Repository navigation
proposed overview structure #21
Copy link
Copy link
Open
Milestone
Description
Activity
Protocol Overview
layered suite; each layer inherits the previous one and adds restrictions; fund safety never depends on peer honesty at any layer
(local validation, sign only what you accept); goals are defined by the cost function (#15), this doc is the accounting of the means.Sneakernet / implicit transport (honest)
- no transport assumed: PSBT files exchanged by any available means
- all messages are PSBTs with a partial order; join-semilattice not guaranteed in general
- data format: concurrent PSBTs & extensions (Concurrent PSBT spec #16)
- privacy domain boundaries: scrubbing (Add scrubber bip #12)
- optional in-band messaging: hpke encrypted fragments (WIP - encrypted fragments bip outline #10)
- net settlement / payment confirmation: out-of-band by default, in-band with hpke
- privacy discussion: at this layer privacy rests entirely on the honesty assumption; problem definition in Define the on-chain privacy problems being addressed #7
Interactive construction, pluggable transports (honest)
- use cases: multisig, internally segregated wallets, collaborative batching, net settlement
- message space (avoid in-band), framing for duplex streams
- broadcast: leader / clique / gossip
- optional lightning interactive-tx compatibility by bridging
- detail doc: roles, timeouts, graph model, session parameters (Add honest overview #11)
Semi-honest
- peers comply but are not trusted with privacy
- on-chain structure considerations
- transport restrictions
- anonymous broadcast by relay over anonymous p2p transport
- liveness implications
BFT
- threat model, incentives
- coalition formation (Coalition formation #18): ownership proofs & online key enrollment, listen advertisements, co-spend proposals, coalition formation proposal, aggregator bootstrapping agreement
- causal log, bft crdts = liveness under async/eventually consistent communication; whether the non-bft component moves to interactive stays a note here, decided at detail-doc level
- validity proofs
- agreement candidates: setchain/redbelly + weak coordinator (bootstrapped by aggregator), TEE leader (with or without redbelly/weak coordinator; open), distributed set union consensus
Detailed documentation (todo index)
- message types, framing, threat models
- gossip: p2p topology w/ and w/o OHTTP service, set reconciliation
- OHTTP service: bridging, rate limiting, mailboxes, broadcast, multi-server set reconciliation
if it sounds good, happy to work on a PR!
sorry i already called dibs on it in #11 gonna self assign to make that clear
Reacted by Cindy
Metadata
Metadata
Assignees
Labels
No labels
each layer inherits most of the previous layer's functionality and adds additional restrictions:
Originally posted by @nothingmuch in #11 (comment)