Skip to content
OpenNHPPublic

About

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the AI-driven world.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

13.9k stars

Watchers

829 watching

Forks

Latest commit

 

History

3,003 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

en zh-cn zh-tw de ja fr es id

OpenNHP Logo

OpenNHP: Open Source Zero Trust Security Toolkit

Build Release License codecov Ask DeepWiki

OpenNHP is a lightweight, cryptography-powered, open-source toolkit implementing Zero Trust security for infrastructure, applications, and data. It is the reference implementation of the Cloud Security Alliance (CSA) Network-infrastructure Hiding Protocol (NHP) specification, and features two core protocols:

  • Network-infrastructure Hiding Protocol (NHP): Conceals server ports, IP addresses, and domain names to protect applications and infrastructure from unauthorized access.
  • Data-content Hiding Protocol (DHP): Ensures data security and privacy via encryption and confidential computing, making data "usable but not visible."

Website · Vision · Live Demo · Documentation · Discord


Why OpenNHP

The modern internet is a dark forest. Attackers — increasingly backed by LLMs that scan, fingerprint, and exploit at machine speed via Autonomous Vulnerability Exploitation — treat every reachable service as a target. Gartner projects AI-driven cyberattacks will rise rapidly. Traditional defenses authenticate users after the network lets them in, leaving exposed ports, IPs, and domains as a permanent attack surface.

In the AI era, VISIBILITY = VULNERABILITY.

OpenNHP inverts that model: invisible until trusted. Every port, IP, and hostname sits behind a default-deny gate. Access is granted only after a cryptographically signed knock is authenticated and authorized out-of-band. Attackers can't exploit what they can't discover.

The third-generation network hiding protocol

NHP is the next step in a line of "hide the service first" designs:

Generation Protocol Limitations
1 Port Knocking Plaintext, replay-prone
2 Single Packet Authorization (SPA) Shared secrets, one-way, typically hides ports only, typically C/C++
3 NHP Modern crypto, bi-directional with status, hides domain + IP + ports, stateless and horizontally scalable, memory-safe Go

NHP slots in alongside existing IAM, DNS, FIDO, and Zero Trust policy engines rather than replacing them — it extends your stack instead of forking it.


Architecture

OpenNHP follows a modular design with three core components, inspired by the NIST Zero Trust Architecture:

OpenNHP architecture

Core Component Role
NHP-Agent Client that sends encrypted knock requests to gain access
NHP-Server Authenticates and authorizes requests; runs separately and is architecturally decoupled from the protected host
NHP-AC Access controller that manages firewall rules on the protected server
Addon Component Role
NHP-Relay HTTP-to-UDP bridge enabling browser-based agents to send NHP knocks via HTTPS
NHP-KGC Key Generation Center for Identity-Based Cryptography (IBC)

Protocol flow

  1. Agent sends an encrypted knock (NHP_KNK) to the Server.
  2. Server validates the knock and sends an operation request (NHP_AOP) to the AC.
  3. AC opens the firewall and replies (NHP_ART) to the Server.
  4. Server returns an acknowledgment (NHP_ACK) with access info to the Agent.
  5. Agent reaches the protected resource through the AC.

Cryptography

OpenNHP ships with two interchangeable cipher suites:

  • CIPHER_SCHEME_CURVE — Curve25519 + AES-256-GCM + BLAKE2s
  • CIPHER_SCHEME_GMSM — SM2 + SM4-GCM + SM3

Both are driven by the Noise Protocol Framework. An Identity-Based Cryptography (IBC) mode is available via the Key Generation Center (KGC).

For protocol details, deployment models, and cryptographic design, see the documentation.


Repository Structure

opennhp/
├── nhp/              # Core protocol library (Go module)
│   ├── core/         # Packet handling, cryptography, Noise Protocol, device management
│   ├── common/       # Shared types and message definitions
│   ├── utils/        # Utility functions
│   ├── plugins/      # Plugin handler interfaces
│   ├── log/          # Logging infrastructure
│   └── etcd/         # Distributed configuration support
└── endpoints/        # Daemon implementations (Go module, depends on nhp)
    ├── agent/        # NHP-Agent daemon
    ├── server/       # NHP-Server daemon
    ├── ac/           # NHP-AC (access controller) daemon
    ├── db/           # NHP-DB (Data Broker for DHP)
    ├── kgc/          # NHP-KGC (Key Generation Center)
    └── relay/        # NHP-Relay daemon

Quick Start

Prerequisites

  • Go 1.26+
  • make
  • Docker and Docker Compose (for the full-stack demo)

Build

# Build all components
make

# Build individual daemons
make agentd    # NHP-Agent
make serverd   # NHP-Server
make acd       # NHP-AC
make db        # NHP-DB
make relayd    # NHP-Relay
make kgc       # NHP-KGC

Test

cd nhp && go test ./...
cd endpoints && go test ./...

Run with Docker

cd docker && docker-compose up --build

Follow the Quick Start tutorial to simulate the full authentication workflow in a Docker environment.


Contributing

We welcome contributions! Please read CONTRIBUTING.md before submitting pull requests.

Note: All commits must be signed with a verified GPG or SSH key.

git commit -S -m "your message"

Security

Found a vulnerability? Please follow the responsible-disclosure process in SECURITY.md rather than opening a public issue.


Sponsors

LayerV.ai logo    Atlas Cloud logo    Tencent Cloud logo

License

Released under the Apache 2.0 License.

Contact

About

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the AI-driven world.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

13.9k stars

Watchers

829 watching

Forks

Releases

Packages

Used by

Contributors

Languages