deep dive · protocol economics · kinds 30801 & 30802
Published bilateral budgets, cryptographic receipt chains, and subjective trust weighting in fleetmesh.
Core Architecture
Nodes publish explicit rate budgets and verify consumption using signed receipts. Adverse evidence requires counterparty signatures and direct peering history.
Each node signs and publishes the exact budget allocated to an upstream peer. The peer enforces limits locally and proves consumption through chained cryptographic receipts. Dispute reports require an active grant relationship and subject-signed evidence.
Part 01 · Overview
Static Rate Limiting
Traditional relays configure private rate ceilings, dropping burst traffic silently or returning uninformative HTTP status codes.
Fleetmesh Bilateral Verification
Nodes negotiate explicit throughput allowances and verify accounting using signed delivery receipts.
Kind 30801
An addressable Nostr event using a blinded identifier derived via HKDF-SHA256 from shared Diffie-Hellman secrets. Payloads are encrypted to the subject via NIP-44, defining bandwidth limits, trust tier, shard filters, and window duration.
DIDComm budget/1.0
The subject transmits periodic signed accounting receipts. Receipts chain sequentially using SHA-256 hashes of previous receipts, preventing retroactive modification. Each receipt documents cumulative counter consumption and forwarded origins.
Kind 30802
An addressable event published when sustained protocol violations occur. Reports require an active grant issued by the reporter and must include verifying signatures produced by the subject.
Part 02 · Protocol Mechanics
Protocol remedies follow deterministic, published rules. Breaches distinguish between unmetered volume (S1) and accounting misreporting (S2):
Partition Tolerance · Egress Verification · § Partition tolerance
Asynchronous Silence Classification: To differentiate between network disconnects and deliberate non-accounting, fleetmesh evaluates physical egress counters:
Active Silence (Traffic > 0, receipts missing)
Classified as S2 Misreport. Nodes transmitting events must provide matching signed accounting receipts.
Inactive Silence (Traffic = 0, receipts missing)
Classified as a standard partition. The evaluation window closes without penalty, streaks remain intact, and no adverse report is created. When traffic resumes, a new receipt chain opens.
Mathematical formulation
Every node evaluates a reporter r using the local grant to r, the clean interaction streak age, and historical reporting accuracy for r:
tier_weight: probation (0.00), member (0.25), trusted (0.60), anchor (1.00)age_factor: min(1.0, clean_windows / 168), 168 default hourly epochs (a one-week streak) to reach 100%false_report_rate: (unsupported or refuted reports by r) / (reports by r evaluated); immune when the evidence verifies and the finding follows from itOrdinal threshold
Severity is an ordinal scale rather than an arithmetic average. A finding takes effect when accumulated weighted reports reach the binding horizon:
Part 03 · Simulator
Test reporter tiers, clean-window streaks, and false reports to observe how weight w(r) converges across the evaluation horizon.
Step-by-step calculation
0.601.0001.0000.600
Part 04 · Lifecycle
Phase 1 · onboarding
Nodes establishing peering over DIDComm peering/1.0 begin in the probation tier with conservative traffic limits. Unproven peers hold weight w(r) = 0, preventing malicious claims against third parties.
Phase 2 · active epochs
Traffic circulates under active grants. At the close of each evaluation window, the peer submits chained accounting receipts. Clean windows increment the streak counter and expand bandwidth limits under additive increase.
Phase 3 · disputes
When an issuer detects volume overruns (S1) or receipt discrepancies (S2), it transmits a private DIDComm complaint/1.0 notice. The peer has a grace window to submit missing receipts or accept revised grant terms prior to public filing.
Phase 4 · audits
Before establishing new connections, nodes query mutual trusted peers over standing/1.0. Peers respond with selective tier disclosures (tell) or private refusals (decline). Declining carries zero negative connotation.
Part 05 · Design Rationale
Game theory
Generating arbitrary key pairs yields zero influence (Σ w(r) = 0) because probation nodes carry zero reporting weight. Multihoming and sybil relay farms are countered through ASN diversity checks, explicit leaf selection, and severe S2 penalties for fabricated topology.
Sovereignty
The network operates without global reputation registries or consensus voting rounds. Nodes evaluate peers through direct bilateral relationships and local trust parameters, remaining immune to coordinated third-party censorship.
Accountability
Filing unverified or fraudulent dispute claims penalizes the reporter false_report_rate, permanently devaluing future testimony across the network.
The alpha contract · safety guarantee
Zero Risk to Existing Infrastructure: Participating in fleetmesh peer accounting never compromises local database state or existing relay operations. Bilateral rate enforcement affects only inter-node replication budgets, and operators can disengage via configuration at any time.
Specification references: § Grants, § Severity ladder, and § Trust weighting. Visual references are available on the Protocol Emblems page.