Add cloud E2E crypto primitives

Client-side half of the cloud backup/sync privacy model (cloud repo
docs/DESIGN.md): master key generation, BIP39 recovery phrase escrow
(Argon2id KEK), X25519 device keypairs with sealed-box MK wrapping, and
the VBX1 blob envelope — XChaCha20-Poly1305 under a per-blob content key
wrapped by MK, with AAD binding each blob to its (object, role, version)
slot so the server can't swap blobs undetected.

Pure functions over bytes, no I/O. Keychain persistence and the sync
engine come next. Deps: pynacl, mnemonic.
This commit is contained in:
Jamie Pine
2026-07-01 14:48:59 -07:00
parent 376afad852
commit 9a8425f401
3 changed files with 369 additions and 0 deletions
+4
View File
@@ -7,6 +7,10 @@ pydantic>=2.5.0
sqlalchemy>=2.0.0
alembic>=1.13.0
# Cloud backup/sync E2E encryption (services/cloud_crypto.py)
pynacl>=1.5.0
mnemonic>=0.21
# ML models
torch>=2.2.0
transformers>=4.36.0,<=4.57.6