Steganographic encoder
Hide a message in a grid of numbers — double referent ansate cross + Jacquard
See the interactive Carter Random demo (French) — a visualisation of the grid (referents derived from the key), freely available
Loading referents…
Demonstration: message ANIBALAMIOTX
ANIBALAMIOTX is first encrypted with XChaCha20-Poly1305 (256-bit master key), then the ciphertext is spread across the blocks that one and the same key designates as “message” in a 90×90 grid — the rest is indistinguishable noise, including the “structured” blocks, which are statistically identical to the “message” blocks without the key. Confidentiality comes from the encryption; the geometry only hides where the ciphertext is.
Key exchange — authenticated X25519 (triple DH)
Two correspondents derive the same session without transmitting any secret. Three Diffie-Hellman exchanges go into the derivation: ephemeral × ephemeral for forward secrecy, then ephemeral × identity on each side, which binds the long-term identities to the session. A relay that substitutes its own ephemeral keys holds neither of the two private identities: it cannot compute the key. Same protocol as the Python CLI — a session derived here and a session derived by secu-box exchange arrive at the same key.
About your identity: its private key is kept in this browser in a form the page’s code cannot read — it can only use it to derive. The trade-off: it can be neither backed up nor moved to another browser. Clearing the site’s data destroys it permanently, along with the fingerprint your correspondents know. An identity from the Python CLI cannot be imported here either: each side keeps its own, which does not prevent the two from communicating.
Step 0 — Your identity
Step 1 — Your offer
Step 2 — Your correspondent’s offer
Session keys are stored in your browser (localStorage). Clearing your history or using private browsing deletes them. No data is sent to the server.
Active session
Send with the active session
Encode a message (free key)
Carter grid (grammar derived from the key)
A single passphrase derives, via HKDF-SHA256, the encryption key and the grammar of the grid (the role — pure / structured / message — and the shape of each of its blocks) — no placement is stored outside the key. The “structured” and “message” blocks are statistically indistinguishable without it. Each encoding draws a random salt, displayed afterwards: send it along with the passphrase. It is not secret and does not appear in the CSV, but without it the grid stays closed — and it is what prevents a table precomputed over common passphrases from opening every user’s grids at once.
Decrypt with the active session
Decode with a manual key
Load from a file
Decode a Carter grid
Encrypted vault — files
Encrypts your files in the browser (AES-256-GCM per entry, encrypted manifest, global HMAC-SHA256 — format inspired by vault_lib.py). No file or passphrase is sent to the server.
secu-box vault (see About).Add a file
Vault contents
Export
Referent 256 — Table of the shapes of the ansate cross
256 distinct geometric configurations: not rotations, but all the colourings that satisfy criteria I to IV of the ansate cross (exhaustive enumeration, 128 per chirality EGO/ALTER — see the article The Ansate Cross). Hover over a cell to see its positions. ×2 colours = 512 usable shapes.
Referent 360 — Jacquard layers
60 images × 6 levels = 360 layers (15 families × 4 natures). Each layer selects 8 reading positions in a 12×12 block. (— shapes extracted from the source SVG files.)
Geometric steganography — encrypt, then conceal
This system is a cryptographic application of the arithmo-geometric constructions developed in La Livrée d'Hermès (Anibal Edelberto Amiot, 2026). Submitted to the IACR Cryptology ePrint Archive in September 2026. Architecture revised following an external cryptological audit (2026-09-10).
Master key: 256 bits, randomly generated (or derived from a passphrase, or from an Exchange session). A single key, derived by HKDF-SHA256 into an encryption key and a grammar key — these two uses never share the same key material.
Grammar: the grammar key assigns each block of the grid a role (pure / structured / message) and a shape, drawn from the Referent 256 (ansate cross) or from a 6×6 referent regenerated for Carter-Random. The “structured” and “message” blocks are statistically indistinguishable from one another without the key — they exist precisely for that reason, not to carry content.
Authentication: a wrong key or incorrect data explicitly fail authentication (Poly1305), never returned as a plausible false reading.
