AQ-MSA-001 — Master System Architecture Document
This document formalises Part 12 of the Akasha-Q Scientific Programme Charter. Everything described here is an intended design. The architecture as a whole sits at Concept; individual layer contracts sit at Theory; no layer has an artefact at Lab validation or above. Nothing here is a statement about achieved performance, and no sentence in it may be quoted as one.
1. PURPOSE AND SCOPE
Akasha-Q is a communications programme organised as ten layers (L0 to L9), instantiated in the node article AQ-NODE-01 and advanced along a six-rung reach ladder: optical bench → metro fibre and free-space → 20-30 km HAPS relay → CubeSat → operational LEO satellite → constellation. The layer contracts do not change with reach. What changes at each rung is the physical realisation of a layer and the evidence attached to its claims. A design that needs a new layer, a new decision outcome or a new trust state in order to reach a higher rung is a design defect, not a rung problem.
Visvambhara is a separate aerospace programme and the first platform designed to carry an Akasha-Q terminal. It is a consumer of this architecture, not its rationale; the two programmes share one restricted-access record, and nothing in this document depends on Visvambhara existing.
Security properties are never stated here as adjectives. Each layer states a named property, the assumption set under which that property is claimed, and the evidence level of the claim. A layer without all three has no claim, only an intention.
2. THE TWO DIRECTIONAL RULES
A layer publishes attributed observations, never conclusions about the layers above it. A consuming layer may not assert a property its supplier did not measure, and may not upgrade a provenance tag: an input tagged MODELLED cannot be republished as DERIVED, and a DERIVED value does not become MEASURED by being copied (DC-1).
Policy issued at L9 and applied at L5 can only remove permitted actions. No downward message may create authority, widen a scope, or convert an undetermined input into a benign one (DC-2). This is the structural reason Q4 can only ever reduce what Q1-Q3 allowed.
Figure 1 — The AQ-NODE-01 stack, with enforcement class and trust boundary per layer
EVIDENCE up (attributed observation) POLICY down (constraint only)
^ |
| v
+----------------------------------------------------------------------+
| LAYER | ENFORCEMENT | BOUND |
+----------------------------------------------------------------------+
| L9 Systems Engineering and Safety Governance | S | TB-5 |
| L8 AI-Assisted Analysis (advisory only) | I | TB-5 |
| L7 Network and Orchestration | S + C | TB-5 |
| L6 Evidence and Provenance Fabric | C + S | TB-5 |
| L5 Command Authority (Q1-Q3 hard, Q4 reduces) | H + C | TB-4 |
| L4 Dynamic Trust State (AQ-TSE-01) | S | TB-3 |
| L3 Identity and Cryptographic Trust | C | TB-3 |
| L2 Timing and Temporal Integrity | P + H | TB-2 |
| L1 Sensing and Entropy Trust | P + H | TB-2 |
| L0 Physical Reality (bench .. constellation) | P | TB-1 |
+----------------------------------------------------------------------+
TB-1 physical/system TB-2 deterministic acquisition (FPGA)
TB-3 trust reasoning TB-4 decision/physical effect (hardware-gated)
TB-5 runtime/evidence
L0 is the referent: it is measured, never asserted.
3. ENFORCEMENT CLASSIFICATION
Every architectural claim is classified by what actually enforces it. The classification is not a quality ranking; it states what remains true when the software above it is wrong.
| Class | Enforced by | Can do | Can never do |
|---|---|---|---|
| P | Physical measurement by an instrument | Tie a claim to reality; produce MEASURED values carrying an uncertainty statement | Establish intent, or by itself separate a hostile disturbance from a natural one |
| H | Hardware the runtime cannot bypass (TB-2 acquisition, TB-4 effect gate) | Make a permission physically unavailable; hold a gate de-armed irrespective of runtime state | Interpret meaning; be reconfigured by the same runtime it constrains |
| C | Cryptographic verification | Return a deterministic pass or fail; fail closed on any error condition | Be stronger than key custody at L3; return a likelihood in place of a verdict |
| S | Software policy in the runtime | Express constraint that is auditable and revisable | Survive its own edit; substitute for class H at TB-4 |
| I | Inference, including the whole of L8 | Annotate, prioritise for a human reader, recommend a reduction of authority | Authorize anything, widen any scope, or act as an input to L4 or L5 |
A composite claim inherits the weakest class in its chain. A cryptographic verdict computed over a value whose provenance is MODELLED is an I-class claim, not a C-class one. Class may change only at a trust boundary, and every crossing is recorded at L6 with the class on each side.
