Delivery and recovery
Encryption is a Poseidon2 stream cipher over field elements, proven in K:
eph_sk ← random; eph_pk = eph_sk·G
shared = ECDH(eph_sk, stakeholder.epk).x
ct[i] = pt[i] + H(ENC, shared, i)
One hash per plaintext field, so proving correct encryption for eight
envelopes of a few dozen fields each is cheap. The recipient derives
shared from eph_pk and esk. Because encryption is inside the proof,
every stakeholder is guaranteed to be able to open what was created for
them, and unattended delivery is sound. There is no review-before-signing
step. RFC-020's "responsible signers decrypt and call review" becomes
unnecessary; wallets still display the manifest.
Recovery, kept from RFC-020:
- Inputs are marked consumed on finality even if outputs are unavailable; consumed inputs are never revived.
- An output is spendable only after finalized creation plus verified decryption; otherwise it stays in pending recovery.
- A recovery journal consumes finalized outputs and all nullifiers and persists cursor, openings, statements, and backups. Archives serve ciphertext and inclusion proofs; clients verify them.
- Key restoration cannot recover lost openings. Nullifiers are never pruned while records they guard may still be claimed.
Transport is calldata in v1. A blob target requires a proof that ciphertext equals blob contents and is deferred.