Copy the local key vault (src/, tests/) verbatim from alknet/crates/alknet-vault and create a standalone Cargo.toml (workspace-inherited fields inlined). Port the architecture docs (specs, ADRs 018-026, OQs 020-022) from alknet's nested multi-crate layout to a flat single-crate layout, fixing relative link paths. ADR and OQ numbers are preserved from alknet; a subsequent pass will renumber them to a per-project sequence (001, 002, ...) and rebrand alknet-vault -> alkvault (crate name, lib name, prose), updating the cross-references to non-vault alknet ADRs (003, 005, 008, 010, 014, 064) that are referenced in the copied docs but not copied over. Build, 108 tests, and clippy all pass clean.
862 B
862 B
OQ-20: Salt/KDF and Encryption Key Derivation Method
- Origin: encryption.md
- Status: resolved
- Door type: One-way (key derivation method), two-way (salt field usage)
- Priority: high
- Resolution: The vault uses SLIP-0010 HD derivation from the BIP39 seed at path
m/74'/2'/0'/0'to produce the AES-256-GCM encryption key — not PBKDF2. Thesaltfield inEncryptedDatais unused for key derivation (kept for wire-format compatibility with the TS predecessor). The TypeScript@alkdev/storagecrypto module used PBKDF2 with a password + salt; data encrypted by that method (key_version=1) cannot be decrypted by the vault and must be migrated via one-time re-encryption to key_version=2. See ADR-020 for the full rationale and migration path. - Cross-references: ADR-020, encryption.md