Open reference implementation · Apache-2.0
A layer for moving data across intermittent, multi-hop links you do not control, and proving, later and offline, that it arrived intact, in order, through a known chain of custody, and was paid for. Built on delay-tolerant networking, settled on BSV.
See it run
Nothing staged: the acceptance suite, the full pipeline, a real Linux netem blackout, real Bundle Protocol v7 custody across a contact gap, and delivery bound to a real on-chain settlement. It closes by reading the anchor transaction live from the chain.
The problem
Between a sensor and a server, data often crosses relays, store-and-forward hops, and links that go dark. You still need to trust what comes out the other end.
Content-addressed, signed data is checked locally, later, with nobody on the other end. No callback to the source.
Each hop leaves a signed, content-addressed receipt, forming a verifiable chain across parties you do not operate.
Delivery is bound to a real on-chain BSV settlement, and the data's root is anchored on chain for tamper-evident provenance.
How it works
Bundle Protocol v7 (µD3TN) carries the bundles. DTN standardizes how bundles move, but not who paid or how you prove custody later, and that is the gap this layer fills. The custody, verification, and payment work sits on top as an application-layer agent, using the same content-addressed receipt route as the BSVKey x402 client.
The same content-addressing route as @bsvkey/x402-bsv-client. It works over any link and any settlement rail; the reference uses BSV.
By design it does not touch RF, optical, coding, or FEC. It is the trust and settlement layer over whatever carries the bits.
Proven on real infrastructure
The reference implementation runs end to end against real systems, one command each.
| Layer | What runs |
|---|---|
| make spike | Real Linux tc netem links with a real 100%-loss link blackout; the payload survives and reassembles. |
| make r2 | Real Bundle Protocol v7 (µD3TN), bundles held in µD3TN storage across a scheduled contact gap, genuine DTN bundle custody. |
| make live | Delivery bound to a real on-chain BSV settlement, and the manifest root anchored on chain in an OP_RETURN. |
The boundary
Authentic evidence can still be insufficient for the claim asked of it. The boundary is stated per field.
| Evidence | Proves | Does not prove |
|---|---|---|
| content address | the record is intact and addressed by its content | that the numbers describe a real event |
| signature recovery | the signer authored these exact bytes | that the payload is correct |
| Merkle branch | this chunk belongs at this position under the root | that the whole payload is complete on its own |
| custody chain | the record passed this ordered set of hops | what happened between the observed hops |
| settlement on chain | money moved from that payer to that payee | that it was your payment, until you bind it |
Where it is useful
Delay-tolerant networking was designed for exactly these regimes, including deep space, where the same constraints appear in the extreme.
Quickstart
Node 18+. The core is dependency-free; Docker is only needed for the real BPv7 and netem runs.
# clone
git clone https://github.com/BSVKey/dtn-custody-demo
cd dtn-custody-demo
npm test # acceptance criteria, offline, deterministic
npm run demo # the full pipeline over the in-process simulator
make spike # real veths + tc netem + a real link blackout (Docker)
make r2 # custody chain over real µD3TN BPv7 (Docker)
make live # delivery bound to a real on-chain BSV settlement
FAQ
What this is, what it proves, and where the honest edges are.
settlementRef against the transaction you actually paid. An unbound check refuses rather than passing.npm test and npm run demo need only Node; make spike, make r2, and make live exercise the real netem, real BPv7, and real on-chain paths.Open core
The protocol, agent library, DTN adapters, verifiers, and on-chain checks are open under Apache-2.0. A hosted BSV settlement facilitator and relay marketplace, managed key custody, and the BSVKey brand are operated separately. The open core settles on BSV; running a production relay-payment service on top of it is the hosted offering.