Message for SKB distribution

A message type is to be defined for distributing SKB to the initial set of Readers, as well as for distributing a new decryption key SKB’ during bucket key rotation. The plain format of the message is expected to resemble the following structure, where latestKey contains a new key to be distributed while previousKeys can be used to disclose or reference keys that had been distributed earlier, such as in a key rotation:

This message is destined for multiple recipients and thus looks slightly different in its encrypted form (m’) compared to the encryption of the content message m. CEK, required for decrypting the JWE m’ is encrypted individually for each recipient's PKUser, in addition to the (new) bucket key SKB/SKB’:

Last updated