Encryption hides what you said. This hides that you spoke.
Encryption keeps the contents of a message private. It does not hide that the message happened. An observer watching the network still sees who is talking to whom, when, and how many kilobytes (KB) moved — which in sensitive settings can matter as much as the words. AEGIS keeps traffic between the members of a closed group flowing at a constant rate whether there is anything to send or not, so the timing and the volume carry no signal.
“Nothing is done until an attack simulation confirms it.”
Intuition about traffic analysis failed repeatedly during development. Only the
simulation harness proved trustworthy, so it became the gate. The Python harness in
sim/ is the evidence ledger behind every quantitative claim in the
specification — not an afterthought that validates a design already shipped.
What this is, in one minute
Someone who can watch the network does not need to break the encryption. They see that one endpoint sent 14 KB at 09:41:03 and another received 14 KB three seconds later, and that the same thing happens twice a day for eleven weeks. Repeated often enough, that is a map of who works with whom, drawn without reading a single message.
AEGIS makes the wire look the same at all times. Traffic goes out at a constant rate whether there is anything to send or not, and what arrives is padded to a fixed size, so there is no burst at one end to match against a burst at the other. It costs bandwidth and it adds delay; the demonstration below shows the protection and the price side by side.
Newsrooms and anyone protecting a source, where the time and the size of a contact are what expose a person. Banks, insurers and industry bodies that compete with each other and still have to exchange data. Organisations that share warnings about attacks, where being seen to share can itself be the sensitive part.
Metadata is the part that identifies you
A global passive adversary cannot read your messages. It does not need to. It watches every link at once and correlates: this endpoint transmitted 14 KB at 09:41:03, that endpoint received 14 KB at 09:41:06, and the pattern repeats twice a day for eleven weeks.
Volume and timing are enough to reconstruct the relationship graph of an entire organisation without breaking a single cipher. For a consortium — banks settling with each other, hospitals sharing records, newsrooms with sources — the graph is the sensitive information.
AEGIS makes the wire a flat, unchanging wall. Constant rate regardless of what is happening underneath, so volume and timing carry no signal at all. The demonstration below lets you run the attack against both configurations and see the difference.
Shaped mixnet
Small and bursty data plus all control traffic. Sphinx packets emitted at a constant rate, with hard-cap receiver padding so a receiver’s inbound volume is also fixed.
Bulk plane
Large file transfer with a tunable security level — raw, bucketed, or uniformly batched. You choose where you sit on the cost curve; nothing is hidden about the price.
Be the global passive adversary
Five senders are each talking to exactly one of five receivers. You see only the traffic volume on every link — never the contents, never the routing. Correlate the series and try to recover the pairing. Then switch the constant-rate defence on and try again.
traffic-analysis harness
Adversary’s conclusion
Cost of the defence
Chance is 20% — one pair in five recovered by guessing. Anything meaningfully above that is the adversary winning. The cost figures are the honest other half: constant-rate shaping is not free, and AEGIS does not pretend it is.
Eight phases, each behind a red-team gate
Implementation is complete through Phase 8, hardening. These are the numbers the repository reports: the fuzzing ran under the Windows Subsystem for Linux (WSL), and the testnet ran over real Transmission Control Protocol (TCP) sockets.
| Area | Result | Notes |
|---|---|---|
| Crypto vectors | 36 / 36 | |
| Relay routing | 14 / 14 | |
| Topology | 41 / 41 | |
| Negotiator / bulk correlation | 25 / 25 | |
| Workspace tests | 195 | All passing |
| Security fuzzing | 1.17M+ | libFuzzer via WSL, zero crashes |
| Testnet | Real TCP | Sphinx packet routing over real sockets |
| Trace analysis | Benign vs malicious | Real-trace comparison |
Hides who is talking, not just what was said
Scrambling a message is a solved problem. What it does not hide is that you sent one, who to, when, and how much. That pattern alone is often enough to identify people.
Newsrooms and anyone protecting a source
Nobody needs to read the message if they can see that a particular person contacted a particular journalist at two in the morning. The timing and the size are what expose people.
Rival companies that still have to share data
Banks, insurers and industry groups exchange information while competing. Who you are suddenly talking to, and how often, gives away what you are working on.
Organisations swapping warnings about attacks
Sharing threat information is useful, but being seen to share it can itself be the sensitive part. This keeps the fact of the conversation private, not just its contents.
What sits on top of the shaping
- Forward-secrecy handshakes. Compromise of long-term keys does not retroactively expose sessions.
- Reputation-aware path selection. Routes prefer relays with established behaviour.
- Distributed randomness beacons. No single party controls path selection entropy.
- Zero-knowledge reputation proofs. A relay proves it exceeds a reputation threshold without revealing its score.
- Guard-node vetting. Sybil resistance at the point where it matters most.
Where the guarantees stop
- Internal traffic only. Strong guarantees apply inside the consortium. Clearnet exit is weaker and is not claimed otherwise.
- Empirical, not proven. Results are empirical bounds under the stated adversary model. They are not mathematical proofs.
- Latency is inherent. Multi-second latency is a property of the design, not a tuning problem that will be optimised away.
- Wrong tool for two parties. AEGIS suits relationship-graph hiding across many endpoints. For a two-party link, link-layer defences do better.
- Open research remains.
docs/ops/RESEARCH_AGENDA.mdis the honest backlog of what is not finished.
cargo deny dependency auditing, and a workspace-wide policy forbidding unsafe
code. For a Rust network stack
handling adversarial input, #![forbid(unsafe_code)] across the workspace is the
single most load-bearing line in the project.