NNomadAnonymity research
Back to overview

Evidence register

Every gate below is reproduced from the project's own documents: the live fabric-to-cache release gate, the distributed key-generation gate, and the production register that governs any anonymity claim.

Live testnet gate — 19 of 19 met

A gate is met only when it exists in the live data path, has a negative test, and the same commit passes race tests, vet and multi-process deployment evidence.

  • LIVE-01One pinned authority signature and every operator attestation bind the same complete topology draft.MET
  • LIVE-02Each node holds only its own identity and epoch key; hop keys are derived locally and fail closed on loose file permissions.MET
  • LIVE-03Every emitted packet is exactly 1200 bytes at the signed interval, including idle periods.MET
  • LIVE-04The 1152-byte mix ciphertext is unchanged; the padding region authenticates stream, batch, sender and sequence.MET
  • LIVE-05Unknown sources, wrong sizes, invalid tags, wrong receivers and duplicates are rejected before cache or relay.MET
  • LIVE-06Queues and stream counts are publicly bounded; cover cells are not cached; cache pressure cannot change the schedule.MET
  • LIVE-07Raw cache coordinates are immutable, atomically written and committed by a digest over the whole ordered batch.MET
  • LIVE-08The sending node imports no selection or reconstruction code; the materialiser imports no network code.MET
  • LIVE-09Three or more operators run with distinct identities, endpoints, caches, sequence state and threshold shares.MET
  • LIVE-10Partial proofs arrive through a separate fixed-cadence fetcher; the offline materialiser never contacts an operator.MET
  • LIVE-11A 2-of-3 threshold decrypt requires unique, proof-valid shares; no aggregate secret is reconstructed.MET
  • LIVE-12The descriptor carries one signed Neff shuffle per operator, and the materialiser verifies the full chained transcript.MET
  • LIVE-13Acceptance requires exact coding dimensions, SHA-256 commitment and Ed25519 signature over the object header.MET
  • LIVE-14Output is an immutable .nomadobject already trusted by the current browser trust anchor.MET
  • LIVE-15Race tests, vet, module tidiness, snapshot checks, container isolation and capture verification pass on one commit.MET
  • LIVE-16Operators generate credentials independently, exchange only public enrolments and attest one common draft offline.MET
  • LIVE-17Every operator runs the official Pedersen DKG state machine over signed, bounded messages on a public schedule.MET
  • LIVE-18Epoch activation requires one attestation from every operator over one identical public committee and transcript.MET
  • LIVE-19The descriptor embeds the distributed certificate, and live services use those exact per-operator shares.MET

Distributed key generation gate — 12 of 12 met

This gate closes the software gap between independently held operator identities and threshold decryption. Passing it does not establish independent administration.

  • DKG-01The signed topology binds membership, threshold, session, start time, phase duration and a dedicated key per operator.MET
  • DKG-02Ceremony keys are distinct from node identity and hop keys, stored 0600 and verified against the signed topology.MET
  • DKG-03The process uses an established Pedersen DKG state machine; Nomad implements no replacement primitive.MET
  • DKG-04Every message has a bounded canonical encoding and an outer signature over network, topology, epoch, session and sender.MET
  • DKG-05The transport broadcasts to every signed member, disables proxies and redirects and requires TLS 1.3.MET
  • DKG-06No message is accepted before the signed start or after its deadline; missing delivery aborts the ceremony.MET
  • DKG-07The append-only journal makes retries idempotent, treats a second value as fatal and refuses to resume a broken session.MET
  • DKG-08Activation requires the exact ordered membership; threshold-only or partial success is rejected.MET
  • DKG-09Every operator independently derives the same public committee and signs the same manifest.MET
  • DKG-10Each operator writes only its own private share, proved against the certified public share; no aggregate secret exists.MET
  • DKG-11The descriptor embeds the exact certificate; share service and materialiser reject anything not bound to it.MET
  • DKG-12The isolated deployment runs three ceremony processes over TLS and records one certificate and three distinct shares.MET

Production register — 0 of 30 met

The authoritative production register lives in nomad-protocol. No production gate is met; several are partial, and each names its own blocker.

  • PROD-01Protocol freeze and a conformance suite.REMAINS
  • PROD-02Full traceability from every production claim to a test.REMAINS
  • PROD-03An independent second implementation.REMAINS
  • PROD-04Independent cryptographic review of the mix.REMAINS
  • PROD-05At least five independently administered operators with real endpoints, witnessed key custody and drills.REMAINS
  • PROD-06+The remaining production criteria, each with its own recorded blocker in the project's register.REMAINS

Wire measurement

Recorded by a dedicated bridge during the live deployment run. Every payload was exactly 1200 bytes.

SenderCellsMeanMedianMinMax
operator a10249.993 ms49.976 ms46.516 ms53.398 ms
operator b10249.994 ms49.979 ms42.292 ms56.923 ms
operator c10249.993 ms49.965 ms48.883 ms51.748 ms

capture sha-256 630286a8740c6c39df7e9c580f5d4721901b47b0636d9b2c5cc96baaa80bb9e6