A secure key management service built with Rust, featuring a dual-mode architecture that supports both local development and production deployment with AWS Nitro Enclaves.
Enclave is a cryptographic key management solution that provides secure key generation, digital signatures, and verification operations. It supports two deployment modes:
- Local Mode: For development and testing with local storage
- Enclave Mode: For production with AWS Nitro Enclaves and KMS encryption
- π Multi-Algorithm Support: Ed25519 and Secp256k1 cryptographic algorithms
- ποΈ Dual Architecture: Local development and production Enclave modes
- π‘οΈ Hardware Security: AWS Nitro Enclaves for production deployment
- π KMS Integration: AWS KMS for encryption/decryption in Enclave mode
- π JSON-RPC API: HTTP API following JSON-RPC 2.0 standard
- π¦ Docker Support: Containerized deployment with Docker Compose
- π§ Flexible Storage: Multiple storage backends (File, Database)
- π High Performance: Async/await architecture with Tokio
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Local Service β
β ββββββββββββββββββββββββββββββββββββββββββββββββ β
β β HTTP JSON-RPC Server (Port 8080) β β
β β βββββββββββββββββββ βββββββββββββββββββ β β
β β β Key Manager β β Storage β β β
β β β - Generate β β - File System β β β
β β β - Sign/Verify β β - Database β β β
β β βββββββββββββββββββ βββββββββββββββββββ β β
β ββββββββββββββββββββββββββββββββββββββββββββββββ β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Client Service (Parent Instance) β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β HTTP JSON-RPC Server (Port 8080) β β
β β βββββββββββββββββββ ββββββββββββββββββββββ β β
β β β Request Router β β Response Handler β β β
β β βββββββββββββββββββ ββββββββββββββββββββββ β β
β β βββββββββββββββββββββββββββββββββββββββββββββ β β
β β β Vsock Client (Port 5005) β β β
β β βββββββββββββββββββββββββββββββββββββββββββββ β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β AWS Nitro Enclave β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β Vsock Server (Port 5005) β β
β β βββββββββββββββββββ βββββββββββββββββββ β β
β β β KMS Integrationβ β Key Manager β β β
β β β - kmstool genkeyβ β - Generate β β β
β β β - kmstool decryptβ β - Sign/Verify β β β
β β β - AWS KMS β β - AES Encrypt β β β
β β βββββββββββββββββββ βββββββββββββββββββ β β
β β βββββββββββββββββββββββββββββββββββββββββββββ β β
β β β Secure Key Storage (Hardware Isolated) β β β
β β β - Encrypted Private Keys β β β
β β β - KMS Ciphertext Blobs β β β
β β βββββββββββββββββββββββββββββββββββββββββββββ β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Inside Enclave
ββ 1. Receive key generation request
ββ 2. kmstool genkey (generate AES data key)
β ββ Call AWS KMS GenerateDataKey
β ββ Get (ciphertext, plaintext)
β ββ plaintext is AES key
ββ 3. Generate original key pair
ββ 4. Encrypt private key with AES key
ββ 5. Store encrypted private key + KMS ciphertext
ββ 6. Return KeyPair (with encrypted private key)
Inside Enclave
ββ 1. Receive signing request
ββ 2. kmstool decrypt (decrypt KMS ciphertext)
β ββ Call AWS KMS Decrypt
β ββ Get AES key
ββ 3. Decrypt private key with AES key
ββ 4. Sign with original private key
ββ 5. Return signature
- Rust 1.90+
- Docker (optional)
- AWS CLI (for Enclave mode)
# Clone the repository
git clone https://github.com/iamnivekx/enclave.git
cd enclave
# Build the project
cargo build --release# Start local server
cargo run --bin enclave-node -- server --port 5005
# Start local client
cargo run --bin enclave-node -- client --port 5005 --http-port 8080Before starting the enclave application, you need to set up the vsock-proxy for KMS communication:
Option 1: Using systemd services (Recommended)
# Start the nitro-enclaves-allocator service
sudo systemctl start nitro-enclaves-allocator.service
# Enable and start the vsock-proxy service
sudo systemctl enable --now nitro-enclaves-vsock-proxy.serviceOption 2: Manual vsock-proxy setup
# Start vsock-proxy manually (replace with your AWS region)
vsock-proxy 8000 kms.ap-east-1.amazonaws.com 443 &The vsock-proxy forwards requests from port 8000 on the parent instance to the KMS endpoint (kms.ap-east-1.amazonaws.com:443). Make sure to use the correct AWS region for your deployment.
# Start Enclave server
cargo run --bin enclave-node -- server --region us-east-1 --key-id your-kms-key-id --port 5005
# Start Client service
cargo run --bin enclave-node -- client --cid 16 --port 5005 --http-port 8080build the kmstool-enclave-cli image as base image
git clone https://github.com/aws/aws-nitro-enclaves-sdk-c.git
cd aws-nitro-enclaves-sdk-c
./bin/kmstool-enclave-cli
./build.sh
docker image ls# Build images
docker build -t enclave-client -f Dockerfile.client .
docker build -t enclave-server -f Dockerfile.server .
