
Secure (with AEAD) version of USTP, called USTP-Secure (ustps://)
USTP means UDP Speedy Transmission Protocol.
USTP keeps the same authenticated transport model, but the project name is now simply USTP again.
By default, USTP uses AEAD for DATA.
It also supports an optional negotiated cleartext + HMAC mode for DATA, where payload bytes are visible on the wire but tampering is detected and rejected.
USTP now supports an optional congestion controller called USTP Congestion. It is still UDP-first, but it can optionally slow down and ramp back up when the path starts showing congestion signals.
Status: Beta
USTP is no longer just a proof of concept. It is currently in the Beta phase.
USTP can be used for many kinds of applications and transports.
This repository, however, is focused specifically on streaming over USTP.
02/08/2026: USTP-Secure is now back to USTP.
USTP-Secure was an old project name and no longer a good fit for the project.USTP name is now preferred again.UDP Speedy Transmission Protocol, without Secure in the title.2026-07-18: USTP/2 Beta was removed from the current tree.
Codex using GPT-5.4 (Low).--loss 33.Brazil -> Canada with about 140ms RTT.chacha20 = CHACHA20_POLY1305aes-256-gcm = AES_256_GCMaes-128-gcm = AES_128_GCMchacha20DATA protection mode is AEAD.DATA protection mode is cleartext + per-packet HMAC.HELLO, ACK, RETRANSMIT_REQUEST, CLOSE) stay plaintext on purpose.ACK and NACK/RETRANSMIT_REQUEST remain plaintext, but are authenticated with a per-session HMAC tag.DATA packets use a binary frame format named UPACK (UPAK on the wire).IP:port.--cipher is set on the server, the server uses that exact cipher.--cipher is omitted or set to auto, the server uses the cipher requested by the client.DATA protection mode is negotiated separately from cipher choice:
--cleartext auto|on|off--cleartext on|offautooffauto, the server follows the client request.on, the server forces cleartext + HMAC.off, the server forces AEAD.~/.ustps_host_key by default so TOFU remains stable across reconnects and restarts.--regen-key on the server only when you intentionally want to rotate that host key.ACK:, NACK:, HELLO:, and CLOSE: are the plaintext control record prefixes.USS1 means UDP Speedy Secure, version 1.USC1 means UDP Speedy Clear, version 1.UPAK is the binary UPACK DATA frame marker.ACK: 10, NACK: 42, HELLO: ..., and CLOSE:.UPAK identifies binary DATA packets after decryption.USS1 is the outer secure AEAD envelope format.USC1 is the outer cleartext+HMAC DATA envelope format.USS1... for AEAD-protected DATAUSC1... for cleartext+HMAC DATAUSTP Congestion, negotiated during the handshake.seq and an application-facing stream_pos.seq is used for ACK, loss detection, retransmission, and RTT sampling.stream_pos tells the application where the payload belongs in the logical byte stream.seq is a 32-bit counter that starts at 1 for each fresh session.stream_pos is a 64-bit byte counter that starts at 0 for each fresh logical stream.HELLO carrying its X25519 public key, requested cipher, requested congestion-control mode (on or off), and requested DATA protection mode (cleartext on|off).session_idDATA protection modeDATA.IP:port that completed the challenge.session_id is still used as a session label, but it is not accepted from a different IP:port.HELLOUSTPS-CHALLENGE1 carrying token, session_id, selected cipher, negotiated congestion-control mode, negotiated DATA protection mode, and server public keyUSTPS-CHALLENGE-REPLY1USTPS-SESSION1IP:port can actually receive packets thereUSTP, but several on-wire ASCII identifiers still use the historical USTPS-* prefix.USTPS-KEX1USTPS-CHALLENGE1USTPS-CHALLENGE-REPLY1USTPS-SESSION1USTPS-RESUME1USTPS-RTT1USTP, but those historical wire identifiers were not renamed in the protocol bytes.