{"_id":"@aithos/data-crypto","_rev":"2-f3d6801cc522b6ed4970dda331815471","name":"@aithos/data-crypto","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@aithos/data-crypto","version":"0.1.0","keywords":["aithos","data","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption"],"author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"license":"Apache-2.0","_id":"@aithos/data-crypto@0.1.0","maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"dist":{"shasum":"821bd498e6eeabfc3438923cf6ed4b81bcbe2a40","tarball":"https://registry.npmjs.org/@aithos/data-crypto/-/data-crypto-0.1.0.tgz","fileCount":15,"integrity":"sha512-ApHpY5H3GBgHq+/esJkT9AsrraKCsLc7V3ja/zQytoCEVP62iBGpRZaCNK2odG2CleVKtleCFk+FnoxiQMsEGQ==","signatures":[{"sig":"MEUCIA6NPIU3PpWIrDhr4DeoK3gj0nfFsKJ6hEn52HZoQ8j2AiEApglN9GXnQj0al8OAlKMc/ddilHHrNA3+Gvt8R5aGDvY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58624},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./cmk":{"types":"./dist/cmk.d.ts","import":"./dist/cmk.js"},"./dek":{"types":"./dist/dek.d.ts","import":"./dist/dek.js"},"./types":{"types":"./dist/types.d.ts","import":"./dist/types.js"},"./record":{"types":"./dist/record.d.ts","import":"./dist/record.js"},"./collection":{"types":"./dist/collection.d.ts","import":"./dist/collection.js"}},"gitHead":"561ab80c64515d2ad9a04fa41944d235657c19b9","scripts":{"test":"node --import tsx --test --test-reporter=spec \"test/**/*.test.ts\"","bench":"node --import tsx test/bench.ts","build":"tsc -p tsconfig.json","clean":"rm -rf dist","check-types":"tsc --noEmit"},"_npmUser":{"name":"aithos","email":"mathieu@aithos.be"},"repository":{"url":"git+https://github.com/aithos-protocol/aithos-protocol.git","type":"git","directory":"packages/data-crypto"},"_npmVersion":"10.9.2","description":"Reference cryptographic primitives for the Aithos data sub-protocol (PDS): CMK, DEK, wraps, record encryption. See spec/data/.","directories":{},"_nodeVersion":"23.9.0","dependencies":{"ulid":"^2.3.0","@scure/base":"^1.1.6","@noble/curves":"^2.2.0","@noble/hashes":"^1.4.0","@stablelib/hkdf":"^2.0.1","@stablelib/sha256":"^2.0.1","@stablelib/xchacha20poly1305":"^2.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.11.0","typescript":"^5.5.0","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/data-crypto_0.1.0_1779692060455_0.6855969388663743","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@aithos/data-crypto","version":"0.1.1","description":"Reference cryptographic primitives for the Aithos data sub-protocol (PDS): CMK, DEK, wraps, record encryption. See spec/data/.","license":"Apache-2.0","author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","repository":{"type":"git","url":"git+https://github.com/aithos-protocol/aithos-protocol.git","directory":"packages/data-crypto"},"keywords":["aithos","data","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./cmk":{"types":"./dist/cmk.d.ts","import":"./dist/cmk.js"},"./dek":{"types":"./dist/dek.d.ts","import":"./dist/dek.js"},"./record":{"types":"./dist/record.d.ts","import":"./dist/record.js"},"./collection":{"types":"./dist/collection.d.ts","import":"./dist/collection.js"},"./types":{"types":"./dist/types.d.ts","import":"./dist/types.js"}},"scripts":{"build":"tsc -p tsconfig.json","check-types":"tsc --noEmit","clean":"rm -rf dist","test":"node --import tsx --test --test-reporter=spec \"test/**/*.test.ts\"","bench":"node --import tsx test/bench.ts"},"dependencies":{"@noble/curves":"^2.2.0","@noble/hashes":"^1.4.0","@stablelib/xchacha20poly1305":"^2.0.1","@stablelib/hkdf":"^2.0.1","@stablelib/sha256":"^2.0.1","@scure/base":"^1.1.6","ulid":"^2.3.0"},"devDependencies":{"@types/node":"^20.11.0","tsx":"^4.11.0","typescript":"^5.5.0"},"engines":{"node":">=20"},"_id":"@aithos/data-crypto@0.1.1","gitHead":"55c966d2a6e34ed6cee4ff5259cb385d9a7d4cc1","bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"_nodeVersion":"23.9.