Skip to content

proposed overview structure #21

Description

@nothingmuch

each layer inherits most of the previous layer's functionality and adds additional restrictions:

  • sneakernet/implicit transport honest threat model
    • bip draft dependencies:
      • concurrent & extensions - basic data format
      • scrubbing - enforcing boundary between privacy domains e.g. own signing devices and collaborative txn construction
      • hpke - optional - for embedding of out-of-band messages into psbt files
    • define net settlement / payment confirmation
      • base definition assumes out-of-band
      • can be made in-band with hpke
    • all "messages" are just PSBTs with a partial order (can't guarantee a join semilattice in general)
    • should have discussion of privacy
  • interactive transaction construction w/ pluggable transports in honest threat model
    • use cases
      • multisig
      • internally segregated wallets (e.g. operational vs. customer funds)
      • collaborative batching
      • net-settlement
    • define message space to avoid in-band
    • framing format for duplex stream transports
    • broadcast
      • leader
      • clique
      • gossip
    • optional compatibility with lightning interactive-tx by bridging
  • semi-honest
    • considerations for on chain structure
    • restrictions on transport
    • anonymous broadcast by relay w/ anonymous p2p transport
    • implications for liveness
  • bft
    • threat model, incentives
    • coalition formation
      • ownership proofs & online key enrollment
      • listen advertisements
      • co-spend proposals
      • coalition formation proposal
      • role of aggregator in bootstrapping agreement
    • causal log structure, bft crdts = liveness in async/eventual consistency communication model (this may make sense to split, and move the non-bft component to interactive honest)
    • validity proofs
    • bft agreement
      • setchain/redebelly + weak coordinator (bootstrapped by aggregator)
      • TEE leader without redbelly? weak coordinator?
      • distributed (set union consensus)

Originally posted by @nothingmuch in #11 (comment)

Activity

  1. bc1cindy commented on Aug 10, 2026

    @bc1cindy
    Member

    Protocol Overview

    layered suite; each layer inherits the previous one and adds restrictions; fund safety never depends on peer honesty at any layer
    (local validation, sign only what you accept); goals are defined by the cost function (#15), this doc is the accounting of the means.

    Sneakernet / implicit transport (honest)

    Interactive construction, pluggable transports (honest)

    • use cases: multisig, internally segregated wallets, collaborative batching, net settlement
    • message space (avoid in-band), framing for duplex streams
    • broadcast: leader / clique / gossip
    • optional lightning interactive-tx compatibility by bridging
    • detail doc: roles, timeouts, graph model, session parameters (Add honest overview #11)

    Semi-honest

    • peers comply but are not trusted with privacy
    • on-chain structure considerations
    • transport restrictions
    • anonymous broadcast by relay over anonymous p2p transport
    • liveness implications

    BFT

    • threat model, incentives
    • coalition formation (Coalition formation #18): ownership proofs & online key enrollment, listen advertisements, co-spend proposals, coalition formation proposal, aggregator bootstrapping agreement
    • causal log, bft crdts = liveness under async/eventually consistent communication; whether the non-bft component moves to interactive stays a note here, decided at detail-doc level
    • validity proofs
    • agreement candidates: setchain/redbelly + weak coordinator (bootstrapped by aggregator), TEE leader (with or without redbelly/weak coordinator; open), distributed set union consensus

    Detailed documentation (todo index)

    • message types, framing, threat models
    • gossip: p2p topology w/ and w/o OHTTP service, set reconciliation
    • OHTTP service: bridging, rate limiting, mailboxes, broadcast, multi-server set reconciliation

    if it sounds good, happy to work on a PR!

  2. nothingmuch commented on Aug 10, 2026

    @nothingmuch
    ContributorAuthor

    sorry i already called dibs on it in #11 gonna self assign to make that clear

  3. self-assigned this
    on Aug 10, 2026
  4. added this to the BRW milestone on Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions