nivek3/enclave

β˜… 0Forks 0RustGitHub β†—Compare

README

Enclave - Secure Key Management Service

A secure key management service built with Rust, featuring a dual-mode architecture that supports both local development and production deployment with AWS Nitro Enclaves.

Overview

Enclave is a cryptographic key management solution that provides secure key generation, digital signatures, and verification operations. It supports two deployment modes:

  • Local Mode: For development and testing with local storage
  • Enclave Mode: For production with AWS Nitro Enclaves and KMS encryption

Features

  • πŸ” Multi-Algorithm Support: Ed25519 and Secp256k1 cryptographic algorithms
  • πŸ—οΈ Dual Architecture: Local development and production Enclave modes
  • πŸ›‘οΈ Hardware Security: AWS Nitro Enclaves for production deployment
  • πŸ”‘ KMS Integration: AWS KMS for encryption/decryption in Enclave mode
  • 🌐 JSON-RPC API: HTTP API following JSON-RPC 2.0 standard
  • πŸ“¦ Docker Support: Containerized deployment with Docker Compose
  • πŸ”§ Flexible Storage: Multiple storage backends (File, Database)
  • πŸš€ High Performance: Async/await architecture with Tokio

Architecture

Local Development Mode

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    Local Service                   β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚  HTTP JSON-RPC Server (Port 8080)            β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”‚  β”‚  Key Manager    β”‚    β”‚  Storage        β”‚  β”‚  β”‚
β”‚  β”‚  β”‚  - Generate     β”‚    β”‚  - File System  β”‚  β”‚  β”‚
β”‚  β”‚  β”‚  - Sign/Verify  β”‚    β”‚  - Database     β”‚  β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Production Enclave Mode

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚           Client Service (Parent Instance)            β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚  HTTP JSON-RPC Server (Port 8080)               β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”‚  β”‚  Request Router β”‚    β”‚  Response Handler  β”‚  β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”‚  β”‚  Vsock Client (Port 5005)                 β”‚  β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 β”‚
                                 β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                AWS Nitro Enclave                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚  Vsock Server (Port 5005)                       β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”‚  β”‚
β”‚  β”‚  β”‚  KMS Integrationβ”‚    β”‚  Key Manager    β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  - kmstool genkeyβ”‚   β”‚  - Generate     β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  - kmstool decryptβ”‚  β”‚  - Sign/Verify  β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  - AWS KMS      β”‚    β”‚  - AES Encrypt  β”‚     β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”‚  β”‚  Secure Key Storage (Hardware Isolated)   β”‚  β”‚  β”‚
β”‚  β”‚  β”‚  - Encrypted Private Keys                 β”‚  β”‚  β”‚
β”‚  β”‚  β”‚  - KMS Ciphertext Blobs                   β”‚  β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Key Generation Workflow

Inside Enclave
β”œβ”€ 1. Receive key generation request
β”œβ”€ 2. kmstool genkey (generate AES data key)
β”‚   β”œβ”€ Call AWS KMS GenerateDataKey
β”‚   β”œβ”€ Get (ciphertext, plaintext)
β”‚   └─ plaintext is AES key
β”œβ”€ 3. Generate original key pair
β”œβ”€ 4. Encrypt private key with AES key
β”œβ”€ 5. Store encrypted private key + KMS ciphertext
└─ 6. Return KeyPair (with encrypted private key)

Signing Workflow

Inside Enclave
β”œβ”€ 1. Receive signing request
β”œβ”€ 2. kmstool decrypt (decrypt KMS ciphertext)
β”‚   β”œβ”€ Call AWS KMS Decrypt
β”‚   └─ Get AES key
β”œβ”€ 3. Decrypt private key with AES key
β”œβ”€ 4. Sign with original private key
└─ 5. Return signature

Quick Start

Prerequisites

  • Rust 1.90+
  • Docker (optional)
  • AWS CLI (for Enclave mode)

Installation

# Clone the repository
git clone https://github.com/iamnivekx/enclave.git
cd enclave

# Build the project
cargo build --release

Local Development

# Start local server
cargo run --bin enclave-node -- server --port 5005

# Start local client
cargo run --bin enclave-node -- client --port 5005 --http-port 8080

Production Deployment

Prerequisites for Enclave Mode

Before starting the enclave application, you need to set up the vsock-proxy for KMS communication:

Option 1: Using systemd services (Recommended)

# Start the nitro-enclaves-allocator service
sudo systemctl start nitro-enclaves-allocator.service

# Enable and start the vsock-proxy service
sudo systemctl enable --now nitro-enclaves-vsock-proxy.service

Option 2: Manual vsock-proxy setup

# Start vsock-proxy manually (replace with your AWS region)
vsock-proxy 8000 kms.ap-east-1.amazonaws.com 443 &

The vsock-proxy forwards requests from port 8000 on the parent instance to the KMS endpoint (kms.ap-east-1.amazonaws.com:443). Make sure to use the correct AWS region for your deployment.

Starting the Services

# Start Enclave server
cargo run --bin enclave-node -- server --region us-east-1 --key-id your-kms-key-id --port 5005

# Start Client service
cargo run --bin enclave-node -- client --cid 16 --port 5005 --http-port 8080

Docker Deployment

build the kmstool-enclave-cli image as base image

git clone https://github.com/aws/aws-nitro-enclaves-sdk-c.git
cd aws-nitro-enclaves-sdk-c
./bin/kmstool-enclave-cli
./build.sh

docker image ls
# Build images
docker build -t enclave-client -f Dockerfile.client .
docker build -t enclave-server -f Dockerfile.server .

