Files
alkvault/docs/architecture/questions/022-key-rotation-mechanism.md
T
glm-5.2 110146870a Rebrand alknet-vault -> alkvault
Rename the crate from alknet-vault to alkvault across source and docs:
- Cargo.toml: package name and lib name (alknet_vault -> alkvault)
- src/ doc comments and doc-test use statements
- tests/ use statements and one string literal

Convert references to non-vault alknet ADRs (003, 005, 008, 010, 014,
064) that were broken local links into @alkdev/alknet: cross-repo
references, matching the alktype sibling pattern. Local ADR/OQ
references are now proper links. Rewrote monorepo path references
(crates/alknet-vault/src/...) to the flat layout (src/...). Fixed
sdd_process.md package name (@alkdev/storage -> @alkdev/alkvault).

ADR/OQ renumbering is deferred to a subsequent pass per the alknet-
origin numbering convention. Generic prose 'vault' and type names
(VaultServiceHandle, VaultServiceError, etc.) are unchanged.

Build, 108 tests, and clippy all pass clean.
2026-08-02 09:25:43 +00:00

1.0 KiB

OQ-22: Key Rotation Mechanism

  • Origin: encryption.md
  • Status: resolved
  • Door type: One-way (path scheme), two-way (rotation policy)
  • Priority: medium
  • Resolution: Key rotation uses version-indexed derivation paths. Each key version maps to a distinct SLIP-0010 path: m/74'/2'/0'/{version-2}'. v2 (current) is at m/74'/2'/0'/0'; v3 is at m/74'/2'/0'/1'; etc. The decrypt method derives the key at the path indicated by encrypted.key_version (not always at PATHS::ENCRYPTION). The rotate method decrypts with the old version's key and re-encrypts with the new version's key — no new mnemonic needed. The assembly layer or a migration tool iterates stored blobs and calls rotate on each; the vault does not self-rotate. Partial rotation is safe (old keys remain derivable). See ADR-021.
  • Cross-references: ADR-020, ADR-021, encryption.md, service.md