Mehr Proof-of-Work (PoW)
Transparent, long-lasting anti-bot architecture: Stateless HMAC challenges, non-blocking Web Workers, and zero-wait human UX.
Waiting for challenge generation...
Visual Design Language & Components
Reusable, production-ready UI gates and progress state components for project-wide account generation.
Technical Specification & Architecture
Cryptographic HMAC tokens, context fingerprinting, replay resistance, and multi-tenant sharding.
1. The Stateless HMAC Challenge Token
Zero Database StateServers do not store active challenges in Redis or databases. Puzzles are distributed as cryptographically signed stateless tokens verified in O(1) time:
سرورها چالشهای فعال را در دیتابیس یا ردیس ذخیره نمیکنند. معماها به عنوان توکنهای بدون حالت و امضاشده صادر میشوند که در زمان O(1) تأیید میگردند:
2. Context Binding & Swapping Prevention
Every challenge binds cryptographically to the exact form context: ctx = SHA256(form_fields). A bot cannot pre-compute a proof for account A and reuse it for account B or an invoice.
هر چالش به صورت رمزنگاریشده به زمینه فرم متصل است. باتها نمیتوانند اثبات حلشده را از یک حساب به حساب یا عملیات دیگر منتقل کنند.
3. Dynamic Difficulty & Subnet Escalation
Clean residential traffic receives effortless baseline difficulty (14–16 bits, ~0.8s). Datacenter/Tor subnets generating rapid requests face scaled difficulty (18–22 bits), exhausting automated bot servers.
کاربران عادی سختی پایه (۰.۸ ثانیه) دریافت میکنند؛ در حالی که دیتاسنترها و باتهای مشکوک با سختیهای تصاعدی مواجه شده و توان سرورشان مسدود میشود.
Production Implementation Examples
Self-contained solvers and middleware for Go, JavaScript/TypeScript, Python, PHP, and POSIX Shell.
1package main2 3import (4 "crypto/hmac"5 "crypto/sha256"6 "encoding/hex"7 "fmt"8 "math/bits"9 "net/http"10 "strconv"11 "strings"12)13 14// VerifyPoW verifies client proof in O(1) time15func VerifyPoW(secretKey, token string, nonce int64, context string) (bool, error) {16 parts := strings.Split(token, ".")17 if len(parts) != 2 {18 return false, fmt.Errorf("invalid token format")19 }20 payloadB64, sig := parts[0], parts[1]21 22 // 1. Verify HMAC-SHA256 signature23 mac := hmac.New(sha256.New, []byte(secretKey))24 mac.Write([]byte(payloadB64))25 expectedSig := hex.EncodeToString(mac.Sum(nil))26 if !hmac.Equal([]byte(sig), []byte(expectedSig)) {27 return false, fmt.Errorf("signature mismatch")28 }29 30 // 2. Count leading zero bits of candidate hash31 candidate := fmt.Sprintf("salt:%d:%s", nonce, context)32 h := sha256.Sum256([]byte(candidate))33 34 var zeroBits int35 for _, b := range h {36 if b == 0 {37 zeroBits += 838 } else {39 zeroBits += bits.LeadingZeros8(b)40 break41 }42 }43 return zeroBits >= 16, nil44}
1// Background Web Worker PoW Solver (worker.js)2self.onmessage = async (e) => {3 const { salt, context, difficulty } = e.data;4 const encoder = new TextEncoder();5 let nonce = 0;6 7 while (true) {8 const candidate = `${salt}:${nonce}:${context}`;9 const buf = await crypto.subtle.digest("SHA-256", encoder.encode(candidate));10 const bytes = new Uint8Array(buf);11 12 // Count leading zero bits13 let zeroBits = 0;14 for (let i = 0; i < bytes.length; i++) {15 if (bytes[i] === 0) zeroBits += 8;16 else { zeroBits += Math.clz32(bytes[i]) - 24; break; }17 }18 19 if (zeroBits >= difficulty) {20 self.postMessage({ solved: true, nonce });21 return;22 }23 nonce++;24 }25};
1import hashlib, hmac2 3def verify_pow(secret_key: str, token: str, nonce: int, context: str) -> bool:4 parts = token.split(".")5 if len(parts) != 2:6 return False7 payload_b64, signature = parts8 9 # 1. Verify HMAC10 expected = hmac.new(secret_key.encode(), payload_b64.encode(), hashlib.sha256).hexdigest()11 if not hmac.compare_digest(signature, expected):12 return False13 14 # 2. Check hash difficulty15 candidate = f"salt:{nonce}:{context}".encode()16 digest = hashlib.sha256(candidate).digest()17 18 zero_bits = 019 for byte in digest:20 if byte == 0:21 zero_bits += 822 else:23 zero_bits += (8 - byte.bit_length())24 break25 26 return zero_bits >= 16
12function verify_pow($secret_key, $token, $nonce, $context) {3 $parts = explode(".", $token);4 if (count($parts) !== 2) return false;5 list($payload_b64, $signature) = $parts;6 7 // 1. Verify HMAC8 $expected = hash_hmac("sha256", $payload_b64, $secret_key);9 if (!hash_equals($signature, $expected)) return false;10 11 // 2. Check hash candidate12 $candidate = "salt:" . $nonce . ":" . $context;13 $raw_hash = hash("sha256", $candidate, true);14 15 $zero_bits = 0;16 for ($i = 0; $i < strlen($raw_hash); $i++) {17 $byte = ord($raw_hash[$i]);18 if ($byte === 0) {19 $zero_bits += 8;20 } else {21 $zero_bits += (8 - strlen(decbin($byte)));22 break;23 }24 }25 return $zero_bits >= 16;26}
1#!/bin/sh2# POSIX-compliant PoW solver3SALT="a1b2c3d4e5f67890"4CTX="job_context_fingerprint"5 6nonce=07while :; do8 hash=$(printf "%s:%s:%s" "$SALT" "$nonce" "$CTX" | sha256sum | awk "{print \$1}")9 case "$hash" in10 0000*)11 printf "Solved! Nonce: %s Hash: %s\n" "$nonce" "$hash"12 break13 ;;14 esac15 nonce=$((nonce + 1))16done