BlockchainCommons / BlockchainCommons/Community

PROJECT: Collaborative Seed Recovery (CSR)

Ouverte
#149 15 commentaires 3 réactions 0 personnes assignées Voir sur GitHub
program: gordian
Langage dominant
Aucune donnée de langage
Étoiles
68
Forks
7
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Collaborative Seed Recovery, or CSR, is a new system intended to automate the recovery of seeds and other sensitive digital data in a way that is safe, secure, and simple to use. It is not a methodology to prevent compromise, but simply to add resilience to recovery in the case of failure or loss.

CSR allows for the recovery of seeds and other secrets by dividing responsibility for recovery up between multiple devices, some (but not all) of which will be necessary for recovery. Its baseline recovery mechanism uses self-sovereign recovery, while more advanced scenarios allow for social recovery. Backup is meant to be largely automated, especially in the baseline scenario, while recovery may require some user intervention.

CSR is built using _SSKR_ to lock _crypto-envelopes_ of data and to allow recovery using a variety of _authentication_ methods.

Please see the [CSR Overview](https://hackmd.io/D1caESQTRFi0FRtW1kNwMg) for more information.

**TODO: Documentation & Prep**

- [x] Decide Who Will Be Involved at Each Principal Company
- [ ] Share Individual Goals
- [x] Decide Shamir or VSS
- [x] Write Use Cases
- [ ] Write Cryptographic Design
- [ ] Write System Requirements
- [ ] Spec Out Automated `crypto-envelope` with multiple types of SSKR Permits (2 of 3 + 4 of 9) + metadata
- [ ] Spec out related `crypto-requests`
- [ ] Update any necessary papers, test vectors, etc
- [ ] Create Reference App for Sending SSKRs
- [ ] Write White Paper
- https://github.com/BlockchainCommons/Gordian/blob/master/Docs/CSR.md
- [x] Clearly define: CSR does not defend the use of your keys, it simply makes recovery easy and minimizes SPOFs in recovery.
- [x] Lay out how it works
- [ ] Describe why Proxy, Bitmark, and other parties would support it.
- [ ] Build a roadmap for a fall release.
- [ ] Preview how this will lead to CKM in 2023.

**TODO: Specification Work**

- [ ] Design Hash Inclusion Proof for Envelope

**TODO: Level 0**

- [ ] Design Level 0 of CSR
- [ ] User makes no decisions
- [ ] One Share is stored in iCloud
- [ ] Information on location of other shares is stored in iCloud
- [ ] Other shares are stored on remote sites in an automated way
- [ ] User must do no auth to recover, other than verify their iCloud login
- [ ] Develop Level 0 of CSR

**TODO: Level 1**

- [ ] Design Level 1 of CSR
- [ ] User makes one choice for a share to be given to someone
- [ ] Option: offline
- [ ] Option: given to a friend running an app
- [ ] Option: given to an online service
- [ ] At least two shares for automated recovery are deleted
- [ ] Auth is required for new share management
- [ ] Develop Level 1 of CSR

**TODO: Post-Release**
- [ ] Write test cases
- [ ] Choose a branding name
- [ ] Decide if there is a seal for this

This is expected to be a joint project of Blockchain Commons, Bitmark, and Proxy with a planned start date around July 5th.

**Essential Links: CSR**

* [CSR Overview](https://hackmd.io/D1caESQTRFi0FRtW1kNwMg)
* [CSR & CKM Use Cases](https://hackmd.io/ZbRiwvUfQSy-1RKM15bM8Q)
* [CSR Intro for RWOT](https://github.com/WebOfTrustInfo/rwot11-the-hague/blob/master/advance-readings/collaborative-seed-recovery-csr.md)
* [CSR Intro Poster for RWOT](https://github.com/WebOfTrustInfo/rwot11-the-hague/blob/master/advance-readings/posters/collaborative-seed-recovery-csr-poster.pdf)

**Essential Links: SSKR**

* [SSKR for Developers](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/sskr-developers.md)
* [SSKR Test Vector](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/sskr-test-vector.md)
* [Developing SSKR Share Scenarios](https://github.com/BlockchainCommons/SmartCustody/blob/master/Docs/SSKR-Sharing.md)
* [The Dangers of Secret-Sharing Schemes](https://github.com/BlockchainCommons/SmartCustody/blob/master/Docs/SSKR-Dangers.md)

**Essential Links: URs**

* [Uniform Resources (UR)](https://github.com/BlockchainCommons/Research/blob/master/papers/bcr-2020-005-ur.md)
* [UR Type Definition for Sharded Secret Key Reconstruction (SSKR)](https://github.com/BlockchainCommons/Research/blob/master/papers/bcr-2020-011-sskr.md)
* [URs: An Overview](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/ur-1-overview.md)
* [A Guide to Using URs for SSKR](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/ur-3-sskrs.md)
* [A Guide to Using UR Request & Response](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/ur-99-request-response.md)
* [Crypto-Request Test Vectors](https://github.com/BlockchainCommons/crypto-commons/blob/master/Docs/crypto-request-test-vectors.md)

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par les documents liés CSR Overview et CSR & CKM Use Cases, puis lisez les documents SSKR, UR et crypto-request référencés. Cette issue contient plusieurs axes de travail non cochés concernant la conception, la spécification, l’implémentation et la documentation, plutôt qu’un seul point d’entrée ; le travail n’est terminé que lorsqu’un axe de travail précis est défini et que sa conception, ses exigences, ses tests ou son application de référence sont terminés.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
cryptography
Domaine
cryptography, documentation, security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
18/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.