v2.0.1 Protocol

The Synchronization Protocol

The ultimate cryptographic engine. Flawless multi-device data resolution without ever exposing a single byte of plaintext.

1. Secure Handshake

Devices establish a secure X3DH key agreement over TLS 1.3 before any vault data is initialized.

[TLS] X3DH Key Agreement
// Ephemeral keys exchanged

2. Key Wrapping

The Master Key is generated locally (CSPRNG) and immediately wrapped using a hardware enclave key.

[HW] SecEnclave Wrap MK
// Hardware isolation active

3. Local Decryption

The vault is decrypted into a strict, memory-safe SecureBuffer that zeroes itself out upon exit.

[MEM] SecureBuffer Init
// RAM wipe guaranteed

4. CRDT Diffing

Vector Clocks calculate the exact delta to avoid syncing redundant data across the network.

[DIFF] LWW Vector Merge
// Deltas isolated

5. Encryption

Changes are encrypted using XChaCha20-Poly1305. Metadata is padded to obscure payload sizes.

[ENC] XCHACHA20_ENCRYPT
// Obfuscated payload

6. Epoch Sync

The ciphertext is pushed to the Relay Server, which blindly accepts it without holding any keys.

[SYNC] POST /v1/relay
// Sync complete

Vector Clocks

Multi-device edits are resolved locally using cryptographic vector clocks (Epochs), preventing race conditions without ever needing server-side inspection or plaintext exposure. Each device maintains a strict, verifiable lineage of state changes.

Encrypted Sync

We never transmit the full vault. The engine encrypts changed records locally, syncs only what changed, and delivers them instantly over a realtime channel.

Stateless Relay

Our servers do not compute your data. They act strictly as blind relay nodes that store opaque ciphertexts with zero knowledge of their contents.

Verifiable Merkle Chains

Medodi protects against server-side tampering and rollback attacks by structuring sync logs as a continuous Merkle Hash Chain. Each operation is cryptographically signed using Ed25519.

Open Source Transparency

Verify the cryptography yourself. The sync engine is built in Rust for memory safety.

fn apply_remote_epoch(local: &VaultState, remote: &EncryptedEpoch) -> Result<()> {
  // 1. Verify remote signature
  if !crypto::verify_sig(&remote.payload, &remote.sig, &local.pub_key) {
    return Err(SyncError::InvalidSignature);
  }

  // 2. Decrypt payload in memory via Enclave
  let plaintext = crypto::xchacha20_poly1305_decrypt(&remote.payload, &local.mk)?;

  // 3. CRDT Merge using Vector Clocks
  let merged = crdt::merge(&local.data, &plaintext);
  local.update(merged);

  Ok(())
}