Kihagyás

Nostr Cryptography - Deep Technical Reference

Verzió: 1.0
Mélység: Cryptographic Implementation
Cél: Production-ready cryptographic operations


1. Kriptográfiai Alapok

1.1 Nostr Crypto Stack

┌─────────────────────────────────────────────────────────────┐
│                    CRYPTOGRAPHIC LAYER                       │
├─────────────────────────────────────────────────────────────┤
│  ┌──────────────┐ ┌──────────────┐ ┌─────────────────────┐│
│  │   Schnorr    │ │   secp256k1  │ │   Key Management    ││
│  │   Signatures │ │   Elliptic   │ │   (BIP-32/39/44)  ││
│  │              │ │   Curve      │ │                      ││
│  └──────┬───────┘ └──────┬───────┘ └──────────┬──────────┘│
│         │                │                    │           │
│  ┌──────┴───────┐ ┌──────┴───────┐ ┌──────────┴──────────┐│
│  │   Signing    │ │   ECDH       │ │   Derivation        ││
│  │   (BIP-340)  │ │   (Key Agree)│ │   (HD Wallets)      ││
│  └──────────────┘ └──────────────┘ └─────────────────────┘│
├─────────────────────────────────────────────────────────────┤
│                    ENCRYPTION LAYER                          │
│  ┌──────────────┐ ┌──────────────┐ ┌─────────────────────┐│
│  │   NIP-04     │ │   NIP-44     │ │   NIP-59           ││
│  │   (AES-CBC)  │ │   (ChaCha20) │ │   (Gift Wrap)      ││
│  └──────────────┘ └──────────────┘ └─────────────────────┘│
└─────────────────────────────────────────────────────────────┘

1.2 Schnorr Signatures (BIP-340)

Nostr uses BIP-340 Schnorr signatures over secp256k1.

Signature Formula:

s = k + e*d mod n

Where:
- k = random nonce
- d = private key
- e = hash(R || P || m) [challenge]
- R = k*G (public nonce point)
- P = d*G (public key point)
- m = message (32-byte hash)
- n = curve order


2. Key Formats (Bech32 - NIP-19)

Formats: - nsec1... - Private key (32 bytes, bech32) - npub1... - Public key (32 bytes, bech32) - note1... - Event ID - nprofile1... - Profile + relay hints (TLV encoded) - nevent1... - Event + metadata

Encoding: 1. 256-bit key -> 5-bit groups (52 groups) 2. Add BCH checksum 3. Encode using bech32 charset


3. Key Derivation (BIP-32/39/44 + NIP-06)

3.1 HD Wallet Path for Nostr

Master Seed (256 bits)
    │
    └─ m/1237'/0'/0/0 ─ First Nostr identity
    └─ m/1237'/0'/0/1 ─ Second identity

1237 = Nostr coin type (registered in SLIP-44)

Mnemonic to Nostr Key: 1. Generate mnemonic (12-24 words) 2. Seed = PBKDF2(mnemonic, passphrase, "mnemonic", 2048 iterations) 3. Extended key = BIP-32 master key from seed 4. Derive path: m/1237'/0'/{account}'/0/{index} 5. Result = secp256k1 secret key


4. Encryption Schemes

4.1 NIP-04 - Legacy (AES-CBC) ⚠️ DEPRECATED

Flow:

1. Shared secret = ECDH(sender_priv, recipient_pub)
2. Key = SHA256(shared_secret)
3. IV = random(16 bytes)
4. Ciphertext = AES-256-CBC(key, IV, plaintext)
5. Format: base64(ciphertext) + "?iv=" + base64(iv)

Flow:

1. Shared secret = ECDH(sender_priv, recipient_pub)
2. Conversation key = HKDF(shared_secret, salt="nip44-v2")
3. Nonce = random(32 bytes for v2)
4. Ciphertext + MAC = ChaCha20-Poly1305(conv_key, nonce, plaintext)
5. Format: base64(version || nonce || ciphertext || mac)

4.3 NIP-59 - Gift Wrap (Sealed Sender)

Anonymous messaging:

1. Generate ephemeral keypair
2. Encrypt message to recipient (NIP-44)
3. Wrap in outer envelope (kind 1059)
4. Sign with ephemeral key
5. Recipient unwraps and decrypts inner message


5. NIP-46 - Remote Signing (nsecBunker)

Architecture:

Client (Browser) <-> Signer (Mobile/Hardware) <-> Optional Server

Methods: - connect(pubkey, secret) - Authorize client - sign_event(event) - Sign with user's key - get_public_key() - Get user's npub - nip04_encrypt/decrypt() - Encryption operations

URI Format:

bunker://<signer_pubkey>?relay=<wss://relay>&secret=<auth_secret>


6. NIP-49 - Encrypted Private Key Storage

Password-protected nsec:

1. Password + salt + PBKDF2(100k iterations) = key
2. IV = random(16)
3. Ciphertext = AES-256-CBC(key, IV, nsec_bytes)
4. Store: base64(salt || IV || ciphertext)


7. Security Best Practices

Key Generation

  • Use cryptographically secure RNG (OsRng)
  • NEVER use time-based seeds or Math.random()

Side-Channel Protection

  • Constant-time comparison for signatures
  • Use libraries with timing attack resistance

Memory Safety

  • Clear sensitive memory with zeroize
  • Use secure enclaves where available

Storage Tiers

  1. Hardware signer (best) - Air-gapped signing
  2. Mobile signer (Amber/diVine) - App isolated keys
  3. Browser extension (Alby/nos2x) - Extension isolated
  4. Remote signer (nsecBunker) - Network signing
  5. Password manager - Encrypted backup

8. Implementation Checklist

  • [ ] Schnorr signing (BIP-340) with proper nonce generation
  • [ ] Bech32 encoding/decoding for all formats
  • [ ] BIP-06 key derivation from mnemonic
  • [ ] ECDH for shared secrets
  • [ ] NIP-44 encryption (ChaCha20-Poly1305)
  • [ ] NIP-59 gift wrap for sealed sender
  • [ ] NIP-46 remote signing client/signer
  • [ ] NIP-49 password encryption
  • [ ] Side-channel resistant implementations
  • [ ] Memory clearing for sensitive data

Document Version: 1.0
Cryptographic primitives: secp256k1, BIP-340, ChaCha20-Poly1305, HKDF, PBKDF2

Vissza a tetejére