identity-and-kts</link>
      <guid isPermaLink="false">qeryx:identity-and-kts:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>The two-layer identity model — a device-only 256-bit Serpent ID and a public BLAKE3-derived Profile ID — plus the Key Transparency System: an append-only Merkle log with ML-DSA-87 Signed Tree Heads, consistency proofs, TOFU operator pinning, and out-of-band gossip that makes operator equivocation detectable.</description>
    </item>
    <item>
      <title>Known Limitations and Open Work</title>
      <link>https://qeryx.com/research/known-limitations</link>
      <guid isPermaLink="false">qeryx:known-limitations:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>security-analysis</category>
      <description>The honesty layer of the specification: every gap between the spec and the shipping snapshot, enumerated — audit items not yet in code, items that require user action, cadence trade-offs, optional features off by default, open production symptoms, and the v1.1 roadmap. Where spec and code diverge, code is canonical.</description>
    </item>
    <item>
      <title>Message AEAD, Frame Header v2, and the Padding Ladder</title>
      <link>https://qeryx.com/research/aead-frame-padding</link>
      <guid isPermaLink="false">qeryx:aead-frame-padding:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>The on-the-wire shape of one encrypted message: plaintext snapped to one of nine fixed buckets with crypto-random fill, ChaCha20-Poly1305 with the full Q-Ratchet header bound as AAD, and the Frame Header v2 outer envelope that makes peer re-registration detectable before decryption fails.</description>
    </item>
    <item>
      <title>Q-Ratchet: Four Parallel Ratchets</title>
      <link>https://qeryx.com/research/q-ratchet</link>
      <guid isPermaLink="false">qeryx:q-ratchet:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>The per-message key ratchet behind every QERYX session: a classical X25519 ratchet every message, an ML-KEM-1024 ratchet every epoch, a symmetric HKDF chain every message, and QRNG entropy injection every few messages. Forward secrecy and post-compromise security arguments, header AAD binding, and skipped-key bounds.</description>
    </item>
    <item>
      <title>The Hybrid Handshake: SP 800-227 Combiner and Entangled Session v1</title>
      <link>https://qeryx.com/research/handshake-entangled-session</link>
      <guid isPermaLink="false">qeryx:handshake-entangled-session:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>Two interlocking handshake layers: a NIST SP 800-227 hybrid KEM combiner over X25519 + ML-KEM-1024, and Entangled Session v1 — the mutual-authentication handshake that mixes both peers’ QRNG contributions, signs each leg under a distinct FIPS 204 context, and echoes nonces in constant time.</description>
    </item>
    <item>
      <title>The QERYX Protocol: Overview and Design Goals</title>
      <link>https://qeryx.com/research/protocol-spec-overview</link>
      <guid isPermaLink="false">qeryx:protocol-spec-overview:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>protocol-spec</category>
      <description>The tier-1 summary of the QERYX cryptographic protocol specification (Entangled v1): what ships, the one-paragraph threat model, seven design goals, and the map of per-chapter publications. Every load-bearing claim in the specification cites a path and line in the shipping source.</description>
    </item>
    <item>
      <title>The QERYX Threat Model</title>
      <link>https://qeryx.com/research/threat-model</link>
      <guid isPermaLink="false">qeryx:threat-model:v1.0</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <category>security-analysis</category>
      <description>The adversary QERYX is built against: full active network capability, a coercible server operator, and a cryptographically-relevant quantum computer. Twenty-one attack classes with their mitigations and residual risks, the defense-in-depth table, and — stated plainly — what QERYX cannot promise.</description>
    </item>
  </channel>
</rss>
