System Architecture &
Cryptography
PWDnow is a zero-knowledge, local-first password manager designed to operate at NIST Security Level 5 with full CNSA 2.0 readiness. Explore the complete mathematical and architectural foundations.
Core Architectural Invariants
Cryptographic Confinement
All key derivation, encryption, and decryption occur exclusively within the Rust daemon process. The web layer receives only opaque ciphertexts and session tokens.
Defense in Depth
Data is encrypted at three independent layers before reaching persistent storage: individual DEK, overarching VMK, and a SQLCipher envelope.
Post-Quantum Readiness
Utilizes a hybrid X448 + ML-KEM-1024 Key Encapsulation Mechanism and ML-DSA-87 signatures, maintaining both classical security and NIST Level 5 quantum resistance.
Cryptographic Primitives
| Primitive | Implementation | Purpose in PWDnow |
|---|---|---|
| AES-256-GCM | FIPS 197 / NIST SP 800-38D | Primary AEAD. Used for VMK, DEK, and Credential payload encryption. |
| Argon2id | v1.3 (m=1GiB, t=4, p=2) | Primary KDF. Key Encryption Key (KEK) derivation from master password. |
| ML-KEM-1024 | FIPS 203 (NIST Level 5) | Post-Quantum Key Encapsulation Mechanism (used in hybrid with X448). |
| ML-DSA-87 | FIPS 204 (NIST Level 5) | Post-Quantum Authenticator assertions and nightly audit log root signing. |
| HMAC-SHA-512 | FIPS 198-1 | Blind Indexes for searching encrypted fields securely without decryption. |
| XChaCha20-Poly1305 | RFC 8439 | Legacy secondary AEAD (24-byte nonces), supported for backward compatibility. |
Daemon Key Hierarchy
(64 bytes total material)
PROT_NONE Isolated
Standards Compliance Matrix
NIST SP 800-63B-4
AAL3Authentication and AAL3 memory-hard KDF. Satisfied by employing Argon2id with an intentional 1 GiB memory cost and execution tuning.
NSA CNSA 2.0
STRICTPost-Quantum compliance. Integrates ML-KEM-1024, ML-DSA-87, AES-256-GCM, and strictly enforces SHA-384 as required by the 2030 CNSA deadline.
NIST SP 800-88 Rev. 2
ERASEComplete media sanitization. Cryptographic erase implemented via zeroization of VMK key fields locally, rendering persistent data irrecoverable instantly.
FIDO2 / WebAuthn
LEVEL 3Hardware passkey support. Integrates standard FIDO2 functionality along with WebAuthn PRF extensions for Quick Unlock key wrapping and binding.