Skip to content

Sentinel (Validator)

Sentinel - The Validator

256MB RAM · $25 · IoT-scale protection

Sentinel is the lightweight validation tier designed for IoT gateways, LTE devices, and other constrained environments.

What Sentinel Enables

Role: DSM validation and health monitoring with minimal footprint.

CapabilityDescription
DSM ValidationParticipate in mesh consensus
Health MonitoringTrack device and network health
TER GenerationCreate temporal event records
Mesh ParticipationContribute to collective defense

Best For

  • IoT deployments
  • LTE/5G gateways
  • Edge validators
  • Minimal footprint needs
  • Constrained devices

Hardware Requirements

ResourceMinimumRecommended
CPU1 core2 cores
RAM256MB512MB
Storage4GB8GB
Network100Mbps1Gbps
  • ESP32-based gateways (with Linux)
  • Raspberry Pi Zero 2 W
  • OpenWrt-compatible routers
  • Industrial IoT gateways

Approximate cost: ~$25

Installation

Terminal window
sudo ./install.sh --tier sentinel

Installation Options

Terminal window
# Basic installation
sudo ./install.sh --tier sentinel
# With LTE modem support
sudo ./install.sh --tier sentinel --enable-lte
# With custom mesh bootstrap
sudo ./install.sh --tier sentinel --bootstrap-nodes "node1.mesh:7946,node2.mesh:7946"

What’s Included

ComponentPurpose
TER GeneratorSensor data collection
DSM NodeMicroblock creation and gossip
Health AgentSystem monitoring
HTP ClientSecure mesh communication

What’s NOT Included

ComponentReason
L2-L7 DetectionRequires more RAM
dnsXaiNot enough memory for ML
WiFi HotspotDifferent use case
Web DashboardMinimal footprint

Functionality

DSM Validation

Sentinel participates in the Decentralized Security Mesh:

# Sentinel creates microblocks for:
- Health status changes
- TER chain updates
- Attestation events
- Network anomalies

Health Monitoring

Continuous monitoring of:

  • CPU usage
  • Memory utilization
  • Network connectivity
  • Disk space
  • Process health

TER Generation

Temporal Event Records capture system state:

TER (64 bytes):
├── H_Entropy (32 bytes): SHA256(system metrics)
├── H_Integrity (20 bytes): RIPEMD160(critical files)
├── Timestamp (8 bytes): Unix microseconds
├── Sequence (2 bytes): Monotonic counter
└── Chain_Hash (2 bytes): CRC16(previous TER)

Configuration

Basic Config

/etc/hookprobe/sentinel.conf
TIER=sentinel
MESH_ENABLED=true
BOOTSTRAP_NODES="validator1.hookprobe.mesh:7946"
TER_INTERVAL_MS=1000

Advanced Options

/etc/hookprobe/config.yaml
sentinel:
node_id: "${HOOKPROBE_NODE_ID}"
role: "edge"
tpm:
enabled: false # Not required for Sentinel
fallback: "software"
health:
check_interval: 30
report_interval: 300
mesh:
bootstrap_nodes:
- "validator1.hookprobe.mesh:7946"
gossip_port: 7946

Management

Status Commands

Terminal window
# Check Sentinel status
hookprobe-ctl status
# View health metrics
hookprobe-ctl health
# Check mesh connectivity
hookprobe-ctl mesh status

Log Locations

LogPath
Agent/var/log/hookprobe/agent.log
Health/var/log/hookprobe/health.log
Mesh/var/log/hookprobe/mesh.log

Resource Usage

Typical resource consumption:

ResourceUsage
RAM150-200MB
CPU5-10%
Disk I/OMinimal
Network~10KB/s

Transparency Features

Even at the smallest tier, you get:

FeatureAvailable
Full visibility into DSM decisionsYes
Auditable health logsYes
TER chain verificationYes
Mesh contribution statsYes

Upgrade Path

Ready for more capability?

Terminal window
# Upgrade to Guardian
sudo ./install.sh --tier guardian --migrate

Guardian adds:

  • L2-L7 threat detection
  • dnsXai DNS protection
  • WiFi hotspot creation
  • Full web dashboard

Sentinel vs Guardian

FeatureSentinelGuardian
RAM Required256MB1.5GB
Cost$25$75
DSM ValidationYesYes
L2-L7 DetectionNoYes
dnsXaiNoYes
WiFi HotspotNoYes
DashboardHealth onlyFull

Use Cases

IoT Gateway Monitoring

Deploy Sentinel on IoT gateways to:

  • Monitor device fleet health
  • Detect anomalous behavior
  • Participate in mesh consensus
  • Report to central Nexus

LTE Failover Validator

Use Sentinel on LTE modems for:

  • Connection health monitoring
  • Failover event detection
  • Mobile network trust assessment
  • Backup link validation

Edge Validation

Deploy Sentinel at network edges:

  • Minimal resource impact
  • Continuous health attestation
  • Early warning detection
  • Mesh participation

Next Steps

AI Intelligence (HIP)

Sentinel reports hardware capabilities via the HookProbe Intelligence Platform:

  • Hardware Detection: Reports accelerator type and capabilities in heartbeat data
  • Rule-Based Classification: Lightweight threat scoring without ML overhead
  • No LLM: Too memory-constrained for local inference — uses mesh intelligence instead

See Brain & NPU Detection for the hardware detection system.