Home/Guides/Zero-Knowledge Cryptography
Applied Cryptography

Zero-Knowledge Architecture: How Scrypt Key Derivation Protects Vaults

By Locky Security Research•8 min read•Updated October 2026

What Does "Zero-Knowledge" Actually Mean?

In cybersecurity and cryptography, a zero-knowledge system is an architectural design where the server operator possesses zero mathematical capability to read, inspect, or reconstruct user secrets. In traditional SaaS applications, user data is often protected by server-side encryption keys managed by the company's cloud provider, meaning employees, database administrators, or sub-processors can technically view raw files.

Locky implements a stateless, zero-database architecture. We do not store user accounts, persistent customer records, email addresses, or plaintext passwords. Media files uploaded to Locky are encrypted and verified using keys derived from a 4-digit PIN chosen exclusively by the user.

Why Scrypt Over Standard Hash Functions (SHA-256 / MD5)

A 4-digit numeric passcode consists of 10,000 possible combinations (0000 to 9999). On modern GPU clusters or Application-Specific Integrated Circuits (ASICs), standard cryptographic hash functions like SHA-256 or MD5 can compute billions of operations per second, which would allow an attacker to test all 10,000 combinations in milliseconds.

To make brute-force attacks computationally impractical, Locky uses the scrypt key derivation function (RFC 7914):

// Locky Cryptographic Scrypt Configuration
const SCRYPT_N = 16384; // CPU/Memory cost parameter (2^14)
const SCRYPT_r = 8; // Block size parameter
const SCRYPT_p = 1; // Parallelization parameter
const KEY_LENGTH = 64; // Output key length (512 bits)

Unlike SHA-256, scrypt is a memory-hard algorithm. It requires substantial RAM to compute every single hash, making it impossible to run massive parallel calculations on custom GPU or FPGA hardware. Furthermore, Locky pairs every passcode with a cryptographically secure 16-byte random salt, rendering precomputed rainbow tables entirely useless.

Advertisement

Three-Tier Defense Against Automated Scraping

Because Locky is publicly accessible on the web, attackers might try to crawl the verification endpoint over HTTP. Locky deploys a three-tier defense to block programmatic scraping:

  1. Cloudflare Turnstile Bot Defense: Every passcode verification request requires a valid cryptographic token generated by Cloudflare Turnstile. Command-line curl scripts, Python bots, and automated scrapers that do not render JavaScript or pass human heuristics are rejected immediately with HTTP 403.
  2. Dynamic IP & Vault Rate Limiting: Verification attempts are tracked in memory per client IP and media vault ID. If an IP fails 5 consecutive attempts, the vault is locked down for 15 minutes (HTTP 429).
  3. Short-Lived 5-Minute Presigned Tokens: When the PIN matches, the server returns a temporary signed GET URL valid for only 300 seconds. Direct cloud links cannot be shared or permanently hotlinked.

Summary: Security Through Simplicity

By combining client-side metadata stripping, memory-hard scrypt key derivation, automated 24-hour self-destruction, and Cloudflare Turnstile bot protection, Locky delivers military-grade temporary file privacy without compromising on user experience.