Axowl.com
000
%

Technical evaluation · for defense communications engineers

Tamper-evident comm logs for contested environments.

For RF / PHY engineers at defense primes and government laboratories evaluating performance and forensic posture in contested-spectrum operations. We extract the channel state M t in real time, seal it into a transition hash chain bound to an FPGA-resident PUF key, and replay the verified prior under jamming and CSI degradation. The chain is the audit-grade record of the link. Every figure on this page was produced by the reproducible Python pipeline; channel models are ITU-R and 3GPP conformance profiles — no service-classified data, no proprietary captures.

Request technical briefing Read the whitepaper

§0 · Reader's note — what is and is not claimed

Two independent value props on this page. Evaluate them separately.

(1) Link resilience under jamming / CSI degradation (§3 – §6). Channel-aware reception under partial-band jamming and protocol spoofing on ITU-R / 3GPP conformance profiles. This is well-trodden comms-theory territory — Kalman / RLS / MMSE-LE equalizers under realistic interference are the production baseline in fielded SDRs (STANAG 4539 HF, Link 16, MUOS). The contribution here is the integrity-gated recursive smoother — the receiver's reliance on past M t collapses automatically when the chain detects tampering, never degrading below the memoryless single-shot baseline. Pilot integration with a real fielded waveform stack is where service-relevant numbers come from.

(2) After-action / coalition evidence chain (§7 – §8). The FPGA-PUF sealed transition hash chain + multi-party offline verification (XC4) is the standalone licensable asset. Coalition partners verify the same M t history offline without trusting each other or a central custodian — a neutral basis for shared post-action findings, EW forensics, and investigation. Survives compromise of the recording node. Applies regardless of which receiver produced M t upstream.

A service program sceptical of (1) on well-known-reception grounds can still adopt (2) standalone — the chain primitive is waveform-agnostic.

⚡ Signal / Data Restoration

Jammed / spoofed channel → original signal anchored to verified prior.

Patent core claim: "recover original modal information from broken received signal via medium forward model + integrity-anchored prior" . Under partial-band jamming and protocol-level spoofing, the M t recursive smoother reconstructs intent from the last verified chain link — forensic timeline pinpoints spoof/jam onset to 1-frame resolution. Independent parties verify offline without custodian comms (XC4).

§1 · Why a defense program should read this

Two value axes: link resilience, and after-action evidence.

Channel-aware reception under jamming and CSI degradation is well-known communications-theory territory; the difference here is the second product — a per-snapshot signed record of channel state, chained to an FPGA-resident PUF key, that survives compromise of the recording node. The signed chain provides forensic-grade evidence for after-action review, coalition data-sharing, and incident investigation in spectrum-contested operations.

Link survivability

Channel-aware reception recovers usable BER on degraded multipath / partial-band jammed channels (§3 / §4).

After-action review

Replay the channel state history with cryptographic guarantee that no node — friendly or hostile — rewrote the record.

Coalition evidence

Independent parties can verify the same M t chain offline with the public verification key — neutral basis for shared findings.

EW forensics

The chain attests when the channel state changed. Drift, spoof attempts, and sudden CSI shifts are all on the immutable record.

GPS Chimera composition (§4.5)

US Air Force's pre-deployment Chimera anti-spoof (~30 s TTFAF) vs Axowl 20 ms = ~1,500× faster . Axowl composes on top of Chimera-authenticated GPS — sealing the full mission record (GPS + radar + EW + comms) on a tactical platform.

Alt-PNT + Iridium STL comparison (§4.6)

Iridium STL (~60–90 s TTFAF, commercial subscription) vs Axowl 20 ms = ~3,000–4,500× faster . Foundry-PUF root-of-trust alternative (8" CMOS) for the alt-PNT mission — no constellation-subscription dependency.

Tactical aircraft M t -rail (§4.7)

Civil-aviation M t -rail rescaled to 3-D, 0.5-s, 6-DOF fighter dynamics. AESA + IRST + IMU sensor fusion. One kernel covers contested-EM operation, multi-sensor fusion, real-time atmospheric rail, and sealed autonomy.

§2 · Experimental setup

SISO QPSK over standardized multipath profiles — no service-specific waveform.

Deliberately neutral baseband chain: SISO, QPSK, no spreading, no FH (frequency hopping), no MIMO. The result in §3 / §4 isolates the channel-state-aware reception primitive (Subsystem B of the underlying patent) from the application-layer waveform. Production integration into a fielded SDR — STANAG 4539 HF, Link 16, MUOS tactical waveforms — is separate work; the same M t chain primitive (§5) attaches to any waveform.

