Skip to content

feat: zero-access key-hierarchy primitives (password KDF, key-wrap records, nmcs1 stream) - #12

Merged
kauandotnet merged 1 commit into
mainfrom
feat/zero-access-key-primitives
Aug 16, 2026
Merged

feat: zero-access key-hierarchy primitives (password KDF, key-wrap records, nmcs1 stream)#12
kauandotnet merged 1 commit into
mainfrom
feat/zero-access-key-primitives

Conversation

@kauandotnet

Copy link
Copy Markdown
Contributor

Groundwork for the artifact-studio zero-access encryption program.

What

  • @nestm/crypto/password — registry-based scrypt KDF (absolute param ceilings + hard maxmem cap, versioned canonical params codec) and recovery codes (Crockford base32, checksum-padded groups).
  • @nestm/crypto/keysKeyWrapRecord (A256GCMKW secret wraps + X25519 sealed boxes) with recipient-identity-bound AAD and length-checked unwrap; hmacSha256 / timingSafeEqualBytes.
  • @nestm/crypto/stream — the nmcs1 chunked AEAD container: fixed 512-byte header, per-chunk keys/nonces derived via HKDF from a per-object random fileId; truncation/reorder/splice/header-tamper resistant; buffered + Web-stream APIs. fileId is a testing-only seam, never a public option.
  • isCipherEnvelope exported from ./core. No new runtime deps; ESM-only.

Security review

A 15-agent adversarial review found 1 critical (public fileId → keystream reuse) + 13 high; all fixed and re-verified, plus two extra hardening fixes (chunk-count off-by-one with no reader cap; unbounded record count on the header decode path). Frozen wire vectors added for format stability.

Verification

pnpm test 251 passed · pnpm run check · pnpm run build · check-package.mjs · test:packed — all green.

…cords, nmcs1 stream)

Add three capabilities that the artifact-studio zero-access encryption program
builds on:

- @nestm/crypto/password: registry-based scrypt KDF with absolute parameter
  ceilings and a hard maxmem cap, canonical versioned params codec, and
  recovery codes (Crockford base32, checksum-padded groups).
- @nestm/crypto/keys: KeyWrapRecord (A256GCMKW secret wraps + X25519 sealed
  boxes) with recipient-identity-bound AAD and length-checked unwrap, plus
  hmacSha256 / timingSafeEqualBytes.
- @nestm/crypto/stream: the nmcs1 chunked AEAD container (fixed 512B header,
  per-chunk HKDF-derived keys/nonces from a per-object random fileId, truncation/
  reorder/splice/header-tamper resistant, buffered + Web-stream APIs). fileId is
  a testing-only seam, never a public option, so nonce reuse cannot be caused by
  a caller.

Also export isCipherEnvelope from ./core. No new runtime deps; ESM-only.
@kauandotnet
kauandotnet merged commit 5d1f9fa into main Aug 16, 2026
5 checks passed
@kauandotnet
kauandotnet deleted the feat/zero-access-key-primitives branch August 16, 2026 20:19
@kauandotnet
kauandotnet restored the feat/zero-access-key-primitives branch August 16, 2026 20:23
@kauandotnet

Copy link
Copy Markdown
Contributor Author

Note: this PR was merged by mistake and immediately reverted (main rolled back). Superseded by #14, which is intentionally left open for implementation comparison.

@kauandotnet
kauandotnet deleted the feat/zero-access-key-primitives branch August 16, 2026 20:29
@kauandotnet
kauandotnet restored the feat/zero-access-key-primitives branch August 16, 2026 20:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant