Rename the crate from alknet-vault to alkvault across source and docs: - Cargo.toml: package name and lib name (alknet_vault -> alkvault) - src/ doc comments and doc-test use statements - tests/ use statements and one string literal Convert references to non-vault alknet ADRs (003, 005, 008, 010, 014, 064) that were broken local links into @alkdev/alknet: cross-repo references, matching the alktype sibling pattern. Local ADR/OQ references are now proper links. Rewrote monorepo path references (crates/alknet-vault/src/...) to the flat layout (src/...). Fixed sdd_process.md package name (@alkdev/storage -> @alkdev/alkvault). ADR/OQ renumbering is deferred to a subsequent pass per the alknet- origin numbering convention. Generic prose 'vault' and type names (VaultServiceHandle, VaultServiceError, etc.) are unchanged. Build, 108 tests, and clippy all pass clean.
1.0 KiB
1.0 KiB
OQ-22: Key Rotation Mechanism
- Origin: encryption.md
- Status: resolved
- Door type: One-way (path scheme), two-way (rotation policy)
- Priority: medium
- Resolution: Key rotation uses version-indexed derivation paths. Each key version maps to a distinct SLIP-0010 path:
m/74'/2'/0'/{version-2}'. v2 (current) is atm/74'/2'/0'/0'; v3 is atm/74'/2'/0'/1'; etc. Thedecryptmethod derives the key at the path indicated byencrypted.key_version(not always atPATHS::ENCRYPTION). Therotatemethod decrypts with the old version's key and re-encrypts with the new version's key — no new mnemonic needed. The assembly layer or a migration tool iterates stored blobs and callsrotateon each; the vault does not self-rotate. Partial rotation is safe (old keys remain derivable). See ADR-021. - Cross-references: ADR-020, ADR-021, encryption.md, service.md