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-f75m/sCm4O6J5sWucLLms/VAPhgCRl6HEc6G5Lzjsgk9Rxq9aJvS763JebiOJDWXC4/9O0ApJXGbgRhMtsPc3w==","shasum":"a9715731d0e6341f9eabcf4486a237945dc6d4cf","tarball":"https://registry.npmjs.org/@aithos/data-crypto/-/data-crypto-0.1.1.tgz","fileCount":17,"unpackedSize":60494,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD18WFdlhR2WATgzSTDUCES9JKE1pciM9rQTrXR85mQXAIhAI4KMGpELsS1SMoCgW8VPrjwm09lKRLkeh1OLwH3yghj"}]},"_npmUser":{"name":"aithos","email":"mathieu@aithos.be"},"directories":{},"maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/data-crypto_0.1.1_1779694506668_0.21277033546199076"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T06:54:20.309Z","modified":"2026-05-25T07:35:06.936Z","0.1.0":"2026-05-25T06:54:20.581Z","0.1.1":"2026-05-25T07:35:06.832Z"},"bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"license":"Apache-2.0","homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","keywords":["aithos","data","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption"],"repository":{"type":"git","url":"git+https://github.com/aithos-protocol/aithos-protocol.git","directory":"packages/data-crypto"},"description":"Reference cryptographic primitives for the Aithos data sub-protocol (PDS): CMK, DEK, wraps, record encryption. See spec/data/.","maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"readme":"# @aithos/data-crypto\n\nReference cryptographic primitives for the Aithos **data sub-protocol** —\nthe PDS layer that complements the Ethos protocol for operational records\n(see [`spec/data/`](../../spec/data/00-overview.md)).\n\n> **Status:** Jalon 2 POC. Standalone primitives, no network or storage.\n> Validates the construction described in\n> [`spec/data/02-key-hierarchy.md`](../../spec/data/02-key-hierarchy.md) end to end.\n\n## What this package provides\n\n| Module | Exports |\n|---|---|\n| `@aithos/data-crypto/cmk` | `generateCMK`, `wrapCMKForRecipient`, `unwrapCMK` |\n| `@aithos/data-crypto/dek` | `generateDEK`, `wrapDEKForCMK`, `unwrapDEKFromCMK` |\n| `@aithos/data-crypto/record` | `encryptRecord`, `decryptRecord` |\n| `@aithos/data-crypto/collection` | `createCollection`, `authorizeApp`, `revokeApp`, `rotateCMK` |\n| `@aithos/data-crypto/types` | Shared types: `CMKEnvelope`, `WrapEntry`, `RecordPayload`, etc. |\n\nThe construction follows spec §2 exactly:\n\n```\nsphere key  ──wraps──→  CMK  ──wraps──→  DEK  ──encrypts──→  payload\n```\n\nEach `wrap` is X25519-HKDF-SHA256-AEAD; payload AEAD is XChaCha20-Poly1305\nwith AAD bindings to `(subject_did, collection_name, record_id)`.\n\n## Quick start\n\n```ts\nimport { generateX25519Keypair } from '@aithos/data-crypto/types';\nimport { createCollection, authorizeApp } from '@aithos/data-crypto/collection';\nimport { encryptRecord, decryptRecord } from '@aithos/data-crypto/record';\n\n// Setup: owner key + app key\nconst owner = generateX25519Keypair();\nconst app = generateX25519Keypair();\nconst subjectDid = 'did:aithos:z6MkSubjectExample';\nconst collectionName = 'contacts';\n\n// Owner creates a collection\nconst collection = createCollection({\n  subjectDid,\n  collectionName,\n  ownerRecipientDidUrl: `${subjectDid}#data-kex`,\n  ownerPublicKey: owner.publicKey,\n});\n\n// Owner authorizes an app\nconst updated = authorizeApp({\n  collection,\n  recipientDidUrl: 'did:key:z6Mk…app#kex',\n  recipientPublicKey: app.publicKey,\n  unwrapperPrivateKey: owner.privateKey,\n  unwrapperRecipientDidUrl: `${subjectDid}#data-kex`,\n});\n\n// Owner inserts a record\nconst encrypted = encryptRecord({\n  subjectDid,\n  collectionName,\n  recordId: 'record_01J9TEST',\n  payload: { notes: 'Important prospect' },\n  cmk: /* unwrapped from updated using owner.privateKey */,\n});\n\n// App decrypts the record\nconst payload = decryptRecord({\n  subjectDid,\n  collectionName,\n  recordId: 'record_01J9TEST',\n  encrypted,\n  cmk: /* unwrapped from updated using app.privateKey */,\n});\n\nconsole.log(payload); // { notes: 'Important prospect' }\n```\n\n## Tests\n\n```bash\nnpm install\nnpm test\n```\n\nTests cover:\n\n- CMK roundtrip (wrap + unwrap)\n- DEK roundtrip under a CMK\n- Full record encrypt/decrypt\n- Owner → authorize app → app reads (O(1) authorization)\n- Revoke app, with and without CMK rotation\n- AAD binding enforcement (cross-collection, cross-record replay rejected)\n- CMK rotation (re-wrap all DEKs under new CMK)\n\n## Benchmark\n\n```bash\nnpm run bench\n```\n\nReports microbenchmarks of:\n\n- CMK generation + wrap for owner\n- DEK generation + wrap under CMK\n- Record encryption (10 KB payload)\n- Record decryption\n- Authorize new app\n- Rotate CMK with N records\n\n## Notes on scope\n\nThis POC is **standalone** — no network, no storage, no scheduler.\nIt validates the cryptographic construction. The backend (Jalon 3)\nwill wrap these primitives in RPC handlers. The SDK (Jalon 4) will\nexpose ergonomic client APIs.\n\nWhat is NOT in this POC:\n- Schema validation (Jalon 5)\n- Mandate verification (reused from `@aithos/protocol-core`)\n- Persistence (Jalon 3)\n- Gamma chain integration (Jalon 6 / threaded later)\n\n## License\n\nApache-2.0 © Mathieu Colla\n","readmeFilename":"README.md"}