Transactions on Ambient Computation · Vol. 14, No. 3, September 2031 pp. 411–429 doi:10.4471/tac.2031.0603

Drift-Tolerant Consensus for Intermittently Powered Sensor Meshes

Ines Vahl-Rehnquist1, Tobias Ferreira Lund1,2, Amara Osei-Whitfield2, Piotr Sandberg3

1Laboratory for Ambient Systems, Kalmar Institute of Technology · 2Department of Distributed Computing, Northgate University · 3Meridian Grid Research, Tromsø
Received 4 March 2031; revised 21 June 2031; accepted 2 August 2031.

Abstract

Energy-harvesting sensor meshes operate under power budgets that collapse without warning, leaving nodes unable to complete a consensus round before brownout. Classical quorum protocols assume that a node which stops responding has failed permanently; in intermittently powered deployments this assumption produces a churn rate high enough to prevent any decision from ever committing. We present Halcyon, a drift-tolerant consensus layer that treats power loss as a first-class scheduling event rather than a fault. Halcyon nodes persist a compact intent digest to ferroelectric memory before each voltage cliff and resume the round on the next harvest window, allowing a logical quorum to be assembled across time as well as across space.

Across 14 months of field data from 340 solar- and vibration-harvested nodes, Halcyon committed 99.2% of proposed rounds at a median latency of 41 seconds, against 62.7% and 6.4 minutes for a hardened Raft baseline. Energy cost per committed round fell by 3.1×. We characterise the failure envelope, prove safety under arbitrary suspension, and release the trace corpus and reference implementation.

Index terms — intermittent computing, consensus protocols, energy harvesting, wireless sensor networks, non-volatile memory, distributed systems

Introduction

Batteryless devices have moved from laboratory curiosities to production infrastructure. Structural monitors embedded in bridge decks, soil-chemistry probes buried below the plough line, and cold-chain tags stitched into pallet wrap all now run on scavenged energy alone.[1] The engineering appeal is obvious: no battery means no replacement schedule, and no replacement schedule means a device can be installed in places a technician will never revisit.

The software consequence is less comfortable. A node powered by a 4 mm² photovoltaic cell may execute for 180 milliseconds, brown out for eleven minutes, and wake with volatile state erased. Every distributed protocol designed for continuously powered machines interprets that silence as death.[2]

We argue that the correct abstraction is not failure but suspension. A suspended node has not lost its identity, its log, or its intent — it has lost only its clock and its radio. If the protocol can recover intent from non-volatile storage, then a quorum need not be simultaneous.

Contributions

  1. A consensus formulation in which quorum is accumulated over a bounded temporal window rather than a single synchronous round.
  2. An intent digest of 34 bytes that survives brownout and is sufficient to resume any protocol phase.
  3. A safety proof under arbitrary suspension patterns, including adversarially scheduled harvest windows.
  4. A 14-month, 340-node field deployment with an openly released trace corpus.

Background and Related Work

Intermittent computing research has largely focused on single-device correctness — checkpointing, idempotent task decomposition, and memory consistency across power cycles.[3] These systems make a single program resumable but say nothing about agreement between programs.

On the distributed side, partition-tolerant protocols such as Raft and its hardened derivatives assume that unavailability is exceptional and bounded by a timeout constant.[4] Tuning that constant upward to accommodate eleven-minute brownouts destroys responsiveness during the intervals when nodes are awake.

The duty-cycle mismatch

Let d denote a node's duty cycle and n the quorum size. Under independent harvest schedules, the probability that a majority is simultaneously awake decays sharply, which is the analytical root of the churn behaviour we observe in practice.[5]

Psync  =  n!k!(n−k)!  dk(1−d)n−k,   k = ⌈n/2⌉ (1)

For d = 0.03 and n = 7 — values typical of our bridge-deck cluster — equation (1) yields a synchronous-majority probability below 10−5 per window. Halcyon sidesteps the term entirely by relaxing simultaneity.

t₀t₀+4mt₀+8mt₀+12mcommit node A · solar node B · solar node C · vibration node D · thermal node E · solar Σ = 5/5 intents Filled bars = harvest windows in which an intent digest was written to FRAM. No two nodes overlap; quorum accrues temporally.
Figure 1. Temporal quorum accumulation across five heterogeneously harvested nodes over a twelve-minute window. Under a synchronous protocol none of these windows form a majority; Halcyon commits at t₀+13m once the fifth durable intent is observed by the aggregator.

The Halcyon Protocol

Halcyon replaces the notion of a live quorum with a durable one. Each node, upon receiving a proposal, evaluates it locally and writes a 34-byte intent digest to ferroelectric RAM before the supply voltage crosses the cliff threshold.[6] The digest encodes the proposal hash, an epoch counter, the vote, and a monotonic write seal.

Intent digests

The write completes in 260 µs and costs 1.9 µJ, which fits inside the residual charge of every harvester class we tested. Because the seal is monotonic, a replayed or truncated write is detectable without a second round trip.

Invariant H1 — A node never emits a vote for epoch e unless a sealed digest for e is already durable. Safety therefore does not depend on the node surviving the transmission.

Aggregation

An aggregator — any node, elected lazily by harvest capacity — collects digests opportunistically as peers wake. When the accumulated set crosses the majority threshold within the epoch's validity window, the decision commits and is gossiped on subsequent wakes.[7]

Crucially, aggregation is monotone: adding a digest can never invalidate a previously accumulated set, so partial progress is never discarded when the aggregator itself browns out.

Evaluation

We deployed 340 nodes across three sites: a highway viaduct in Kalmar, a district-heating trench in Tromsø, and an indoor logistics hall with vibration harvesting only. Table 1 summarises headline results against two baselines.

Table 1 — Field results, 14 months, 340 nodes
ProtocolCommit rateMedian latencyµJ / round
Raft (hardened)62.7%6.4 min418
EPaxos-IC81.3%2.9 min297
Halcyon99.2%41 s134
Halcyon (no seal)99.4%39 s129

The unsealed variant is marginally faster but forfeits replay detection; we report it only to isolate the seal's 4% overhead.

Failure envelope

Halcyon degrades gracefully until the epoch validity window falls below roughly twice the mean inter-harvest interval, at which point commit rate drops sharply. Operators can measure this interval in situ and size the window accordingly.[8]

Limitations and Future Work

Halcyon assumes a bounded clock drift of ±2% between wakes, provided in our deployment by a nanopower RTC drawing 38 nA. Nodes without any persistent timekeeping cannot participate in epoch validity checks and must be treated as observers.[9]

We have not yet addressed Byzantine participants; the seal protects against accidental replay but not against a node that fabricates digests. Extending the construction with lightweight attestation is ongoing work.[10]

Conclusion

Treating power loss as scheduling rather than failure changes what a quorum can be. By making intent durable before it is communicable, Halcyon assembles agreement across time and turns the defining weakness of energy-harvested hardware into an ordinary operating condition. The trace corpus, reference implementation, and hardware bill of materials are available under a permissive licence.

Artefact availability — Traces (2.4 GB), firmware, and the analysis notebooks are archived at meridian-grid.org/halcyon and mirrored in the ACM Digital Library.

References

  1. [1]M. Aldridge and K. Nwosu. Batteryless infrastructure sensing at civic scale. Proc. SenSys, pp. 88–101, 2029.
  2. [2]J. Halvorsen. Silence is not death: rethinking failure detectors. ACM SIGOPS Oper. Syst. Rev., 63(2):17–29, 2028.
  3. [3]R. Petrova, D. Kim, and L. Barreau. Idempotent task decomposition for intermittent execution. ASPLOS, pp. 604–618, 2027.
  4. [4]C. Ongaro-Meyer. Hardened Raft under adversarial partitions. IEEE Trans. Dependable Secure Comput., 25(4):1102–1117, 2028.
  5. [5]S. Iyengar and F. Okonkwo. Duty-cycle interference in low-power mesh agreement. IPSN, pp. 233–245, 2030.
  6. [6]T. Ferreira Lund and A. Osei-Whitfield. Sub-millijoule durability with ferroelectric memory. J. Low Power Electron., 19(1):44–61, 2030.
  7. [7]N. Brandt. Lazy leader election by harvest capacity. EuroSys, pp. 311–326, 2029.
  8. [8]P. Sandberg. In-situ characterisation of harvest intervals in Arctic deployments. Energy Harvest. Syst., 12(3):201–219, 2030.
  9. [9]Y. Tanaka and G. Mbeki. Nanopower timekeeping for suspended nodes. Microelectron. J., 141:105–118, 2031.
  10. [10]I. Vahl-Rehnquist. Attestation budgets for scavenged silicon. Tech. Rep. KIT-LAS-31-04, Kalmar Inst. of Technology, 2031.
© 2031 Kalmar Institute of Technology · CC BY 4.0 Set in Iowan Old Style · Composed 19 · 09 · 2031