Skip to content

Architecture

Yura Filatov edited this page Jun 27, 2026 · 1 revision

Architecture

Occulta/
├── Services/
│   ├── Crypto+Manager.swift       # AES-GCM encrypt/decrypt (local + transport)
│   ├── Key+Manager.swift          # Secure Enclave ops, ECDH, HKDF, hybrid derivation
│   ├── Exchange+Manager.swift     # MC + NI + ML-KEM exchange orchestration
│   └── Contact+Manager.swift      # SwiftData CRUD, bundle encrypt/decrypt dispatch
│
├── Features/
│   ├── PostQuantum/
│   │   ├── PQProvider.swift       # ML-KEM-1024 operations (iOS 26+, SE-backed)
│   │   └── QuantumKeyMaterial.swift  # Codable struct for ML-KEM artifacts
│   │
│   ├── Forward+Secrecy/
│   │   ├── OccultaBundle.swift    # Wire format: version, SecrecyContext, SealedPayload
│   │   ├── PrekeyManager.swift    # SE prekey lifecycle: generate, retrieve, consume, delete
│   │   └── ForwardSecrecy.swift   # Per-contact FS state (encrypted at rest)
│   │
│   └── SecureMode/
│       ├── Manager+Security.swift       # PIN state machine, verifier ops, 11-step key rotation
│       ├── PIN+Manager.swift            # AES-GCM verifier construction and checking (pure crypto)
│       ├── SecureMode+LayerStore.swift  # 32-slot fixed-size layer store; push/pop/maintain
│       └── AppLayerConfig+Model.swift   # SwiftData model; verifier arrays; forensic padding
│
├── Models/
│   ├── Contact+Model.swift        # SwiftData schema (Profile, Key, PhoneNumber, …)
│   ├── Identity.swift             # Local device identity record
│   └── Transfers.swift            # Basket, File, OwnedBasket
│
├── Protocols/
│   └── KeyManagerProtocol.swift   # Abstraction for testing (TestKeyManager)
│
└── UI/
    └── ...

Dependencies: All cryptographic operations use Apple-native frameworks only — CryptoKit, Security.framework, NearbyInteraction, and MultipeerConnectivity. No external package manager (no CocoaPods, SPM, or Carthage).

Clone this wiki locally