AQ-SCN-002 — Scenario 2 specification: Degraded information
This document specifies one scenario in the AQ-SCN series for AQ-NODE-01 (written AKQ-NODE-1 in Parts up to 12; the same article is meant). It is a specification of an intended procedure. No run of AQ-SCN-002 has been performed at any evidence level. Every expected behaviour below is a design intent to be confirmed or refuted by measurement, not a reported result.
References to the conflict register CF-1..CF-7, the failure-mode register F-1..F-14 and the decision boundaries B-1..B-5 name the register entries this scenario is designed to provoke. Where a register text differs from the reading here, the register governs and this document is corrected.
F1 — IDENTIFIER AND STATUS
- Identifier
AQ-SCN-002. Subject article:AQ-NODE-01. Architecture tier: CA for the transition logic under test, Y1 for the bench implementation that will execute it. - Current evidence level: Concept. Target progression: Theory → Simulation → Lab validation, in that order, on rung 1 of the reach ladder (optical bench). Nothing in this scenario addresses metro fibre, free-space, HAPS relay, CubeSat, LEO or constellation reach.
- Layers exercised: L1, L2, L3, L4 (AQ-TSE-01, primary), L5, L6, L8 (advisory only), L9 (run governance).
F2 — QUESTION THE SCENARIO ANSWERS
Does the node distinguish degraded input from benign world? The scenario tests one proposition: that when the information reaching L4 loses timeliness, presence, agreement, currency or declared quality, the trust state falls on the evidence of that loss alone, the loss is named in the record, and no downstream consumer receives a value whose degradation has been erased in transit.
Out of scope: no adversary is modelled in AQ-SCN-002. All five injections are environmental or operational. Adversarial content, forged credentials and injected commands belong to other scenarios in the series; mixing them here would make an unfavourable result unattributable.
F3 — EVIDENCE LEVEL AND CLAIM CEILING BY STAGE
| Stage | Executed on | Level reached | Ceiling on what may be claimed |
|---|---|---|---|
| A | Desk model of the AQ-TSE-01 transition function | Theory | Internal logical consistency of the transition function only. No claim about any physical input. |
| B | Injected and replayed feed traces against the implemented state machine | Simulation | Behaviour of the implementation on the injected traces only. No claim about real sensing behaviour. |
| C | Optical bench, instrumented feeds, TB-4 gate into a dummy load | Lab validation | Behaviour for the bench feed set, at the declared bounds, at the run-card magnitudes, on that bench. Nothing beyond. |
F4 — TRUST BOUNDARIES AND DECLARED PARAMETERS
The injections cross TB-1 (physical/system) and TB-2 (deterministic acquisition, FPGA); the response is computed at TB-3 (trust reasoning), constrained at TB-4 (decision/physical effect, hardware-gated) and recorded through TB-5 (runtime/evidence). Six declared parameters bound the feeds. Their numeric values are not asserted in this document. Each is fixed on the run card from bench measurement of the feed itself, and the derivation is recorded with the run:
Bffreshness bound — maximum admissible arrival lag, expressed as a multiple of the feed's nominal reporting interval.Naabsence tolerance — consecutive missed reports before the input is declared undetermined.Waagreement window — admissible divergence between nominally redundant sources.Bccontent-age bound — maximum admissible age of the content carried, independent of packet timing.Wtattestation validity window — L3 credential currency limit.Qfquality floor — the declared per-feed quality metric below which the feed is not admissible as a basis for a consequential decision.
F5 — PRECONDITIONS AND ENTRY STATE
- Node in NORMAL with a recorded baseline dwell at that state.
- Every feed declares its nominal reporting interval and its quality metric before the run; a feed without a declared metric is not admitted to the run.
- DC-1 pre-check: every value crossing TB-3 carries a MEASURED / DERIVED / MODELLED tag. A single untagged value aborts the run before injection begins — an untagged value makes every later result unattributable.
- Evidence Fabric writable and confirmed durable; if it is not, the run does not start (DC-5 cannot be satisfied retrospectively).
- Every injection is bracketed: the run card sets at least one magnitude below the relevant bound and one above it, so the run measures where the transition occurs rather than only that one occurred.
F6 — INJECTION SET: MAGNITUDE, TIMING, TELEMETRY
| Ref | Injection | Magnitude (run-card parameter) | Timing | Telemetry label |
|---|---|---|---|---|
| I2-1 | Input delay | Arrival lag of k × nominal reporting interval on one feed; k stepped upward to bracket Bf. Packet content unaltered. | Phase P1, after baseline dwell; held for a fixed number of reporting intervals at each step. | aq.l1.feed.arrival_lag, aq.l2.time.stamp_delta |
| I2-2 | Missing input | Complete suppression of one feed for m consecutive expected reports; m stepped to bracket Na. No error message is emitted — the feed simply stops. | Phase P2, previous injection cleared and state re-baselined. | aq.l1.feed.absent, aq.l4.input.undetermined |
| I2-3 | Contradictory input | Divergence imposed between two nominally redundant sources, stepped to bracket Wa. Run both a symmetric case (neither source identifiable as wrong) and an asymmetric case. | Phase P3, both sources timely and present throughout. | aq.l1.xcheck.divergence, aq.l6.conflict.ref (CF entry) |
| I2-4 | Stale information | Packet timing nominal; carried content frozen and validity epoch held, for durations bracketing Bc. Separately, an L3 attestation held past Wt. | Phase P4; the attestation case is run against a command arrival, the sensing case against continuous evaluation. | aq.l1.feed.content_age, aq.l3.attest.validity_epoch |
| I2-5 | Reduced source quality | Declared quality metric driven downward across Qf while timing, presence and agreement all remain nominal. | Phase P5; then all injections cleared (P6) and the recovery sequence run (P7). | aq.l1.quality.declared, aq.l4.basis.admissible |
Figure 1 - AQ-SCN-002 phase timeline and intended trust-state path
P0 base P1 P2 P3 P4 P5 P6 clear P7 recover
|--------|-------|-------|--------|-------|-------|----------|-----------|
I2-1 I2-2 I2-3 I2-4 I2-5 all off recovery
delay absent conflict stale quality sequence
intended AQ-TSE-01 path:
NORMAL --> RESTRICTED ------------------> CRITICAL ---> RECOVERING --> NORMAL
^ ^ ^
| | |
first bound breach accumulated or full recovery
(DC-4: one observation) compound breach sequence only
forbidden path: any upward step that does not pass through RECOVERING
forbidden path: any injection phase that produces no recorded evaluation
F7 — EXPECTED BEHAVIOUR AND FAILURE CRITERION PER INJECTION
| Ref | Domain it should affect | Expected transition | Permitted decision outcome | Failure criterion if not detected |
|---|---|---|---|---|
| I2-1 | L1 sensing freshness, L2 temporal integrity; the delayed value must not be admitted as current at TB-3. | NORMAL → RESTRICTED at the first evaluation cycle in which lag exceeds Bf. | execute-restricted; abstain where the delayed feed is the sole basis. | The lagged sample is consumed with a current-arrival tag; or state remains NORMAL past Bf; or the lag is recorded but no evaluation is triggered by it. |
| I2-2 | L1/L4 input completeness. DC-2 governs: absence is a value and must appear as undetermined. | → RESTRICTED at Na; → CRITICAL if the absent feed is one no other input can substitute for. | abstain or safe-hold for any command depending on that input. | Last-known-good re-use. Any substitution of a prior value carrying a current timestamp, any silent default to a benign reading, or any outcome of execute on an undetermined basis. |
| I2-3 | L1 cross-check and L6 conflict record; the disagreement itself is the finding, not the two values. | → RESTRICTED on divergence beyond Wa, with a CF entry written before the outcome is issued. | abstain, or safe-hold where a hold state exists. | Silent arbitration — one source selected, or the two averaged into a plausible value — with no conflict record; or a conflict record written after the decision rather than before it. |
| I2-4 | Sensing case: L1 content currency. Attestation case: L3, evaluated at Q3 (authorised now). | Sensing: → RESTRICTED at Bc. Attestation: no trust-state change required; the command fails a hard constraint. | Sensing: execute-restricted / abstain. Attestation past Wt: deny at Q3. | Timely packets treated as current content; or an expired attestation reduced to a Q4 trust discount instead of a Q3 refusal. Q4 may only ever reduce what Q1–Q3 allowed; it may never rescue a Q3 failure. |
