RKE Services Overview (Group 15)

RKE: Alows a client computer and a content server to exchange AES 256 encryption keys by sending key parts through the raida. Expand-Only HKDF, 32-byte shares, dual keys (K_rke / K_sess), and CS IdP redeem.

Overview

Group 15 is the live RKE surface. Normative freeze: core/docs/rke-redesign-v2.md Appendix F.

  • 01 preload_master_key — The content server (such as a QMail Server) uploads a master key to the RAIDA. Each record is key_id (1–255, a vault family, not a RAIDA index) plus a 32-byte part for that RAIDA.
  • 03 get_share_and_ticket — Client goes to RAIDA to get a key part and a ticket. The client sends key_id; the RAIDA does not assign a different one.
  • 04 redeem_identity_ticket — RAIDA verifies the ticket for the content server.
  • 05 SESSION_OPEN — Content Server only (not raidax). Group 15 command 5, encryption type 9. Opens a session under K_rke; every later command on that session also uses type 9 with the 5-byte handle. Specified on Header Version 2 and in fab.type9-wire-spec.md §4. Parallel HTTP envelope: POST /rke/v2/session/open.

Content-server wire: POST /rke/v2/session/open under K_rke, then POST /rke/v2/cmd under K_sess (stripe put/get, ECHO). Auth quorum ≥13/25 ticket redeems.

Scope boundary

Group 15 is the active RKE documentation set. Group 4 public-key-exchange pages remain dormant and intentionally stay out of the live navigation.

Universal preamble (48 bytes)

Modern RKE requests start their bodies with a 48-byte authenticated preamble. This structure identifies the coin being used for the operation and provides replay protection.

CH (Challenge - 16B) 0 Session ID (8B) 16 CT 24 DN 26 SN (4B) 27 DV 31 AN (Authenticity Number - 16B) 32