Active
Desktop
2024 - PresentLead Architect & Developer

CN Vault

A secure, local-first desktop password manager and credential vault.

Executive Overview

CN Vault addresses the growing vulnerabilities and distrust associated with centralized cloud password managers. By adopting a local-first architectural paradigm, credentials are encrypted and decrypted strictly inside the client's memory on the host operating system, ensuring zero exposure over networks.

The Problem & Motivation

Cloud-hosted credential vaults present high-value targets for catastrophic breaches. When third-party providers experience downtime or security compromises, users face total lockouts or leaked secrets. Furthermore, existing local password solutions often suffer from archaic interfaces or clunky sync mechanisms.

Architecture & System Design

Designed as an offline-first desktop application utilizing Kotlin and modern desktop runtime environments. The storage engine operates over an encrypted local database file protected by authenticated encryption.

Architectural PipelineMaster Password + Salt -> Argon2id Key Derivation -> AES-256-GCM Cipher -> Encrypted Local Storage -> Zero Network Footprint
Argon2id Key Derivation: Derives cryptographic encryption keys from the user's master password with high memory hardness parameters to resist GPU/ASIC brute-force attacks.
AES-256-GCM Authenticated Encryption: Guarantees both confidentiality and ciphertext integrity for every stored vault record.
Volatile Memory Sanitization: Ensures decrypted credential strings are overwritten in memory as byte arrays immediately after use rather than persisting in garbage-collected pools.
Auto-Clearing System Clipboard: Automatically sanitizes the OS clipboard within 30 seconds of credential copying to prevent background clipboard scrapers from intercepting secrets.

Security & Cryptographic Model

Strict zero-knowledge security guarantees. No master passwords or decryption keys are ever persisted to disk in plaintext.

• Cryptographic Salt: Cryptographically secure random 32-byte salt generated per database instance.
• Authenticated Ciphertext: Every record includes a 128-bit authentication tag to immediately detect tampering or bit-flipping.
• Inactivity Auto-Lock: Configurable session timers enforce database lock and purge ephemeral keys upon user inactivity.
• Zero Telemetry: No network tracking, crash telemetry, or external pings exist in the codebase.

Technical Challenges & Solutions

1Challenge: Preventing sensitive password strings from lingering in JVM/OS memory allocations.

Engineered Solution: Employed direct byte-array manipulation with explicit Arrays.fill(0) overwrites instead of immutable standard string objects wherever passwords are handled.

2Challenge: Delivering instant sub-10ms search across hundreds of encrypted records without compromising metadata privacy.

Engineered Solution: Built an in-memory encrypted cache loaded during vault unlocking, enabling instantaneous fuzzy search while maintaining zero plaintext persistence on disk.

Key Outcomes & Impact

  • Engineered an uncompromised local security architecture with zero reliance on cloud infrastructure.
  • Achieved sub-50ms vault unlocking and instantaneous record search on consumer hardware.
  • Created an intuitive desktop workflow with password generation, breach-resistant master keys, and audit logs.

Technology Stack

Release Changelog

v1.0.02024-11-15
  • • Core AES-256-GCM vault storage engine
  • • Argon2id key derivation integration
  • • Automated clipboard sanitizer and session timer
v1.1.02025-02-10
  • • Secure password generator with entropy indicator
  • • CSV vault backup and encrypted JSON export
  • • Enhanced keyboard shortcuts for fast credential lookup

Related Engineering Notes