Prototypes StrongroomP13 · Team vault
The server

What the vault’s server holds

Every row the server keeps for the team vaults, read every 2 seconds. It holds the signed log, team keys wrapped for one member each, secrets as ciphertext, recovery backups encrypted with a key from 12 words, and open invites. None of it opens a secret.

What each party can and cannot do

WhoCanCannot
The server, or someone who controls itSee the team’s name, the members’ names and public keys, the devices, how many secrets there are, their sizes and when they changed. Refuse to answer, or keep an update back.Read a secret or its name. Add a member or a device, or swap a key: every device checks the signed log and refuses an entry that an admin or the member did not sign. Open a recovery backup, which is encrypted with a key from the 12 words.
A member who was removedKeep what they read or copied while they were a member, and the old team keys this device still holds.Open anything written after they were removed. The new team key was wrapped only for the members who stayed, and every secret was encrypted again with it, so the old keys open nothing on the server. The server also refuses every request from their devices.
Someone with a stolen deviceOpen the vault on it, as the member could, until the member acts.Open anything written after the member restores the vault on a new device with the 12 words and marks the stolen device as lost. That removes the device, replaces the member’s keys and gives the team a new key.
Someone with an invite codeAsk to join the team, once.Join without the admin’s approval. The admin approves only when the digits on both screens match.
Someone with the 12 wordsOpen the vault as the member, on any device.Be told apart from the member. The words are the member’s last key, so they belong on paper, away from the devices.

The signed log

EntryWhatSigned bySignature

Team keys, wrapped for one member each

KeyForWrapped key

Secrets

SecretKeyCiphertext

Recovery backups

Found atMemberSize
How Strongroom is built
  1. A member has two key pairs: X25519 to receive team keys and Ed25519 to sign. Each device has its own pair of each, and signs every request it makes.
  2. The team key is a random AES-256 key. It is wrapped for each member with an X25519 agreement, HKDF and AES-GCM, and every secret is encrypted with it in the browser.
  3. Every change to the team is an entry in a log, signed by an admin or by the member it concerns and linked to the entry before it by its hash. The server and every device check each entry.
  4. Removing a member makes a new team key for everyone who stays and encrypts every secret again with it, in one step that the server accepts only whole.
  5. A new device of the same member is linked with a code of 9 digits. Both devices agree on a key over the server and show the same digits, and the member’s keys go over only when the person confirms.
  6. The 12 words are a BIP39 recovery code. They give the address of an encrypted backup of the member’s keys and the key that opens it.