Skip to main content
Version: beta_0.0.0

Overview

An NTL signal is the atomic unit of data transfer. This document specifies the binary format, field definitions, encoding rules, and validation requirements for signals.

Wire Format

Signals are encoded in CBOR (RFC 8949) by default. The wire format consists of a fixed header followed by a CBOR-encoded body.

Header (8 bytes)

Flags

Body (CBOR)

The body is a CBOR map with the following fields:

Field Definitions

id (Signal Identifier)

  • Type: ULID (16 bytes)
  • Requirement: REQUIRED
  • Description: Universally unique, lexicographically sortable identifier. Generated by the emitting node. MUST be unique across the network.

origin (Origin Node)

  • Type: 32 bytes (BLAKE3 hash of node public key)
  • Requirement: REQUIRED
  • Description: Identifies the node that originally emitted this signal. Used for signature verification and trust scoring.

sig (Signature)

  • Type: Variable-length bytes
  • Requirement: REQUIRED
  • Description: Cryptographic signature over the signal body (excluding the signature field itself). Generated using the active crypto module. Receiving nodes MUST verify the signature before processing.

ts (Timestamp)

  • Type: Unsigned 64-bit integer
  • Requirement: REQUIRED
  • Description: Nanoseconds since Unix epoch (1970-01-01T00:00:00Z). Used for ordering, deduplication, and TTL expiry.

w (Weight)

  • Type: 32-bit float
  • Requirement: REQUIRED
  • Constraints: MUST be in range [0.0, 1.0]
  • Description: Signal priority and intensity. Affects activation thresholds and propagation priority.

ttl (Time-to-Live)

  • Type: Unsigned 16-bit integer
  • Requirement: REQUIRED
  • Constraints: MUST be > 0 on emission. Decremented at each hop.
  • Description: Maximum number of hops this signal may traverse. When TTL reaches 0, the signal MUST NOT be propagated further.

p (Payload)

  • Type: Variable-length bytes
  • Requirement: REQUIRED (may be empty)
  • Description: The actual data carried by the signal. Encoding determined by the enc field.

enc (Encoding)

  • Type: Unsigned 8-bit integer
  • Requirement: OPTIONAL (default: 0 = CBOR)
  • Values:

scope (Propagation Scope)

  • Type: Unsigned 8-bit integer
  • Requirement: OPTIONAL (default: 1 = Weighted)
  • Values:

Signal Types

del (Delivery Class)

  • Type: Unsigned 8-bit integer
  • Requirement: OPTIONAL (default: 0 = best-effort)
  • Values:
The delivery class is part of the signed body, so an intermediate node cannot downgrade it. A node that does not support acknowledged MUST reject such a signal with a negative receipt rather than accept it and degrade silently. See delivery-semantics.

Receipt Signals

A Receipt (type 6) reports the outcome of an acknowledged signal. It MUST set cor to the identifier of the signal it acknowledges, and MUST use scope Targeted toward that signal’s origin. Its payload is a CBOR map:
reason takes one of the values enumerated in delivery-semantics §2.2. A Receipt MUST NOT itself be acknowledged — receipts are not acknowledged, so the protocol cannot recurse.
Signal type 6 was named Ack in 0.1.0-draft. The wire value is unchanged; the type now carries a structured outcome rather than bare confirmation, since a plain acknowledgement cannot express why a signal failed.

Validation Rules

A signal is valid if and only if:
  1. The magic bytes are 0x4E544C
  2. The version is supported by the receiving node
  3. The body length matches the actual CBOR body size
  4. All REQUIRED fields are present
  5. The id is a valid ULID
  6. The w (weight) is in range [0.0, 1.0]
  7. The ttl is > 0
  8. The sig (signature) verifies against the origin node’s public key
  9. The ts (timestamp) is not in the future (with 30-second tolerance)
  10. The signal id has not been seen before (deduplication)
  11. The del (delivery class) is a value this node supports
Nodes MUST drop invalid signals and MUST NOT propagate them. Validation MUST be ordered cheapest-first: magic bytes, version, size, TTL, and deduplication before signature verification (rule 8). Verifying first lets an attacker impose expensive asymmetric cryptography with malformed traffic; see threat-model §5. Dropping is silent for best-effort signals. For an acknowledged signal that fails rules 1-7 or 9, the node cannot trust the origin field enough to reply and MUST drop silently; for one that fails only rule 11, it MUST emit a negative receipt with reason unsupported_type.

Maximum Signal Size

The maximum signal size (header + body) is 1 MB (1,048,576 bytes). Signals exceeding this size MUST be rejected. For payloads exceeding 1 MB, applications SHOULD use chunked signals with correlation IDs to reassemble at the destination.
Last modified on September 11, 2026