Skip to content
LogoLogo

The envelope

envelope = { epk_eph, ct_user, ct_fi }
plaintext = shared leaves ‖ payload leaves ‖ sender_private_root ‖ attestation preimage

ct_user is encrypted to the recipient's pk_d (Sapling-style ECDH with an ephemeral key). ct_fi is encrypted to the recipient FI's epk. Both carry the same plaintext. The attestation preimage is included so the recipient FI can check attestation_in.is(kind) (§5.6) without an out-of-band channel. The sender FI receives the plaintext directly from the sender; it is never on chain for the sender FI.

Non-custodial recipients work: the recipient decrypts ct_user, and their FI decrypts ct_fi. Neither needs the other.