Active
Desktop
2024 - PresentLead Architect & DeveloperCN Vault
A secure, local-first desktop password manager and credential vault.
Executive Overview
CN Vault addresses the growing vulnerabilities and distrust associated with centralized cloud password managers. By adopting a local-first architectural paradigm, credentials are encrypted and decrypted strictly inside the client's memory on the host operating system, ensuring zero exposure over networks.
The Problem & Motivation
Cloud-hosted credential vaults present high-value targets for catastrophic breaches. When third-party providers experience downtime or security compromises, users face total lockouts or leaked secrets. Furthermore, existing local password solutions often suffer from archaic interfaces or clunky sync mechanisms.
Architecture & System Design
Designed as an offline-first desktop application utilizing Kotlin and modern desktop runtime environments. The storage engine operates over an encrypted local database file protected by authenticated encryption.
Architectural PipelineMaster Password + Salt -> Argon2id Key Derivation -> AES-256-GCM Cipher -> Encrypted Local Storage -> Zero Network Footprint
Argon2id Key Derivation: Derives cryptographic encryption keys from the user's master password with high memory hardness parameters to resist GPU/ASIC brute-force attacks.
AES-256-GCM Authenticated Encryption: Guarantees both confidentiality and ciphertext integrity for every stored vault record.
Volatile Memory Sanitization: Ensures decrypted credential strings are overwritten in memory as byte arrays immediately after use rather than persisting in garbage-collected pools.
Auto-Clearing System Clipboard: Automatically sanitizes the OS clipboard within 30 seconds of credential copying to prevent background clipboard scrapers from intercepting secrets.
Security & Cryptographic Model
Strict zero-knowledge security guarantees. No master passwords or decryption keys are ever persisted to disk in plaintext.
• Cryptographic Salt: Cryptographically secure random 32-byte salt generated per database instance.
• Authenticated Ciphertext: Every record includes a 128-bit authentication tag to immediately detect tampering or bit-flipping.
• Inactivity Auto-Lock: Configurable session timers enforce database lock and purge ephemeral keys upon user inactivity.
• Zero Telemetry: No network tracking, crash telemetry, or external pings exist in the codebase.
Technical Challenges & Solutions
1Challenge: Preventing sensitive password strings from lingering in JVM/OS memory allocations.
Engineered Solution: Employed direct byte-array manipulation with explicit Arrays.fill(0) overwrites instead of immutable standard string objects wherever passwords are handled.
2Challenge: Delivering instant sub-10ms search across hundreds of encrypted records without compromising metadata privacy.
Engineered Solution: Built an in-memory encrypted cache loaded during vault unlocking, enabling instantaneous fuzzy search while maintaining zero plaintext persistence on disk.
Key Outcomes & Impact
- Engineered an uncompromised local security architecture with zero reliance on cloud infrastructure.
- Achieved sub-50ms vault unlocking and instantaneous record search on consumer hardware.
- Created an intuitive desktop workflow with password generation, breach-resistant master keys, and audit logs.
Technology Stack
Release Changelog
v1.0.02024-11-15
- • Core AES-256-GCM vault storage engine
- • Argon2id key derivation integration
- • Automated clipboard sanitizer and session timer
v1.1.02025-02-10
- • Secure password generator with entropy indicator
- • CSV vault backup and encrypted JSON export
- • Enhanced keyboard shortcuts for fast credential lookup