How the design was derived

Five dissemination designs were analysed and measured against the same reachability target: every honest publisher can reach every honest node despite silent Byzantine peers. The CIP selects M4, with bidirectional links, a verifiable eligibility rule and an admissions budget. These tools preserve the comparisons behind that choice. P(bad) is the probability of a topology that fails the reachability target; it does not establish an application delivery deadline.

How the models were judged

All five were measured against one shared bar, the good graph: every message of every honest publisher must reach all other honest nodes. And all faced the same adversary, a fraction μ of silent Byzantine nodes that receive every message and never relay one. Formally it is scored as the probability that the honest network stays strongly connected.

The evaluated models draw links once per epoch and use them for every publication during that epoch. The formal analyses call this the standing structure. M3 has separate relay links and publishing links; M4 uses the same bidirectional links for both. The experiment driver establishes the topology during a sync phase before propagating messages. Rotation, recovery and real transport timing require separate validation.

All five have evaluated configurations that meet the model's target. More links can reduce isolation risk, but the resulting estimate still depends on the population, adversarial assumptions and model limits. The comparison prices the links every node holds whether or not anything is published, and the copies of each message the network transmits. Giving publishing its own links cuts the copies but adds to the links each node must hold.

A bad graph is rarely a broken network. Anything short of full strong connectivity counts as bad, and in practice the failures are not large splits but single stranded nodes. A node can strand in two ways: its outgoing links all landed on adversaries, so nobody hears it, or its incoming links did, so it hears nobody. Which of the two dominates is a property of the design rather than of luck — under M2 and M3 most failures are publishers that cannot be heard. Under M4 the links are bidirectional, so an isolated node can neither send to nor receive from the other honest nodes.

That distinction decides what a bad graph actually costs. A node stranded as a publisher costs nothing unless it happens to be the one publishing, and is invisible to everyone else's dissemination; a node stranded as a subscriber is missing whoever publishes. It is why a bad graph does not imply a lost message, and why the same failure rate is worth more under one design than another.

Where the comparison stands

At the CIP's ungated comparison points, M4 uses less bandwidth, holds fewer logical links and absorbs more predicted downtime than M5, while tying it on mean full-coverage hops. M5 similarly improves three axes over M1 and ties on hops. M2 remains the fastest measured design at 4.8 hops, compared with M4's 5.0; M3 uses the least bandwidth. These are comparisons at specific configurations, not universal rankings.

The CIP selects M4 within the evaluated family and assumptions. The later gated comparison supports that choice at matched expected eligible reach per identity. M3 remains the bandwidth alternative documented in the companion comparison.

M4's gate and admissions budget have their own experiments and reproduced analytical estimates. The measured reference uses B = 500 and C = 23; at 20,000 nodes and 20% adversarial membership, the CIP's candidate uses B = 512, k = 10 and C = 24. That candidate still needs simulation and a justified allowance for model error. Formal gated derivation and the remaining interoperability rules are also activation requirements.