Stores per-sender encryption keys across MLS epochs for DAVE E2EE.
Maintains a mapping of {ssrc, epoch} -> key and tracks the current
epoch's self-key and nonce counter.
Summary
Functions
Advances to a new epoch with the given self-key, resetting the nonce counter.
Retrieves the sender key for the given SSRC and epoch.
Creates a new empty key store.
Returns the next nonce and an updated store with incremented counter.
Removes keys from epochs older than the most recent keep epochs.
Stores a sender key for the given SSRC and epoch.
Types
@type t() :: %EDA.Voice.Dave.KeyStore{ current_epoch: non_neg_integer(), keys: %{required({non_neg_integer(), non_neg_integer()}) => binary()}, self_key: binary() | nil, self_nonce: non_neg_integer() }
Functions
@spec advance_epoch(t(), non_neg_integer(), binary()) :: t()
Advances to a new epoch with the given self-key, resetting the nonce counter.
@spec get_sender_key(t(), non_neg_integer(), non_neg_integer()) :: binary() | nil
Retrieves the sender key for the given SSRC and epoch.
@spec new() :: t()
Creates a new empty key store.
@spec next_nonce(t()) :: {non_neg_integer(), t()}
Returns the next nonce and an updated store with incremented counter.
@spec prune_old_epochs(t(), non_neg_integer()) :: t()
Removes keys from epochs older than the most recent keep epochs.
@spec put_sender_key(t(), non_neg_integer(), non_neg_integer(), binary()) :: t()
Stores a sender key for the given SSRC and epoch.