Skip to content

ssh keys as seed entropy for key derivation #2

Description

@hitchho

ssh keys today are used directly as signing/encryption keys. this works but limits what you can derive from them.

proposal: use the ssh key as entropy input to a domain-separated kdf, then derive purpose-specific keys from that root. the ssh key becomes a seed, not a leaf.

root = hkdf(ssh_private_key_bytes, "zcli-v1")
  ├── signing   = hkdf(root, "ed25519-signing")
  ├── license   = hkdf(root, "zpro-license")
  ├── ring-vrf  = hkdf(root, "bandersnatch-ring")
  ├── encryption = hkdf(root, "x25519-encryption")
  └── ...future purposes without touching the ssh key again

backwards compat: if the derived signing key doesn't match existing on-chain state, fall back to direct ssh key usage. new users get the kdf path by default.

why:

  • one ssh key -> unlimited purpose-specific keys
  • domain separation prevents cross-protocol attacks
  • ring vrf needs bandersnatch keys, not ed25519 - kdf handles this naturally
  • license identity needs a stable non-rotating key - another derivation path
  • no new secrets to manage. ssh-agent already protects the root.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions