Commit Graph
3 Commits
Author SHA1 Message Date
Johnathan Corgan 738775258a Session 41: Peer authentication protocol design
Design 3-message peer auth handshake (AuthInit → AuthChallenge → AuthComplete):
- Deterministic crossing connection handling via npub ordering
- Domain-separated signatures (fips-peer-auth-v1)
- New message types: 0x09 AuthInit, 0x0a AuthChallenge, 0x0b AuthComplete

fips-design.md:
- Replace 4-message auth with 3-message design
- Add crossing connection handling rules
- Add message structures and signature construction

fips-architecture.md:
- Expand peer lifecycle state machine with auth states
- Add Node Startup Sequence section
- Add Static Peer Retry Policy (exponential backoff, jitter)
- Add Inbound Connection Acceptance section
- Update peer config for static-only initial impl

fips-protocol-flow.md:
- Add §7 Peer Connection Establishment
- Add §7.2 Post-Authentication flow

Design decisions: static peers only, always do peer auth regardless of
transport, accept all authenticated inbound connections.
2026-01-31 19:13:15 +00:00
Johnathan Corgan b54c347e76 Session 40: Reconcile design docs with protocol flow decisions
Align terminology and cross-references across all FIPS design documents
based on decisions made in fips-protocol-flow.md (Session 39).

Key changes:
- Distinguish "Routing Session" (hop-by-hop cache) from "Crypto Session"
  (end-to-end Noise KK encryption) throughout all docs
- Add handshake_payload field to SessionSetup/SessionAck for combined
  establishment of routing and crypto sessions
- Update fips-design.md encryption section to reference Noise KK
- Add SessionSetup (0x06), SessionAck (0x07), CoordsRequired (0x08)
  message types
- Add Crypto Session Management config section to fips-architecture.md
- Add cross-references to fips-protocol-flow.md in all design docs
- Update reconciliation tracking in protocol-flow.md §7
2026-01-31 18:28:14 +00:00
Johnathan Corgan 5d190885ec Session 39: Protocol traffic flow design document
Add comprehensive design doc for FIPS protocol message flow covering:

- DNS-based identity cache priming (npub.fips format)
- TUN reader processing pipeline
- Crypto session (Noise KK with secp256k1) vs routing session distinction
- Combined establishment model (routing + crypto in single round-trip)
- Noise KK pattern with ChaCha20-Poly1305, AEAD-only authentication
- Route discovery via bloom filters and LookupRequest flooding
- Crossing hellos handling with deterministic tie-breaker (lower npub wins)

Includes reconciliation section tracking alignment with existing design docs
(fips-routing.md terminology updates pending).
2026-01-31 18:09:38 +00:00