| I2-5 | L1 entropy/quality trust; the admissibility of the feed as a basis, distinct from its availability. | → RESTRICTED on the first evaluation below Qf (DC-4: one observation is sufficient to fall). | execute-restricted, or abstain where the feed is the sole basis for the trust term. | Quality metadata dropped anywhere in the pipeline, so a downstream consumer receives an untagged value (a DC-1 violation); or a degraded-quality value admitted as a MEASURED basis without the degradation appearing in the record. |
Recovery leg (P7). With all injections cleared, the node must not return to NORMAL on the first clean sample. The expected path is CRITICAL → RECOVERING → RESTRICTED → NORMAL, each step requiring the full recovery sequence to complete. Any breach during recovery restarts it. A direct upward step is a DC-4 violation and fails the run regardless of every other result.
Across all five injections the most probable defect is not a wrong state — it is a correct-looking value. Last-known-good substitution, quality-tag stripping and silent arbitration all produce output that is internally consistent and downstream-plausible. The run therefore instruments the pipeline at TB-3 entry, not only at the decision point: a value must be compared against what actually arrived at TB-2, and any difference not explained by a recorded transform is a finding.
F8 — INSTRUMENTATION
- The FPGA acquisition record at TB-2 is the ordering authority for the run. Host-side timestamps are recorded but are never used to order events.
- Every telemetry point is written with its DC-1 tag. Derived indicators (divergence, content age, lag) are tagged DERIVED and carry the identifiers of the measured values they were computed from.
- L8 output is captured for later comparison but takes no part in the decision path. Any run in which an L8 output is observed to have changed a decision outcome is stopped and reported as a boundary violation, whatever the merits of the change.
- Per-phase records: entry state, every evaluation cycle, every transition with its triggering observation, every decision outcome with its reason, and the operator's run-card values.
F9 — RUN-LEVEL FAILURE CRITERIA
- Any injection phase that produces no recorded trust evaluation — a phase in which nothing happened and nothing was written is a failure irrespective of the final state.
- Any
executeoutcome issued while an input on which it depended was undetermined. - Any upward transition that did not pass the full recovery sequence.
- Any consequential transition not reconstructable under F11.
- Any transition whose recorded reason does not name the observation that caused it.
F10 — ABORT AND CONTAINMENT
- Bench execution only. TB-4 is gated into an instrumented dummy load; no effector is connected for any stage of AQ-SCN-002.
- Abort immediately and record the abort if: the Evidence Fabric becomes non-durable; the DC-1 tagging pre-check fails mid-run; TB-2 acquisition timing is observed to shift with host activity; or an injection escapes its intended feed and affects another.
- An aborted run is retained in the record with its cause. Aborted runs are not overwritten by later clean runs.
F11 — EVIDENCE RECORD AND RECONSTRUCTION TEST
DC-5 is verified explicitly and not assumed. After the run, a person who did not operate it reconstructs, from the Evidence Fabric alone and with no access to console output, operator notes or the run card: the entry state; every state transition with its cause and time; every decision outcome with the inputs and their DC-1 tags; every conflict entry; and the recovery sequence. Anything that cannot be reconstructed is recorded as a DC-5 gap against the F-series register and is a finding of the run, not a documentation task to be completed afterwards.
A complete Stage C pass supports one statement: that on this bench, with these feeds, at these declared bounds, the implemented state machine detected these five degradations and recorded them as specified. It supports no claim about performance at any other rung of the reach ladder, no claim of operational readiness, no claim about behaviour under an adversary, and no security property of any kind. A result at Lab validation is reported as Lab validation.