Skip to content

feat: zero-access key-hierarchy primitives (password KDF, key-wrap records, nmcs1 stream) - #14

Merged
kauandotnet merged 1 commit into
mainfrom
feat/zero-access-key-primitives
Aug 16, 2026
Merged

feat: zero-access key-hierarchy primitives (password KDF, key-wrap records, nmcs1 stream)#14
kauandotnet merged 1 commit into
mainfrom
feat/zero-access-key-primitives

Conversation

@kauandotnet

Copy link
Copy Markdown
Contributor

Groundwork for the artifact-studio zero-access encryption program. Left open intentionally for comparison against an alternative implementation — do not merge yet.

What

  • @nestm/crypto/password — registry-based scrypt KDF (absolute param ceilings + hard maxmem cap, versioned canonical params codec) and recovery codes (Crockford base32, checksum-padded groups).
  • @nestm/crypto/keysKeyWrapRecord (A256GCMKW secret wraps + X25519 sealed boxes) with recipient-identity-bound AAD and length-checked unwrap; hmacSha256 / timingSafeEqualBytes.
  • @nestm/crypto/stream — the nmcs1 chunked AEAD container: fixed 512-byte header, per-chunk keys/nonces from a per-object random fileId; truncation/reorder/splice/header-tamper resistant; buffered + Web-stream APIs. fileId is a testing-only seam, never public.
  • isCipherEnvelope exported from ./core. No new runtime deps; ESM-only.

Security review

A 15-agent adversarial review found 1 critical (public fileId → keystream reuse) + 13 high; all fixed and re-verified, plus two extra hardening fixes. Frozen wire vectors added.

Verification

pnpm test 251 passed · check · build · check-package · test:packed — all green.

…cords, nmcs1 stream)

Add three capabilities that the artifact-studio zero-access encryption program
builds on:

- @nestm/crypto/password: registry-based scrypt KDF with absolute parameter
  ceilings and a hard maxmem cap, canonical versioned params codec, and
  recovery codes (Crockford base32, checksum-padded groups).
- @nestm/crypto/keys: KeyWrapRecord (A256GCMKW secret wraps + X25519 sealed
  boxes) with recipient-identity-bound AAD and length-checked unwrap, plus
  hmacSha256 / timingSafeEqualBytes.
- @nestm/crypto/stream: the nmcs1 chunked AEAD container (fixed 512B header,
  per-chunk HKDF-derived keys/nonces from a per-object random fileId, truncation/
  reorder/splice/header-tamper resistant, buffered + Web-stream APIs). fileId is
  a testing-only seam, never a public option, so nonce reuse cannot be caused by
  a caller.

Also export isCipherEnvelope from ./core. No new runtime deps; ESM-only.
@kauandotnet
kauandotnet merged commit 8bff31b into main Aug 16, 2026
10 checks passed
@kauandotnet
kauandotnet deleted the feat/zero-access-key-primitives branch August 16, 2026 20:29
@kauandotnet
kauandotnet restored the feat/zero-access-key-primitives branch August 16, 2026 20:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant