All notable changes to Secure LSL will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- First stable release of the security layer (dropped the
alphastage) - License clarified to permit non-commercial academic reproduction, benchmarking, and modification to verify or extend results; commercial and competitive use remain licensed separately
- ESP32 support: liblsl-ESP32, a clean-room C reimplementation of the LSL wire protocol for ESP32 microcontrollers with full secureLSL encryption
- ESP32 outlet and inlet with ChaCha20-Poly1305 encryption, wire-compatible with desktop
- Four ESP32 examples: basic_outlet, basic_inlet, secure_outlet, secure_inlet
- ESP32 benchmark suite: throughput firmware and desktop Python collection scripts
- ESP32 documentation integrated into mkdocs site
- Bidirectional encrypted interop: ESP32 to desktop and desktop to ESP32
- Zero packet loss at 250/500 Hz, 0.02% at 1000 Hz
- Zero measurable encryption overhead on ESP32 push path (dual-core async)
- Initial security layer implementation
- Ed25519 device authentication
- ChaCha20-Poly1305 authenticated encryption
- X25519 + BLAKE2b session key derivation
- Replay attack prevention with nonce tracking
- Security configuration via lsl_api.cfg [security] section
- Key generation tool:
lsl-keygen - Configuration validator:
lsl-config - Version query API:
lsl_is_secure_build()- detect secure library at runtimelsl_base_version()- get upstream liblsl versionlsl_security_version()- get security layer versionlsl_full_version()- get combined version string
- C++ wrappers for all version functions
- Renamed binary to
liblsl-secureto prevent confusion - MkDocs documentation site with security guides
- Cross-platform test suite (Python, MATLAB, C++)
- Interoperability tests between all language bindings
- Library output name:
liblsl->liblsl-secure - Version string includes security info in
lsl_library_info()
- All data encryption uses libsodium (NIST-validated)
- Constant-time cryptographic operations
- Secure memory zeroing for sensitive data
- Unanimous security enforcement (secure outlets reject insecure inlets and vice versa)
Secure LSL uses dual versioning:
- Base version: Tracks upstream liblsl (e.g., 1.16.1)
- Security version: Tracks security layer (e.g., 1.0.0)
- Combined:
{base}-secure.{security}[-stage]
Stages: alpha -> beta -> rc.N -> (stable)