aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_NODE_PROTOCOL.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md14
1 files changed, 13 insertions, 1 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 9efef08..9e51dc9 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -1001,6 +1001,9 @@ D_req = "meshbay:device_req:v1" || LP(node_pk) || LP(user_id) || LP(pk_ed) ||
D_add = "meshbay:device_add:v1" || LP(node_pk) || LP(user_id) || LP(pk_ed) ||
LP(pk_x) || LP(nonce_s) || LP(ts) signed by a PINNED device
+D_rev = "meshbay:device_revoke:v1" || LP(node_pk) || LP(user_id) || LP(pk_ed) ||
+ LP(nonce_s) || LP(ts) signed by a PINNED device
+
code_hash = sha256( code "\x1f" pk_ed25519_b64 "\x1f" pk_x25519_b64 )
```
@@ -1009,6 +1012,11 @@ code_hash = sha256( code "\x1f" pk_ed25519_b64 "\x1f" pk_x25519_b64 )
* `D_add` deliberately **omits the code**: the code is a bearer secret used to find the
request, never signed, never echoed. What is signed is the key pair being admitted,
so a signature collected for one device cannot admit another.
+* `device_add` **must name a pending request** (`code_hash`) filed by the same
+ `pk_ed25519` and `pk_x25519`; without one, or with one filed by other keys, it is
+ refused and the request is not spent. A countersignature alone admits nothing.
+* `D_rev` has a prefix of its own. Were a retirement signed over `D_add`, a signature
+ given to retire a key would admit that key wherever it is not pinned yet.
* Because both keys go into `code_hash`, a node cannot answer the approver with a
substituted key: the approver recomputes the hash from what it typed and what it was
given. Nothing here rests on a human comparing digits.
@@ -1022,7 +1030,7 @@ code_hash = sha256( code "\x1f" pk_ed25519_b64 "\x1f" pk_x25519_b64 )
N -> C device_list_result {pending, devices: [{pk_ed25519, label, pinned_at,
pinned_via, added_by_pk, is_this_one}]}
- C -> N device_revoke {pk_ed25519, ts, sig over D_add for the victim's keys}
+ C -> N device_revoke {pk_ed25519, ts, sig over D_rev for the victim's key}
N -> C device_add_ack {revoked: pk_ed25519}
```
@@ -2361,6 +2369,10 @@ device add "meshbay:device_add:v1" LP(node_pk) LP(user_id) LP(pk_ed25519) LP
LP(nonce_s) LP(ts)
-> Ed25519 by an ALREADY-PINNED device of the same account
+device rev "meshbay:device_revoke:v1" LP(node_pk) LP(user_id) LP(pk_ed25519)
+ LP(nonce_s) LP(ts)
+ -> Ed25519 by an ALREADY-PINNED device of the same account
+
device hello "meshbay:device_hello:v1" LP(node_pk) LP(group_id) LP(user_id)
LP(pk_ed25519) LP(nonce_s) LP(ts)
-> Ed25519 by the device claiming this connection