Modulation

QPSK, Gray-coded, unit symbol energy

Channel models

ITU-R Rec. M.1225 Vehicular-A / Pedestrian-A; 3GPP TS 36.101 Annex B EPA / EVA (delay spreads representative of urban / vehicular / pedestrian environments)

Sample rate

10 Msps (100 ns sample period)

Noise

Complex AWGN, identical realization for both receivers within each trial (no partial-band jammer modeled here — see §8)

Sample size

200,000 bits per E b /N 0 per channel

Receiver A — no M t

Coherent QPSK with single-tap carrier recovery (no equalization)

Receiver B — with M t

Frequency-domain MMSE-LE, full channel response (perfect CSI assumed in §3 — relaxed in §4)

Theoretical bound

QPSK AWGN: P b = Q(√(2 E b /N 0 ))

§3 · Results · multipath conformance channels

Channel-aware reception removes the ISI floor — standard equalization gain.

This section is intentionally unsurprising. MMSE-LE with perfect CSI on the standard channel profiles gives the expected gain over unequalized reception. We reproduce these textbook numbers to ground every claim that follows in figures any link-level engineer can replay from the published Python pipeline.

Channel

Receiver A — BER

Receiver B — BER

Δ E b /N 0 to BER 10⁻³

ITU-R Pedestrian-A

0.30 %

0.0025 %

Receiver A never reaches 10⁻³

3GPP EPA

0.32 %

0.0025 %

Receiver A near 3 ⋅ 10⁻³ floor

3GPP EVA

13.92 %

0.058 %

Receiver A bounded above 10⁻¹

ITU-R Vehicular-A

21.55 %

0.31 %

Receiver A bounded above 0.2

Numbers at E b /N 0 = 10 dB. The point of this table is not the equalization gain — it is that the table is reproducible bit-for-bit by anyone running the published pipeline. The audit primitive in §5 is what makes the same table verifiable across nodes and across time.

§4 · Time-varying CSI · contested-environment proxy

When CSI is degraded, the verified-past prior wins.

In a contested-spectrum operation the channel estimate ĥ t is degraded by partial-band noise, brief jammer dwell, terminal motion, and limited pilot budget. Below we model a slow AR(1) drift channel (ρ = 0.97) with realistic per-tap CSI noise (σ ε = 0.18) — a first-order proxy for those impairments, in a regime where there is no service-specific waveform to confuse the result. Three receivers compete at fixed E b /N 0 = 10 dB over 24 channel updates.

h t = ρ·h t−1 + √(1−ρ²)·ν t     (slow channel drift) ĥ t = h t + ε t     (per-snapshot CSI estimation noise) M̂ t = (1 − w) · ρ · M̂ t−1 + w · ĥ t     (recursive smoother — uses verified past)

Receiver

Avg BER (24 steps)

Worst step

Best step

A — no M t (carrier recovery only)

15.30 %

29.89 %

2.77 %

B — memoryless M t (per-step noisy CSI)

4.67 %

12.70 %

0.39 %

C — M t with verified-past memory hop

2.76 %

7.60 %

0.33 %

The memory-hop receiver wins by 1.69 × on average BER and — more relevant for tactical links — its worst-step BER is roughly halved. Worst-step behavior dominates burst-error patterns and FEC failure modes. The trust in the past prior is what §5 secures.

§4.5 · Head-to-head with GPS Chimera (US Air Force L1C anti-spoof)

Pre-deployment Chimera ~30 s TTFAF · Axowl 20 ms · ~1,500× faster.

GPS Chimera is the US Air Force Research Lab (AFRL) initiative to add cryptographic authentication to the GPS L1C civil signal. TESLA-style delayed-key disclosure + ECDSA P-256 root signing per flight. Status: 2023 – 2024 test campaigns at Holloman / White Sands; expected operational deployment ≥ 2027 . Spec target: TTFAF ~ 30 s with full chain (faster than Galileo OS-NMA Reduced mode ~ 100 s, due to dual-band cross-auth and pre-cached ECDSA root).

This comparison matters for any platform that will encounter Chimera-authenticated GPS in the late-2020s. Axowl's spacecraft- /platform-side chain composes on top of Chimera rather than replacing it.

Pre-deployment caveat. Chimera TTFAF estimates below are from published AFRL / Mitre presentations and academic papers (Anderson et al. 2017 onward) — not from measured field operations. Numbers may shift ± 30 % once operational test data is published. The qualitative ranking (Chimera faster than OS-NMA, slower than Axowl frame-rate seal) is robust regardless of those adjustments.