# Run with Docker Compose
docker-compose up -d

API Usage

JSON-RPC Interface

The service provides a JSON-RPC 2.0 compatible API:

Generate Key Pair

curl -X POST http://localhost:8080 \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "generate_key",
    "params": {"algo": "Ed25519"},
    "id": 1
  }'

Sign Message

# Note: message needs to be Base64 encoded
curl -X POST http://localhost:8080 \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "sign",
    "params": {
      "algo": "ed25519",
      "privkey": "dGVzdC1wcml2YXRlLWtleS1kYXRh", // Base64 encoded private key
      "message": "SGVsbG8gV29ybGQ=" // Base64 encoded "Hello World"
    },
    "id": 2
  }'

Response Example:

{
  "jsonrpc": "2.0",
  "result": {
    "algo": "ed25519",
    "pubkey": "dGVzdC1wdWJsaWMta2V5LWRhdGE=",
    "signature": "dGVzdC1zaWduYXR1cmUtZGF0YQ=="
  },
  "id": 2
}

Verify Signature

# Verify signature using public key
curl -X POST http://localhost:8080 \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "verify",
    "params": {
      "algo": "ed25519",
      "pubkey": "dGVzdC1wdWJsaWMta2V5LWRhdGE=", // Base64 encoded public key
      "message": "SGVsbG8gV29ybGQ=", // Base64 encoded "Hello World"
      "signature": "dGVzdC1zaWduYXR1cmUtZGF0YQ==" // Base64 encoded signature
    },
    "id": 3
  }'

Response Example:

{
  "jsonrpc": "2.0",
  "result": true,
  "id": 3
}

Health Check

curl -X POST http://localhost:8080 \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "system.health",
    "params": [],
    "id": 4
  }'

Configuration

Environment Variables

Variable Description Default Required
ENCLAVE_CID Enclave CID for vsock communication 1 No
ENCLAVE_HOST Enclave host address 127.0.0.1 No
ENCLAVE_PORT Enclave port 5005 Yes
SERVICE_PORT HTTP service port 8080 No
SERVICE_KEY_STORE_PATH Key storage path ./keys No
ENCLAVE_REGION AWS region for KMS - Yes (Enclave mode)
ENCLAVE_KEY_ID KMS key ID - Yes (Enclave mode)

Storage Backends

File Storage (Default)

[storage]
backend = "file"
path = "./keys"

Database Storage

[storage]
backend = "database"
url = "postgresql://user:password@localhost/enclave"
table_name = "key_pairs"

Project Structure

enclave/
β”œβ”€β”€ Cargo.toml                 # Workspace configuration
β”œβ”€β”€ Dockerfile.client          # Client Docker image
β”œβ”€β”€ Dockerfile.server          # Server Docker image
β”œβ”€β”€ docker-compose.yml         # Docker Compose configuration
β”œβ”€β”€ crates/
β”‚   β”œβ”€β”€ enclave-node/          # Main service binary
β”‚   β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”‚   β”œβ”€β”€ main.rs        # Entry point
β”‚   β”‚   β”‚   β”œβ”€β”€ commands/      # CLI commands
β”‚   β”‚   β”‚   β”œβ”€β”€ nitro/         # Enclave communication
β”‚   β”‚   β”‚   β”œβ”€β”€ server.rs      # RPC server
β”‚   β”‚   β”‚   └── storage.rs     # Storage wrapper
β”‚   β”‚   └── Cargo.toml
β”‚   β”œβ”€β”€ enclave-types/         # Core types and traits
β”‚   β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”‚   β”œβ”€β”€ key.rs         # Key types and traits
β”‚   β”‚   β”‚   β”œβ”€β”€ health.rs      # Health types
β”‚   β”‚   β”‚   β”œβ”€β”€ algo.rs        # Algorithm enum
β”‚   β”‚   β”‚   └── error.rs       # Error types
β”‚   β”‚   └── Cargo.toml
β”‚   β”œβ”€β”€ enclave-storage/       # Storage abstraction
β”‚   β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”‚   β”œβ”€β”€ backends/      # Storage implementations
β”‚   β”‚   β”‚   β”œβ”€β”€ config.rs      # Storage configuration
β”‚   β”‚   β”‚   └── manager.rs     # Storage manager
β”‚   β”‚   └── Cargo.toml
β”‚   β”œβ”€β”€ enclave-keyring/       # Cryptographic keyring
β”‚   β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”‚   β”œβ”€β”€ keyring/       # Algorithm implementations
β”‚   β”‚   β”‚   └── registry.rs    # Keyring registry
β”‚   β”‚   └── Cargo.toml
β”‚   └── rpc/                   # RPC components
β”‚       β”œβ”€β”€ rpc-api/           # RPC API definitions
β”‚       β”œβ”€β”€ rpc/               # RPC implementations
β”‚       └── rpc-client/        # RPC client
└── keys/                      # Local key storage

Development

Building

# Build all crates
cargo build

# Build specific crate
cargo build -p enclave-node

# Build with features
cargo build --features kms

Testing

# Run all tests
cargo test

# Run specific tests
cargo test -p enclave-types

# Run with logging
RUST_LOG=debug cargo test

Linting

# Run clippy
cargo clippy

# Run clippy with all targets
cargo clippy --all-targets --all-features

Security

Enclave

  • Private keys encrypted by AWS KMS-generated AES keys
  • Hardware-level security isolation
  • All key operations performed inside Enclave
  • Private keys never leave the Enclave in plaintext
  • Double encryption: KMS encrypts data keys + AES encrypts private keys
  • Supports attestation verification

Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Make your changes
  4. Add tests
  5. Run cargo test and cargo clippy
  6. Submit a pull request

License

This project is licensed under the MIT OR Apache-2.0 dual license.

Support

References

$$

Contributors

nivek3

Issues