← Part 12

AQ-MSA-001

Formalises the ten-layer AQ-NODE-01 stack: per-layer mission, inputs, outputs, trusted assumptions, failure classes, evidence generated, Y1 form and future evolution, with the enforcement classification and the two directional rules (evidence up, policy down).

Charter artifact · gated by Part 12 · revision 0, draft for internal review

AQ-MSA-001 — Master System Architecture Document

DOCUMENT STATUS

This document formalises Part 12 of the Akasha-Q Scientific Programme Charter. Everything described here is an intended design. The architecture as a whole sits at Concept; individual layer contracts sit at Theory; no layer has an artefact at Lab validation or above. Nothing here is a statement about achieved performance, and no sentence in it may be quoted as one.

1. PURPOSE AND SCOPE

Akasha-Q is a communications programme organised as ten layers (L0 to L9), instantiated in the node article AQ-NODE-01 and advanced along a six-rung reach ladder: optical bench → metro fibre and free-space → 20-30 km HAPS relay → CubeSat → operational LEO satellite → constellation. The layer contracts do not change with reach. What changes at each rung is the physical realisation of a layer and the evidence attached to its claims. A design that needs a new layer, a new decision outcome or a new trust state in order to reach a higher rung is a design defect, not a rung problem.

Visvambhara is a separate aerospace programme and the first platform designed to carry an Akasha-Q terminal. It is a consumer of this architecture, not its rationale; the two programmes share one restricted-access record, and nothing in this document depends on Visvambhara existing.

Security properties are never stated here as adjectives. Each layer states a named property, the assumption set under which that property is claimed, and the evidence level of the claim. A layer without all three has no claim, only an intention.

2. THE TWO DIRECTIONAL RULES

RULE MSA-D1 — TRUST FLOWS UPWARD AS EVIDENCE

A layer publishes attributed observations, never conclusions about the layers above it. A consuming layer may not assert a property its supplier did not measure, and may not upgrade a provenance tag: an input tagged MODELLED cannot be republished as DERIVED, and a DERIVED value does not become MEASURED by being copied (DC-1).

RULE MSA-D2 — POLICY FLOWS DOWNWARD AS CONSTRAINT

Policy issued at L9 and applied at L5 can only remove permitted actions. No downward message may create authority, widen a scope, or convert an undetermined input into a benign one (DC-2). This is the structural reason Q4 can only ever reduce what Q1-Q3 allowed.

Figure 1 — The AQ-NODE-01 stack, with enforcement class and trust boundary per layer

   EVIDENCE up (attributed observation)     POLICY down (constraint only)
                  ^                                        |
                  |                                        v
   +----------------------------------------------------------------------+
   | LAYER                                          | ENFORCEMENT | BOUND |
   +----------------------------------------------------------------------+
   | L9  Systems Engineering and Safety Governance  | S           | TB-5  |
   | L8  AI-Assisted Analysis (advisory only)       | I           | TB-5  |
   | L7  Network and Orchestration                  | S + C       | TB-5  |
   | L6  Evidence and Provenance Fabric             | C + S       | TB-5  |
   | L5  Command Authority (Q1-Q3 hard, Q4 reduces) | H + C       | TB-4  |
   | L4  Dynamic Trust State (AQ-TSE-01)            | S           | TB-3  |
   | L3  Identity and Cryptographic Trust           | C           | TB-3  |
   | L2  Timing and Temporal Integrity              | P + H       | TB-2  |
   | L1  Sensing and Entropy Trust                  | P + H       | TB-2  |
   | L0  Physical Reality (bench .. constellation)  | P           | TB-1  |
   +----------------------------------------------------------------------+

   TB-1 physical/system   TB-2 deterministic acquisition (FPGA)
   TB-3 trust reasoning   TB-4 decision/physical effect (hardware-gated)
   TB-5 runtime/evidence
   L0 is the referent: it is measured, never asserted.

3. ENFORCEMENT CLASSIFICATION

Every architectural claim is classified by what actually enforces it. The classification is not a quality ranking; it states what remains true when the software above it is wrong.

ClassEnforced byCan doCan never do
PPhysical measurement by an instrumentTie a claim to reality; produce MEASURED values carrying an uncertainty statementEstablish intent, or by itself separate a hostile disturbance from a natural one
HHardware the runtime cannot bypass (TB-2 acquisition, TB-4 effect gate)Make a permission physically unavailable; hold a gate de-armed irrespective of runtime stateInterpret meaning; be reconfigured by the same runtime it constrains
CCryptographic verificationReturn a deterministic pass or fail; fail closed on any error conditionBe stronger than key custody at L3; return a likelihood in place of a verdict
SSoftware policy in the runtimeExpress constraint that is auditable and revisableSurvive its own edit; substitute for class H at TB-4
IInference, including the whole of L8Annotate, prioritise for a human reader, recommend a reduction of authorityAuthorize anything, widen any scope, or act as an input to L4 or L5
CLASS INHERITANCE

A composite claim inherits the weakest class in its chain. A cryptographic verdict computed over a value whose provenance is MODELLED is an I-class claim, not a C-class one. Class may change only at a trust boundary, and every crossing is recorded at L6 with the class on each side.

4. LAYER CONTRACTS

LayerMissionPrimary inputsPrimary outputsEnf.
L0Define the physical channel, platform and environment the system is permitted to make claims about at the current rungNone — L0 is the referentDeclared environment envelope; the phenomena available to be measuredP
L1Acquire observations and entropy at the terminal with per-sample provenance and source-health qualificationL0 phenomena; sensor and entropy-source telemetryMEASURED samples; source-health verdicts; explicit undetermined where a source is silentP + H
L2Establish the time base that evidence is ordered by, and detect manipulation of that time baseLocal oscillator; external references; L1 samplesTimestamps with uncertainty statements; divergence observations; ordering input for L6P + H
L3Bind identities to key material and answer Q1 and Q2 deterministicallyKey material; role and revocation data; received framesVerification verdicts (pass or fail only); key-lifecycle eventsC
L4Compute the discrete trust state from per-domain confidence and enforce DC-4L1, L2, L3 observations; L6 continuity; L9 policyCurrent state; the causing observation; the per-domain confidence recordS
L5Answer Q1-Q4 and emit exactly one decision outcome per commandAuthenticated command; L3 verdicts; L4 state; L9 policyexecute, execute-restricted, safe-hold, abstain or deny, each with a reasonH + C
L6Record every consequential transition so that it is reconstructable from the record alone (DC-5)Records from every layerAppend-only integrity-protected record; continuity and gap statementsC + S
L7Manage links, sessions and node roles across the reach ladder; plan contactsLink state; node inventory; policySession state; contact plans; link observations to L1 and L4S + C
L8Annotate and prioritise recorded evidence for human review — advisory onlyL6 records, read-onlyAnnotations tagged MODELLED; never a state, never a decisionI
L9Own requirements, hazards, the F-1..F-14 register, CF-1..CF-7, B-1..B-5, evidence-level assignment, DM-0..DM-6 maturity and change controlAll layers; review artefactsPolicy as constraint; evidence-level assignments; release gatesS

5. LAYER LIFECYCLE

LayerHeadline trusted assumptionFailure classes (mapped into the L9 F-1..F-14 register)Evidence generatedY1 formEvolution
L0The environment envelope declared for a rung is the envelope the hardware experiencesUndeclared environment excursion; a natural disturbance read as hostile, and the reverseEnvironment logs; rung declaration recordOptical bench in a controlled room Y1Fibre and free-space, HAPS, CubeSat, LEO, constellation FR/LH
L1A source that reports nothing is not thereby healthy (DC-2)Silent sensor; stuck or biased source; a health test that passes on stale data; provenance tag lost at TB-2Sample provenance records; health-test results; gap recordsBench entropy source behind an acquisition FPGA Y1Per-terminal qualification at every rung; in-flight health tests FR
L2An external time reference is an untrusted input until cross-checked; hold-over behaviour is known by measurement, not from a datasheetUndetected drift; spoofed reference; ordering inversion; an uncertainty figure with no measured basisDivergence logs; hold-over characterisation runsBench time base, one reference, divergence recorded and never silently corrected Y1Multi-reference cross-check; platform-motion effects FR/LH
L3Key material was generated from L1 entropy that passed its health test at generation timeKey use after a compromise indication; a verification error mapped to "unknown" rather than to failure; stale role dataVerification records; key-lifecycle recordsBench key hierarchy, signed frames, revocation exercised Y1Cross-rung identity; key distribution over the channel; algorithm agility FR
L4One qualifying observation is sufficient to degrade; restoration is never automatic (DC-4)Thresholds set without measurement; state oscillation; state computed from stale inputs; an advisory value reaching the state functionTransition records naming the causing observation; confidence snapshotsImplemented with every threshold declared as an assumption and no measured value Y1 — see AQ-TSM-000Thresholds derived from bench, then field, measurement FR
L5A hardware gate at TB-4, not software, is what prevents a physical effect when the outcome does not permit oneQ4 widening a Q1-Q3 result; a gate armed without a current evidence record; an outcome emitted with no reason; abstain treated as a retryable errorDecision records carrying all four answers and their inputsBench command path gating one benign physical effect Y1Identical contract at every rung; bounded delegated-authority windows for link-limited operation FR/LH
L6A gap in the record is itself an observation, and degrades the evidence domainAn effect reported complete before its record is durable; silent truncation; dependence on an unverified L2; a reconstruction that needs the live systemThe fabric itself; periodic reconstruction drillsLocal append-only signed store plus one reconstruction drill Y1Cross-node fabric; store-and-forward across intermittent contact FR/LH
L7Link availability is never an authorization input; loss of contact means undetermined, not benignA partition handled as degraded-but-permitted; a plan that assumes contact; unauthenticated topology dataSession and contact records; partition recordsTwo bench nodes, one link, deliberate partition tests CA/Y1Metro multi-node, HAPS relay scheduling, orbital contact planning FR/LH
L8Deleting L8 entirely changes no decision the system makesAn annotation persisted where a decision function can read it; an operator reading an annotation as a measurement; model output tagged MEASURED or DERIVEDAnnotation records; the L9 check that L4 and L5 carry no L8 dependencyOffline analysis over recorded bench data CA/Y1Larger corpora, still excluded from the decision path by construction FR
L9An evidence level is assigned from an artefact, never from the confidence of its authorClaim escalation with no artefact; a demonstration described above its DM rung; a policy change made as though it were a mechanism changeGate records; hazard analyses; review minutes; the F, CF and B registersWritten, reviewed, and applied to all bench work Y1Independent review introduced at the field and flight rungs FR/LH

