← Executive Summary • Pillar 05: Customer-Centric UX & Sovereign Identity
Decentralized Protocols, KERI DHT & Key Derivation

Decentralized Protocols, KERI DHT &
HKDF Key Derivation Engines

Designing peer-to-peer protocols, Key Event Receipt Infrastructure (KERI), Kademlia Distributed Hash Tables (DHT), hardware entropy collection, BIP-39 / HKDF key derivation, and Stellar blockchain DEX tokenization. Upstream libraries (such as OpenDHT, Libsodium, and Stellar Horizon) are explicitly attributed.

Digital credentials connecting through a cryptographic key to verification
ISSUE → SIGN → VERIFY Hyperledger Indy DID Pools, W3C Verifiable Credentials & Zero-Knowledge Cryptographic Privacy
Executive TL;DR

Decentralized Identity & Cryptography

View 5 Pillars →
🎯 Business Context

Self-sovereign decentralized identity (SSI) and privacy-first biometric credential signing ecosystems.

⚡ Technical Hurdle

W3C DID document resolution, Hyperledger Indy/Aries agent cryptographic handshakes, and HSM key isolation.

🏆 Deliverable & Impact

Native Android/iOS sovereign identity wallets, hardware-backed ECDSA signing, and verifiable credential verification.

256 Bits
Entropy Key Derivation
BIP-39 Mnemonics & HKDF-SHA256 Spreading
0 Central Server
Kademlia DHT Discovery
P2P KERI Key Log Verification
100%
Decentralized Storage
ClearGFS Distributed Framework
1 DEX Horizon
Stellar Blockchain Integration
Asset Tokenization & Trading Nodes

Decentralized Projects & Protocols

Select any project card below to view its technical sub-page.

ClearNODE Peer-to-Peer Daemon

Peer-to-peer daemon software enabling decentralized node communication, state synchronization, and encrypted payload routing.

  • ✓
    Decentralized P2P Service Daemon: Built native C++/Go network daemon running peer-to-peer node discovery, node health heartbeats, and encrypted message routing.
  • ✓
    Kademlia XOR Distance Routing: Implemented Kademlia routing table algorithm using 256-bit XOR metric distance for efficient O(log N) peer lookups.
  • ✓
    NAT Traversal & Hole Punching: Engineered UDP STUN/TURN NAT traversal mechanisms to establish direct peer-to-peer socket connections across restrictive firewalls.
  • ✓
    UPnP & Port Mapping Automation: Integrated Universal Plug and Play (UPnP) port mapping protocols for seamless home router configuration without user intervention.
  • ✓
    Encrypted Wire Guard Transport Protocol: Secured node-to-node communication channels using Noise protocol framework and Curve25519 public-key encryption.
  • ✓
    Cross-Platform System Daemon Deployment: Packaged clearnode as a system service for Linux, macOS, and custom AOSP Android background initialization.

ClearGFS Storage Framework

Distributed storage protocol providing encrypted file chunking, replication, and seamless Android OS file system integration.

ClearGFS Distributed Storage Architecture
Inspect Architecture Diagram
Distributed Storage • P2P Swarm

ClearGFS Chunking, AES-GCM & Merkle Tree Pipeline

Seamless POSIX virtual file system mounting over decentralized, erasure-coded P2P storage node clusters.

  • ✓
    Distributed Encrypted File System Engine: Architected cleargfs protocol handling client-side AES-256-GCM chunk encryption before transmitting storage blocks to P2P nodes.
  • ✓
    AES-GCM Authenticated Encryption: Embedded MAC integrity tags on every file chunk payload to detect network bit flips or malicious node storage tampering.
  • ✓
    Fuse Virtual File System Integration: Developed user-space Fuse file system driver exposing decentralized storage as a standard local directory on desktop and mobile platforms.
  • ✓
    Redundant Reed-Solomon Erasure Coding: Implemented Reed-Solomon (k, n) erasure coding to reconstruct missing file chunks even if n-k storage nodes go offline.
  • ✓
    Asynchronous Local Caching Layer: Designed high-throughput SQLite local cache managing LRU chunk eviction and background syncing over cellular/Wi-Fi mesh interfaces.
  • ✓
    Integrity-Checking Merkle Trees: Built Merkle tree root hash generation for instant zero-knowledge validation of multi-gigabyte decentralized file trees.
GitHub Repo

KERI Key Event Receipt Infrastructure & Kademlia DHT

Kademlia Distributed Hash Table (DHT) engine written to discover and verify Key Event Receipt Infrastructure (KERI) logs without central servers.

KERI & Kademlia DHT Architecture
Inspect Architecture Diagram
Self-Sovereign Identity • WebOfTrust

KERI Key Event Logs & Kademlia DHT Resolution Pipeline

Cryptographically verifiable key rotation and decentralized identifier resolution without central databases or blockchain consensus overhead.

