Bảo vệ blind relay khỏi lạm dụng
Cách node AeroNyx chặn replay, vòng lặp, quá tải và peer lỗi mà không đọc ciphertext, đồng thời cung cấp bằng chứng vận hành bảo vệ riêng tư.
Blind Relay Abuse Guard là ranh giới an toàn của chuyển tiếp mã hóa phi tập trung AeroNyx. Nó giới hạn relay lạm dụng hoặc bất ổn mà không phân tích ciphertext, không tạo lịch sử route lâu dài và không biến operator thành người quan sát traffic.
Trạng thái và phạm vi
Guard được triển khai bằng Rust và kết quả tổng hợp xuất hiện trong node health metadata cùng Nodeboard. Vai trò là kiềm chế và cung cấp bằng chứng trung thực: opaque relay work được accepted, protected, degraded hay stale, không tiết lộ nội dung.
| Kiểm soát | Trạng thái |
|---|---|
| Blind payload forwarding | Đã triển khai |
| Signed freshness and replay suppression | Đã triển khai |
| Previous-hop rate limiting and quarantine | Đã triển khai |
| Privacy-safe runtime evidence | Đã triển khai |
| Nodeboard operator visibility | Đã triển khai |
| Plaintext or payload inspection | Bị cấm |
| User, route, or social-graph analytics | Bị cấm |
Bất biến node mù
Relay có thể xác thực chữ ký routing metadata, áp dụng policy hữu hạn, chuyển opaque envelope và trả terminal-signed receipt. Relay không được kiểm tra hoặc suy ra payload, cũng không lộ metadata có thể dựng lại route, danh tính hay quan hệ xã hội.
- message plaintext, packet payload, media content hoặc MemChain plaintext
- DNS content, destination, domain, URL hoặc browsing history
- route ID, complete path, endpoint URL hoặc client public IP
- full public key, receiver identity, message ID hoặc social graph
- private key, voucher secret, wallet-level traffic hoặc decryption material
Luồng tiếp nhận
Mỗi request qua kiểm tra hữu hạn trước khi dùng forwarding capacity. Thứ tự dưới đây mang tính khái niệm; quyết định chỉ dùng signed routing metadata và local aggregate state, không dùng nội dung giải mã.
verify signed previous_hop and envelope
apply in-flight backpressure
check timestamp freshness
check route replay cache
apply previous-hop rate/quarantine decision
validate TTL, loop safety, next-hop descriptor, and endpoint
forward opaque ciphertext or terminate into pending store
Bảo vệ replay và độ mới
Replay suppression là local, ngắn hạn và giới hạn dung lượng. Signed timestamp loại frame cũ hoặc quá xa trong tương lai. Bảng là runtime default hiện tại của main, không phải cam kết protocol vĩnh viễn; thay đổi phải cập nhật test và docs.
| Hằng runtime | Mặc định hiện tại |
|---|---|
MAX_BLIND_RELAY_SEEN_ROUTES | 8192 route IDs |
BLIND_RELAY_ROUTE_REPLAY_WINDOW_SECS | 600 seconds |
BLIND_RELAY_PREVIOUS_HOP_RATE_LIMIT | 120 requests / 60 seconds |
BLIND_RELAY_PREVIOUS_HOP_FAILURE_THRESHOLD | 12 scored failures / 300 seconds |
BLIND_RELAY_PREVIOUS_HOP_QUARANTINE_SECS | 300 seconds |
MAX_BLIND_RELAY_PREVIOUS_HOP_BUCKETS | 4096 buckets |
BLIND_RELAY_MAX_ENVELOPE_AGE_SECS | 600 seconds |
BLIND_RELAY_MAX_FUTURE_SKEW_SECS | 120 seconds |
BLIND_RELAY_DELIVERY_RECEIPT_MAX_AGE_SECS | 120 seconds |
MAX_BLIND_RELAY_FORWARD_ATTEMPTS | 3 attempts |
Giới hạn tốc độ và cách ly hop trước
Rate limit theo signed previous-hop identity. Hơn 120 request trong 60 giây bắt đầu local quarantine 5 phút. Failure score riêng bắt đầu cùng cách ly sau 12 validation failure có tính tấn công trong 5 phút.
invalid_previous_hop | invalid_signature | self_loop | route_loop | ttl_exhausted
Chỉ adversarial validation reason tăng score. Transport timeout, ACK mất và duplicate route retry không phạt peer khỏe. Bucket store có giới hạn, idle state hết hạn nên không trở thành communication graph lâu dài.
Tính idempotent và retry
Route ID lặp trong replay window nhận idempotent success: ghi một aggregate replay drop nhưng không giao hoặc forward envelope lần hai. Next-hop failure tạm thời thử tối đa ba lần với bounded jitter; validation failure vĩnh viễn không retry.
duplicate route_id -> accepted=true, reason=duplicate_route, no second delivery
transient next-hop failure -> bounded retry with deterministic jitter
permanent validation failure -> no retry
Counter runtime tổng hợp
Rust cung cấp coarse cumulative counter và freshness timestamp ở hai path sau. Đây là node-scoped operational evidence, không phải message log, analytics tính phí hay bằng chứng về một conversation cụ thể.
