-
Notifications
You must be signed in to change notification settings - Fork 0
Architecture
Yura Filatov edited this page Jun 27, 2026
·
1 revision
Occulta/
├── Services/
│ ├── Crypto+Manager.swift # AES-GCM encrypt/decrypt (local + transport)
│ ├── Key+Manager.swift # Secure Enclave ops, ECDH, HKDF, hybrid derivation
│ ├── Exchange+Manager.swift # MC + NI + ML-KEM exchange orchestration
│ └── Contact+Manager.swift # SwiftData CRUD, bundle encrypt/decrypt dispatch
│
├── Features/
│ ├── PostQuantum/
│ │ ├── PQProvider.swift # ML-KEM-1024 operations (iOS 26+, SE-backed)
│ │ └── QuantumKeyMaterial.swift # Codable struct for ML-KEM artifacts
│ │
│ ├── Forward+Secrecy/
│ │ ├── OccultaBundle.swift # Wire format: version, SecrecyContext, SealedPayload
│ │ ├── PrekeyManager.swift # SE prekey lifecycle: generate, retrieve, consume, delete
│ │ └── ForwardSecrecy.swift # Per-contact FS state (encrypted at rest)
│ │
│ └── SecureMode/
│ ├── Manager+Security.swift # PIN state machine, verifier ops, 11-step key rotation
│ ├── PIN+Manager.swift # AES-GCM verifier construction and checking (pure crypto)
│ ├── SecureMode+LayerStore.swift # 32-slot fixed-size layer store; push/pop/maintain
│ └── AppLayerConfig+Model.swift # SwiftData model; verifier arrays; forensic padding
│
├── Models/
│ ├── Contact+Model.swift # SwiftData schema (Profile, Key, PhoneNumber, …)
│ ├── Identity.swift # Local device identity record
│ └── Transfers.swift # Basket, File, OwnedBasket
│
├── Protocols/
│ └── KeyManagerProtocol.swift # Abstraction for testing (TestKeyManager)
│
└── UI/
└── ...
Dependencies: All cryptographic operations use Apple-native frameworks only — CryptoKit, Security.framework, NearbyInteraction, and MultipeerConnectivity. No external package manager (no CocoaPods, SPM, or Carthage).