AEGIS · Phase 8 complete

Encryption hides what you said. This hides that you spoke.

Encryption keeps the contents of a message private. It does not hide that the message happened. An observer watching the network still sees who is talking to whom, when, and how many kilobytes (KB) moved — which in sensitive settings can matter as much as the words. AEGIS keeps traffic between the members of a closed group flowing at a constant rate whether there is anything to send or not, so the timing and the volume carry no signal.

LanguageRust
AdversaryGlobal passive
Workspace tests195 passing
Fuzzing1.17M+ execs
Last pushrecently
The one rule

“Nothing is done until an attack simulation confirms it.”

Intuition about traffic analysis failed repeatedly during development. Only the simulation harness proved trustworthy, so it became the gate. The Python harness in sim/ is the evidence ledger behind every quantitative claim in the specification — not an afterthought that validates a design already shipped.

In plain English

What this is, in one minute

The problem

Someone who can watch the network does not need to break the encryption. They see that one endpoint sent 14 KB at 09:41:03 and another received 14 KB three seconds later, and that the same thing happens twice a day for eleven weeks. Repeated often enough, that is a map of who works with whom, drawn without reading a single message.

The solution

AEGIS makes the wire look the same at all times. Traffic goes out at a constant rate whether there is anything to send or not, and what arrives is padded to a fixed size, so there is no burst at one end to match against a burst at the other. It costs bandwidth and it adds delay; the demonstration below shows the protection and the price side by side.

Who it is for

Newsrooms and anyone protecting a source, where the time and the size of a contact are what expose a person. Banks, insurers and industry bodies that compete with each other and still have to exchange data. Organisations that share warnings about attacks, where being seen to share can itself be the sensitive part.

Hiding the contents is the easier half. Hiding the pattern is the part that needs the engineering below: the threat in full, an attack you can run yourself against both configurations, the test numbers, and where the guarantees stop.
The threat

Metadata is the part that identifies you

A global passive adversary cannot read your messages. It does not need to. It watches every link at once and correlates: this endpoint transmitted 14 KB at 09:41:03, that endpoint received 14 KB at 09:41:06, and the pattern repeats twice a day for eleven weeks.

Volume and timing are enough to reconstruct the relationship graph of an entire organisation without breaking a single cipher. For a consortium — banks settling with each other, hospitals sharing records, newsrooms with sources — the graph is the sensitive information.

AEGIS makes the wire a flat, unchanging wall. Constant rate regardless of what is happening underneath, so volume and timing carry no signal at all. The demonstration below lets you run the attack against both configurations and see the difference.

Mode 1

Shaped mixnet

Small and bursty data plus all control traffic. Sphinx packets emitted at a constant rate, with hard-cap receiver padding so a receiver’s inbound volume is also fixed.

Mode 2

Bulk plane

Large file transfer with a tunable security level — raw, bucketed, or uniformly batched. You choose where you sit on the cost curve; nothing is hidden about the price.

Interactive

Be the global passive adversary

Five senders are each talking to exactly one of five receivers. You see only the traffic volume on every link — never the contents, never the routing. Correlate the series and try to recover the pairing. Then switch the constant-rate defence on and try again.

Two wire profiles compared: unshaped traffic shows traceable bursts and the adversary recovers the relationship graph; constant-rate shaped traffic is flat and recovery drops to chance
scroll to see the whole diagram →
What the adversary actually sees. Run the attack yourself below — the numbers in this picture are the ones the demo produces.

traffic-analysis harness

Sender link Receiver link Correlation, high Correlation, low

Adversary’s conclusion

Correlating…
 
Pairs recovered
—
Peak correlation
—

Cost of the defence

Bandwidth
1.0×
Added latency
0 ms

Chance is 20% — one pair in five recovered by guessing. Anything meaningfully above that is the adversary winning. The cost figures are the honest other half: constant-rate shaping is not free, and AEGIS does not pretend it is.

A single-hop illustration written for this page. The real system layers Sphinx routing, guard-node vetting, distributed randomness beacons and zero-knowledge reputation proofs on top of the shaping shown here.
Evidence

Eight phases, each behind a red-team gate

Implementation is complete through Phase 8, hardening. These are the numbers the repository reports: the fuzzing ran under the Windows Subsystem for Linux (WSL), and the testnet ran over real Transmission Control Protocol (TCP) sockets.

36/36
Crypto test vectors
195
Workspace tests passing
1.17M+
Fuzz executions, zero crashes
41/41
Topology tests
AreaResultNotes
Crypto vectors36 / 36 
Relay routing14 / 14 
Topology41 / 41 
Negotiator / bulk correlation25 / 25 
Workspace tests195All passing
Security fuzzing1.17M+libFuzzer via WSL, zero crashes
TestnetReal TCPSphinx packet routing over real sockets
Trace analysisBenign vs maliciousReal-trace comparison
Who it is for

Hides who is talking, not just what was said

Scrambling a message is a solved problem. What it does not hide is that you sent one, who to, when, and how much. That pattern alone is often enough to identify people.

01

Newsrooms and anyone protecting a source

Nobody needs to read the message if they can see that a particular person contacted a particular journalist at two in the morning. The timing and the size are what expose people.

02

Rival companies that still have to share data

Banks, insurers and industry groups exchange information while competing. Who you are suddenly talking to, and how often, gives away what you are working on.

03

Organisations swapping warnings about attacks

Sharing threat information is useful, but being seen to share it can itself be the sensitive part. This keeps the fact of the conversation private, not just its contents.

Recognise your situation here? This is open for beta testing now, and the people it is built for are the ones whose feedback actually changes it. Become a beta tester →
Defences

What sits on top of the shaping

  • Forward-secrecy handshakes. Compromise of long-term keys does not retroactively expose sessions.
  • Reputation-aware path selection. Routes prefer relays with established behaviour.
  • Distributed randomness beacons. No single party controls path selection entropy.
  • Zero-knowledge reputation proofs. A relay proves it exceeds a reputation threshold without revealing its score.
  • Guard-node vetting. Sybil resistance at the point where it matters most.
Honest boundaries

Where the guarantees stop

  • Internal traffic only. Strong guarantees apply inside the consortium. Clearnet exit is weaker and is not claimed otherwise.
  • Empirical, not proven. Results are empirical bounds under the stated adversary model. They are not mathematical proofs.
  • Latency is inherent. Multi-second latency is a property of the design, not a tuning problem that will be optimised away.
  • Wrong tool for two parties. AEGIS suits relationship-graph hiding across many endpoints. For a two-party link, link-layer defences do better.
  • Open research remains. docs/ops/RESEARCH_AGENDA.md is the honest backlog of what is not finished.
Repository hygiene: Continuous Integration (CI) on GitHub Actions, cargo deny dependency auditing, and a workspace-wide policy forbidding unsafe code. For a Rust network stack handling adversarial input, #![forbid(unsafe_code)] across the workspace is the single most load-bearing line in the project.