Skip to content

Commit

Permalink
Merge pull request #93 from WebOfTrust/2byrds-patch-1
Browse files Browse the repository at this point in the history
Update README.md
  • Loading branch information
2byrds authored Aug 16, 2023
2 parents 23027b8 + 05c7eab commit 5bf91c0
Showing 1 changed file with 24 additions and 0 deletions.
24 changes: 24 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,30 @@ KERI Agent in the cloud

Split from KERI Core

## KERIA Service Architecture
Here we detail the components of a single KERIA instance. This architecture protects the host and the holder private keys. All client tasks/calls are signed 'at the edge', not in the hosted KERIA instance. Therefore, KERIA relies on the Signify protocol for all calls. The Architecture provides three endpoints for Signify clients to create their KERIA agents. The Agency (boot) endpoint establishes an agent. The API Handler and Message Router endpoints would be exposed to the internet for creating identifiers, receiving credentials, etc.
![KERIA](https://github.com/WebOfTrust/keria/assets/681493/a64212ef-e343-428d-954f-1aa81222ae63)

### Message Router
The Message Router receives external KERI protocol messages. These are KERI protocol messages for instance coordinating multi-sig, revoking credentials, etc. It routes these messages to the appropriate Agent(s). For instance a multisig message requires asynchronous waiting (for signature responses from other participants) and the message router would route those incoming KERI protocol responses to the appropriate agents.
From Signify client calls, this service endpoint corresponds to the *http port* (default is 3902).
This enpoint allows all KERI clients (not just Signify) to interact in a seamless way.

### The Agency
The Agency receives API requests (/boot requests) to provision agents. It is the central repository for initializing agents.
The Agency database persists all of the information to track the existing agents, allowing recovery on restart.
From Signify clients calls, this service endpoint corresponds to the *boot port* (default is 3903).
A common entry in the agency is the mapping between a managed AID and the agency that handles that managed AID.

### API Handler
The API Handler receives agent API requests (/agent requests) including for Signify clients to create identifiers, receiving credentials, etc. All API calls are signed by the Signify client headers so that all calls are secure.
This API interacts with agents and those interactions are stored in the agent databases.
From Signify clients calls, this service endpoint corresponds to the *admin port* (default is 3901).

### Agents
Agents act on behalf of their Signify clients. They don't have the secrets of the client. Instead, they handle all actions for the clients, other than secret/encryption/signing. However, Agents do have their own keys and do sign all of their messages BACK to the Signify client, so the client can verify that all messages received are from their agent.
Agents use KERI HIO to handle all of the different asynchronous actions that are occuring. HIO is an efficient and scalable orchestration/processing mechanism that leverages queues, handlers, coroutines, etc.
All Agent db access is through the associated Agent.

## Development

Expand Down

0 comments on commit 5bf91c0

Please sign in to comment.