mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-02 17:31:39 +00:00
* feat: Add Enclave Usage Examples * feat(es/ucan): Add comprehensive integration tests - Create integration.test.ts with full UCAN token lifecycle testing - Cover end-to-end token creation, parsing, and validation - Test capability attenuation and delegation chains - Validate multi-algorithm support and timestamp scenarios - Implement error recovery and performance test scenarios 🤖 Generated with Claude Code Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * No commit suggestions generated * chore: Remove migrated components and add migration documentation Removed all code and references for components that have been moved to separate repositories: **Moved to sonr-io/hway:** - bridge/ - HTTP service with OAuth2/OIDC/WebAuthn handlers - cmd/hway/ - Highway service binary - internal/migrations/ - PostgreSQL schema migrations **Moved to sonr-io/motr:** - cmd/motr/ - Motor worker service (WASM vault operations) - cmd/vault/ - Vault CLI tool - crypto/ - Comprehensive cryptographic library - packages/ - TypeScript SDK packages (es, sdk, ui, com, pkl) - web/auth/ - Authentication web application - web/dash/ - Dashboard web application **Updated Configuration:** - Makefile: Removed build/test/release targets for moved components - CLAUDE.md: Simplified to focus on core blockchain components - devbox.json: Removed scripts for moved services - docker-compose.yml: Removed hway, postgres, redis, auth, dash services - .github/scopes.yml: Removed CI scopes for migrated components - .goreleaser.yml: Updated release configuration **Added Migration Documentation:** - MIGRATE_HWAY.md: Comprehensive Highway service architecture and migration guide - MIGRATE_MOTR.md: Comprehensive Motor/Worker/Vault architecture and migration guide These migration documents provide complete context for setting up the new repositories including architecture diagrams, component breakdowns, API documentation, and migration checklists. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * chore: Remove contracts references and documentation Removed all references to the contracts directory that was migrated to a separate repository. **Changes:** - .gitignore: Removed contract-specific ignore patterns for DAO and wSNR contracts - .gitignore: Removed hway and motr binary references (already migrated) - .rgignore: Removed contracts, chains, and crypto directory references - docs/reference/contracts/: Removed DAO.mdx and wSNR.mdx documentation files This completes the cleanup of migrated components from the repository. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * docs: add crypto library migration documentation Added comprehensive migration documentation for the crypto library that was moved to sonr-io/crypto repository. This documentation provides complete context for understanding the cryptographic primitives and protocols used throughout the Sonr ecosystem. ## Key Documentation Added ### MIGRATE_CRYPTO.md Complete documentation of the crypto library covering: **Core Cryptographic Primitives** - Elliptic curve implementations (Ed25519, Secp256k1, P-256, BLS12-381, Pallas/Vesta) - Native curve arithmetic with optimized field operations - Pairing-friendly curves for BLS signatures **Multi-Party Computation (MPC)** - MPC enclave for vault key generation and management - Threshold cryptography (TECDSA, TED25519 with FROST protocol) - Distributed Key Generation (DKG) via Gennaro and FROST protocols - Secret sharing schemes (Shamir, Feldman VSS, Pedersen VSS) **Digital Signature Schemes** - BLS signatures with aggregation support - BBS+ signatures for selective disclosure - Schnorr signatures (standard and Mina/NEM variants) - ECDSA with deterministic nonce generation **Zero-Knowledge Proofs** - Bulletproofs for range proofs - Inner Product Arguments (IPA) - Batch verification support **Advanced Cryptographic Protocols** - Cryptographic accumulators for set membership proofs - Paillier homomorphic encryption - Oblivious Transfer (OT) protocols - Verifiable Random Functions (VRF) **Key Management & Identity** - DID key management with multi-chain support - Multi-algorithm public key handling - Wallet address derivation (Bitcoin, Ethereum, Cosmos, Solana, etc.) **UCAN Integration** - User-Controlled Authorization Networks - Capability delegation and attenuation - JWT-based capability tokens - MPC-enabled UCAN signing **Security Utilities** - AEAD encryption (AES-GCM, AES-SIV) - Argon2 key derivation - ECIES encryption - Secure memory handling ### MIGRATE_MOTR.md Updates Updated Motor migration documentation to clarify that the crypto library is now a separate external dependency at github.com/sonr-io/crypto v1.0.1 ## Repository Context The crypto library has been successfully migrated to its own repository and is published as a Go module. It serves as the foundational cryptographic layer for: - Sonr blockchain (snrd) - DID signatures, vault operations - Highway service (hway) - UCAN token signing, WebAuthn - Motor/Worker (motr) - MPC vault operations, threshold signatures ## Integration Impact All Sonr ecosystem components now depend on the external crypto library: ```go require github.com/sonr-io/crypto v1.0.1 ``` The migration enables independent versioning and maintenance of cryptographic primitives while maintaining security and compatibility across the ecosystem. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * No commit suggestions generated * No commit suggestions generated --------- Co-authored-by: Claude <noreply@anthropic.com>
