Skip to content
LogoLogo

Delivery and recovery

Encryption is a Poseidon2 stream cipher over field elements, proven in K:

eph_sk ← random; eph_pk = eph_sk·G
shared = ECDH(eph_sk, stakeholder.epk).x
ct[i]  = pt[i] + H(ENC, shared, i)

One hash per plaintext field, so proving correct encryption for eight envelopes of a few dozen fields each is cheap. The recipient derives shared from eph_pk and esk. Because encryption is inside the proof, every stakeholder is guaranteed to be able to open what was created for them, and unattended delivery is sound. There is no review-before-signing step. RFC-020's "responsible signers decrypt and call review" becomes unnecessary; wallets still display the manifest.

Recovery, kept from RFC-020:

  • Inputs are marked consumed on finality even if outputs are unavailable; consumed inputs are never revived.
  • An output is spendable only after finalized creation plus verified decryption; otherwise it stays in pending recovery.
  • A recovery journal consumes finalized outputs and all nullifiers and persists cursor, openings, statements, and backups. Archives serve ciphertext and inclusion proofs; clients verify them.
  • Key restoration cannot recover lost openings. Nullifiers are never pruned while records they guard may still be claimed.

Transport is calldata in v1. A blob target requires a proof that ciphertext equals blob contents and is deferred.