# Run with Docker Compose
docker-compose up -dThe service provides a JSON-RPC 2.0 compatible API:
curl -X POST http://localhost:8080 \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "generate_key",
"params": {"algo": "Ed25519"},
"id": 1
}'# Note: message needs to be Base64 encoded
curl -X POST http://localhost:8080 \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "sign",
"params": {
"algo": "ed25519",
"privkey": "dGVzdC1wcml2YXRlLWtleS1kYXRh", // Base64 encoded private key
"message": "SGVsbG8gV29ybGQ=" // Base64 encoded "Hello World"
},
"id": 2
}'Response Example:
{
"jsonrpc": "2.0",
"result": {
"algo": "ed25519",
"pubkey": "dGVzdC1wdWJsaWMta2V5LWRhdGE=",
"signature": "dGVzdC1zaWduYXR1cmUtZGF0YQ=="
},
"id": 2
}# Verify signature using public key
curl -X POST http://localhost:8080 \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "verify",
"params": {
"algo": "ed25519",
"pubkey": "dGVzdC1wdWJsaWMta2V5LWRhdGE=", // Base64 encoded public key
"message": "SGVsbG8gV29ybGQ=", // Base64 encoded "Hello World"
"signature": "dGVzdC1zaWduYXR1cmUtZGF0YQ==" // Base64 encoded signature
},
"id": 3
}'Response Example:
{
"jsonrpc": "2.0",
"result": true,
"id": 3
}curl -X POST http://localhost:8080 \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "system.health",
"params": [],
"id": 4
}'| Variable | Description | Default | Required |
|---|---|---|---|
ENCLAVE_CID |
Enclave CID for vsock communication | 1 | No |
ENCLAVE_HOST |
Enclave host address | 127.0.0.1 | No |
ENCLAVE_PORT |
Enclave port | 5005 | Yes |
SERVICE_PORT |
HTTP service port | 8080 | No |
SERVICE_KEY_STORE_PATH |
Key storage path | ./keys | No |
ENCLAVE_REGION |
AWS region for KMS | - | Yes (Enclave mode) |
ENCLAVE_KEY_ID |
KMS key ID | - | Yes (Enclave mode) |
[storage]
backend = "file"
path = "./keys"[storage]
backend = "database"
url = "postgresql://user:password@localhost/enclave"
table_name = "key_pairs"enclave/
βββ Cargo.toml # Workspace configuration
βββ Dockerfile.client # Client Docker image
βββ Dockerfile.server # Server Docker image
βββ docker-compose.yml # Docker Compose configuration
βββ crates/
β βββ enclave-node/ # Main service binary
β β βββ src/
β β β βββ main.rs # Entry point
β β β βββ commands/ # CLI commands
β β β βββ nitro/ # Enclave communication
β β β βββ server.rs # RPC server
β β β βββ storage.rs # Storage wrapper
β β βββ Cargo.toml
β βββ enclave-types/ # Core types and traits
β β βββ src/
β β β βββ key.rs # Key types and traits
β β β βββ health.rs # Health types
β β β βββ algo.rs # Algorithm enum
β β β βββ error.rs # Error types
β β βββ Cargo.toml
β βββ enclave-storage/ # Storage abstraction
β β βββ src/
β β β βββ backends/ # Storage implementations
β β β βββ config.rs # Storage configuration
β β β βββ manager.rs # Storage manager
β β βββ Cargo.toml
β βββ enclave-keyring/ # Cryptographic keyring
β β βββ src/
β β β βββ keyring/ # Algorithm implementations
β β β βββ registry.rs # Keyring registry
β β βββ Cargo.toml
β βββ rpc/ # RPC components
β βββ rpc-api/ # RPC API definitions
β βββ rpc/ # RPC implementations
β βββ rpc-client/ # RPC client
βββ keys/ # Local key storage
# Build all crates
cargo build
# Build specific crate
cargo build -p enclave-node
# Build with features
cargo build --features kms# Run all tests
cargo test
# Run specific tests
cargo test -p enclave-types
# Run with logging
RUST_LOG=debug cargo test# Run clippy
cargo clippy
# Run clippy with all targets
cargo clippy --all-targets --all-features- Private keys encrypted by AWS KMS-generated AES keys
- Hardware-level security isolation
- All key operations performed inside Enclave
- Private keys never leave the Enclave in plaintext
- Double encryption: KMS encrypts data keys + AES encrypts private keys
- Supports attestation verification
- Fork the repository
- Create a feature branch
- Make your changes
- Add tests
- Run
cargo testandcargo clippy - Submit a pull request
This project is licensed under the MIT OR Apache-2.0 dual license.
- Issues: GitHub Issues
- Documentation: Project Wiki
$$