6. DEPENDENCY ORDER AND INTERFACE RULES

  • Strict downward dependency. A layer consumes from the layers below it and constraint from L9. No layer calls upward. L8 reads L6 and nothing else.
  • Every inter-layer message carries four fields: the value; its provenance tag MEASURED, DERIVED or MODELLED (DC-1); the observation time with the uncertainty statement supplied by L2; and an explicit undetermined flag wherever the value could not be established (DC-2).
  • No layer substitutes a default for a missing input. A layer that cannot produce its output emits undetermined with a reason. Silence is a fault, never a pass.
  • Enforcement class changes only at a trust boundary. Every crossing of TB-1 to TB-5 is recorded at L6, with the class on each side of the crossing.
  • Naming. AQ-NODE-n is canonical; AKQ-NODE-n in Parts up to 12 denotes the same articles. Naming and interface conflicts are logged against CF-1..CF-7 and resolved at L9, never locally.

7. COMMAND PATH THROUGH THE STACK

Figure 2 — Q1 to Q4 across the trust boundaries; Q4 reduces and never widens

   command frame arrives (L7)
        |
        v
   [L3] Q1  who sent it ................ identity resolved?   -> no: deny
        |
        v
   [L3] Q2  cryptographically valid? ... verdict pass/fail    -> no: deny
        |
        v
   [L5] Q3  authorised now? ............ role, scope, window  -> no: deny
        |                                HARD CONSTRAINTS, class C + S
        v
   [L4] trust state + per-domain confidence record
        |
        v
   [L5] Q4  should it execute under the current trust state?
        |        may only REDUCE the Q1-Q3 result
        +--> execute | execute-restricted | safe-hold | abstain | deny
                 |
                 v
   [TB-4] hardware gate arms a physical effect only for execute and
          execute-restricted, and only while the arming evidence
          record is current (class H)
                 |
                 v
   [L6] the decision record is durable BEFORE the effect is
        reported complete (DC-5)

8. EVIDENCE POSITION AND CLAIMS NOT MADE

Nothing in this architecture has been built. The correct reading of every row above is: this is the contract a future implementation must satisfy. For each layer, the L9 gate is the artefact that would move it from Theory to Lab validation, and no such artefact exists yet.

CLAIMS THIS DOCUMENT DOES NOT MAKE

No claim of interception impossibility, of information-theoretic security at system level, of readiness for any flight platform, or of demonstrated behaviour at any rung above the optical bench. No performance figure appears anywhere above, because none has been measured: where a target belongs, the metric is named and the method by which a target will later be set from measurement is stated instead no measured value.

9. OPEN ITEMS

  • Whether TB-4 hardware gating is achievable inside the mass, power and radiation envelope of the CubeSat rung is unanalysed. It is a gating question for rung 4, not a detail of it.
  • Reconstruction of a consequential transition from the Evidence Fabric alone has never been exercised. Until one drill has run, DC-5 is an intention rather than a property.
  • The L4 thresholds are undefined and are carried as declared assumptions in AQ-TSM-000; L4 cannot be gated above Theory while that remains true.
  • The interaction between L2 hold-over and L6 ordering under loss of an external reference has no analysis yet, and is the most probable source of a silent evidence defect.