Variants: Carter-256 (fixed ansate cross referent) and Carter-Random (6×6 referent regenerated per key) are ported to JavaScript and verified against the vectors produced by the Python code. The other variants of the same system (Deniable, Carter-360, Carter-Mix, Carter-18, Carter-Hybrid) exist on the Python side but are not yet ported to the browser.
Prior patent: FR2865054 (2004) — automated composition of a symbolic pattern from a mathematical relation.
Contact: anibaledel@gmail.com · anibal-amiot.com · Wikidata Q141191562
SecuBox architecture
SecuBox brings together five independent components, each documented and verified separately in its own tabs:
secu-box exchange arrive at the same key — verified by cross-derivation between the two implementations. Only the identity itself cannot be carried from one side to the other: the CLI protects its own with Argon2id, which Web Crypto lacks, and the browser’s is non-extractable by design. Each side therefore keeps its own.2. Message / Decrypt — Carter geometric steganography (see above), using the master key derived by the active Exchange session, a passphrase, or one entered directly.
3. Vault — local file encryption, AES-256-GCM per entry, encrypted manifest, global HMAC-SHA256 (architecture inspired by
vault_lib.py).4. File encryption — geometric SPN (Ref256+Ref360) as a key-diversification layer, AES-256-GCM as the authenticated-encryption layer (see the Encryption tab).
5. Referents 256 and 360 — the tables of geometric shapes (ansate cross, Jacquard) that feed the components above.
Note on cipher substitutions: the Message/Decrypt component (2) uses XChaCha20-Poly1305 in pure JavaScript, identical to the Python reference (
stegano/carter.py, stegano/carter_random.py) and verified against its vectors — no more substitution here. The Vault (3) and File encryption (4) remain on the browser’s native AES-256-GCM, as XChaCha20-Poly1305 is not exposed by the Web Crypto API for these two components; same class of guarantee (AEAD, 256 bits, audited standard). X25519 is implemented natively and identically on both sides.Known gap — Vault key derivation: since its version 1.2,
vault_lib.py uses Argon2id (memory-hard, GPU/ASIC-resistant) instead of PBKDF2 for its internal key derivation. Browsers have neither Argon2id nor scrypt natively — unlike the cases above, there is no Web Crypto equivalent to substitute without adding an external dependency. The Vault on this page therefore remains on PBKDF2 (300,000 iterations) and is, as a result, less resistant to GPU/ASIC brute force than its Python counterpart. For sensitive production use, prefer the Python CLI (secu-box vault).General warning: SecuBox is an experimental system based on original geometric constructions. The cryptographic layer (AES-256-GCM, X25519, HKDF, PBKDF2) is standard and audited. The geometric layer (La Livrée d'Hermès) is undergoing formal evaluation — see the external cryptological audit of 2026-09-10 mentioned in the Encryption and Decrypt tabs.
Hybrid encryption — geometric + AES-256-GCM
A two-layer architecture, following an external cryptological audit: a geometric layer (SPN Ref256+Ref360, S-box GF(2⁸), 4 rounds) derives a unique session key per sector — key diversification, not the encryption itself — then AES-256-GCM encrypts and authenticates each sector individually, with a global HMAC-SHA256 authentication on top. A wrong passphrase or a tampered file is detected, never returned as silent noise. Separate from the steganography tool above. Entirely client-side: the passphrase and the files never leave the browser.
Entered once, used directly by the Encrypt and Decrypt buttons below.
Encrypt a file
Decrypt a file
A wrong passphrase or a tampered file triggers an explicit error (HMAC-SHA256 verification) rather than producing silent noise.
Security statistics
Licence
This software is distributed under the GNU AGPL v3.
Commercial licence on request, for use without the obligations of the AGPL (product integration, defence application, paid service): anibaledel@gmail.com — see also the commercial licence.
Algorithm described in the IACR ePrint 2026 (CC BY) · Prior patent: FR2865054 · Wikidata Q141191562

