#if OCTAGON
#import <Foundation/Foundation.h>
#import <SecurityFoundation/SFEncryptionOperation.h>
#import <SecurityFoundation/SFKey.h>
#import "keychain/ckks/CKKS.h"
#import "keychain/ckks/CKKSKeychainBackedKey.h"
#import "keychain/ckks/CKKSPeer.h"
NS_ASSUME_NONNULL_BEGIN
typedef NS_ENUM(NSUInteger, SecCKKSTLKShareVersion) {
SecCKKSTLKShareVersion0 = 0, };
#define SecCKKSTLKShareCurrentVersion SecCKKSTLKShareVersion0
@interface CKKSTLKShare : NSObject <NSCopying, NSSecureCoding>
@property SFEllipticCurve curve;
@property SecCKKSTLKShareVersion version;
@property NSString* tlkUUID;
@property NSString* receiverPeerID;
@property NSData* receiverPublicEncryptionKeySPKI;
@property NSString* senderPeerID;
@property NSInteger epoch;
@property NSInteger poisoned;
@property (nullable) NSData* wrappedTLK;
@property (nullable) NSData* signature;
@property CKRecordZoneID* zoneID;
- (instancetype)init NS_UNAVAILABLE;
- (instancetype)init:(CKKSKeychainBackedKey*)key
sender:(id<CKKSSelfPeer>)sender
receiver:(id<CKKSPeer>)receiver
curve:(SFEllipticCurve)curve
version:(SecCKKSTLKShareVersion)version
epoch:(NSInteger)epoch
poisoned:(NSInteger)poisoned
zoneID:(CKRecordZoneID*)zoneID;
- (instancetype)initForKey:(NSString*)tlkUUID
senderPeerID:(NSString*)senderPeerID
recieverPeerID:(NSString*)receiverPeerID
receiverEncPublicKeySPKI:(NSData* _Nullable)publicKeySPKI
curve:(SFEllipticCurve)curve
version:(SecCKKSTLKShareVersion)version
epoch:(NSInteger)epoch
poisoned:(NSInteger)poisoned
wrappedKey:(NSData*)wrappedKey
signature:(NSData*)signature
zoneID:(CKRecordZoneID*)zoneID;
- (CKKSKeychainBackedKey* _Nullable)recoverTLK:(id<CKKSSelfPeer>)recoverer
trustedPeers:(NSSet<id<CKKSPeer>>*)peers
ckrecord:(CKRecord* _Nullable)ckrecord
error:(NSError* __autoreleasing*)error;
+ (CKKSTLKShare* _Nullable)share:(CKKSKeychainBackedKey*)key
as:(id<CKKSSelfPeer>)sender
to:(id<CKKSPeer>)receiver
epoch:(NSInteger)epoch
poisoned:(NSInteger)poisoned
error:(NSError**)error;
- (bool)signatureVerifiesWithPeerSet:(NSSet<id<CKKSPeer>>*)peerSet
ckrecord:(CKRecord* _Nullable)ckrecord
error:(NSError**)error;
- (CKKSKeychainBackedKey* _Nullable)unwrapUsing:(id<CKKSSelfPeer>)localPeer
error:(NSError**)error;
- (NSData* _Nullable)signRecord:(SFECKeyPair*)signingKey
ckrecord:(CKRecord* _Nullable)ckrecord
error:(NSError**)error;
- (bool)verifySignature:(NSData*)signature
verifyingPeer:(id<CKKSPeer>)peer
ckrecord:(CKRecord* _Nullable)ckrecord
error:(NSError**)error;
- (NSData*)dataForSigning:(CKRecord* _Nullable)record;
@end
NS_ASSUME_NONNULL_END
#endif // OCTAGON