Coming soon to iPhone

How time-lock encryption keeps a message closed

Updated · 5 min read

Time-lock encryption makes a message unreadable until a chosen moment, with no company holding the key. It works by encrypting to a future value from a public beacon such as drand. The value does not exist yet, so nobody can decrypt early. Once the beacon publishes it, anyone can. This guide shows how that works.

Coming soon to iPhone

What problem does time-lock encryption solve?

You want to say "open this in 2031" and mean it. A normal password does not help, since the person who knows it can use it at any time. A website that promises to hold a message depends on a company staying honest and in business. Time-lock encryption replaces the promise with mathematics.

How does it work?

A public beacon publishes a new random value on a fixed schedule, each one signed. The value for a future round cannot be computed in advance. With a technique called identity-based encryption, you can encrypt to a round number as if it were an address. Decryption needs that round's signature, which exists only after the beacon publishes it.

In practice the message is first encrypted with a fast symmetric cipher, here AES-256-GCM, and only the small content key is locked to the future round. This is how Sealday works, with the open-source tlock library and the drand quicknet network.

Who runs drand?

drand is run by the League of Entropy, a voluntary consortium of independent organizations that jointly produce randomness, and no single member can predict or change it. Wikipedia describes the group. Clients verify each value against a fixed public key, so a relay cannot send a forged value.

Where does the idea come from?

The goal is older than the tools. Wikipedia's article on time-lock puzzles credits Timothy C. May with describing the concept and Ron Rivest, Adi Shamir and David Wagner with a working solution in 1996. Their puzzle forces a calculation that must run step after step, so adding computers does not make it faster. The delay is measured in computing work.

The same article lists a second route: trusted agents who hold the key and release it later. Most future-message websites work this way. A third route needs identity-based encryption. Shamir proposed the idea in 1984, and the Boneh–Franklin and Cocks schemes made it work in 2001. tlock applies it to a public beacon, with a round number as the identity.

The League of Entropy was inaugurated in 2019, and the drand team publishes an open-source library, tlock-js, which Sealday uses.

What is inside a sealed capsule?

Three parts: a ciphertext, a locked key and, for capsules you send, a readable envelope. Your guesses, letter, photos and voice note are packed into one payload, compressed, and encrypted with AES-256-GCM under a random 32-byte key made on the phone, with a fresh 96-bit nonce. That is the ciphertext.

The 32-byte key is then wrapped by tlock into a small file in the standard age format, which names the drand round it waits for. The round number is visible in that file, and nothing about your content is.

PartWhat it isReadable before the date?
CiphertextYour content, encrypted with AES-256-GCMNo
Locked keyThe content key, wrapped for one drand roundNo
EnvelopeSender name, recipient name and open date, on capsules you sendYes, on purpose, so a countdown can show

How does a date become a round number?

Sealday converts your moment into the first drand round published at or after it. The quicknet network started on 23 August 2023 at 15:09:27 UTC and publishes a round every 3 seconds. The arithmetic is short: seconds since the start, divided by 3, rounded up, plus one.

For midnight UTC on 1 January 2028 that gives round 45,831,412. Because rounds are 3 seconds apart, a capsule can open a few seconds after the exact moment but never before it. Rounds are numbered from 1 at the network's start, so every future date maps to exactly one round number that anyone can work out. Your time is read in your own time zone, so a New Year capsule opens at 00:00 where you live.

What does the app need from the network?

Only one request on the open date: "give me round N". It contains no message and no identifier. Sealing is done offline, because encrypting to a future round needs only public information.

What are the limits?

Be honest with yourself about three things.

  • If the beacon network stopped publishing for good, messages locked only to it could not be opened.
  • Time lock hides content from everyone, including you. A spare key for yourself is a separate trade-off.
  • The date is fixed at sealing; it cannot be moved.

How does Sealday handle those limits?

Capsules you send have no spare key, which keeps the promise honest. Capsules for yourself have a spare key in your iPhone Keychain, behind a 24-hour wait and a permanent "Opened early" mark, and it is also used if the beacon is unreachable for 72 hours after the date. Details are on the time lock page. For making your own capsule, start with letter to your future self.

What does a worked example look like?

Here is the sequence for one capsule.