  • ✓
    Zero-Trust KERI Key Log Verification: Implemented Key Event Receipt Infrastructure (KERI) validation routines for verifying self-sovereign identity key rotation logs.
  • ✓
    Kademlia DHT Key Discovery (keridemlia): Engineered specialized Kademlia Distributed Hash Table (keridht) for storing and looking up KERI key event logs without central servers.
  • ✓
    Autonomic Identifier Resolution: Resolved Decentralized Identifiers (DIDs) by querying distributed DHT nodes, enforcing cryptographic signature chain validation.
  • ✓
    Duplicity & Compromise Detection: Built consensus validation rules flagging conflicting key rotation events to prevent double-spending or identity hijacking.
  • ✓
    Lightweight Android & Embedded Bindings: Compiled keridht core modules into lightweight C/C++ static libraries exposed to Java/Kotlin via JNI interface bindings.
  • ✓
    Zero Blockchain Overhead: Eliminated proof-of-work gas fees and latency by anchoring trust entirely in cryptographic event logs and P2P DHT receipts.

Entropy, BIP-39 & HKDF Key Derivation

Hardware entropy collection, BIP-39 mnemonic phrase generation, and HKDF-SHA256 key expansion engines enabling on-device derived key generation.

Hardware Entropy & HKDF Key Derivation Architecture
Inspect Architecture Diagram
Key Lifecycle • TEE Security

BIP-39 Mnemonic Seed & HKDF Context Expansion Pipeline

Deriving mathematically isolated subsystem keys for identity, file storage, and encrypted P2P transport backed by hardware security modules.

  • ✓
    Hardware Entropy Aggregation Engine: Built entropy collection library blending Android KeyStore hardware random bytes (SecureRandom), CPU jitter, and OS entropy pools.
  • ✓
    BIP-39 Mnemonic Phrase Generation: Implemented BIP-39 standard converting 128/256-bit raw entropy seeds into 12/24-word cryptographic mnemonic passphrases (python-bip39).
  • ✓
    BIP-32 / BIP-44 Hierarchical Deterministic Keys: Engineered HD key tree derivation paths (m/44'/60'/0'/0/0) for generating unlimited child key pairs from a single master seed.
  • ✓
    HKDF-SHA256 Secret Expansion: Architected HMAC-based Extract-and-Expand Key Derivation Function (HKDF-SHA256) for deriving context-specific sub-keys.
  • ✓
    Secure Zeroization & Memory Protection: Implemented explicit memory wiping (explicit_bzero) to securely clear sensitive private key material from RAM immediately after use.
  • ✓
    ARM TrustZone TEE Backing: Integrated key derivation pipelines directly with ARM TrustZone Trusted Execution Environments for tamper-proof key computation.

Stellar Blockchain Asset & Horizon DEX

Issuing custom cryptographic assets on the Stellar blockchain network, running local Horizon DEX nodes in Docker, and managing automated liquidity and fee accounts.

  • ✓
    Custom Tokenization Asset Issuance: Issued custom cryptographic payment and utility tokens on the Stellar blockchain network using Ed25519 signing keys.
  • ✓
    Dockerized Horizon DEX Node Architecture: Built automated Docker container orchestration (docker-dex-horizon) running local Stellar Core and Horizon REST API nodes.
  • ✓
    Automated Liquidity & Trading Scripts: Developed Python/Node.js market-making scripts executing automated order book placement and DEX liquidity provision.
  • ✓
    Fee Account & Escrow Management: Managed multi-signature escrow accounts and automated transaction fee pools for fee-less user payment experiences.
  • ✓
    Path Payment & Atomic Asset Conversion: Implemented Stellar Path Payment operations for instant atomic conversion between custom tokens and XLM/USD assets.
  • ✓
    Stellar SDK Integration: Built custom Kotlin/C++ wrapper SDK handling transaction envelope XDR encoding, fee bumping, and Horizon stream listeners.

OpenDHT & Libsodium (PyNaCl)

C++ OpenDHT integration and Libsodium bindings for authenticated public-key encryption and low-overhead P2P data transport.

  • ✓
    C++ OpenDHT Distributed Infrastructure: Integrated OpenDHT C++ library (opendht) into mobile and desktop system daemons for decentralized value storage and RPC messaging.
  • ✓
    Libsodium (PyNaCl) Cryptographic Bindings: Implemented high-level Python and Kotlin bindings over Libsodium (PyNaCl) for authenticated public-key encryption (crypto_box).
  • ✓
    Ed25519 & Curve25519 Key Exchange: Handled ECDH key exchange and Ed25519 digital signature creation/verification across all P2P network layers.
  • ✓
    Asynchronous Non-Blocking P2P Listeners: Built event-driven C++ callbacks handling non-blocking DHT value changes and real-time push notification relays.
  • ✓
    End-to-End Encrypted Payload Delivery: Wrapped all DHT values in NaCl authenticated encryption boxes, ensuring stored data is readable only by intended recipient public keys.
  • ✓
    Cross-Platform C++ & JNI Bridge: Compiled native C++ OpenDHT and Libsodium modules for Android NDK target architectures (arm64-v8a, x86_64).