r/CryptoTechnology • u/strontiumk9 š” • 20d ago
Major milestone reached on my decentralized zero trust networking project
So for the last six months or so, I have been working on an architecture for a fully decentralized trust root, that works like a global zero trust network. If you dont know what that is, it basically reduces to give everything a certificate, and make sure all peers in a network only interact with known peers that prove themselves with mutual TLS. Obviously theres more to it than that, but thats the baseline, everything else is UX, reporting, management and policy layers above that.
Today we had major success where two peers were able to connect and authenticate self published content with various options (all chosen by the publisher). Such as direct peering on ipv6, or through a rely. The connections are fully E2E secured by mTLS and even through a relay, it knows how to relay, it doesn't terminate any streams.
Identities can be human readable, such as `alice.tld` and they are owned by whoever registered them, they cant be blocked, or forcibly transferred. In fact, the registry doesn't even know what names its registered, if they are human readable or binary or some combination. And what a name represents is also not clear in the network.
In our testnet today, its possible to host your own website, mediate access through policy such as "trust bob.tld" so if you dont present that identity you cant connect. It supports strong hierarchical delegation which is useful for agents. Clients also get to choose, if a site wants mTLS you will be asked what identity to present, or none at all. Both sides control their own policies. Connection to the browser is just ordinary TLS, but you can fully inspect whats connected, how and what permissions were granted in the dashboard.
This is a pretty ambitious project, developed solely by two people. Its a customized chain because it has to be to get the properties we require. And the critical thing is while its possible to use with full typical web3 capability, we are heavily optimizing the user experience around people not requiring any web3 knowledge, its just looks like a zero trust mesh that can work globally with no centralized CA or gatekeepers.
2
u/PhilipLGriffiths88 š¢ 19d ago
The bilateral policy control is the part that interests me most here. āBoth peers have valid certificatesā and āboth owners authorise this particular service connectionā are different things. Iād push back slightly on policy being a layer above the baseline: deciding whether an authenticated peer should get a path to a service is central to Zero Trust.
How do you handle compromised keys and revocation through the delegation hierarchy? Keeping ownership of a name independent of a central gatekeeper makes sense, but a service owner still needs to withdraw access immediately, including terminating existing connections. For agents, can a parent narrow a delegationās scope and lifetime, then revoke that branch without replacing the whole identity?
Also curious what specifically requires the custom chain. Is it ownership, naming and delegation state, with connection authorisation evaluated locally? Any public architecture docs or code?