GhostMesh
DownloadServersSRSPFAQPricingBlog
Login
GhostMesh

© 2026 SRS Conglomerate. All rights reserved.

Service StatusDocumentationSecurityTerms & ConditionsTransparency reportPrivacy policy

GhostMesh transport

SRSP: SRS Secure Session Protocol

GhostMesh advanced-beta transport for Windows and Android: TLS 1. 3, Chrome 150-shaped ClientHello, REALITY-required auth, GMNPP mux with a warm pool, probing guard, plus default-on canonical session (rekey/resume) and Native UDP v2.

TLS 1.3REALITY requiredCanonical sessionNative UDP v2
Download GhostMeshView pricing

Comparison with rated protocols

Comparative 0–100 editorial scores for ten protocols. Hysteria3, Mieru, TrustTunnel, OlcRTC, and operator bundles are excluded from the scored set.

Scores are comparative editorial ratings 0–100 for the GhostMesh shipped path and public protocol documentation — not independent laboratory measurements. Bands remain labels for the same scores.

Sort by

SRSP / GhostCloak

GhostMesh
Field score pending: the seven-day regional shaped, unshaped, VLESS+REALITY, and ordinary HTTPS controls are not complete.
Read the full review

VLESS + REALITY

Masking92Excellent
Efficiency78Strong
Resilience80Strong
Read the full review

WireGuard

Masking28Limited
Efficiency94Excellent
Resilience58Moderate
Read the full review

AmneziaWG 2.0

Masking55Moderate
Efficiency82Strong
Resilience58Moderate
Read the full review

NaiveProxy

Masking80Strong
Efficiency55Moderate
Resilience76Strong
Read the full review

OpenVPN

Masking52Moderate
Efficiency55Moderate
Resilience78Strong
Read the full review

IKEv2 / IPsec

Masking30Limited
Efficiency78Strong
Resilience80Strong
Read the full review

Shadowsocks

Masking55Moderate
Efficiency78Strong
Resilience52Moderate
Read the full review

Hysteria2

Masking55Moderate
Efficiency92Excellent
Resilience78Strong
Read the full review

TUIC

Masking52Moderate
Efficiency80Strong
Resilience78Strong
Read the full review

What SRSP is

SRSP (SRS Secure Session Protocol) is GhostMesh’s own transport for Windows and Android. The default egress path uses real TLS 1. 3 with a Chrome 150-shaped ClientHello, required REALITY/EKM authentication, GMNPP multiplexing with a warm pool, a probing guard, plus a canonical session with jittered rekey, sticky resume, and Native UDP v2. Editorial profile: 89 overall (masking 92 / efficiency 90 / resilience 85). Advanced-beta: shipped and tested, with shorter public multi-ISP field history than mature VLESS+REALITY fleets.

TLS 1.3 + Chrome 150 ClientHelloShipped default

Default Windows and Android transport. JA4 is fingerprint camouflage, not a separate cipher.

REALITY / EKM authenticationShipped default

Required on enabled SRSP nodes; API refuses silent standard TLS fallback.

GMNPP mux + warm poolShipped default

Default path reuses protected connections for multiple streams.

Active probing guardShipped default

IPv4 /24 and IPv6 /48 limits, strict validation, and a bounded HTTP masquerade fallback are wired; defense in depth, not indistinguishability.

Canonical session + Native UDP v2Shipped default

Default-on for egress (API flags + templates); relay stays off. Live fleet soak still operator-owned.

Automatic rekey + sticky resumeShipped default

On the default egress canonical path: jittered RekeyScheduler, UDP v2 owner rotation, server resume tickets. Sustained multi-ISP field history remains shorter than mature stacks.

How it is layered

SRSP separates transport, session lifecycle, and VPN/proxy wire format so camouflage, cryptography, multiplexing, and resource limits can evolve independently.

Transport

GhostCloak over TLS 1.3 with a Chrome 150-shaped ClientHello and REALITY-required

Session

Session keys derive from the TLS 1.3 handshake. Default egress path: canonical session with jittered rekey, sticky resume, and Native UDP v2 (relay remains non-canonical).

Mux

GMNPP full-duplex multiplexing with a warm connection pool

VPN / proxy

Windows Wintun and Android VpnService with TCP CONNECT and UDP ASSOCIATE

How we rate protocols

Ratings use 0–100 editorial scores for masking, efficiency, and resilience, They are comparative engineering profiles of the GhostMesh shipped path and public protocol documentation—not independent laboratory measurements.

What ships by default

Everything listed here is enabled by default on the shipped Windows and Android path.

TLS 1.3 with Chrome 150-shaped ClientHello

The default transport uses TLS 1.3 and a Chrome 150-shaped ClientHello for fingerprint camouflage. JA4 describes that camouflage; it is not a separate cipher.

REALITY / EKM authentication (required)

Enabled SRSP nodes require REALITY keys (mode + hex); the API refuses silent standard TLS fallback.

GMNPP mux and warm pool

The default path reuses protected connections for multiple streams through GMNPP multiplexing and a warm pool.

Probing guard on Windows and Android

IPv4 /24 and IPv6 /48 limits, strict validation, and a bounded HTTP masquerade fallback are wired. This is defense in depth, not an indistinguishability guarantee.

Canonical session with rekey and sticky resume

Default egress runs a canonical session: jittered rekey, sticky resume tickets, and owner rotation. Relay stays non-canonical.

Native UDP v2 on the default path

Native UDP v2 is enabled by default on the egress path (API flags + templates). It is not an experimental opt-in.

Honest boundary

SRSP is not a universal replacement for every protocol. WireGuard remains excellent on open networks, OpenVPN and IKEv2 win on maturity, and VLESS+REALITY still has deeper censorship-field history. SRSP gives GhostMesh a modern owned transport where masking, resilience, and connection behavior matter—with advanced-beta honesty.

Where SRSP helps most

Use SRSP when stable private access on Windows/Android, TLS-shaped camouflage, and mux reuse matter more than multi-year third-party deployment history. On ordinary open networks, GhostMesh can still prefer other modern paths.

Protocol boundary reference: git:f144c34 · regional shaped/unshaped and VLESS+REALITY controls pending