Noise Protocol IK (Poket PC Handshake)
The Noise Protocol Framework is a set of patterns for building encrypted transports. Poket PC uses the IK pattern, as Noise_IK_25519_ChaChaPoly_SHA256, both for pairing and for every connection after it. The iPhone (initiator) already knows the Mac’s long-term public key from the QR code, and both sides prove possession of their identity keys before application data flows.
Handshake sketch
<- s (known in advance: the Mac's static key, from the QR code)
...
-> e, es, s, ss iPhone: new ephemeral key, then its own static key, encrypted
<- e, ee, se Mac: new ephemeral key
--> two ChaCha20-Poly1305 keys, one for each direction
Before the first message, both sides mix a prologue into the transcript. For a first pairing it holds the six-digit code and the rendezvous token; for a reconnect it is empty, and the Mac admits only a phone it already knows.
X25519 carries the Diffie-Hellman work, and SHA-256 hashes the transcript. ChaCha20-Poly1305 encrypts and authenticates each record afterward, with counters that reject replays.
Why not TLS alone to the relay?
TLS ends at a server. Poket PC’s link to the relay does use TLS, but that layer ends at the relay. Poket PC needs keys to exist only on your phone and Mac, so the Noise channel runs over the relay pipe, not to the relay as the crypto endpoint.
Pairing vs session
- Pairing: the iPhone learns the Mac’s public key from the QR code, and the Mac records the phone’s key when the first handshake, bound to the six-digit code, succeeds.
- Each connection runs Noise IK again with fresh ephemeral keys, so every session gets its own keys. Recorded traffic from an earlier session stays sealed even if a long-term key is stolen later: that is forward secrecy.
Full consumer explanation: /security/. Pairing steps: /features/pairing/.
Frequently asked questions
What does IK mean in Noise IK?
I: the initiator sends its static public key, encrypted, in the first message. K: the initiator already knows the responder's static public key; in Poket PC the iPhone gets the Mac's key from the QR code.
How does the six-digit code fit in?
For a first pairing, the code and the rendezvous token are mixed into the handshake's prologue. A phone with the wrong code produces a different handshake hash, so the Mac cannot open its first message. The code travels only in the QR code, never through the relay.