一项概念验证项目在Yggdrasil覆盖网络上实现了朋友之间的分片加密文件存储功能1。该项目将文件分割成4 MiB块,采用AES-256-GCM加密,并通过Reed-Solomon纠删码生成冗余备份1。系统根据在线机器数量动态调整分片策略:3台机器时采用4+2配置,6至8台机器时保持4+2配置,9台及以上时升级为6+3配置1。任何单个节点最多只持有一个块的2个分片,确保即使任意节点故障也不会导致数据丢失1。
项目提供了仪表板界面、文件版本历史、消息传递和网站托管等功能1。系统采用从公钥派生的Yggdrasil地址作为节点标识,并通过peers.json中的成员列表限制访问权限1。新版本存储时仅记录相比前版本的变更部分,以优化存储效率1。项目已开源发布,支持Windows、Linux、macOS及树莓派等多个平台1。
该项目目前处于实验阶段,其密码学实现尚未经过独立审查,因此不建议作为数据的唯一副本使用1。
A new experimental project enables secure, distributed file storage among trusted peers using the Yggdrasil overlay network 1. The system, which remains in early stages, divides files into sharded fragments protected with encryption and redundancy mechanisms to prevent data loss even when individual nodes fail 1.
Files are split into 4 MiB blocks and encrypted using AES-256-GCM, then encoded with Reed-Solomon erasure codes to create redundant copies across the network 1. The sharding strategy adapts based on the number of online machines: configurations use 4+2 encoding for networks with three to eight participants, and 6+3 encoding for nine or more machines 1. Critically, no single node stores more than two fragments of any given block, ensuring that the failure of any individual machine cannot result in data loss 1. The system derives node identities from public keys formatted as Yggdrasil addresses, restricting access to members listed in a peers.json configuration file 1.
Beyond basic storage, the platform offers file version history with incremental updates, peer-to-peer messaging, and website hosting capabilities 1. The project is open source and available across multiple operating systems, including Windows, Linux, macOS, and Raspberry Pi 1. However, the developers caution that the cryptography has not undergone independent security review and recommend against relying on the system as a sole backup for critical data 1.
评论
还没有评论,欢迎留下第一条。