architecture · system capabilities · § Compute · § Shards · § Delivery · § Identity · § Reputation
fleetmesh coordinates independent relays through verifiable transmission, granular shard replication, discrete compute escrow, and deterministic protocol accounting.
This document outlines core design capabilities. Peering, synchronization, published budgets,
dispute reports, and shard claims run on the reference node. The compute market
(§ Compute) is formally specified across compute/1.0 and kinds 11803,
30810, and 30811.
Architectural Overview
Bilateral accounting provides verifiable bounds on relay resource consumption.
Nodes coordinate using W3C DIDs, negotiate explicit bilateral budgets, verify message transmission with signed receipt hash chains, and settle discrete computation through cryptographic preimage escrow.
Section 01 · Distributed Compute Layer
fleetmesh enables relays to negotiate discrete computational tasks. Every node possesses a verified cryptographic identity (DID), authenticated bilateral messaging (DIDComm v2), and an established bilateral ledger. Computation is negotiated and settled directly between client and executor.
k and delivered
before payment; payment reveals the preimage that decrypts the result.
The compute architecture provides four core mechanisms:
ComputeExecutor), encrypts the result payload with an ephemeral key k, and issues
an invoice whose payment hash is SHA256(k). The buyer receives the sealed ciphertext first.
Settling the invoice reveals key k to decrypt the payload.
view_transit) and compute execution (view_compute). A node that fails
a compute job receives a finding scoped strictly to compute, leaving message transit standing unaffected.
Section 03 · Verifiable Transmission & Delivery
fleetmesh implements verifiable event delivery using signed receipt hash chains. Peers confirm event acceptance and custody with signed statements.
This audit chain enables verifiable service agreements across independent relays, providing mathematical confirmation of data delivery.
Section 04 · Sovereign Identity
fleetmesh anchors every node and agent in a decentralized identifier (W3C DID) that operates independently of DNS, hosting providers, or external certificate authorities.
Three specialized keys unified under a single DID subject
Authorization via cryptographic keys
did:key, did:peer, and did:nostrAccess control, routing limits, and peering privileges are managed through signed capability grants. Node identity remains portable across host migrations without loss of peering history or standing.
Section 05 · Protocol Interoperability
fleetmesh integrates with existing network infrastructure and standard protocols across the decentralized stack.
Compatibility with NIP-01 (event model), NIP-42 (authentication), NIP-44 (encryption), NIP-59 (gift wrapping), NIP-66 (relay monitoring), and NIP-77 (Negentropy).
Adherence to W3C DID Core v1.0 and DIDComm Messaging v2. Nodes speak universal protocols capable of federating with standard identity systems and mobile enclaves.
Cryptographic boundary mapping compatible with NIST FIPS 140-3 environments, alongside routing interoperability with the Free Internetworking Peering System (FIPS).
Settlement adapters for the Lightning Network (BOLT-11, BOLT-12, L402) and Cashu ecash mints, supporting sub-satoshi accounting and micro-payments for compute and retrieval.
Deterministic execution sandboxes using Wasmtime and Wasmer, enabling portable, secure, and verifiable compute workloads.
All specifications, schemas, test vectors, and the reference node (meshnode) are dedicated
to the public domain under CC0 1.0 Universal.
Section 06 · Relay Protection & Rate Accounting
fleetmesh regulates resource usage through bilateral published grants and deterministic severity ratings.
| Threat Vector | Traditional Open Relay | Closed Paywalled Relay | fleetmesh Bilateral Mesh |
|---|---|---|---|
| Sybil Key Generation | Unbounded new key generation | Per-key fee requirement | Quarantined: Fresh keys are constrained to Tier 0 sandbox budgets until proving clean window streaks over time |
| Relay Traffic Floods | Resource exhaustion under load | Arbitrary administrative caps | Hard Bounded: Bilateral grant (kind 30801) enforces strict byte and event limits per time window |
| Malicious Withholding | Unprovable event drops | Unprovable operator drops | Provable Fault: Signed receipt chains reveal custody; withholding data claimed complete yields an S2 breach |
| Blacklisting & Censorship | Opaque IP or pubkey blocklists | Administrative account suspension | Objective Evidence: Only signed cryptographic proofs (S1–S4) impact standing; trust is weighted locally (view(x)) |
Protocol non-conformance follows an objective severity ladder:
fleetmesh avoids centralized blocklists. When Node A detects that Node B committed
an S2 breach, Node A publishes a signed finding with evidence. Node C receives the
finding, validates the signature and proof, and updates its local trust score
view(B) according to its own weights.
Section 07 · Autonomous Systems
fleetmesh provides infrastructure for autonomous agents and resilient network operation:
Autonomous software agents require an open, identity-native substrate to discover peers, purchase compute, exchange encrypted shards, and settle micropayments in real time. fleetmesh provides standard protocols for autonomous agent interaction.
Through dynamic capacity management (node/capacity.py) and directional strain ledgers
(node/strain.py), fleetmesh nodes manage high traffic surges. Under pressure, nodes shed
low-priority sync tiers while maintaining core routing.
The multi-hop store-and-forward architecture and localized Negentropy reconciliation allow disconnected network partitions to continue operating independently, reconciling delta logs once connectivity is restored.
Next steps in the reference architecture:
Explore the hands-on deployment guide in Running a Node and Operator Manual,
study the accounting principles in Reverse Reputation & Receipt Chains,
inspect storage economics in Retrieval-Based Settlement,
or read the formal fleetmesh Specification.