User Manual: End-to-End Sovereign Lifecycle v1.0
Zero-Trust: No Phone Numbers • No Email • No Servers
Anti-Forensics: DoD 5220.22-M 7-Pass RAM & Flash Shredding
COMPLETE OPERATIONAL LIFECYCLE

SIAR End-to-End User & Operator Guide

Everything you need to know about installing, setting up self-sovereign cryptographic identities, pairing devices offline, exporting encrypted vaults, and triggering anti-forensic panic data shredding.

CHAPTER 01

Downloading & Verifying SIAR

SIAR is strictly peer-to-peer and distributed as sovereign native binaries for all major desktop, mobile, and headless server environments.

📱 Mobile (Android)

  • Direct APK: Download signed universal APK from Package Center
  • F-Droid Repository: Add custom mirror https://fdroid.siar.irshad.org.in/repo
  • Permissions required: Bluetooth Scan & Connect (BLE 5.x), Nearby Wi-Fi Devices (Wi-Fi Direct), Camera (QR Scanning). No contacts or phone permissions ever requested.

💻 Desktop (Linux, macOS, Windows)

  • Linux: sudo apt install siar-desktop (or .rpm, .AppImage, Arch AUR)
  • macOS: brew install --cask siar-messenger (or Universal .dmg)
  • Windows: winget install SIARMessenger (or MSIX package)
  • One-Line POSIX Installer: curl -fsSL https://siar.irshad.org.in/install.sh | sh
🔒 SLSA Level 3+ Cryptographic Verification:

Verify your download before execution using Minisign: minisign -Vm siar-desktop_0.1.0_amd64.deb -p pkg/gpg/minisign.pub or paste the SHA-256 hash into our in-browser SLSA Verifier.

CHAPTER 02

First-Time Setup & Sovereign Identity Generation

SIAR requires no phone numbers, email addresses, SMS verification, or central registration. Your identity is a pure cryptographic keypair generated locally in hardware memory.

1. Master Passphrase & Argon2id Derivation

On first launch, you select a local device passphrase. This passphrase is run through memory-hard Argon2id (64MB RAM, 4 iterations) to encrypt your local database vault and device Ed25519 signing keys.

⚠️ Important: SIAR has zero password recovery servers. If you forget your master passphrase, you must restore your identity using your 24-word BIP-39 mnemonic seed phrase.

2. Cryptographic Root Identity

Your node generates:

  • Ed25519 Root Identity Key (Public verification and signature signing)
  • X25519 Diffie-Hellman Key (Ephemeral pairwise key exchange)
  • OpenMLS RFC 9420 KeyPackage (Asynchronous Tree-KEM group ratchet)
🛠️ Interactive Simulator: Local Cryptographic Identity Generator
Click "Generate New Identity" to test local Ed25519/X25519 key derivation in real-time.
CHAPTER 03

Offline Pairing, QR Scanning & NFC Handshakes

To prevent Man-in-the-Middle (MITM) attacks and ensure zero-trust peer verification, SIAR uses physical-proximity rendezvous tickets.

📷 Visual QR Ticket Pairing

1. Open SIAR → Tap "Show My Ticket".
2. Your friend opens SIAR → Taps "Scan Peer QR".
3. The camera reads the compact binary ticket containing their Ed25519 public key, short authentication string (SAS), and supported radio channels (BLE, Wi-Fi Direct, LoRa).
4. Both devices display a 4-word Short Authentication String (e.g. ALPHA-FALCON-COBALT-ORBIT) to confirm physical authenticity.

📡 NFC Tap & Acoustic Pairing

NFC Tap: Hold two Android phones back-to-back. The NDEF payload transmits the OpenMLS bootstrap package in under 200 milliseconds.
Acoustic Chirp: In dark or camera-impaired disaster zones, phones can emit an ultrasonic near-inaudible FSK acoustic chirp to exchange public tickets through the microphone!

CHAPTER 04

Daily Messaging, Groups & Emergency SOS Mode

How communication flows seamlessly whether you have full internet, local Wi-Fi, or zero connectivity in an off-grid wilderness.

💬 1:1 Direct Encrypted Chat

Every message is sealed with forward-secret Double-Ratchet keys and sent directly over the best available radio link (BLE L2CAP, Wi-Fi Direct, or QUIC).

👥 OpenMLS Multi-Party Groups

Supports up to 500 members in a single group with Tree-KEM logarithmic key updates. Adding or removing members immediately rotates the group encryption epoch.

📦 DTN Store-Carry-Forward

If your friend is 5 km away with no direct signal, intermediate moving nodes automatically carry your encrypted bundle in their flash storage and deliver it upon proximity rendezvous.

🚨 Emergency SOS Beacon

One-tap distress beacon that overrides duty cycles, emits LoRa and Wi-Fi emergency frames with highest RFC 9171 priority, and strobes flashlight SOS.

CHAPTER 05

Exporting, Importing & Device Migration

You own 100% of your data. You can back up your entire sovereign vault, migrate to a new device, or export readable archives at any time.

📦 Full Encrypted Vault Export (`.siarvault`)

1. Go to Settings → Security & Storage → Export Vault.
2. Enter your master password.
3. SIAR compiles your identity keys, contact verification tickets, OpenMLS group trees, and message database into a single binary file encrypted with ChaCha20-Poly1305 + Argon2id.
4. Save this file to a USB drive, air-gapped microSD card, or sovereign storage.

🔄 Restoring Vault on a New Device

1. Install SIAR on your new phone or computer.
2. On first run, choose "Import Existing Vault / Seed".
3. Select your .siarvault file or type your 24-word seed phrase.
4. Enter your passphrase. All your groups, contacts, and message histories are decrypted and restored immediately.

📦 Interactive Simulator: Encrypted Vault Structure Inspector
Click "Inspect Mock Vault" to see how SIAR packages encrypted data streams into a portable .siarvault container.
CHAPTER 06

Deleting Data & Panic Anti-Forensics Purge

In hostile environments or emergency confiscation scenarios, SIAR provides multi-level data sanitization and instant zero-residual cryptographic destruction.

1. Selective Chat / Message Deletion

Swipe left on any conversation or message and choose "Secure Delete". Rather than marking rows as deleted, SIAR overwrites SQLite database pages with cryptographically secure random bytes before invoking PRAGMA wal_checkpoint(TRUNCATE).

2. Duress PIN / Fake Vault

You can configure a secondary "Duress Passcode". If forced to unlock your device, entering the duress passcode opens a plausible clean decoy account while silently destroying the master encryption keys in background RAM!

3. Instant Panic Button (Emergency Purge)

Tapping the Panic Button (or shaking device 5 times if configured) executes:
• Zeroizes RAM encryption keys via zeroize::Zeroize.
• Overwrites database files using DoD 5220.22-M 7-pass random wipe.
• Deletes all credentials and terminates the process in under 100ms.

🔥 Interactive Simulator: Anti-Forensic Zeroization & Shredding
Click "Trigger Mock Panic Purge" to simulate real-time RAM zeroization and 7-pass flash overwriting.