system_stats.discovery_status.peer_store.runtime.blind_relay
system_stats.discovery_status.peer_store.peer_health_summary
| Nhóm counter | Trường |
|---|---|
| Tiếp nhận và kết quả | received, terminal, forwarded, rejected |
| Xác thực và bảo vệ | invalid_signature, envelope_too_large, ttl_exhausted, no_route, invalid_endpoint, loop_detected, replay_dropped, timestamp_rejected, rate_limited, quarantined, quarantine_started |
| Transport và retry | backpressure_dropped, forward_failed, retry_attempted, retry_succeeded, retry_exhausted |
| Bằng chứng tổng hợp | probe_attempted, probe_succeeded, probe_failed, two_hop_probe_attempted, two_hop_probe_succeeded, two_hop_probe_failed |
| Giao thực và độ mới | verified_client_onion_deliveries, last_verified_client_onion_delivery_at, last_accepted_at, last_event_at |
Ngữ nghĩa chất lượng bằng chứng
Quality summary tách accepted opaque work, synthetic probe, synthetic two-hop proof và terminal-signed client receipt. real_relay_ready yêu cầu fresh authenticated client-originated receipt do expected terminal ký. Không trình bày synthetic evidence như App/user traffic.
status | Ý nghĩa |
|---|---|
idle | Chưa có relay hoặc probe evidence. |
observing | Có evidence một phần nhưng readiness chưa thiết lập. |
stale | Evidence thành công trước không còn fresh. |
ready | Có fresh accepted work hoặc proof, không có active transport attention. |
protecting | Counter bảo vệ đang hoạt động và relay vẫn chạy. |
degraded | Forwarding hoặc probe failure cần điều tra. |
attention | Backpressure hoặc retry cạn cần xử lý ngay. |
proof_scope tách client_message_delivery, relay_acceptance, message_delivery, control_plane, single_hop_control_plane, attempted, none. Historical totals tích lũy; readiness cần fresh evidence và tính active transport failures.
Sức khỏe peer bảo vệ riêng tư
peer_health_summary dùng node identifier rút gọn và coarse health bucket để cô lập failing/quarantined peer mà không lộ traffic relationship. Đây là control-plane diagnostic với privacy boundary rõ ràng.
Được phép:
node_id_prefixrút gọn- coarse health và descriptor state
- gossip và route success freshness bucket
- aggregate route success/failure counts
- aggregate loop/replay/rate-limit/quarantine counts
- thời gian quarantine còn lại và bounded reason bucket
Không được phép:
- full node public keys
- route IDs hoặc endpoint lists
- encrypted blobs hoặc payload hashes
- message IDs hoặc receiver identity
- client IP, destinations hoặc DNS
- social graph hoặc quan hệ giao tiếp
Quy trình operator
Mở Nodeboard, chọn node, xem Discovery và Security / Relay Protection. Chỉ diễn giải xu hướng cùng node health, reachability, queue pressure và signed proof freshness.
- Xác nhận freshness của descriptor và bootstrap recovery.
- So sánh
accepted_total,accepted_percentvà last accepted age trước khi tuyên bố ready. - Phân biệt
real_relay_readyvới synthetic readiness; chỉ cái đầu chứng minh authenticated client-originated terminal receipt. - Khi protecting, degraded hoặc attention, xem aggregate bucket và transport health mà không yêu cầu user-level log.
Bản đồ source
Dùng repository-relative path để đặc tả vẫn đúng khi chuyển host. Backend và Nodeboard ở repository riêng, chỉ dùng owner-scoped privacy-safe metadata.
| Lớp | Đường dẫn repository | Vai trò |
|---|---|---|
| Rust relay API | crates/aeronyx-server/src/api/chat_peer.rs | Xác thực envelope, áp dụng loop, replay, freshness, rate, quarantine, retry và terminal receipt. |
| Rust PeerStore | crates/aeronyx-server/src/services/peer_store.rs | Lưu bounded counters, peer health, readiness và proof classification. |
| Rust health API | crates/aeronyx-server/src/api/vpn_health.rs | Xuất local privacy-safe health JSON. |
| Rust reporter | crates/aeronyx-server/src/management/reporter.rs | Mang aggregate status trong heartbeat metadata. |
| Backend observability | privacy_network/api/vpn_observability.py | Trả owner-scoped metadata cho operator console. |
| Nodeboard types | types/index.ts | Định nghĩa blind relay và peer health type. |
| Nodeboard detail và i18n | app/dashboard/nodes/[id]/page.tsx and lib/i18n/index.ts | Hiển thị Security / Relay Protection với privacy-boundary copy đã dịch. |
Nền tảng cho routing nhiều hop
Multi-hop cần replay resistance, loop containment, bounded retry, peer quarantine và evidence không bị nhầm với user traffic. Guard tạo nền cho layered encryption và route diversity mà không làm yếu blind-node invariant.
Quy tắc phát triển
Mỗi field mới là một privacy review. Metric phải trả lời độ tin cậy node mà không nhận dạng payload, sender, receiver, path, endpoint hoặc conversation.
- Giữ
payload_b64opaque trong mọi relay path. - Chỉ thêm aggregate counter hoặc bounded reason bucket.
- Không join counter với route, endpoint, user, receiver hoặc message metadata.
- Không cộng synthetic probe vào encrypted message, packet và byte totals.
- Cập nhật Rust tests, Nodeboard types và mọi ngôn ngữ khi semantics đổi.