90 karma · joined April 27, 2018
Maybe, we can just follow facebook.com: "Use with Consent"
And I put it into CQL Database for easier usage.
To implement a decentralized system, I wrote a TLS like P2P net stack. The main idea is removing CA Cert from the whole system by using a DHT for Naming and Key Exchange. I am not a crypto expert, so if there's any flaw please point it out for me here or Github I use an Elliptic Curve for asymmetric encryption
DH-RPC NodeID is generated by hash of Node PublicKey and an Uint256 Nonce:
NodeID := sha256(blake2b-512(NodePublicKey + Uint256Nonce))
I refer to S/Kad idea to define the number of consecutive 0s in front of the NodeID as difficulty and to impose a minimum limit on the difficulty of the NodeID allowed to be stored on the DHT. DHT is used to hold the NodeID:PublicKey NodeID:Addr map. NodeID and Nonce are sent to do ECDH getting shared secret after TCP connection established.
GenECDHSharedSecret(APub, BPriv) == GenECDHSharedSecret(BPub, APriv)
The main procedure is described as sequence chart: https://github.com/CovenantSQL/CovenantSQL/blob/develop/logo...
Because in the decentralized system NodeID is the URI, not "Bob/Alice.com". So anyone tries to fake NodeB by overwriting the address or public key on DHT without the private key of NodeB will be failed to get the correct shared secret.Github: https://github.com/CovenantSQL/CovenantSQL/tree/develop/rpc
Adversarial Routing is a bit related to DOS Attack you described. As the DHT is a gossip protocol organized network, maybe some Peer Rating stuff with PoW NodeId will work out an intergalactic-internet scale DHT. Just a well behaved proper difficulty NodeID will be trusted to spread more NodeID routing info.