Authentication latency vs. GPS Chimera (3-mode × 2-rate matrix)

Chimera operational mode

Estimated TTFAF

Axowl 50 Hz (20 ms)

Axowl 1.25 Hz (800 ms)

Cold-start (no cache) first power-up, no TESLA history

≈ 60 s

≈ 3,000×

≈ 75×

Standard (single-sat) typical operational mode

≈ 30 s

≈ 1,500×

≈ 38×

Aggressive (cached ECDSA root) warm-start with sideband update

≈ 10 s

≈ 500×

≈ 12×

How to read. Chimera's steady-state per-subframe authentication (after TTFAF elapses) is ~ 6 s per new MACK. Axowl 50 Hz frame = 20 ms. Steady-state speedup ≈ 300× at 50 Hz, ≈ 7× at 1.25 Hz. Both systems eventually reach cryptographic security — Axowl's advantage is when authentication becomes available.

Architectural comparison — Chimera and Axowl compose, not compete

Dimension

GPS Chimera (AFRL)

Axowl PUF chain

Operational status

Pre-deployment (2027+)

Simulation + AWS F2 FPGA prototype

Authentication scope

GPS L1C civil signal only

Any M t time series — GPS, telemetry, RF link, EW logs

Cryptographic primitive

TESLA delayed-key + ECDSA P-256

HMAC-SHA256 + PUF, monotonic 64-bit metering

Root of trust

USAF Ground Segment ECDSA private key

FPGA-resident PUF (8" CMOS fab option)

Cross-authentication

Dual-band L1C / L5 (when deployed)

XC4 multi-party offline N-of-K verification

Root-of-trust control

Operator-controlled ground-segment key

Vendor-independent PUF root path

Composability

Receiver-only (must be in the GPS receiver)

Wraps any sensor / telemetry / consensus output

Composition narrative. A tactical platform using Chimera-authenticated GPS can additionally seal the full mission record (GPS + radar returns + EW logs + comms) with Axowl chain. Chimera proves the GPS signal is authentic at receive time; Axowl proves the platform's entire data history is authentic at audit time. The two layers stack cleanly.

Honest limitations. (1) Chimera TTFAF estimates are pre-deployment published values — actual field numbers may differ once USAF publishes operational test data. (2) Chimera's cryptographic strength (ECDSA P-256 + TESLA) is robust; the comparison is operational latency, not security strength. (3) Axowl chain does not provide GPS / PNT functionality — it provides integrity on the data already generated. (4) Speedup ratios scale with Axowl source frame rate (50 Hz launch telemetry vs 1.25 Hz LEO downlink). (5) Axowl pitches as the data-layer wrap, not the GPS-receiver replacement.

§4.6 · Head-to-head with Iridium STL (Satellites Time & Location)

Deployed STL ~ 60–90 s TTFAF · Axowl 20 ms · ~3,000–4,500× faster.

Iridium STL (Satellite Time and Location, operated by Satelles) is the deployed PNT authentication service running on the Iridium NEXT 66-satellite LEO constellation. Commercially deployed; used by financial trading infrastructure, critical- power-grid time references, and a growing number of timing-security users.

Unlike Chimera (still pre-deployment) and OS-NMA (open-civilian), STL is commercially deployed today and the most realistic deployed alt-PNT reference for commercial-grade evaluation. Published TTFAF: 60 – 90 s typical for first authenticated fix; per-position update authenticated continuously thereafter.

Commercial-product caveat. STL internals are partially proprietary. Numbers below come from Satelles whitepapers and independent measurement studies (Fernandez-Hernandez et al. 2022, Dovis et al. 2024). Comparison is operational latency and architectural fit, not cryptographic equivalence.

Authentication latency vs. Iridium STL

STL operational regime

Published TTFAF / cadence

Axowl 50 Hz

Axowl 1.25 Hz

Cold-start (first authenticated fix)

≈ 90 s

≈ 4,500×

≈ 112×

Warm-start (cached ephemeris)

≈ 60 s

≈ 3,000×

≈ 75×

Steady-state per-fix update

≈ 2 s (per Iridium pass)

≈ 100×

≈ 2.5×

Architectural comparison — Iridium STL vs. Axowl chain

Dimension

Iridium STL

Axowl PUF chain

Operational status

Live since 2017, government-deployed

Simulation + FPGA prototype

Authentication scope

PNT (position + time) authentication only

Any M t time series

Service model

Satelles subscription service via Iridium

One-time IP license, customer-operated infrastructure

Root of trust

Satelles operations center + Iridium NOC

FPGA-resident PUF (customer-operated)

Dependency

Iridium constellation (commercial, end-of-life ≥ 2030)

None — Axowl runs on any spacecraft / platform

Geographic coverage

Global (Iridium 66-sat LEO)

Platform-local — wherever the spacecraft / receiver is

Procurement model

Iridium / Satelles subscription

One-time IP license + 8" CMOS fab PUF, customer-operated

Procurement positioning. Iridium STL is the subscription path; Axowl chain is the capex / IP-license path with a customer-operated PUF root of trust. Both can coexist: STL provides PNT today, Axowl wraps the platform's full data record. For an independent alt-PNT receiver, Axowl's spacecraft- / platform-side seal becomes the integrity layer.

