Connectivity resilience

What is Reticulum?

Reticulum is a cryptography-based networking stack for building local and wide-area networks with readily available hardware, such as LoRa radios, packet radio, serial links, Wi-Fi and IP networks. It does not need IP, routes across several hops over mixed carriers, and encrypts all traffic by default. Its Python reference implementation is the authoritative definition of the protocol.

Learning objectives

After reading this article you will be able to:

  • Describe how Reticulum routes across mixed carriers such as LoRa, serial links and IP
  • Identify the cryptography Reticulum uses and why it drops unencrypted packets
  • Distinguish Reticulum's public domain protocol from its reference implementation's license

What Reticulum is

Reticulum describes itself as “the cryptography-based networking stack for building local and wide-area networks with readily available hardware”. Its manual says it can keep operating under adverse conditions, such as very high latency and extremely low bandwidth.

It is a complete networking stack rather than an application on top of IP. It does not need IP or higher layers, though it can use TCP or UDP over IP as an underlying carrier, which makes it straightforward to tunnel over the internet or a private network. The reference implementation runs in userland on systems that run Python 3, with no kernel modules or drivers.

The project frames Reticulum as a tool for building many independent networks rather than as one network, with no central body that controls the address space. It is maintained by Mark Qvist. The GitHub repository is a public mirror; the README states that development happens elsewhere.

How it carries data

Reticulum is built around interfaces, each of which connects it to one medium. The manual lists Ethernet and Wi-Fi devices, LoRa radios running RNode firmware, packet radio TNCs in KISS mode, devices with a serial port, the I2P network, TCP and UDP over IP, external programs through stdio, and custom interface modules written in Python. According to the manual, it can run over practically any medium that supports at least a half-duplex channel with more than 5 bits per second of throughput and an MTU of 500 bytes.

Several interfaces can be attached to one Reticulum instance, and the stack routes between them. The project lists “fully self-configuring multi-hop routing over heterogeneous carriers” among its features. The manual’s example is a Raspberry Pi connected to a LoRa radio, a packet radio TNC and a Wi-Fi network, so that devices on the Wi-Fi side can reach nodes on the radio sides.

Addressing has no central allocation. Anyone can create addresses when they need them, and the project states that an address stays reachable when its owner moves to another place in the network. Packets carry no source address. The reference implementation includes a daemon, rnsd, for running Reticulum as an always-available service, plus utilities for interface status, path lookup, connectivity probes, file transfer and remote commands.

Encryption and identity

Encryption is not optional. The project states that it is not possible to establish unencrypted links or send unencrypted packets to a destination, and that destinations drop unencrypted packets as invalid.

The README lists X25519 key exchange and Ed25519 signatures as the basis for all communication, with ephemeral per-packet and link keys derived over Curve25519, AES-256 in CBC mode, and HMAC-SHA256 for authentication. Forward secrecy is available for all communication types. Setting up an encrypted, verified link costs 3 packets totalling 297 bytes, according to the README, and packet delivery confirmations are designed to be unforgeable.

Specification, implementations and license

There is no separate written standard. The README states that the Python reference implementation, with its manual, is the authoritative specification, and that there will not be a derived formal specification or RFC. An implementation counts as Reticulum if it is fully interoperable and has sufficient functional parity with the reference implementation.

The Reticulum protocol was dedicated to the public domain in 2016. The reference implementation is released under the Reticulum License, which grants broad rights to use, copy, modify and distribute the software, with added conditions: it must not be used in systems designed to purposefully harm people, or in creating training datasets for artificial intelligence, machine learning or language models. Because it is not a standard license, GitHub’s license detection reports it as “Other”.

The README names the community implementations it recognises, microReticulum in C++ for 32-bit microcontrollers and Reticulum-Go, and warns against unreviewed implementations marketed under misleading claims. Applications built on Reticulum include LXMF, a delay and disruption tolerant message transfer protocol; Sideband, an app for Android, Linux, macOS and Windows with messaging, file transfer and voice features; and Nomad Network.

Reaching Reticulum from an app

A phone has no LoRa radio of its own, so an app reaches a radio-based Reticulum network through a Reticulum instance that has the right interfaces attached, which is a form of gateway. Where that instance runs, how the app authenticates to it, and what counts as delivered are deployment decisions.

The Offline Protocol mesh SDK lists Reticulum as an opt-in transport, but it does not ship a Reticulum stack or daemon. The app connects to a separately deployed gateway daemon, and the Reticulum and Nostr docs say to qualify its authentication, framing, delivery verdicts and reconnect behaviour against the SDK’s gateway contract. In the Python manager, the default Reticulum callback is a stub that has to be replaced before the path works.

Frequently asked questions

Can Reticulum run on a phone?

The README lists Sideband, an app built on Reticulum for Android, Linux, macOS and Windows. A phone still needs a carrier to reach other Reticulum nodes, such as an IP network or a radio interface attached to a Reticulum instance.

Does Reticulum need the internet?

No. Reticulum does not rely on IP and can run entirely over radio or serial links. It can also use TCP or UDP over IP as one of its carriers, which lets Reticulum instances connect to each other across the internet.

Sources

Build it with Offline Protocol

The Reticulum and Nostr page explains that Reticulum is an opt-in path in the mesh SDK, reached through a gateway daemon your deployment provides, and how to qualify that gateway against the SDK's gateway contract.

Read Reticulum and Nostr