Class: OpenLoam::Encryption::HkdfKeyProvider
- Inherits:
-
KeyProvider
- Object
- KeyProvider
- OpenLoam::Encryption::HkdfKeyProvider
- Defined in:
- lib/open_loam/encryption/key_provider.rb
Overview
Default provider: derive a per-scope, per-purpose key from one master key
with HKDF-SHA256. Deterministic, so no key needs to be stored, and one
scope's key can NEVER equal another's because the scope is bound into the
HKDF info. Purpose separation means the encryption key and the
blind-index (HMAC) key derived for one scope are independent.
Constant Summary collapse
- SALT =
A fixed, non-secret salt. HKDF's strength comes from the master key's entropy; the salt only has to be stable so derivation is reproducible.
"loam.encryption.hkdf.v1".freeze
- KEY_BYTES =
AES-256 and HMAC-SHA256 both take a 32-byte key
32
Instance Method Summary collapse
- #data_key(scope:, purpose:) ⇒ Object
-
#previous_data_key(scope:, purpose:) ⇒ Object
The same derivation under the key being rotated away from, so decryption can fall back to it while open_loam:encryption:rotate rewrites rows under the new one.
Instance Method Details
#data_key(scope:, purpose:) ⇒ Object
28 29 30 |
# File 'lib/open_loam/encryption/key_provider.rb', line 28 def data_key(scope:, purpose:) derive(scope, purpose, OpenLoam::Encryption.master_key) end |
#previous_data_key(scope:, purpose:) ⇒ Object
The same derivation under the key being rotated away from, so decryption can fall back to it while open_loam:encryption:rotate rewrites rows under the new one. nil when no previous key is configured.
35 36 37 38 39 40 |
# File 'lib/open_loam/encryption/key_provider.rb', line 35 def previous_data_key(scope:, purpose:) previous = OpenLoam::Encryption.previous_master_key return nil if previous.nil? derive(scope, purpose, previous) end |