AQ-SDD-001-S1 — Worked Dossier: Scenario 1, Normal Conditions
Status: DRAFT, not sealed. This document shows sections 1 to 9 as they would be registered before the first run of AQ-NODE-01, and shows sections 10 to 17 unfilled with the reason. It asserts no result.
AQ-NODE-01 has not been built. The version fields in section 5 therefore carry field definitions and no values. Sealing is prohibited until every field in section 5 is populated from built hardware and both reviewers have signed. Nothing here is evidence of anything: current level Concept for the integrated path, no run attempted.
SECTION 1 — DOSSIER IDENTITY AND REGISTRATION
| Field | Registered value |
|---|---|
| Dossier | AQ-SDD-001-S1 |
| Run id | assigned at seal, format RUN-S1-nnn |
| Scenario | S1, Normal conditions. This is the control scenario against which S2 and later fault-injection scenarios are read. |
| Article | AQ-NODE-01 (the same article appears as AKQ-NODE-1 in Parts up to 12) |
| Reach ladder | Rung 1 of 6: optical bench. No metro fibre, free-space, HAPS, CubeSat, LEO or constellation element is present. |
| Tier | Y1 (Year-1 prototype) |
| Level held | Theory for the trust-state reasoning; Concept for the integrated acquisition-to-decision path |
| Level sought | Lab validation, bench scope only, for the path L1/L2 → TB-2 → L4 → L5 → TB-4 → L6 |
| Reviewers | R1 scientific; R2 safety and governance (L9). Neither is an author. |
| Supersedes | none |
SECTION 2 — OBJECTIVE
To establish, under bench conditions with no injected fault, the baseline behaviour of the acquisition-to-decision path of AQ-NODE-01 across trust boundaries TB-1 to TB-5, and to produce the first measured distributions from which later thresholds will be defined. The run informs two programme decisions: whether the fault-injection scenarios S2 onward may proceed against this article, and whether any metric in section 9 produces a distribution stable enough to carry a threshold at all. If the control run cannot be interpreted, no fault-injection result against this article can be interpreted either.
SECTION 3 — RESEARCH QUESTION
Under bench conditions with no injected fault, does AQ-NODE-01 hold trust state NORMAL for the full run while every value presented to L4 carries a DC-1 tag, and is every L5 decision taken during the run reconstructable from the Evidence Fabric alone?
SECTION 4 — HYPOTHESIS AND FALSIFICATION CONDITION
H-S1. With all commands valid, authorised and issued at the cadence fixed in section 7, and with no fault injected, the trust state remains NORMAL for the whole run, every L5 evaluation returns execute, every value entering L4 is tagged, and an independent reviewer can rebuild each decision from L6 records without recourse to console logs or operator recollection.
Falsification. H-S1 is falsified by any one of: (a) a transition out of NORMAL that cannot be attributed to a recorded environmental observation; (b) any untagged value reaching L4; (c) any consequential transition that a reviewer cannot rebuild from L6 alone; (d) any Q4 outcome that permits more than Q1 to Q3 allowed.
Secondary hypothesis H-S1b. The characterisation statistics M-06 and M-07 are stationary within the run. The assessment method — the statistic, the window and the comparison — is fixed here before the run; no threshold value is declared, because none can be justified before the first distribution exists.
SECTION 5 — SYSTEM VERSION AND CONFIGURATION RECORD
| Field | Required form | Value at draft |
|---|---|---|
| V-01 | AQ-NODE-01 article revision and build sheet id | unpopulated, hardware not built |
| V-02 | Optical bench configuration id and layout drawing revision (L0) | unpopulated |
| V-03 | Entropy source part number, serial, and last characterisation date (L1) | unpopulated |
| V-04 | Timing reference: discipline source, holdover configuration, last comparison record (L2) | unpopulated |
| V-05 | FPGA bitstream SHA-256 and toolchain version (TB-2 deterministic acquisition) | unpopulated |
| V-06 | AQ-TSE-01 build id plus rule-set version (L4, TB-3) | unpopulated |
| V-07 | L5 command authority policy id governing Q1 to Q4 | unpopulated |
| V-08 | Hardware gate configuration at TB-4, including its interlock state at power-on | unpopulated |
| V-09 | Evidence Fabric schema version and writer build (L6, TB-5) | unpopulated |
| V-10 | Calibration certificate ids and dates for every instrument named in section 7 | unpopulated |
| V-11 | Environmental logger ids and sampling configuration | unpopulated |
| V-12 | Operator console software commit id and configuration file hashes | unpopulated |
SECTION 6 — ARCHITECTURE EXERCISED
| Layer | Status | Note |
|---|---|---|
| L0 | exercised | Bench optical path only. No propagation path of any kind is represented. |
| L1 | exercised | Entropy source under characterisation; M-06 is the recorded statistic. |
| L2 | exercised | Timing reference and its integrity checks; M-07. |
| L3 | stubbed | Keys issued by a bench-local test authority. This does not represent key custody, enrolment or revocation, and no S1 result may be read as evidence about L3. |
| L4 | exercised | AQ-TSE-01 is the primary subject of the run. |
| L5 | exercised | Q1 to Q4 evaluated for every synthetic command. Q1 to Q3 pass by construction in S1; the run therefore observes Q4 in isolation. |
| L6 | exercised | Recording is itself under test through M-05 and M-09. |
| L7 | stubbed | Single node. No orchestration, no peer, no network path. |
| L8 | not present | Advisory only and excluded from the decision path by construction. No L8 output is admitted to L4 or L5 in S1. |
| L9 | exercised | Abort authority, review roles and the safety brief for bench operation. |
Trust boundaries. TB-1 exercised (physical bench to system). TB-2 exercised (deterministic acquisition on FPGA). TB-3 exercised (trust reasoning). TB-4 exercised, with the physical effect limited to the bench gate and its indicator. TB-5 exercised (runtime to evidence).
