Skip to content

docs(threat-model): add an AES-GCM / PSK key-lifecycle checklist #50

Description

@solomonneas

What

docs/threat-model.md describes the handshake and per-session HKDF derivation but has no consolidated key-lifecycle table: generation, permissions, rotation window, derived session-key lifetime, zeroization, recovery.

Why

SC-12 in NIST SP 800-53 Rev. 5 (doi:10.6028/NIST.SP.800-53r5) calls for defined controls across the full key lifecycle. A short checklist ties the existing 0600-mode, HKDF, and dual-key-rotation invariants together in one operator-facing place. Doc-only.

Effort

S

Source: three-lane research sweep (repo audit + comparables + literature), independently reviewed before filing; run 20260724-040709-e9fc6818.

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationsize/SSmall: under an hour

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions