import { Signer } from './signer.ts'; import { Matter } from './matter.ts'; /** * Secret derivation security tier. */ export declare enum Tier { low = "low", med = "med", high = "high" } interface SalterArgs { raw?: Uint8Array | undefined; code?: string; tier?: Tier; qb64b?: Uint8Array | undefined; qb64?: string; qb2?: Uint8Array | undefined; } /** * Maintains a random salt for secrets (private keys). * Its .raw is random salt, .code as cipher suite for salt */ export declare class Salter extends Matter { private readonly _tier; /** * Creates a Salter from the provided raw salt bytes or generates a random salt if raw is not provided. * Defaults to low security tier. Only supports Salt_128 salt type. * @param salterArgs defines the kind of cryptographic seed to create with a variety of raw material initialization sources. */ constructor(salterArgs: SalterArgs); /** * Stretches the salt to a secret key using the path, .raw, tier, and size determined by self.code. * * @param size number of bytes of the stretched seed * @param path string of bytes prepended (prefixed) to the salt before stretching * @param tier security tier for stretching * @param temp boolean, True means use temporary, insecure tier; for testing only * @returns stretched raw binary seed (secret) derived from path and .raw, and size using argon2d stretching algorithm. * @private */ private stretch; /** * Returns Signer with the private key secret derived from code the path, the user entered passcode as a salt, * and the security tier sized by the CESR cryptographic seed size indicated by the code. See the example below. * The Signer's public key for its .verfer is derived from its private key, the Matter code, and the transferable boolean. * * The construction of the raw hash bytes used looks like this: * ( size, password, salt ) * where * ( code size, path, Base64Decode(passcode) ) * for example, for the initial inception signing key the following parameters are used: * ( 32, "signify:controller00", Base64Decode("Athisismysecretkeyseed") ) * and for the initial rotation key pair the following parameters are used: * ( 32, "signify:controller01", Base64Decode("Athisismysecretkeyseed") ) * * @param code derivation code indicating seed type * @param transferable whether or not the key is for a transferable or non-transferable identifier. * @param path string of bytes prepended (prefixed) to the salt before stretching * @param tier security tier for stretching * @param temp boolean, True means use temporary, insecure tier; for testing only */ signer(code?: string, transferable?: boolean, path?: string, tier?: Tier | null, temp?: boolean): Signer; get tier(): Tier | null; } export {};