4. LAYER CONTRACTS
| Layer | Mission | Primary inputs | Primary outputs | Enf. |
|---|---|---|---|---|
| L0 | Define the physical channel, platform and environment the system is permitted to make claims about at the current rung | None — L0 is the referent | Declared environment envelope; the phenomena available to be measured | P |
| L1 | Acquire observations and entropy at the terminal with per-sample provenance and source-health qualification | L0 phenomena; sensor and entropy-source telemetry | MEASURED samples; source-health verdicts; explicit undetermined where a source is silent | P + H |
| L2 | Establish the time base that evidence is ordered by, and detect manipulation of that time base | Local oscillator; external references; L1 samples | Timestamps with uncertainty statements; divergence observations; ordering input for L6 | P + H |
| L3 | Bind identities to key material and answer Q1 and Q2 deterministically | Key material; role and revocation data; received frames | Verification verdicts (pass or fail only); key-lifecycle events | C |
| L4 | Compute the discrete trust state from per-domain confidence and enforce DC-4 | L1, L2, L3 observations; L6 continuity; L9 policy | Current state; the causing observation; the per-domain confidence record | S |
| L5 | Answer Q1-Q4 and emit exactly one decision outcome per command | Authenticated command; L3 verdicts; L4 state; L9 policy | execute, execute-restricted, safe-hold, abstain or deny, each with a reason | H + C |
| L6 | Record every consequential transition so that it is reconstructable from the record alone (DC-5) | Records from every layer | Append-only integrity-protected record; continuity and gap statements | C + S |
| L7 | Manage links, sessions and node roles across the reach ladder; plan contacts | Link state; node inventory; policy | Session state; contact plans; link observations to L1 and L4 | S + C |
| L8 | Annotate and prioritise recorded evidence for human review — advisory only | L6 records, read-only | Annotations tagged MODELLED; never a state, never a decision | I |
| L9 | Own requirements, hazards, the F-1..F-14 register, CF-1..CF-7, B-1..B-5, evidence-level assignment, DM-0..DM-6 maturity and change control | All layers; review artefacts | Policy as constraint; evidence-level assignments; release gates | S |
5. LAYER LIFECYCLE
| Layer | Headline trusted assumption | Failure classes (mapped into the L9 F-1..F-14 register) | Evidence generated | Y1 form | Evolution |
|---|---|---|---|---|---|
| L0 | The environment envelope declared for a rung is the envelope the hardware experiences | Undeclared environment excursion; a natural disturbance read as hostile, and the reverse | Environment logs; rung declaration record | Optical bench in a controlled room Y1 | Fibre and free-space, HAPS, CubeSat, LEO, constellation FR/LH |
| L1 | A source that reports nothing is not thereby healthy (DC-2) | Silent sensor; stuck or biased source; a health test that passes on stale data; provenance tag lost at TB-2 | Sample provenance records; health-test results; gap records | Bench entropy source behind an acquisition FPGA Y1 | Per-terminal qualification at every rung; in-flight health tests FR |
| L2 | An external time reference is an untrusted input until cross-checked; hold-over behaviour is known by measurement, not from a datasheet | Undetected drift; spoofed reference; ordering inversion; an uncertainty figure with no measured basis | Divergence logs; hold-over characterisation runs | Bench time base, one reference, divergence recorded and never silently corrected Y1 | Multi-reference cross-check; platform-motion effects FR/LH |
| L3 | Key material was generated from L1 entropy that passed its health test at generation time | Key use after a compromise indication; a verification error mapped to "unknown" rather than to failure; stale role data | Verification records; key-lifecycle records | Bench key hierarchy, signed frames, revocation exercised Y1 | Cross-rung identity; key distribution over the channel; algorithm agility FR |
| L4 | One qualifying observation is sufficient to degrade; restoration is never automatic (DC-4) | Thresholds set without measurement; state oscillation; state computed from stale inputs; an advisory value reaching the state function | Transition records naming the causing observation; confidence snapshots | Implemented with every threshold declared as an assumption and no measured value Y1 — see AQ-TSM-000 | Thresholds derived from bench, then field, measurement FR |
| L5 | A hardware gate at TB-4, not software, is what prevents a physical effect when the outcome does not permit one | Q4 widening a Q1-Q3 result; a gate armed without a current evidence record; an outcome emitted with no reason; abstain treated as a retryable error | Decision records carrying all four answers and their inputs | Bench command path gating one benign physical effect Y1 | Identical contract at every rung; bounded delegated-authority windows for link-limited operation FR/LH |