  1. You choose 1 January 2028, midnight.
  2. The app works out which drand round will be published at that moment.
  3. It encrypts your content with a random AES-256-GCM key.
  4. It locks that key to the future round with tlock and stores the locked key with the files.
  5. On 1 January 2028 the beacon publishes the round signature.
  6. The app downloads the signature, checks it and recovers the key.
  7. The files decrypt on your phone.

What happens on open day if something goes wrong?

The app asks four public relays in turn, 10 seconds each: api.drand.sh, api2.drand.sh, api3.drand.sh and drand.cloudflare.com. It checks every signature against the network key built into the app and skips any relay that sends a bad one. A verified signature is kept, so the same date never needs a second download.

If all four relays fail, you see a retry screen and the app tries again when you come back. For your own capsules there is one more exit. Once the date has passed and the beacon has stayed unreachable for 72 hours, the spare key on your iPhone can open the capsule, and the archive marks it Opened without the beacon. Capsules you sent have no such key.

Which attacks does a time lock stop?

The table lists what the design covers and what it leaves to you.

AttemptResult
Changing the iPhone clockNothing opens. The key for a future round does not exist yet.
Copying the capsule file or linkThe copy is locked in the same way.
Breaking into SealdayThere are no Sealday servers holding capsules or keys.
A relay returning a fake valueRejected. The signature fails against the key inside the app.
Someone holding your unlocked phoneThey can start the 24-hour early opening on your own capsules, which leaves a permanent mark. Capsules you sent cannot be opened.
Reading an unsealed draftPossible. Drafts are plain local data until you seal them.

How does it compare with other ways to delay a message?

MethodWho must you trust?Weak spot
A website that promises to hold your messageThe companyBreach, shutdown or bad faith
Giving the key to a friendThe friendLoss or early peeking
A time-lock puzzleNobodyMeasures computing time, not the calendar
Beacon-based time lock (tlock)The beacon network as a groupNetwork must keep publishing

Why a beacon instead of a puzzle?

A time-lock puzzle forces a long computation, so the opening time depends on how fast the hardware is. A beacon ties the key to a calendar moment, which is what a person means by "open it in 2031". The technique relies on identity-based encryption, where an identifier, here a round number, plays the role of a public key.

How can I judge any future-message service?

Ask four questions before you trust a message to a service for years. The answers separate a real time lock from a promise.

QuestionA good answerA red flag
Who holds the key before the date?Nobody, because it does not exist yetThe company, kept safely
What enforces the date?A public signature that appears on that dayA server clock, or your phone's clock
What happens if the company closes?Capsules still open, if the beacon runsThey disappear with the servers
Can you check the method?Open libraries and a public networkA phrase like trust us, with no description

A phone clock is the weakest date check there is, because the person holding the phone controls it.

Is time-lock encryption the right tool for you?

Use it when the delay itself matters: a letter to yourself, a gift that must wait for a birthday, a group game where nobody may peek. Skip it when you may need the content sooner, such as a will, a password or a document with a deadline you could change. For those, give a copy to a person you trust, and keep the time lock for things where waiting is the whole point.

If you want to try it, Tables and capsules for a friend use the same lock, and the backup page explains how to keep a sealed copy safe for years.

Frequently asked questions

Can time-lock encryption be broken early?

Not without the beacon's signature for that round, which does not exist before the date. Today's public tools make early decryption infeasible unless the beacon itself is compromised.

Do I have to trust Sealday?

The lock does not rely on Sealday's servers, since Sealday has none. It relies on standard cryptography and the drand network.

Does this need the blockchain?

No. drand is a threshold network of servers, not a blockchain.

How exact is the opening time?

Within about 3 seconds after the moment you chose. The network publishes a round every 3 seconds, and a capsule opens on the first round at or after your time.

Does Sealday need the internet to seal a capsule?

No. Sealing uses public information bundled in the app. Opening needs one request for the signature of the right round.

Is a time-lock puzzle the same as tlock?

No. A puzzle measures computing work, so its opening time depends on hardware. tlock ties the key to a calendar moment through a public beacon.

Keep exploring

Seal your first capsule in about a minute

  • Predictions, a letter, photos and a voice note
  • Locked until the date by a public time beacon
  • No account, no ads, no analytics

Coming soon to iPhone