← Back to Docs

Key Rotation

Rotation is driven by your integrity server, not by a timer inside the SDK. The server sends a KEY_ROTATE message and the client re-derives its session keys. The interval is set by the integrity server you run; the hosted demo behind the showcase rotates on a fixed short interval.

Why Rotate Keys?

+Limits exposure — key material extracted from memory stops being useful once the server rotates past that epoch.
+Shortens the replay window — data captured under an old key stops verifying once that epoch leaves the grace window.
+Forces cheat tools to continuously re-adapt, increasing maintenance cost for cheat developers.

How It Works

There are two modes. By default only a small rotation identifier travels over the wire, and both sides derive the new key from a secret established at initialization. In a trusted-server session the server may instead deliver the rotation seed itself, so that client and server are guaranteed to land on the same key — that seed does travel over the connection, so the connection has to be one you trust.

// One rotation, counted in epochs
epoch N Key N active
KEY_ROTATE Server sends rotation_id N+1
epoch N+1 Client rotates, replies ROTATE_ACK
Server accepts the current epoch and a short
grace window behind it; older reports no
longer verify

Grace Period

The server accepts the current epoch plus a short grace window behind it, so verification data prepared just before a rotation still verifies through the changeover; reports older than that window are rejected. The window is counted in epochs, not in wall-clock seconds, and its width is a fixed default in the server you host. No special handling is needed on your part.

For Developers

You never derive a key yourself, but you do own the transport. When your connection to the integrity server delivers KEY_ROTATE, hand the new seed to the SDK. There is no per-frame SDK call.

// On KEY_ROTATE from your integrity server:
compuon::api::rotate(new_rotation_seed);

// On a server-issued handshake for an ALREADY initialized
// session, re-key in place -- do not call init() again:
compuon::api::rekey_session(session_seed, rotation_seed);
+Unreal Engine — UCompuonSubsystem does no rotation work of its own. Call api::rotate() from wherever you handle the server connection.
+Custom engines — the same call, from your own message loop.