A client-side profile defining end-to-end encrypted Collections over
Wallet Attached Storage (WAS): the encryption descriptor with its
key-epoch roster, carried from the collection's creation; the Encrypted
Data Vault envelope format with its AEAD-bound was integrity
binding; epoch-configuration authentication; recipient management by
escrow and rotate-first removal; the blinded index for equality
queries over encrypted content; the deferred-minting rules for
local-first writers; and the resource log profile, the hash-linked,
externally authorized log form under which descriptors and key
rosters are co-managed by a wallet's clients. The storage server needs nothing beyond WAS and
never holds key material.
This is an experimental specification and is undergoing regular revisions.