Home/How it works

Patience is a protocol

Store. Carry. Forward.

Delay-tolerant networking for people, not spacecraft. A network doesn’t need a connected path if it has patient storage and moving carriers.

Delay-tolerant networking

It’s a real discipline with real history. NASA built it because a packet to Mars takes four to twenty-four minutes each way and there is no such thing as an end-to-end path. The insight generalizes far beyond space.

The internet is a store-and-forward network measured in milliseconds. A DTN is the same idea measured in hours or days — and it works precisely where the internet’s assumptions break down, which is exactly where a LoRa mesh lives.

Ordinary mesh routing

A → relay → relay → B
all at once, or nothing


Store-carry-forward

A → storage → someone walking
→ storage → someone driving → B
whenever

Custody

When a node takes your message, it takes responsibility for it. It doesn’t forward-and-forget; it holds until somebody better has it.

Opportunism

There is no route. There is only who happens to be here now, and a set of rules for deciding what to hand over in the seconds you’re in range.

Patience

Time is a resource, not a failure. A message that takes six hours is a message that arrived.

A real message

One message, one day, five strangers

No Internet. No central server. Just people, radios, and time.

Infographic: your message doesn't fail, it waits. A timeline follows one message from Adam at 8:04 AM through Station A, Carol's phone, a 35-mile drive, Station B, and delivery to Bob at 5:31 PM, with a delivery receipt back to Adam at 6:58 PM. A panel below shows what each participant knew and did not know: the carrier and the stations never learn the sender, recipient or contents.
Click the diagram to view it full size.

Step by step

The journey of one message

You write it.

It’s sealed on your phone before it touches anything — X25519, HKDF-SHA256 and ChaCha20-Poly1305, addressed to one person’s key. Nothing home-grown, nothing invented here.

If they’re reachable, it goes now.

In Auto, the default, it goes the MeshCore way first: an ordinary MeshCore message, over ordinary repeaters. Set a contact or a single message to MeshDTN and it skips this step and is carried from the start; set it to MeshCore and it ends here, delivered or failed.

If they’re not, your phone keeps it.

Not the radio — the phone. Gigabytes of storage and a battery you charge every night, instead of a few kilobytes of RAM on a device you mounted twenty feet up a pole.

Your radio meets another MeshDTN node.

A stranger walking past. A colleague at the office. A station on a hilltop. The two phones exchange a short list of identifiers — not contents, not destinations, not names — and hand over whatever the other side is missing.

The stranger carries your message and cannot read it.

It’s ciphertext addressed to somebody else. They can’t tell who it’s for, who it’s from, or what it says. They’re doing you a favor they can’t inspect.

Copies spread, under a budget.

Not a flood. Spray-and-Wait replication gives each message a copy budget so the network stays healthy, with copies handed only to peers who don’t already have one.

A copy reaches the recipient and opens.

Their key works. Nobody else’s does.

The network learns it landed.

A kill record propagates back — cryptographically authorized, so nobody can fake one — and every carrier holding a copy drops it. You find out your message arrived. No other off-grid mesh gives you that.

Two ways to send

What each way puts on the air

Every contact is set to MeshCore, Auto or MeshDTN, and any single message can override it. Auto is the default. The difference that matters is what goes on the air.

SentThe MeshCore wayThe MeshDTN way
On the wireA stock MeshCore text message, flood or directMeshDTN carry frames, handed on only between MeshDTN nodes that have switched relaying on
Who can move itAny MeshCore repeater, room server or nodeOnly MeshDTN carriers and stations
Destination on the airA destination hash, visible to every hopNone a carrier can read — an 8-byte tag, different every message
Can a hop log itYes, as any repeater can todayNo
Recipient absentFails after retries, and you are toldWaits, up to ninety days
Delivery receiptMeshCore’s acknowledgementA MeshDTN delivery receipt

Scroll the table sideways to see every column.

A MeshCore-way message is exactly as private as MeshCore

No more. Every hop can see which contact it is for. Auto sends the MeshCore way first, and only a message the radio cannot deliver is carried.

A MeshDTN-way message has no readable destination on the air

Nothing a hop can read says who it is for. The app shows which way each message went, on the message itself, so you never have to guess.

Bounded by design

What makes the maths work

Everything is bounded, because airtime is scarce and honesty about that is the difference between a network and a broadcast storm.

Copy budgets

Cap how many copies of a message exist anywhere in the network.

Per-transport budgets

A fast link can’t burn a budget derived from a slow one.

Fairness rules

Stop one long message monopolizing an encounter.

Rotating offer sets

Guarantee that in a large store, every message gets its turn — not just the newest fifteen.

Exact kill indexes

Delivered messages stop traveling immediately, network-wide, on a record no passer-by can forge.

What a carrier can see

A blob, a size, and an expiry

A node carrying your message can see that it holds a blob of ciphertext of a certain size, a short opaque identifier for it, when it expires, and how many phones have already carried it. That is the entire list.

It cannot see the contents, who it’s from, or who it’s for — because the 8 bytes that identify the recipient are different on every message. It cannot even tell whether a message is for them until they try their own key.

Deliberately absent: the internet

We considered linking stations over IP and rejected it. Payloads would stay sealed, but a central service would see every station, every identifier and every timestamp in one place — and the first station to receive a message got it from someone standing nearby. That reassembles a movement trace of senders in the one component with a complete view.

It’s also a one-way door: you can add a hub later, you can’t credibly remove one. And if an internet path exists it becomes the default path, after which the store-and-carry network rots quietly and fails on the day it’s needed.

Every phone is a mailbag.

See which links carry a message, and what each one costs.