Release of Yggdrasil 0.4, an implementation of a private network operating over the internet

The release of the reference implementation of the Yggdrasil protocol 0.4 has been published, allowing the deployment of a separate decentralized private IPv6 network over the existing global network, using end-to-end encryption to protect privacy. Any existing applications that support IPv6 can work over the Yggdrasil network. The implementation is written in Go and is distributed under the LGPLv3 license. It supports Linux, Windows, macOS, FreeBSD, OpenBSD, and Ubiquiti EdgeRouter platforms.

Yggdrasil develops a new routing concept for creating a global decentralized network, where nodes can connect directly to each other in a mesh network (for example, via Wi-Fi or Bluetooth) and interact over existing IPv6 or IPv4 networks (network over network). A distinctive feature of Yggdrasil is its self-organizing operation, without the need for explicit routing configuration — route information is calculated based on the node's position in relation to other nodes in the network. Devices are addressed using a standard IPv6 address that remains unchanged when the node moves (Yggdrasil uses an unused address range 0200::/7).

The entire Yggdrasil network is viewed not as a collection of disparate subnets, but as a single structured spanning tree, which has one "root", and each node has one parent as well as one or more children. This tree structure allows constructing a route to the destination node relative to the source node, using a "locator" mechanism that determines the optimal path from the root to the node.

Information about the tree is distributed among the nodes and is not stored centrally. A distributed hash table (DHT) is used for routing data exchange, through which a node can retrieve all routing information to another node. The network itself provides only end-to-end encryption (transit nodes cannot determine the content), but does not ensure anonymity (when connected via the internet, peer nodes that interact directly can identify the real IP address, so it is recommended to connect nodes through Tor or I2P for anonymity).

It is noted that despite the project being in the alpha development stage, it is already stable enough for daily use but does not guarantee backward compatibility between releases. For Yggdrasil 0.4, the community supports a set of services including a platform for hosting Linux containers for hosting websites, the YaCy search engine, a communication Matrix, an IRC server, DNS, a VoIP system, a BitTorrent tracker, a connection point map, a gateway to IPFS, and proxies for accessing Tor, I2P, and clearnet networks. server The new routing scheme is not compatible with previous Yggdrasil releases.

In the new version:

  • When establishing TLS connections with nodes, key pinning is employed. If key pinning is absent during the connection, the key obtained will be bound to the connection. If pinning was established but the key does not match it, the connection will be rejected. TLS with key pinning is defined as the recommended method for connecting to the pyramid.
  • The routing and session management code has been completely redesigned and rewritten, increasing throughput and reliability, especially for nodes that frequently change peers. Periodic key rotation has been implemented in cryptographic sessions. Support for source routing has been added, which can be used to redirect user IPv6 traffic. The architecture of the distributed hash table (DHT) has been restructured and support for DHT-based routing has been added. The implementation of routing algorithms has been moved to a separate library.
  • IPv6 addresses are now generated from ed25519 public keys rather than their X25519 hash, which will lead to a change in all internal IPs after transitioning to Yggdrasil 0.4.
  • an IP address Additional settings have been provided for searching Multicast peers.
  • A release of the reference implementation of the Yggdrasil 0.4 protocol has been published, allowing for the deployment of a separate decentralized private IPv6 network on top of the regular global network to protect privacy.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster