AQ-AAR-001 — Architecture Assumption Register
The Part 12 architecture is a design. No element of it has reached Lab validation, and every load-bearing statement it makes about the physical world is therefore an assumption. This register enumerates those assumptions so that each carries a name, an owner, a stated consequence if it turns out to be false, and the specific experiment that would settle it. An assumption absent from this register is not thereby absent from the architecture — it is merely unmanaged, which is the condition this document exists to end.
The register is the mechanism underneath DC-1. A value may be tagged MEASURED only where the assumptions that make the measurement meaningful are themselves recorded and testable; while a deciding experiment is outstanding, every value derived through that assumption is MODELLED regardless of what the acquisition path reports. It is also the mechanism underneath DC-2: an assumption in status assumed is an explicitly undetermined input, never a benign one.
FIELDS
- ID —
AS-nn, permanent. An ID is never reused, and a refuted assumption keeps its row. - Layer — the layer (L0–L9) whose correctness depends on the assumption. Where two layers depend on it, the row is owned by the layer that would have to be re-architected.
- Basis — why the assumption is currently believed, distinguishing established engineering practice from a property of this programme’s own design.
- Consequence if false — what breaks, expressed as a failure of a named design commitment or of a specific decision, not as a general degradation.
- Deciding experiment — the observation that would confirm or refute the assumption, written so that a reader can tell before the run which result counts as refutation.
- Owner — the accountable role. Roles are named rather than people because accountability survives a change of holder; one person may currently hold several.
- Gate — the gate from AQ-ARR-001 at which the deciding experiment is scheduled to run.
- Status — current evidence level plus disposition: assumed, under test, supported, refuted, retired.
Theory supported by established engineering theory or published metrology practice outside this programme; nothing inside this programme has tested it. Concept a property of this programme’s own design, with no evidence of any kind yet. None no evidence and no deciding experiment yet defined — a row may not remain in this state past gate G1. The Lab chip is part of this register’s vocabulary and is used by no row today; the first row to carry it will do so because a bench measurement exists and is recorded in the Evidence Fabric.
WHERE ASSUMPTIONS BIND
Assumptions are grouped by the trust boundary they sit on in AQ-NODE-01, because that is where a false assumption does its damage — a wrong belief at TB-2 is silently laundered into every layer above it.
Figure 1 - Assumptions bound to the AQ-NODE-01 trust boundaries
TB-1 physical / system AS-01 AS-02 AS-18
| (transducers, entropy sources, channel)
v sampled at source, provenance tag attached
TB-2 deterministic acquisition AS-03 AS-04 AS-05
| (FPGA, fixed-function, no inference)
v typed sample + MEASURED / DERIVED / MODELLED tag
TB-3 trust reasoning AS-06 AS-07 AS-08
| (AQ-TSE-01 state, weighting) AS-09 AS-10 AS-11
v trust state + proposed decision outcome
TB-4 decision / physical effect AS-12 AS-13
| (hardware-gated; Q4 may only reduce Q1-Q3)
v effect asserted or withheld, both recorded
TB-5 runtime / evidence AS-14 AS-15 AS-16 AS-17
(Evidence Fabric, build identity, advisory analysis)
A false assumption at TB-1 or TB-2 is not detectable at TB-3 or above:
the tag says MEASURED and nothing downstream can contradict it.
REGISTER §A — ASSUMPTION, BASIS, OWNER, STATUS
| ID | Layer | Assumption | Basis | Owner | Status |
|---|---|---|---|---|---|
| AS-01 | L1 | Every transducer value can be traced to a calibration record whose chain to a reference standard is unbroken and whose validity interval covers the instant of measurement. | Traceable calibration is routine metrology practice; the design carries calibration identity and expiry in the sample header at TB-2. | Metrology owner | Theory assumed |
| AS-02 | L1 | The entropy sources feeding L1 fail independently: no single environmental cause degrades two of them at once. | Sources are selected for distinct physical mechanisms and placed in separate power and thermal domains. Independence is designed for, not yet observed. | L1 Sensing owner | Concept assumed |
| AS-03 | L1 | Continuous health tests detect only the entropy failure classes they were constructed to detect, and are silent on all others. | A property of the test construction rather than a hope. Recorded as an assumption because the system behaves as though it were a general guarantee unless the undetected set is written down. | L1 Sensing owner | Theory assumed |
| AS-04 | L2 | Free-running oscillator drift stays inside a stated bound across the declared holdover interval, so a timestamp taken while discipline is lost remains usable for ordering. | Oscillator classes are characterised by published Allan deviation data; the design allocates holdover against that class. The bound for the actual build is unmeasured. | L2 Timing owner | Theory assumed |
| AS-05 | L2 | The node can always determine whether it is disciplined or in holdover, and the answer reaches L4 as an input. | Discipline state is exposed by the timing subsystem and carried as an explicit field, per DC-2. | L2 Timing owner | Concept assumed |
| AS-06 | L3 | Private key material generated inside the cryptographic boundary never leaves it in plaintext; the handle crosses TB-3, the key does not. | In-boundary generation and use is the stated design. Side-channel egress is a separate and unbounded path. | L3 Identity owner | Concept assumed |
| AS-07 | L3 | A revoked credential is known to be revoked at the node before the node next relies on it, or the node knows its revocation data is stale. | The design carries a maximum revocation age and treats staleness as an L4 input rather than as silence. | L3 Identity owner | Concept assumed |
| AS-08 | L3 | The identity a node presents is bound to that physical node and cannot be presented by a different one. | Binding is intended to rest on in-boundary key generation plus a boot measurement, so that a cloned image does not carry a usable identity. | L3 Identity owner | Concept assumed |
| AS-09 | L4 | The thresholds separating NORMAL, RESTRICTED, CRITICAL and DENY correspond to real differences in operating condition rather than to chosen constants. | The design requires every threshold to be derived from a measured distribution of its observable under known-good and known-degraded conditions. No such distribution exists yet. | L4 AQ-TSE-01 owner | Concept assumed |
| AS-10 | L4 | Declared correlation groups are complete: any inputs sharing a common cause are declared together, so one observation is never counted as several. | Group declaration is a required artefact at input registration and is reviewed at the same gate. | L4 AQ-TSE-01 owner | Concept assumed |
| AS-11 | L4 | The DC-4 recovery sequence can always complete under achievable field conditions, so monotonic degradation does not become a permanent latch. | Recovery is specified as a bounded sequence of positive observations. Whether those observations are obtainable in the field is untested. | L4 AQ-TSE-01 owner | Concept assumed |
| AS-12 | L5 | No implementation path exists by which Q4 grants authority that Q1–Q3 withheld; the trust state can only reduce. | Architectural ordering: the hard constraints are evaluated first and their result is carried as a ceiling into the Q4 evaluation. | L5 Command owner | Concept assumed |
| AS-13 | L5 | No physical effect can occur at TB-4 while the hardware gate is deasserted, including when the runtime above it is fully compromised. | The gate is specified as a physical interlock outside the runtime’s reach. This is the single assumption the compromise argument rests on. | L5 Command owner | Concept assumed |
| AS-14 | L6 | Recorded evidence is sufficient to reconstruct any consequential transition without access to live system state (DC-5). | The evidence schema is designed from the decision function’s inputs. Sufficiency has never been exercised by a reconstruction attempt. | L6 Evidence owner | Concept assumed |
| AS-15 | L6 | Evidence committed before a power loss or link failure is recoverable afterwards with its ordering intact. | Append-only storage with ordering derived from L2 time and a monotonic sequence, both of which depend on AS-04. | L6 Evidence owner | Theory assumed |
| AS-16 | L8 | No AI-derived value enters a hard constraint or a gate; L8 output is advisory in fact and not only in intent. | All L8 output is tagged DERIVED or MODELLED, and L5 refuses those tags on Q1–Q3. The refusal is a design rule that code must be shown to obey. | L8 Analysis owner | Concept assumed |
| AS-17 | L9 | The build identity measured on a node corresponds to the reviewed and signed source revision. | Reproducible build pipeline with the boot measurement carried into the evidence record. Reproducibility is claimed by the toolchain, not yet demonstrated here. | L9 Build & release owner | Theory assumed |
| AS-18 | L0 | Channel and link-budget characterisations established at one reach rung do not transfer to the next without re-measurement. | Stated as a limitation, not a hope: atmospheric, thermal and pointing regimes differ by rung. Recorded so that bench evidence cannot be cited for a rung it does not cover. | L9 Systems engineering owner | Theory assumed |
REGISTER §B — CONSEQUENCE IF FALSE, DECIDING EXPERIMENT, GATE
| ID | Consequence if false | Deciding experiment | Gate |
|---|---|---|---|
| AS-01 | DC-1 collapses. A value tagged MEASURED is in fact modelled through an uncharacterised transfer function, and every trust weight above it rests on an unknown offset that nothing downstream can see. | Cross-calibrate against an independent reference on the bench; inject a known offset and confirm the acquisition path reports drift rather than absorbing it; expire a calibration record mid-run and confirm the sample is tagged undetermined, not benign. Refutation = any of the three absorbed silently. | G3 |
| AS-02 | Combining sources creates apparent margin that does not exist. A common-mode event reduces true min-entropy while every per-source health test still passes. | Instrument both sources through temperature, supply-ripple and EMI sweeps and measure cross-correlation across the sweep. Any pair whose measured coefficient exceeds the threshold established from that same data is declared one correlation group. The threshold is derived from the measurement; none is asserted in advance. | G3 |
| AS-03 | If the tests are treated as general rather than class-specific, an unmodelled failure passes every check and the node reports NORMAL while its entropy is degraded — the worst available outcome under DC-2. | Fault-injection campaign against a catalogue of induced failures, deliberately including modes outside the tests’ design envelope. The deliverable is the enumerated list of undetected classes, published as a limitation of L1 rather than suppressed. | G3 |
| AS-04 | L2 timestamps silently lose their ordering guarantee. L6 evidence ordering and L4 windowing become wrong with no alarm anywhere, so a reconstruction under DC-5 returns a confident false sequence. | Withhold the reference for progressively longer intervals and measure phase error against an independent reference on the actual build. The holdover bound is set from that measurement, not from the datasheet class. | G3 |
| AS-05 | DC-2 is defeated at the timing layer: absent discipline is read as present discipline, and a spoofed or lost reference becomes indistinguishable from a good one. | Remove discipline without announcing it and confirm the node reports holdover to L4 within the interval it claims. Refutation = any path where discipline is lost and the reported state remains disciplined. | G3 |
| AS-06 | Q1 and Q2 become unfalsifiable. A holder of exported key material issues commands that are genuinely valid, and the four-question path answers truthfully in the attacker’s favour. | Enumerate every egress path from the boundary and attempt export through each, expecting refusal; then characterise power and electromagnetic side channels to bound the leakage that is not an API path. Refutation = any plaintext egress, or side-channel recovery within the characterised effort. | G3 |
| AS-07 | A compromised identity retains authority for an unbounded window while Q3 continues to answer “authorised” on a credential the operator believes is dead. | Partition the node from the revocation source, revoke, and measure the interval before the node refuses. Confirm the node moves to RESTRICTED on staleness rather than continuing at NORMAL. The acceptable staleness bound is set from the measured propagation distribution. | G3 |
| AS-08 | Node identity becomes transferable. A cloned image presents a valid identity from a location and platform the operator did not authorise. | Clone the node image onto a second physical unit and attempt to present the original identity; expect failure at boot measurement. Refutation = successful presentation from the clone. | G3 |
| AS-09 | L4 becomes decorative. The state word changes without conveying a difference, which is falsification mode R-02 in AQ-ARR-001 and removes the basis for Q4 having any authority at all. | Held-out evaluation against pre-registered nominal, degraded and adversarial scenario sets: show that state assignment separates them by a statistic named before the run, and publish the separation together with every failure case. | G4 |
