trackslash
VAULT-43 P2

Encryption 4: add the app lock key derivation (Argon2id)

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

Sub-issue 4 of the on-device encryption design (VAULT-26, docs/on-device-encryption.md).

The change:

  • Vendor the PHC reference Argon2id implementation (CC0) as a C target.
  • Add a VaultKeyDeriver.Signature.appLockV1.
  • Zero the working memory after each derivation.

Parameters: chosen on the device when the encrypted file is created, then fixed in its header.

  • Memory: 64 MiB, within the AutoFill extension's headroom.
  • Passes: calibrated to about 0.5 s, with a floor of 3.
  • The unlock deadline is set at the same time.
  • Add a calibration command to vault-keygen-speedtest.

Tests: RFC 9106 test vectors, and calibration bounds.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/630 (merged as af33bfdf).

This adds Argon2id key derivation from the vendored PHC reference implementation (CArgon2, single-threaded, built with -O3), exposed as Argon2idKeyDeriver in CryptoEngine and parameterized by the file header. AppLockKeyDerivationCalibrator in VaultKeygen calibrates on the device: 64 MiB, the fastest of three t = 3 runs, t clamped to 3–32 for about 0.5 s, plus the unlock deadline, all behind an injectable timer. Working memory is zeroed. It's tested against the RFC 9106 vectors and the reference known-answer tests, make calibrate-app-lock measures a device, and Argon2 is credited in the third-party libraries list.