Jump to content

Rainstorm Access Control

From Calamity Wiki
Revision as of 16:26, 19 May 2026 by Vertex (talk | contribs)

Rainstorm Access Control (RAC) is a data protection and access control system based on a number of high-grade quantum encryption algorithms with increasing complexity. Its specification was originally developed by Küiser Laboratories as part of Project Rainstorm, Küiser's internal quantum cryptography R&D program. After Küiser's collapse, it was purchased by Metatron from the Helios Corporation, and standardised by Raven. As with other types of quantum encryption, RAC is regulated by Coalition treaties in which Raven is the licensing body.

Officially, the RAC algorithms are classified, and provided only on Raven-sanctioned cryptographic modules. Despite this, some reverse-engineered open source implementations of its lower security variants exist, including one developed by InterTeck, known as Convoluted Interleaved Non-Restricted Algorithms. These variants remain technically legal, as they're not interoperable with any of the classified versions.

Encryption

RAC in of itself is based on three similar quantum encryption algorithms designed for increasing security at the cost of efficiency; RAC-I, RAC-II, and RAC-III, which provide low, medium, and high levels of security respectively. Category I supports key lengths between 8 and 16, while Category II supports lengths between 24 and 32. Category III supports lengths between 48 and 64. All lengths are given in qubits, and processing time increases exponentially with the length.

RAC-II and RAC-III both require the use of active anti-tamper system which resist physical penetration, and RAC-III additionally requires an explosive self-destruct system, which not only destroys the module, but its surroundings as well. These countermeasures are intended to protect not just the key material, but the confidentiality of the implementation of the high-class algorithms to prevent reverse engineering.

Access Control

RAC’s access control mechanism comprises several components, which is designed to restrict when, where, and how key material can be used. These controls are enforced by the physical RAC cryptographic module, inside its tamper-responsive boundary, ensuring their integrity.

Examples of parameters include Module, which controls on which cryptographic modules key material can be unwrapped and used; User, the presence of one or a quorum of people required to present a smart card to unlock a key; Location, the enforcement of the presence of the module in a specific geographic location enforced by secure geolocation systems; and Time, the requirement to be used only at specific times or not before or after a particular date.

Licensing

It is impossible for a private individual to buy a RAC module outright. Low-grade RAC modules (RAC-I) can only be sold to OEMs for integration into products, while moderate-grade RAC modules (RAC-II) require the end-user to possess a license, which must be applied for from Raven with a justification and may be denied under any number of reasons. Modules higher than RAC-II are classified assets and strictly for military use only, and can only be obtained through accredited government or Raven/IRTO purchasing channels.

Certification

All RAC modules are certified by Raven, and must undergo stringent design and hardware validation depending on their maximum security level. This level determines the highest security RAC algorithm that can be used. After undergoing the certification process, the tamper detection systems are armed permanently, and each individual module is installed with a special "endorsement key" by Raven, which allows it to decrypt Red Tokens, hardware devices that contain the actual encrypted classified RAC algorithms and are used to load said algorithms at the time of deployment of the module. There are different endorsement keys for each hardware integrity level, ensuring the compromise of an endorsement key loaded onto a OEM-grade RAC-I module cannot be used to decrypt Red Tokens holding algorithms for a RAC-III module.

The RAC key parsing format is standardised, which means wrapped keys may be transferred between different certified RAC modules, even ones manufactured by completely different companies. If a module is certified by Raven (which it must be anyway to be loaded with RAC algorithms), compatibility is certain. External interfaces to all RAC modules is also standardised, which means computer systems and key loaders will always stay compatible.