Conflicts and decision boundaries. No conflict case among CF-1 to CF-7 is deliberately induced in S1; a conflict that arises is a section 13 observation and falsifies H-S1 if it moves the trust state. Only the decision boundaries traversed by a NORMAL-state execute path are exercised; every boundary among B-1 to B-5 not traversed is listed in section 16 as untested by this run.
Figure 1 - S1 path under test, acquisition to physical effect to evidence
[L0 optical bench]
| TB-1 physical/system
v
[L1 entropy] [L2 timing]
| |
+-----+------+
| TB-2 deterministic acquisition (FPGA)
| every sample timestamped and tagged MEASURED (DC-1)
v
[L4 AQ-TSE-01 trust state] TB-3 trust reasoning
state in {NORMAL, RESTRICTED, CRITICAL, DENY, RECOVERING}
S1 expectation: NORMAL for the whole run
|
v
[L5 command authority]
Q1 who sent it -> Q2 valid -> Q3 authorised now (HARD)
-> Q4 execute under this trust state
(may only REDUCE what Q1-Q3 allowed)
|
| TB-4 decision / physical effect, hardware-gated
v
outcome in {execute, execute-restricted, safe-hold, abstain, deny}
|
| TB-5 runtime/evidence
v
[L6 Evidence Fabric] -> DC-5 reconstruction source for M-05
[L8 AI-assisted analysis] NOT PRESENT in S1: advisory only, and
no path into L4 or L5 exists in this run.
SECTION 7 — PROTOCOL
- P-01 Record every section 5 field from the article as built; refuse the run if any field is unpopulated.
- P-02 Verify calibration validity dates for every instrument; record certificate ids.
- P-03 Power on with acquisition disabled and the TB-4 gate interlocked; record the cold-state register dump.
- P-04 Start Evidence Fabric recording; write the run start marker and the seal hash reference; confirm the marker is readable back.
- P-05 Warm-up period at the duration fixed in the bench procedure; environmental sample at start and end of warm-up.
- P-06 Baseline acquisition with no commands issued; this window is the source for M-06, M-07 and M-08.
- P-07 Release the TB-4 interlock; issue the synthetic command sequence C-01 onward at the fixed cadence. All commands are valid and authorised by construction.
- P-08 For each command, record the Q1 to Q4 evaluation, the trust state at evaluation time, the outcome, and the gate response at TB-4.
- P-09 Mid-run environmental sample and operator observation note, whether or not anything is observed.
- P-10 Continue to the planned command count.
- P-11 Stop commands, re-interlock the gate, continue acquisition for the tail period.
- P-12 Stop recording; compute and record dataset hashes before leaving the bench.
- P-13 Power down; record the shutdown register dump.
- P-14 Operator writes section 10 deviations at the bench, before leaving it.
Abort criteria. Any condition on the L9 bench abort list; any operator uncertainty about safety; any loss of Evidence Fabric recording. A run that loses recording does not resume — it stops, and a new run identifier is issued, because a gap in L6 makes DC-5 unassessable for the whole run.
SECTION 8 — INPUT AND FAULT CONDITIONS
Controlled: command cadence; command set composition (all valid, all authorised); bench alignment configuration; planned command count; warm-up and tail durations.
Recorded, not controlled: ambient temperature, vibration, supply condition, operator identity, time of day. Each is sampled at the points fixed in section 7; a missing sample is recorded as undetermined under DC-2, never interpolated.
