Status: Active | Language: Rust (Edition 2021) | Platform: Windows / Linux
Aegis is a local-first, confidential memory store designed to address the security risks of managing sensitive credentials in development environments.
Standard methods for handling secrets—such as environment variables or plaintext configuration files—often expose sensitive data to memory inspection and unauthorized read access. Aegis mitigates this by operating as a background daemon that isolates secrets within a protected memory heap. It enforces a strict boundary between the application layer and the storage layer, ensuring that secrets are only accessible through a verified, encrypted Inter-Process Communication (IPC) channel.
This project serves as a demonstration of systems programming concepts, specifically focusing on process isolation, OS-native cryptography, and zero-trust architecture.
The system is architected as a split-process client-server model to ensure maximum isolation.
- The Daemon (Server): A long-running background process responsible for the secure lifecycle of secrets. It handles memory locking, encryption at rest, and automated expiration.
- The Client (CLI): A lightweight terminal interface that serializes user requests and communicates with the daemon.
- The Transport Layer: A custom implementation of Named Pipes (Windows) or Unix Domain Sockets (Linux), providing a secure, local-only communication path that avoids the network stack entirely.
- Request: The client serializes a command (e.g., Store, Retrieve) into a strict binary format.
- Verification: The daemon receives the request, validates the protocol signature, and checks metadata constraints.
- Execution: The daemon decrypts the requested secret using OS-level primitives and returns it to the client.
- Cleanup: Secrets are automatically purged from memory once their Time-To-Live (TTL) expires.
Aegis decouples the storage of secrets from the application that uses them. By keeping secrets inside the daemon's address space, the system protects against memory scraping attacks targeting the client application. The daemon also implements memory locking strategies to prevent the operating system from swapping sensitive data to the disk paging file.
To ensure data remains secure even when the application is idle, Aegis leverages the Windows Data Protection API (DPAPI). This binds the encryption of secrets to the user's login session. Consequently, even if the raw memory or storage were accessed, the data cannot be decrypted by a different user or an external system.
Communication relies on a custom, strongly typed protocol rather than generic text streams.
- Length-Prefixed Framing: Messages are encapsulated with a binary length header to ensure stream integrity.
- Type Safety: Request and Response schemas are defined as Rust enums, ensuring that invalid states are unrepresentable at the protocol level.
The project is organized as a Rust Workspace to enforce separation of concerns:
-
crates/aegis-proto Contains the shared type definitions and the serialization logic for the IPC protocol. This library is the only dependency shared by both the client and the daemon.
-
crates/aegis-enclave Houses the security core. This includes the
unsafeRust bindings for Windows API calls, cryptographic wrappers, and memory management logic. -
services/aegis-daemon The executable binary for the background service. It manages the run-loop, handles concurrent connections, and owns the in-memory hash map of secrets.
-
clients/aegis-cli The user-facing command-line interface. It handles argument parsing and formats the output for the user.
- Rust Toolchain (Latest Stable)
- Operating System: Windows 10/11 or Linux
- Clone the repository.
- Compile the workspace in release mode:
cargo build --release
Starting the Daemon Open a terminal and run the background service. This process must remain running to hold the secrets.
./target/release/aegis-daemon
Storing a Secret In a separate terminal window, use the CLI to store a credential. You can specify a Time-To-Live (TTL) in seconds.
Bash
./target/release/aegis-cli put api_key "sk-secure-token-123" --ttl 3600
Retrieving a Secret
Bash
./target/release/aegis-cli get api_key