| AS-10 | N correlated inputs read as N independent confirmations, so confidence rises fastest exactly when a common-mode fault is in progress — the specific inversion DC-1 exists to prevent. | Measure cross-correlation across the full declared input set under stress. Any undeclared pair above the established threshold is a defect against this register, not a tuning matter, and the campaign is repeated whenever an input is added. | G3 |
| AS-11 | Nodes latch into RESTRICTED and never return. Operators acquire an override habit, and the override becomes the real decision path while L4 becomes a formality. | Measure time-to-recover across induced degradations and count unrecoverable end states. The pass criterion is zero unrecoverable states plus a characterised recovery-time distribution; the rate is reported, not assumed. | G4 |
| AS-12 | The entire command-authority argument inverts: a trust state could authorise what identity and authorisation refused, making the four questions decorative. | Exhaustive enumeration of the decision table plus property-based testing over the decision function, asserting that no input combination yields an outcome more permissive than the Q1–Q3 ceiling. | G2 |
| AS-13 | Every claim that depends on containing a compromised runtime is void, because software alone could then assert a physical effect. | Attempt actuation with the gate deasserted under a red-team assumption that the attacker owns the L7 and L8 runtime entirely; add fault injection at the gate itself. Refutation = any asserted effect. | G3 |
| AS-14 | DC-5 fails. A consequential transition cannot be reconstructed after the fact, so the programme has a record that looks complete and answers no real question. | Reconstruction drill: a reviewer who did not run the test receives only the evidence export and must reproduce the decision and its inputs independently. Every transition they cannot reconstruct is a defect against the evidence schema. | G3 |
| AS-15 | Evidence is lost or reordered precisely at the events most worth reconstructing, because those are the events accompanied by power and link failures. | Repeated power interruption and link-loss injection during writes, followed by recovery and ordering verification against an independently logged ground truth. | G3 |
| AS-16 | An unexplainable model becomes a control element, and the advisory-only commitment becomes false in fact while remaining true in the documentation. | Static dataflow audit from every L8 output to every L5 input, plus a negative test: inject a deliberately poisoned advisory and confirm the decision outcome is unchanged. | G2 |
| AS-17 | The review argument is void. Evidence records attest to the behaviour of a build nobody reviewed, and every other row in this register is evidence about an unknown artefact. | Independent rebuild in a second environment producing bit-identical artefacts; then alter one source file and confirm the measurement differs and attestation fails. | G1 |
| AS-18 | Bench results are cited as though they characterised an atmospheric or orbital link, which is the mechanism by which a design study turns into an unearned capability claim. | Re-run the channel characterisation at each rung. This register requires a separate evidence row per rung; a row may not inherit the result of the rung below it. | G3, G4, G5, G6 |
RULES OF USE
- An assumption is retired only by the recorded result of its deciding experiment, referenced by its Evidence Fabric record identifier. Argument, review consensus and reviewer seniority do not retire a row.
- A refuted assumption is not deleted. It stays, marked refuted, with the architectural change it forced recorded against it.
- Any design change that introduces a new dependency on the physical world adds a row before the change is merged. The row may open with status None, but not past gate G1.
- Where an assumption is outstanding, documents describing capability that depends on it state the evidence level rather than the capability.
An assumption with no deciding experiment is not an assumption — it is a belief with an identifier, and identifiers make beliefs look managed. A row whose experiment column reads “review”, “analysis” or “monitoring” without naming the observation that would count as refutation is a defect in this document and is to be raised as one.
A supported row licenses one statement only: that the named experiment produced the named result at the named evidence level, on the build and at the reach rung where it ran. It does not license describing the system as validated, and it does not transfer to another rung, another build or another configuration. AS-18 exists specifically to block that transfer, and it applies to this register as much as to any external document.