How it works
Open the box.
Two small Linux containers on your Pi, plus a thin proxy on ours. Below is everything that happens between a Bluetooth packet hitting your antenna and the upstream network receiving it.
The data path.
A BLE device broadcasts. Your gateway hears it, along with whatever other gateways are in range. Whichever gateway forwards the packet first earns the discovery bounty when the bounty program ships. Four hops, three machines, none of them ours except the middle one.
BLE device
A tag, an asset tracker, an industrial sensor. The firmware broadcasts an encrypted packet over standard Bluetooth Low Energy.
Your gateway
The worker container scans the radio every few seconds, captures any matching packet in range, and POSTs it to us. The ui container is the dashboard you see at port 8080.
EE proxy
We check the packet against your EE token, log it for future bounty accounting, and forward it to the right upstream network (Hubble Network today). The encrypted payload never opens.
Upstream network
The network's positioning engine combines your packet with thousands of others from satellites and other gateways to fix the device's location.
What runs on your hardware.
What runs on our hardware.
A small Rails service at encryptedenergy.com/api/v1/gateways/*. It checks incoming packets against your EE token, logs activity for your dashboard, attributes each forwarded packet to your gateway for future bounty accounting, and forwards to the right upstream network using our wholesale relationship there. We don't decrypt the packet payload, ever. We can't: the encryption key belongs to the device's owner, not to us.
What you need.
What you don't need.
- · An account with the upstream network. We hold the wholesale relationship.
- · Port forwarding or a public IP. All traffic's outbound HTTPS.
- · A static address. Your gateway's identified by its EE token, not its IP.
- · Payment. Free at signup, free forever (see pricing).
- · A lawyer. The whole thing's GPL-3.0; read every line if you want.
Security, briefly.
Your Pi exposes no public port. The dashboard sits behind Umbrel's reverse proxy and is reachable only on your LAN. Tokens are per-gateway and revocable in one click from your account. If a Pi walks off, revoke its token and the gateway's dead to us within one heartbeat cycle. The entire source for both containers is GPL-3.0 at github.com/Encrypted-Energy/gateway.