Files
alknet/docs/architecture/questions/020-salt-kdf-and-encryption-key-derivation-method.md
T
glm-5.2 1baa619ce9 docs(arch): decompose open-questions.md into per-OQ files under questions/
The monolithic open-questions.md (1310 lines, 47 OQs) was large enough to be
unmanageable, with high size variance (OQ-42 at 220 lines next to OQ-06 at 8).
Decomposed into one file per OQ under docs/architecture/questions/ (NNN-slug.md,
mirroring the ADR convention), with open-questions.md retained as the index:
theme-grouped tables plus a cross-theme Deferred/Blocked section that surfaces
the 6 deferred OQs with their Blocked-on conditions inline (the safe-exit
visibility surface). Per-OQ content moved verbatim; all 62 inbound links stay
valid (none used anchors). README's curated OQ summary dropped (now redundant
with the index tables).

Also seeds tasks/architecture/ with this task plus two follow-ups found during
the decompose: OQ-09/10 missing structured Blocked-on fields, and the
tasks/architecture/ blocker-task half of the Safe Exit protocol being
unenforced.
2026-07-06 16:07:59 +00:00

882 B

OQ-20: Salt/KDF and Encryption Key Derivation Method

  • Origin: encryption.md
  • Status: resolved
  • Door type: One-way (key derivation method), two-way (salt field usage)
  • Priority: high
  • Resolution: The vault uses SLIP-0010 HD derivation from the BIP39 seed at path m/74'/2'/0'/0' to produce the AES-256-GCM encryption key — not PBKDF2. The salt field in EncryptedData is unused for key derivation (kept for wire-format compatibility with the TS predecessor). The TypeScript @alkdev/storage crypto module used PBKDF2 with a password + salt; data encrypted by that method (key_version=1) cannot be decrypted by the vault and must be migrated via one-time re-encryption to key_version=2. See ADR-020 for the full rationale and migration path.
  • Cross-references: ADR-020, encryption.md