No fault among F-1 to F-14 is injected in S1. Each is deliberately excluded and scheduled to a later scenario. Their absence here is not evidence that the article handles them; S1 can produce no statement whatsoever about detection of any F-* condition. No attempt is made to induce RESTRICTED, CRITICAL, DENY or RECOVERING. Should any of those states appear, it is recorded in section 13 and falsifies H-S1.
SECTION 9 — METRICS, SUCCESS AND FAILURE CRITERIA
| ID | Metric | Tag | Success criterion | Failure criterion |
|---|---|---|---|---|
| M-01 | Trust state trajectory over the run | MEASURED | NORMAL for the whole run | Any transition out of NORMAL not attributable to a recorded environmental observation |
| M-02 | DC-1 tag coverage of values entering L4 | DERIVED | Every value carries MEASURED, DERIVED or MODELLED. This is structural, not a tuned target. | One or more untagged values |
| M-03 | Decision outcome distribution across C-01 onward | MEASURED | Every command yields execute. An abstain or safe-hold is not itself a failure under DC-3 but is a section 13 observation and must carry its cause. | Any deny or execute-restricted with no recorded cause; any outcome outside the permitted set |
| M-04 | Q4 reduction events | MEASURED | Zero, or each event traceable to a recorded trust-state input | Any Q4 outcome that permits more than Q1 to Q3 allowed. This is a specification violation: stop the run. |
| M-05 | Reconstruction completeness (DC-5), scored by reviewer replay from L6 alone | DERIVED | Every consequential transition rebuilt without console logs or operator recollection | Any consequential transition not reconstructable |
| M-06 | Entropy source characterisation statistic (L1) | MEASURED | Distribution recorded and stationary by the method fixed in section 4. Target undefined: the S1 distribution is the input from which a threshold for later scenarios is defined, as a stated quantile of that distribution, after the run. | Statistic not computable from the recorded data; or non-stationarity with no recorded environmental correlate |
| M-07 | Timing integrity statistic (L2) | MEASURED | As M-06. Target undefined; the threshold rule is the same and is applied only after the distribution exists. | As M-06 |
| M-08 | Acquisition determinism at TB-2 | MEASURED | Sample-to-record ordering monotone and gap-free across the run | Any dropped or reordered sample not accounted for in the record |
| M-09 | Evidence Fabric write completeness | DERIVED | Fabric record count reconciles with the acquisition counter and the command count | Any unreconciled difference |
| M-10 | Environmental record completeness | MEASURED | Every planned sample present, or explicitly written undetermined per DC-2 | A silently missing sample |
S1 declares no numeric performance target, by design. Before the first run there is no measured distribution from which a threshold could be justified, and a number invented now would become the number the article is later tuned to satisfy. Section 9 therefore fixes what is measured, how it is tagged, and the rule by which each threshold will be derived from S1 data. Thresholds enter the programme through a section 17 disposition and a new dossier, never through an edit to this one.
SECTIONS 10 TO 17 — UNFILLED
| Sec | Status | Reason |
|---|---|---|
| 10 | UNFILLED | Execution Record: no execution has occurred. Written at the bench by the operator at step P-14. |
| 11 | UNFILLED | Raw Data and Custody: no dataset exists. Hashes are computed at P-12 before anyone leaves the bench. |
| 12 | UNFILLED | Measured Results: no measurement exists. Any value written here before the run would be MODELLED and would not belong in this section at all. |
| 13 | UNFILLED | Failure Observations: mandatory after the run. If nothing is observed, the entry requires the signed detection-coverage justification defined in AQ-SDD-001 §5 — which F-* conditions this instrumentation could have detected, and at what sensitivity. |
| 14 | UNFILLED | Analysis: the verdict on H-S1 must be one of supported, not supported, or undetermined, and cannot be anticipated. |
| 15 | UNFILLED | Evidence Level: the article stands at Concept and Theory. A bench run can at most support Lab validation in bench scope; it can support nothing about field, dynamic-platform or flight conditions. |
| 16 | UNFILLED | Threats to Validity: the known-in-advance limitations (L3 stubbed, L7 stubbed, L8 absent, single article, bench-only L0, untraversed B-* boundaries) are carried forward from sections 6 and 8 and completed with what the run actually reveals. |
| 17 | UNFILLED | Disposition: whether S2 fault injection may proceed against this article, and which thresholds S1 data can justify, are outputs of the run and not inputs to it. |
Completing any of sections 10 to 17 before the seal and the run voids pre-registration under AQ-SDD-001 §2. The dossier would be marked VOID, retained in the record, and replaced by a new identifier carrying a supersedes link. Until sections 5 and 10 to 17 are populated from a real run, this document is a registered intention and nothing more.