The storage twin to phone-cluster computing

A sovereign, client-side encrypted cloud on reconditioned phones.

Where projects like UC San Diego's Junkyard Computing turn retired Pixels into a compute cluster, blob.cloud turns them into encrypted personal storage, distributed across people's homes. This page is for doctoral students and engineers who want the raw figures, not the marketing — including where we are honestly weak.

4
node working PoC (reconditioned Pixels + 1 TB SSDs)
~0.1 W
measured idle wall power per node
AES-256
GCM, in the browser, keys never sent
≤1
erasure-coded fragment per node
The honest claim

Energy parity. The win is embodied carbon.

We do not claim an operational-energy advantage over a hyperscaler — per terabyte, modern data centers are extremely efficient, and we measure roughly at parity. The defensible gain is the manufacturing carbon already spent on a phone, recovered through reuse instead of being thrown away.

Why reuse, in one number
Manufacturing a smartphone emits roughly 55–78 kgCO₂e — about 85–95% of its entire lifetime footprint (cf. Junkyard Computing, arXiv:2110.06870). A reconditioned Pixel given a second life as a storage node amortizes that embodied carbon rather than triggering the manufacture of new server hardware. This is the same framing as the Computational Carbon Intensity metric — we simply apply it to storage, with a privacy and sovereignty layer on top.
Architecture

A small but real system, end to end.

📱

Nodes ("Guardians")

Reconditioned Pixel phones, each paired with a 1 TB SSD over a charge-passthrough USB-C hub. Headless, always-on, ~0.1 W at rest. The PoC runs 3 Pixel Guardians + 1 coordinator.

🔒

Encrypted in the browser, by design

Files are encrypted in the browser before they ever leave the device. Guardians only ever see opaque ciphertext fragments — never keys, never plaintext, never filenames.

🧮

Disperse, then store

Each object is erasure-coded and scattered with an audited invariant: at most one fragment per node. Losing a whole node never loses data — it triggers self-healing reconstruction.

What's actually running

Cryptography & storage stack

Confidentiality
AES-256-GCM, native WebCrypto, encryption performed client-side (12-byte IV + GCM tag). Keys never reach a node.
Key derivation
Argon2id — 64 MB memory, 3 iterations, 256-bit output, with a clean KEK/DEK hierarchy.
Durability
Reed-Solomon erasure coding applied to the ciphertext. Adaptive to fleet size: RS 3+1 on the 4-node PoC, converging toward 8+4 at ≥12 nodes.
Dispersion invariant
≤ 1 fragment per node, continuously auditable. Keys and the encrypted index are fully replicated; user data is erasure-coded.
Sovereignty
Nodes are hosted in citizens' homes, not a data center. No single operator can read, correlate, or seize a complete object.
Measured, at the wall

Energy, per node

Measured with a calibrated smart plug (long-window energy integration, not instantaneous readings). Figures are for one Pixel + one 1 TB SSD.

Idle (disk asleep)
~0.1 W — the real state ~99% of the time. ≈ 0.9 kWh/yr, ≈ 0.22 €/yr, ≈ 44 gCO₂/yr. A node draws about as much as a night light.
Real exploitation
~1 W average (battery capped at 55% / resumes at 50% to preserve cells, SSD active a few hours/day). ≈ 9 kWh/yr, ≈ 2.3 €/yr, ≈ 0.45 kgCO₂/yr.
SSD writing
~2.2 W (headless). Confirms an SSD (~2 W active, ~0.3 W asleep) is far better than an HDD (2–5 W) for a "disk that sleeps" design.
Companion study — does all this activity wear the disks out?
Short answer: no — write-wear is not the limiting factor, and an HDD doesn't wear on write at all. See the honest write-amplification model, with an interactive endurance simulator you can drive yourself:
Open the endurance simulator →
The demo we trust

Pull a phone. The file rebuilds.

Durability isn't a slide — it's a reproducible drill in the PoC. With RS 3+1 across 4 nodes, one fragment lives on each.

1

Write an object — it's encrypted, erasure-coded, and one fragment lands on each node.

2

Physically unplug a Guardian, live.

3

The object is read back intact from the surviving nodes; the missing fragment self-heals.

Where we fit

Complement, not competitor.

Phone-cluster computing

  • Repurposes phones for compute
  • Clustered in a lab / facility
  • General-purpose Linux on the motherboard
  • Goal: low-carbon cloud computing for research

blob.cloud

  • Repurposes phones for encrypted storage
  • Distributed across citizens' homes
  • Client-side encrypted, sovereignty-first
  • Assembled by hand from a French refurbishment supply chain — reused hardware, nothing manufactured for the purpose

Tell us where this is naive.

We're a small, mission-led French project, and we'd genuinely value 15 minutes of a researcher's time — feedback, a pointer, or a collaboration. The PoC is real; the questions (density per node, fleet-scale RS, cold-read latency) are open.

Or read the work we build on: Junkyard Computing (UC San Diego)