Team vault (P13)
A team shares passwords and keys. Every secret is encrypted in the browser, and the server keeps only ciphertext. A member who is removed opens nothing written after.
Keys
A member has an X25519 key pair to receive team keys and an Ed25519 key pair to sign. Each device has its own pair of each. Every request a device makes is signed with its Ed25519 key, and the server checks the signature.
The team key is a random AES-256 key. It is wrapped for each member with X25519, HKDF and AES-GCM. Each secret is encrypted with the team key in the browser, and its name is inside the ciphertext.
The signed log
Every change to the team is an entry in a log. An entry names the hash of the entry before it and is signed with Ed25519. An admin signs when a member is added or removed. A member signs when they add a device, remove one, replace their keys or make a new team key.
The server and every device check each entry with the same rules. A forged entry, a changed entry or an entry out of order is refused.
Inviting a person
An admin makes an invite code of 16 characters and gives it to the person outside the app. The person's device sends its public keys with a MAC made from the code, so the server cannot change them. Both screens then show 20 digits made from the code and the keys. The admin approves only when the person reads the same digits.
Removing a member
The admin's device makes a new team key and wraps it for every member who stays. It encrypts every secret again with the new key and sends everything in one request. The server accepts the request only when every secret comes with it, and then deletes the old ciphertext and the old wrapped keys.
The removed member keeps what they already read. Their old keys open none of the secrets on the server, and the server refuses their requests. In the checks, the old key was tried on every secret on the server and opened none.
Linking a device
The member's device shows a code of 9 digits. The new device types it, and the two devices agree on a key with X25519 over the server. Both show 15 digits made from that key. The member confirms on the first device, and only then are the member's keys sent, encrypted with the agreed key.
The recovery code
The recovery code is 12 words from the BIP39 list: 128 random bits and a 4-bit checksum. The words give a seed with PBKDF2-SHA512, as BIP39 describes. The seed gives two values with HKDF: the address of the backup on the server and the key that opens it. The backup holds the member's keys.
On a new device, the words open the backup, and the device joins the log with an entry the member signs. The member then chooses the lost devices. They are removed, the member's keys are replaced, and the team gets a new key. The member's other devices receive the new keys, each wrapped for its own device key.
The threat model
The server page of the prototype lists what each party can and cannot do: the server, a removed member, someone with a stolen device, someone with an invite code and someone with the 12 words.
Previous: CRM on the device (P12). Next: Editor for two (P14).