remove chacha from enrollment

This commit is contained in:
2025-06-26 13:37:50 -05:00
parent 6777a19f5b
commit d22ec80ee7

View File

@@ -52,29 +52,18 @@ sequenceDiagram
rect rgb(191, 223, 255) rect rgb(191, 223, 255)
Server -->> Mobile Client: Store ChaCha20 256-bit key Server -->> Mobile Client: Store ChaCha20 256-bit key
end end
rect rgb(191, 223, 255) Server ->> Mobile Client: Keypad Index Array
Server ->> Server: Shuffled Keypad Index Array =<br/>ChaCha20FisherYates(Keypad Index Array, SharedKey, Nonce)
Server ->> Mobile Client: Shuffled Keypad Index Array + Nonce
end
Note right of Server: Server also sends the 96-bit nonce in plain-text.<br/>The Server must never use the same nonce twice.<br/>It must be randonly generated for every authentication.<br/>The only additional overhead is the 96-bit nonce.
rect rgb(191, 223, 255)
Mobile Client ->> Mobile Client: Keypad Index Array =<br/>Unshuffle(Shuffled Keypad Index Array, SharedKey, Nonce)
end end
Mobile Client ->> User: Render Keypad Mobile Client ->> User: Render Keypad
User ->> Server: Set nKode User ->> Server: Set nKode
Server ->> Server: Disperse Keypad Server ->> Server: Disperse Keypad
rect rgb(191, 223, 255) Server ->> Mobile Client: Keypad Index Array
Server ->> Server: Shuffled Keypad Index Array =<br/>ChaCha20FisherYates(Keypad Index Array, SharedKey, Nonce)
Server ->> Mobile Client: Shuffled Keypad Index Array + Nonce
end
rect rgb(191, 223, 255)
Mobile Client ->> Mobile Client: Keypad Index Array =<br/>Unshuffle(Shuffled Keypad Index Array, SharedKey, Nonce)
end
Mobile Client ->> User: Render Keypad Mobile Client ->> User: Render Keypad
User ->> Server: Confirm nKode User ->> Server: Confirm nKode
Note over User,Server: Login Note over User,Server: Login
rect rgb(191, 223, 255) rect rgb(191, 223, 255)
Server ->> Server: Shuffled Keypad Index Array =<br/>ChaCha20FisherYates(Keypad Index Array, SharedKey, Nonce) Server ->> Server: Shuffled Keypad Index Array =<br/>ChaCha20FisherYates(Keypad Index Array, SharedKey, Nonce)
Note right of Server: Server also sends the 96-bit nonce in plain-text.<br/>The Server must never use the same nonce twice.<br/>It must be randonly generated for every authentication.<br/>The only additional overhead is the 96-bit nonce.
Server ->> Mobile Client: Shuffled Keypad Index Array + Nonce Server ->> Mobile Client: Shuffled Keypad Index Array + Nonce
end end
rect rgb(191, 223, 255) rect rgb(191, 223, 255)