Clean-Room Clean Architecture • Protocol v0.4.0

The sovereign WAN mesh engineered for the post-quantum era.

Global Ghost Net is an autonomous peer-to-peer routing daemon written in pure Rust. It eliminates centralized VPN providers, commercial exit relays, and trusted Certificate Authorities through clean-room multi-hop datagram routing, Reed-Solomon polynomial sharding, and NIST FIPS 203 ML-KEM-512 cryptography.

ML-KEM-512
Lattice Post-Quantum KEM
RS(2,1) GF(256)
Asymmetric Shard Ratio
512 Bytes
Uniform GTF Frame Size
0 Cores / CAs
Central Infrastructure

Reed-Solomon Multi-Path Sharder

See how plain text is encrypted under ephemeral Kyber session keys and dispersed across divergent global routes.

SHARD 1 [DATA POLY A] ROUTE: FRANKFURT → REYKJAVIK
0x8B4E...FIPS203_KYBER_CIPHER_MAT
INTERCEPTOR VIEW: PURE NOISE (ZERO PLAINTEXT)
SHARD 2 [DATA POLY B] ROUTE: WARSAW → TOKYO
0x3A9F...REED_SOLOMON_GF256_PAR
INTERCEPTOR VIEW: PURE NOISE (ZERO PLAINTEXT)
SHARD 3 [PARITY RECOVERY] ROUTE: ZURICH → SAO PAULO
0xF12C...UNIFORM_PADDING_JITTER
RECONSTRUCTION: ANY 2 OF 3 REASSEMBLES EGRESS

512-Byte Ghost Transport Frame (GTF) Structure

Hover over byte boundaries to inspect protocol headers and padding.

STRICT 512-BYTE ENVELOPE
MAGIC [4B]
NONCE [8B]
POLY1305 [16B]
REED-SOLOMON SHARD PAYLOAD [452B]
NOISE [32B]
Field: Hover over a segment above
Range: [0..512 Bytes]

Engineered From First Principles in Rust

Zero C/C++ dependencies. Zero OpenSSL. Clean-room verification.

01 / CRYPTOGRAPHIC SUITE

Dual-Layer Hybrid Key Agreement

Combines classical X25519 ECDH with post-quantum ML-KEM-512 (Kyber / FIPS 203). Secrets are mixed via HKDF-SHA256 with optional pre-shared key injection (GHOST_PSK). Authenticated payload encryption uses ChaCha20-Poly1305 with monotonic 64-bit anti-replay windowing.

  • NIST FIPS 203 Lattice Encryption
  • 64-bit Monotonic Replay Protection
  • Directional Session Hash Nonce Derivation
02 / TRANSPORT MESH

Ghost Transport Frames (GTF)

Avoids TCP circuit stalls and connection resets. Operates over UDP with fixed 512-byte frames. Variable payload chunks are randomized with pseudo-noise padding, blinding Deep Packet Inspection (DPI) heuristics from recognizing stream contents.

  • Zero Head-of-Line Blocking
  • Uniform 512-byte Datagram Envelopes
  • Randomized Jitter Sleep Intervals
03 / PEER DISCOVERY

Zero-Cost Decentralized Seeding

Nodes bootstrap without paying for coordinator servers. Relays discover peers through signed DNS TXT records, local subnet multicast UDP beacons (for zero-config LAN mesh), and gossip-based peer exchange (PEX).

  • Cloudflare DNS TXT Seed Bootstrap
  • LAN Multicast Autodiscovery
  • Autonomous Dynamic Node Failover

Why Legacy Networks Fail Against Modern Surveillance

A technical comparison between traditional commercial VPNs, Tor, WireGuard, and Global Ghost Net.

Cryptographic & Sharding Throughput

Measured on AMD Ryzen / Linux x86_64 using Rust AVX2 vector intrinsics.

18.4 µs
ML-KEM-512 Handshake
NIST Kyber Encapsulation
3.2 GB/s
ChaCha20-Poly1305
Single-Core Encryption
4.1 µs
RS(2,1) Erasure Sharding
Galois Field GF(256) Math
< 14 MB
Memory Footprint
Zero-Allocation Steady State
Protocol Dimension Legacy Commercial VPNs The Tor Project WireGuard Global Ghost Net (v0.4)
Quantum Resistance None (RSA / Classical DH) None (Curve25519) None (Optional static PSK) Native Hybrid ML-KEM-512 + X25519
Single Point of Failure Central VPN Server / Logs Directory Authorities (9 Hardcoded) Static IP Endpoint Required Zero Coordinators (Serverless Mesh)
Transport Transport TCP / UDP encapsulation TCP (Suffers head-of-line blocking) UDP Single-Path Datagram Fixed 512-byte Ghost UDP Frames
Traffic Analysis & DPI Vulnerable to packet-size inspection Cell-padded, vulnerable to timing correlation Strict length leaks packet volume Uniform Padding + Microsecond Jitter
Multi-Path Resilience Single WAN path (Fails on choke) Single sequential circuit Single point-to-point tunnel Reed-Solomon (2,1) Asymmetric Sharding

Run Global Ghost Net in 30 Seconds

Built-in SOCKS5 proxy server immediately exposes 127.0.0.1:1080 for browsers and applications.

ONE-LINE ZERO-CONFIG INSTALL
# Linux / macOS:curl -sSf https://ggn.kellersystems.dev/install.sh | sh
POSIX
# Windows PowerShell:irm https://ggn.kellersystems.dev/install.ps1 | iex
PWSH
git clone https://github.com/KELLERBABG/Global-Ghost-Net.git && cd Global-Ghost-Net && cargo build --release && ./target/release/ggn-daemon --listen 0.0.0.0:2270 --socks 127.0.0.1:1080
CLICK TO COPY