# Nostr Cryptography - Deep Technical Reference

**Verzió:** 1.0  
**Mélység:** Cryptographic Implementation  
**Cél:** Production-ready cryptographic operations

---

## 1. Kriptográfiai Alapok

### 1.1 Nostr Crypto Stack

```
┌─────────────────────────────────────────────────────────────┐
│                    CRYPTOGRAPHIC LAYER                       │
├─────────────────────────────────────────────────────────────┤
│  ┌──────────────┐ ┌──────────────┐ ┌─────────────────────┐│
│  │   Schnorr    │ │   secp256k1  │ │   Key Management    ││
│  │   Signatures │ │   Elliptic   │ │   (BIP-32/39/44)  ││
│  │              │ │   Curve      │ │                      ││
│  └──────┬───────┘ └──────┬───────┘ └──────────┬──────────┘│
│         │                │                    │           │
│  ┌──────┴───────┐ ┌──────┴───────┐ ┌──────────┴──────────┐│
│  │   Signing    │ │   ECDH       │ │   Derivation        ││
│  │   (BIP-340)  │ │   (Key Agree)│ │   (HD Wallets)      ││
│  └──────────────┘ └──────────────┘ └─────────────────────┘│
├─────────────────────────────────────────────────────────────┤
│                    ENCRYPTION LAYER                          │
│  ┌──────────────┐ ┌──────────────┐ ┌─────────────────────┐│
│  │   NIP-04     │ │   NIP-44     │ │   NIP-59           ││
│  │   (AES-CBC)  │ │   (ChaCha20) │ │   (Gift Wrap)      ││
│  └──────────────┘ └──────────────┘ └─────────────────────┘│
└─────────────────────────────────────────────────────────────┘
```

### 1.2 Schnorr Signatures (BIP-340)

Nostr uses BIP-340 Schnorr signatures over secp256k1.

**Signature Formula:**
```
s = k + e*d mod n

Where:
- k = random nonce
- d = private key
- e = hash(R || P || m) [challenge]
- R = k*G (public nonce point)
- P = d*G (public key point)
- m = message (32-byte hash)
- n = curve order
```

---

## 2. Key Formats (Bech32 - NIP-19)

**Formats:**
- `nsec1...` - Private key (32 bytes, bech32)
- `npub1...` - Public key (32 bytes, bech32)
- `note1...` - Event ID
- `nprofile1...` - Profile + relay hints (TLV encoded)
- `nevent1...` - Event + metadata

**Encoding:**
1. 256-bit key -> 5-bit groups (52 groups)
2. Add BCH checksum
3. Encode using bech32 charset

---

## 3. Key Derivation (BIP-32/39/44 + NIP-06)

### 3.1 HD Wallet Path for Nostr

```
Master Seed (256 bits)
    │
    └─ m/1237'/0'/0/0 ─ First Nostr identity
    └─ m/1237'/0'/0/1 ─ Second identity
    
1237 = Nostr coin type (registered in SLIP-44)
```

**Mnemonic to Nostr Key:**
1. Generate mnemonic (12-24 words)
2. Seed = PBKDF2(mnemonic, passphrase, "mnemonic", 2048 iterations)
3. Extended key = BIP-32 master key from seed
4. Derive path: m/1237'/0'/{account}'/0/{index}
5. Result = secp256k1 secret key

---

## 4. Encryption Schemes

### 4.1 NIP-04 - Legacy (AES-CBC) ⚠️ DEPRECATED

**Flow:**
```
1. Shared secret = ECDH(sender_priv, recipient_pub)
2. Key = SHA256(shared_secret)
3. IV = random(16 bytes)
4. Ciphertext = AES-256-CBC(key, IV, plaintext)
5. Format: base64(ciphertext) + "?iv=" + base64(iv)
```

### 4.2 NIP-44 - Modern (ChaCha20-Poly1305) ✅ RECOMMENDED

**Flow:**
```
1. Shared secret = ECDH(sender_priv, recipient_pub)
2. Conversation key = HKDF(shared_secret, salt="nip44-v2")
3. Nonce = random(32 bytes for v2)
4. Ciphertext + MAC = ChaCha20-Poly1305(conv_key, nonce, plaintext)
5. Format: base64(version || nonce || ciphertext || mac)
```

### 4.3 NIP-59 - Gift Wrap (Sealed Sender)

**Anonymous messaging:**
```
1. Generate ephemeral keypair
2. Encrypt message to recipient (NIP-44)
3. Wrap in outer envelope (kind 1059)
4. Sign with ephemeral key
5. Recipient unwraps and decrypts inner message
```

---

## 5. NIP-46 - Remote Signing (nsecBunker)

**Architecture:**
```
Client (Browser) <-> Signer (Mobile/Hardware) <-> Optional Server
```

**Methods:**
- `connect(pubkey, secret)` - Authorize client
- `sign_event(event)` - Sign with user's key
- `get_public_key()` - Get user's npub
- `nip04_encrypt/decrypt()` - Encryption operations

**URI Format:**
```
bunker://<signer_pubkey>?relay=<wss://relay>&secret=<auth_secret>
```

---

## 6. NIP-49 - Encrypted Private Key Storage

**Password-protected nsec:**
```
1. Password + salt + PBKDF2(100k iterations) = key
2. IV = random(16)
3. Ciphertext = AES-256-CBC(key, IV, nsec_bytes)
4. Store: base64(salt || IV || ciphertext)
```

---

## 7. Security Best Practices

### Key Generation
- Use cryptographically secure RNG (OsRng)
- NEVER use time-based seeds or Math.random()

### Side-Channel Protection
- Constant-time comparison for signatures
- Use libraries with timing attack resistance

### Memory Safety
- Clear sensitive memory with zeroize
- Use secure enclaves where available

### Storage Tiers
1. **Hardware signer** (best) - Air-gapped signing
2. **Mobile signer** (Amber/diVine) - App isolated keys
3. **Browser extension** (Alby/nos2x) - Extension isolated
4. **Remote signer** (nsecBunker) - Network signing
5. **Password manager** - Encrypted backup

---

## 8. Implementation Checklist

- [ ] Schnorr signing (BIP-340) with proper nonce generation
- [ ] Bech32 encoding/decoding for all formats
- [ ] BIP-06 key derivation from mnemonic
- [ ] ECDH for shared secrets
- [ ] NIP-44 encryption (ChaCha20-Poly1305)
- [ ] NIP-59 gift wrap for sealed sender
- [ ] NIP-46 remote signing client/signer
- [ ] NIP-49 password encryption
- [ ] Side-channel resistant implementations
- [ ] Memory clearing for sensitive data

---

*Document Version: 1.0*  
*Cryptographic primitives: secp256k1, BIP-340, ChaCha20-Poly1305, HKDF, PBKDF2*