Urgent.News

What's breaking now, across thousands of outlets.

Tech

Defend your endorsement nodes: Token-bucket rate limiting for Fabric.

Defend your endorsement nodes: Token-bucket rate limiting for Fabric. Day 07 of the wFabricSecurity Open-Source Engineering Series. ECDSA signature verification is computationally expensive. Flooding an endorsement node will bring it to its knees. wFabricSecurity defends your cluster with token-bucket rate limiting. The Pain Points We Faced A rogue or looping worker overwhelming endorsement peers…

Preventing overload on endorsement nodes is crucial for maintaining the performance of Hyperledger Fabric clusters. One method for doing this is through token-bucket rate limiting, which is the focus of the wFabricSecurity project. ECDSA signature verification is a resource-intensive operation, and flooding an endorsement node with thousands of signature requests can cause it to become overwhelmed, leading to cryptographic CPU exhaustion and legitimate transactions being dropped due to peer resource starvation.

To address these issues, wFabricSecurity provides a token-bucket rate limiter. The limiter is configured to allow a maximum of 100 tokens, with 10 tokens refilled each second. Each participant is assigned a unique Common Name (CN) or IP address, and distinct limits are enforced for each. If the limiter's consume method is unable to grant a token for a particular participant, a RateLimitError is raised, preventing the expensive ECDSA verification process from being triggered.

This architecture offers several advantages. The token-bucket algorithm smoothly handles bursts of traffic while still enforcing sustained rate caps. By applying distinct limits per participant, the system can prevent a single rogue or looping worker from overwhelming the endorsement node. The RateLimitError mechanism traps abusive request spikes before they can cause damage. The implementation is compatible with Python 3.10 and above, and includes cryptographic identity management and code integrity hashing.

For more information, visit the project's GitHub repository at https://github.com/wisrovi/wFabricSecurity or install the package via PyPI at https://pypi.org/project/wFabricSecurity.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at dev.to →

More in Tech

Archivos PDF, ZIP y binarios viajando en Kafka con nombre intacto.

Archivos PDF, ZIP y binarios viajando en Kafka con nombre intacto. Día 07 de la serie técnica WKafka Open Source. No aprovisiones un bucket en la nube cuando lo único que necesitas es enviar PDFs o…

  • WKafka transmits PDF, ZIP, and binary files with original names intact.
  • Addresses loss of file names and extensions during data conversion.
  • Native serializer packs file names and binary data into one unit.

PDF, ZIP and binary files streaming over Kafka with names intact.

PDF, ZIP and binary files streaming over Kafka with names intact. Day 07 of the WKafka Open-Source Engineering Series. Don't provision a cloud bucket when all you need is sending small PDFs and ZIPs…

  • WKafka library streams PDF, ZIP, binary files over Kafka while preserving file names.
  • Traditional approaches require cloud buckets for small file transfers; WKafka handles it natively.

More from Monday 28 September →