News Part of the AUTHREX Application Set: one Kernel architecture, six application profiles
VIEWING 01 / 06MISSIONAUTHREX-ICS-GATE
● IT/OT AUTHORITY BOUNDARY · REFERENCE ARCHITECTURE

AUTHREX-ICS-GATE
The Authority Boundary Between AI and Live Controllers

AI is being pointed at power grids, water plants, and pipelines to optimize and patch them at machine speed, and it can break them at machine speed. ICS-GATE is the fail-closed gate every AI-proposed OT action must pass: provenance verified, authority scaled to target criticality, human window on high-consequence writes, rollback armed first.

4 BOUNDARY GATESIT / OT ZONE SPLIT23,748 TLA+ STATES62443 · CIP CROSSWALKSTRL 3-4 SELF-ASSESSED REFERENCE
[ The Concept ]

Same Action, Different Target, Different Outcome.

  • OT protection relies on network segmentation and human operators alone
  • AI is granted automated write access faster than those controls were designed for
  • No criticality-aware authority check on AI-proposed OT actions
  • A spoofed sensor reading can drive a physical action
  • SATA verifies action provenance and reading trust before anything else
  • HMAA sets the authority tier by what the action touches: test bench vs live controller
  • FLAME forces a human deliberation window on high-consequence writes
  • CARA pre-arms rollback before any change reaches the controller; unverifiable actions fail closed
VIEWING 02 / 06WHO IT SERVESAUTHREX-ICS-GATE
[ Who It Serves ]

Adopt AI Without Handing Over the Keys.

Utility Operators

A water or power utility can adopt AI-driven optimization without handing an autonomous system unmediated write access to live controllers. Within the stated simulation configuration, the gate enforces that high-consequence actions slow down for human confirmation and remain reversible.

Critical-Infra Owners

Owners get a boundary that is auditable and fail-closed: if the gate cannot verify an action is authorized, the action does not pass. A spoofed sensor reading is refused rather than acted upon, which is exactly the failure mode that causes physical incidents.

Regulators & CISA

Regulators get a concrete control that maps to existing OT-security expectations (NERC CIP, IEC 62443) and to the new CISA/NSA AI-in-OT principles, expressed as an enforceable gate rather than a policy document.

VIEWING 03 / 06NATIONAL CASEAUTHREX-ICS-GATE
[ The National Case ]

Physical Public Safety, Named in Federal Guidance.

Critical infrastructure is a designated national-security priority, and the government has published guidance for exactly this problem:

Author-mapped to named federal guidance

The CISA/NSA "Principles for Secure Integration of AI in Operational Technology" (3 Dec 2025) calls for safe operating bounds, drift monitoring, and validating outputs before redeployment. ICS-GATE is a reference architecture and browser simulation author-mapped to selected principles in that guidance; it has not been demonstrated as an enforced operational IT/OT boundary.

It addresses physical public-safety risks

OT failures are not data breaches, they are blackouts and water-supply events that harm the public directly. A gate that refuses unauthorized actions before they reach a controller is a public-safety control, which is the strongest form of national importance.

It maps to existing standards

The gate cross-walks to NIST SP 800-82, ISA/IEC 62443, and NERC CIP, the standards utilities are already held to, so it extends existing compliance rather than replacing it.

It is sector-portable

Power, water, pipelines, and manufacturing share the same IT/OT boundary problem. A common gate pattern may be adaptable across several critical-infrastructure sectors, subject to sector-specific safety logic, protocols, hazards, and qualified assessment.

VIEWING 04 / 06HEILMEIER CATECHISMAUTHREX-ICS-GATE
[ The DARPA Questions ]

The Heilmeier Catechism, Answered Plainly.

Build an authority gate that decides whether an AI's proposed action is allowed to reach a live operational-technology controller, scaled by how critical the target is. No jargon: a smart safety valve between the AI and the power grid.

Today, OT security relies on network segmentation and human operators. The integration of AI-generated recommendations or control actions into OT introduces authority and assurance questions that conventional segmentation alone may not resolve. In the public sources reviewed for this project, no directly comparable criticality-aware gate was identified for evaluating AI-proposed OT actions at an implemented enforcement boundary. Proprietary, classified, unreleased, or sector-specific capabilities cannot be excluded.

Setting authority by target criticality , the same proposed action gets a different authority tier depending on whether it touches a test bench or a live controller, and arming rollback before the action reaches OT. The gate authorizes the safety logic without ever making the safety decision.

Utilities, infrastructure owners, CISA, and the public care. If it works, AI can optimize critical infrastructure without an autonomous system being able to push an unverified action straight onto a live controller.

The main risks are mis-calibrated criticality tiers (treating a critical target as low-criticality) and latency (a gate that is too slow for real-time OT). The simulation shows the tiering logic so it can be inspected; latency budgets are a design parameter, not yet measured on hardware.

The proposed BLADE-INFRA-OT reference design describes a 1U fanless appliance composed of commercially available components. A physical build and operational validation are not claimed. The governance logic is software. The cost is integration and validation, not exotic hardware.

The architecture and simulation exist now (self-assessed TRL 3 to 4). A documented testbed run against a real OT protocol stack is the next milestone; independent validation follows.

Midterm: the gate correctly refuses a spoofed-reading action and permits a legitimate one in simulation. Final: the gate runs in-line on a real OT testbed, refusing an unauthorized write to a live-equivalent controller within the latency budget.

VIEWING 05 / 06LIVE BOUNDARY GATEAUTHREX-ICS-GATE
[ Try It ]

Send an Action at the OT Boundary.

Pick what the AI is trying to do and what it is trying to touch. A test target may execute autonomously; a live controller requires human handoff; a spoofed or untrusted action is refused at the boundary. Illustrative simulation of the boundary logic, not operational validation.

◇ THE IT/OT AUTHORITY BOUNDARYSELECT · SEND · VERDICT
01SATAAction provenance & reading trust verifiedSTANDBY
02HMAAAuthority tier set by target criticalitySTANDBY
03FLAMEHuman window for high-consequence writesSTANDBY
04CARARollback path pre-armed before OT writeSTANDBY
[ READY ] AWAITING ACTION

All scenarios are synthetic. No real controller is touched.

VIEWING 06 / 06FOUNDATION & SCOPEAUTHREX-ICS-GATE
[ Formal-Methods Foundation ]

Model-Checked, Not Just Described.

Every AUTHREX application shares one model-checked authority core: the HMAA authority state machine, specified in TLA+ and model-checked across the stated finite model. The checker also caught a real S5 view-change regression during development, evidence the method finds defects rather than rubber-stamping them.

The profiles share a model-checked authority-state specification. Results apply to the finite model, properties, and assumptions analyzed and do not validate a spacecraft, vehicle, controller, or operational integration.

23,748 REACHABLE STATES6 PROPERTIES VERIFIED2 VACUOUS AT BOUNDTLA+ FORMAL SPEC
[ Anchors & Honest Limitations ]

What This Rests On, and What It Is Not.

FEDERAL & STANDARDS ANCHORS

CISA/NSA Principles for Secure Integration of AI in Operational Technology (3 Dec 2025) · NIST SP 800-82 · ISA/IEC 62443 · NERC CIP · hardware anchors: BLADE-INFRA-OT → · BLADE-INFRA →

HONEST LIMITATIONS

Reference architecture, self-assessed at approximately TRL 3 to 4: specified and simulated, not fielded or validated on a live OT network. Real-time latency budgets for in-line OT operation are a design parameter, not yet measured on hardware. The criticality-to-tier mapping is one researcher’s analytical judgment, released openly for independent review. No agency adoption or endorsement is implied.