| L6 | A gap in the record is itself an observation, and degrades the evidence domain | An effect reported complete before its record is durable; silent truncation; dependence on an unverified L2; a reconstruction that needs the live system | The fabric itself; periodic reconstruction drills | Local append-only signed store plus one reconstruction drill Y1 | Cross-node fabric; store-and-forward across intermittent contact FR/LH |
| L7 | Link availability is never an authorization input; loss of contact means undetermined, not benign | A partition handled as degraded-but-permitted; a plan that assumes contact; unauthenticated topology data | Session and contact records; partition records | Two bench nodes, one link, deliberate partition tests CA/Y1 | Metro multi-node, HAPS relay scheduling, orbital contact planning FR/LH |
| L8 | Deleting L8 entirely changes no decision the system makes | An annotation persisted where a decision function can read it; an operator reading an annotation as a measurement; model output tagged MEASURED or DERIVED | Annotation records; the L9 check that L4 and L5 carry no L8 dependency | Offline analysis over recorded bench data CA/Y1 | Larger corpora, still excluded from the decision path by construction FR |
| L9 | An evidence level is assigned from an artefact, never from the confidence of its author | Claim escalation with no artefact; a demonstration described above its DM rung; a policy change made as though it were a mechanism change | Gate records; hazard analyses; review minutes; the F, CF and B registers | Written, reviewed, and applied to all bench work Y1 | Independent review introduced at the field and flight rungs FR/LH |
6. DEPENDENCY ORDER AND INTERFACE RULES
- Strict downward dependency. A layer consumes from the layers below it and constraint from L9. No layer calls upward. L8 reads L6 and nothing else.
- Every inter-layer message carries four fields: the value; its provenance tag MEASURED, DERIVED or MODELLED (DC-1); the observation time with the uncertainty statement supplied by L2; and an explicit
undeterminedflag wherever the value could not be established (DC-2). - No layer substitutes a default for a missing input. A layer that cannot produce its output emits
undeterminedwith a reason. Silence is a fault, never a pass. - Enforcement class changes only at a trust boundary. Every crossing of TB-1 to TB-5 is recorded at L6, with the class on each side of the crossing.
- Naming.
AQ-NODE-nis canonical;AKQ-NODE-nin Parts up to 12 denotes the same articles. Naming and interface conflicts are logged against CF-1..CF-7 and resolved at L9, never locally.
7. COMMAND PATH THROUGH THE STACK
Figure 2 — Q1 to Q4 across the trust boundaries; Q4 reduces and never widens
command frame arrives (L7)
|
v
[L3] Q1 who sent it ................ identity resolved? -> no: deny
|
v
[L3] Q2 cryptographically valid? ... verdict pass/fail -> no: deny
|
v
[L5] Q3 authorised now? ............ role, scope, window -> no: deny
| HARD CONSTRAINTS, class C + S
v
[L4] trust state + per-domain confidence record
|
v
[L5] Q4 should it execute under the current trust state?
| may only REDUCE the Q1-Q3 result
+--> execute | execute-restricted | safe-hold | abstain | deny
|
v
[TB-4] hardware gate arms a physical effect only for execute and
execute-restricted, and only while the arming evidence
record is current (class H)
|
v
[L6] the decision record is durable BEFORE the effect is
reported complete (DC-5)
8. EVIDENCE POSITION AND CLAIMS NOT MADE
Nothing in this architecture has been built. The correct reading of every row above is: this is the contract a future implementation must satisfy. For each layer, the L9 gate is the artefact that would move it from Theory to Lab validation, and no such artefact exists yet.
No claim of interception impossibility, of information-theoretic security at system level, of readiness for any flight platform, or of demonstrated behaviour at any rung above the optical bench. No performance figure appears anywhere above, because none has been measured: where a target belongs, the metric is named and the method by which a target will later be set from measurement is stated instead no measured value.
9. OPEN ITEMS
- Whether TB-4 hardware gating is achievable inside the mass, power and radiation envelope of the CubeSat rung is unanalysed. It is a gating question for rung 4, not a detail of it.
- Reconstruction of a consequential transition from the Evidence Fabric alone has never been exercised. Until one drill has run, DC-5 is an intention rather than a property.
- The L4 thresholds are undefined and are carried as declared assumptions in AQ-TSM-000; L4 cannot be gated above Theory while that remains true.
- The interaction between L2 hold-over and L6 ordering under loss of an external reference has no analysis yet, and is the most probable source of a silent evidence defect.