168 lines
4.6 KiB
Go
168 lines
4.6 KiB
Go
package keeper
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
|
|
"github.com/sonr-io/crypto/argon2"
|
|
"github.com/sonr-io/crypto/mpc"
|
|
"github.com/sonr-io/crypto/password"
|
|
didtypes "github.com/sonr-io/sonr/x/did/types"
|
|
)
|
|
|
|
// CreateVaultForDIDSecure creates a vault with user-provided password
|
|
func (k Keeper) CreateVaultForDIDSecure(
|
|
ctx context.Context,
|
|
did string,
|
|
owner string,
|
|
vaultID string,
|
|
keyID string,
|
|
userPassword []byte,
|
|
enclaveData *mpc.EnclaveData,
|
|
) (*didtypes.CreateVaultResponse, error) {
|
|
// Validate password strength
|
|
validator := password.NewValidator(password.DefaultPasswordConfig())
|
|
if err := validator.Validate(userPassword); err != nil {
|
|
return nil, fmt.Errorf("password validation failed: %w", err)
|
|
}
|
|
|
|
// Create Argon2id KDF with default secure parameters
|
|
kdf := argon2.New(argon2.DefaultConfig())
|
|
|
|
// Generate secure salt
|
|
salt, err := kdf.GenerateSalt()
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to generate salt: %w", err)
|
|
}
|
|
|
|
// Derive encryption key using Argon2id
|
|
derivedKey := kdf.DeriveKey(userPassword, salt)
|
|
|
|
// Clear password from memory
|
|
defer password.ZeroBytes(userPassword)
|
|
|
|
// Encrypt enclave data with derived key
|
|
encryptedData, err := k.encryptEnclaveData(enclaveData, derivedKey)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to encrypt vault data: %w", err)
|
|
}
|
|
|
|
// Store vault with encrypted data and salt
|
|
vaultState, err := k.storeSecureVault(ctx, vaultID, owner, encryptedData, salt)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to store secure vault: %w", err)
|
|
}
|
|
|
|
return &didtypes.CreateVaultResponse{
|
|
VaultID: vaultState.VaultId,
|
|
}, nil
|
|
}
|
|
|
|
// UnlockVault unlocks a vault using the user's password
|
|
func (k Keeper) UnlockVault(
|
|
ctx context.Context,
|
|
vaultID string,
|
|
userPassword []byte,
|
|
) (*mpc.EnclaveData, error) {
|
|
// Retrieve vault state with salt
|
|
vaultState, err := k.getVaultState(ctx, vaultID)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to retrieve vault: %w", err)
|
|
}
|
|
|
|
if len(vaultState.Salt) == 0 {
|
|
return nil, fmt.Errorf("vault salt not found")
|
|
}
|
|
|
|
// Create KDF with same config as creation
|
|
kdf := argon2.New(argon2.DefaultConfig())
|
|
|
|
// Derive key using stored salt
|
|
derivedKey := kdf.DeriveKey(userPassword, vaultState.Salt)
|
|
|
|
// Clear password from memory
|
|
defer password.ZeroBytes(userPassword)
|
|
|
|
// Decrypt enclave data
|
|
enclaveData, err := k.decryptEnclaveData(vaultState.EncryptedData, derivedKey)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to decrypt vault: invalid password")
|
|
}
|
|
|
|
return enclaveData, nil
|
|
}
|
|
|
|
// encryptEnclaveData encrypts enclave data with AES-GCM
|
|
func (k Keeper) encryptEnclaveData(data *mpc.EnclaveData, key []byte) ([]byte, error) {
|
|
// Implementation would use AES-GCM for authenticated encryption
|
|
// This is a placeholder - actual implementation needs crypto/cipher
|
|
|
|
// For now, return a placeholder
|
|
// In production, this would:
|
|
// 1. Serialize enclave data to JSON
|
|
// 2. Create AES-GCM cipher with key
|
|
// 3. Generate nonce
|
|
// 4. Encrypt and authenticate data
|
|
// 5. Return nonce + ciphertext
|
|
|
|
return []byte("encrypted_placeholder"), nil
|
|
}
|
|
|
|
// decryptEnclaveData decrypts enclave data
|
|
func (k Keeper) decryptEnclaveData(encryptedData []byte, key []byte) (*mpc.EnclaveData, error) {
|
|
// Implementation would use AES-GCM for authenticated decryption
|
|
// This is a placeholder - actual implementation needs crypto/cipher
|
|
|
|
// For now, return a placeholder
|
|
// In production, this would:
|
|
// 1. Extract nonce from encrypted data
|
|
// 2. Create AES-GCM cipher with key
|
|
// 3. Decrypt and verify authentication
|
|
// 4. Deserialize JSON to enclave data
|
|
// 5. Return decrypted enclave data
|
|
|
|
return &mpc.EnclaveData{}, nil
|
|
}
|
|
|
|
// storeSecureVault stores encrypted vault data with salt
|
|
func (k Keeper) storeSecureVault(
|
|
ctx context.Context,
|
|
vaultID string,
|
|
owner string,
|
|
encryptedData []byte,
|
|
salt []byte,
|
|
) (*VaultStateWithSalt, error) {
|
|
// This would store the vault state with salt in the database
|
|
// For now, return a placeholder
|
|
|
|
vaultState := &VaultStateWithSalt{
|
|
VaultId: vaultID,
|
|
Owner: owner,
|
|
EncryptedData: encryptedData,
|
|
Salt: salt,
|
|
}
|
|
|
|
// In production: k.OrmDB.VaultStateTable().Insert(ctx, vaultState)
|
|
|
|
return vaultState, nil
|
|
}
|
|
|
|
// getVaultState retrieves vault state with salt
|
|
func (k Keeper) getVaultState(ctx context.Context, vaultID string) (*VaultStateWithSalt, error) {
|
|
// This would retrieve the vault state from the database
|
|
// For now, return a placeholder
|
|
|
|
return &VaultStateWithSalt{
|
|
VaultId: vaultID,
|
|
Salt: []byte("placeholder_salt"),
|
|
}, nil
|
|
}
|
|
|
|
// VaultStateWithSalt extends vault state with salt storage
|
|
type VaultStateWithSalt struct {
|
|
VaultId string
|
|
Owner string
|
|
EncryptedData []byte
|
|
Salt []byte
|
|
}
|