RKE Services Overview (Group 15)
RKE: Alows a client computer and a content server to exchange AES 256 encryption keys by sending key parts through the raida. Expand-Only HKDF, 32-byte shares, dual keys (K_rke / K_sess), and CS IdP redeem.
Overview
Group 15 is the live RKE surface. Normative freeze: core/docs/rke-redesign-v2.md Appendix F.
- 01 preload_master_key — The content server (such as a QMail Server) uploads a master key to the RAIDA. Each record is
key_id(1–255, a vault family, not a RAIDA index) plus a 32-byte part for that RAIDA. - 03 get_share_and_ticket — Client goes to RAIDA to get a key part and a ticket. The client sends
key_id; the RAIDA does not assign a different one. - 04 redeem_identity_ticket — RAIDA verifies the ticket for the content server.
- 05
SESSION_OPEN— Content Server only (not raidax). Group 15 command 5, encryption type 9. Opens a session underK_rke; every later command on that session also uses type 9 with the 5-byte handle. Specified on Header Version 2 and infab.type9-wire-spec.md§4. Parallel HTTP envelope:POST /rke/v2/session/open.
Content-server wire: POST /rke/v2/session/open under K_rke, then POST /rke/v2/cmd under K_sess (stripe put/get, ECHO). Auth quorum ≥13/25 ticket redeems.
Scope boundary
Group 15 is the active RKE documentation set. Group 4 public-key-exchange pages remain dormant and intentionally stay out of the live navigation.
Universal preamble (48 bytes)
Modern RKE requests start their bodies with a 48-byte authenticated preamble. This structure identifies the coin being used for the operation and provides replay protection.