Identity & security

x/encryption — Encryption

Public-key encryption so sensitive on-chain data is readable only by intended recipients.

Reference

What it does

The encryption module gives the chain a native envelope-encryption capability: data written into transactions can be sealed to specific recipients' public keys, so it transits the mempool, lives in blocks, and replicates to every node while remaining readable only where intended.

Its most important client is VEID — identity scopes are encrypted to validator recipients so the identity network can score them while the public ledger never exposes raw documents or biometrics. Key registration and fingerprinting let senders discover and pin recipient keys on-chain.

Why it exists: Public ledgers and personal data are structurally at odds: everything on-chain is replicated everywhere, forever. Making recipient-targeted encryption a first-class module resolves the tension — the chain carries ciphertext and its integrity guarantees, while plaintext exists only at authorized endpoints.

State

Primary objects

ConceptDefinition
Envelope encryptionSealing a payload with a symmetric key that is itself encrypted to each recipient's public key.
Key fingerprintA compact, verifiable digest of a registered public key used to pin recipients.

Messages

Messages & queries

Message and query surfaces are documented at implementation level in the module docs ↗ and the source ↗. The objects above are the state those messages create and transition.

Connections

Module interactions

Flows

Core flow

  1. Register — Recipients register keys. Public keys with verifiable fingerprints go on-chain — validators, dispute parties, enclave targets.
  2. Seal — Senders envelope-encrypt. A symmetric key seals the payload; the key itself is encrypted to each recipient's public key.
  3. Transit — Ciphertext rides the chain. Blocks carry ciphertext plus the chain's integrity and ordering guarantees — plaintext exists only at authorized endpoints.
  4. Open — Recipients decrypt. Validators open identity scopes for scoring; entitled parties open sealed dispute evidence.

Questions

Asked about x/encryption

What is envelope encryption?

Sealing a payload with a symmetric key that is itself encrypted to each recipient's public key — efficient for large payloads, precise about who may open them.

What is a key fingerprint?

A compact, verifiable digest of a registered public key, used to pin recipients so senders seal to exactly the key they intend.

Why not keep sensitive data off-chain entirely?

Because the protocol needs integrity and ordering guarantees for that data too. Sealed envelopes give both — the chain carries ciphertext and its guarantees, while plaintext exists only at authorized endpoints.

x/veid module

More questions → FAQ

Related

Related modules