Honest limitations. (1) STL is a positioning authentication service; Axowl is a data integrity layer — they solve different problems. The "latency speedup" comparison is apples-to-apples only for the auth-latency dimension. (2) Iridium 66-sat constellation is reaching end-of-life (≥ 2030 transition planned); STL's long-term roadmap depends on Iridium's next-gen deployment. (3) Axowl chain does not provide positioning — a deploying platform would still need GPS / Galileo / alt-PNT receivers for the actual fix; Axowl wraps that fix in tamper-evident chain. (4) STL subscription is operational cost (per-device / per-year); Axowl is capex (FPGA / PUF chip). Cost structures differ.

§4.7 · Fighter / tactical aircraft M t -rail

Same engine. Rescaled for high-G, 3-D, 0.5-second timescale.

The atmospheric M t -rail primitive demonstrated in the civil aviation demo (200 km en-route slab + memory-hop update, fuel + comfort optimisation for commercial operators) generalises directly to fighter / tactical aircraft with the same modal decomposition + verified-prior loop. The licensable core stays unchanged — what changes is scale, sensor stack, and dynamics.

Civil vs. tactical M t -rail — scale comparison

Dimension

Civil aviation (current demo)

Fighter / tactical

Domain

200 km along-track × 80 km cross-track, 2-D

30 – 80 km forward cone × ±30 – 60° FOV, 3-D voxel grid

Time step

5 s

0.5 – 1.0 s (high-G manoeuvre timescale)

Dynamics model

2-D point-mass, 70 t narrow-body, 240 m/s cruise

3-D, 6-DOF, roll / pitch / yaw, high-G transients

State variables

Turbulence intensity, gust index

E turb , ρ, T, ∇v, gust index, shear (5-D field)

Forward-sense stack

Forward-looking sensor cone (radar-class)

AESA radar + IRST + IMU + AoA + pitot fusion

Memory-hop weight (α)

0.30 (stable cruise)

Dynamic: ↑ in high-G (trust new), ↓ in steady (trust map)

Output to autopilot

Path-replan, fuel-optimal route

"Rail" for the next 10 – 30 s of manoeuvre

Engine reuse. The Python pipeline producing the civil-aviation §3 / §4 figures is the same kernel that would produce fighter Mt fields with the dimensions above swapped in. No new algorithm — the M t + memory-hop + chain primitive is domain-independent. What needs building is the 6-DOF simulator integration (JSBSim / X-Plane / OpenAerial) and the AESA / IRST sensor-fusion stub replacement.

Operational benefit axes for fighter / tactical platform

Benefit axis

Mechanism

Where it shows up

Manoeuvre stability

AI co-pilot pre-corrects for turbulence cores before they hit during high-G turn / pull-up / dive

Reduced trim overshoot, lower control-surface duty cycle, longer airframe life

Pilot fatigue reduction

FCS follows the Mt rail rather than reacting to disturbances

Less "fighting the aircraft" — measurable in pilot HRV / mission-end fatigue scoring

Fuel / range

Drag-equivalent turbulence avoidance on long-CAP / penetration profiles

~ single-digit % fuel savings on representative profiles (pilot validation needed)

Weapon / sensor pointing

AESA / EO / IR sight stays on target during atmospheric perturbation

Lower CEP for guided munitions, longer track-time on contact, fewer break-lock events

Sealed mission record

Every Mt snapshot + manoeuvre decision sealed via FPGA-PUF chain

Coalition / after-action / accident investigation — independent verification

Cross-domain coverage — one engine. The same primitive fuses sensing + communication + autonomy + tamper-evident trust with a single FPGA-PUF root of trust: channel-aware reception and partial-band jamming recovery (§3 / §4), multi-sensor 3-D M t fusion (AESA + IRST + IMU + pitot, this section), and sealed mission history (§5). One mathematical kernel, not four separate point solutions.

Honest limitations of the fighter framing. (1) The simulation pipeline today is the civil-aviation 2-D point-mass demo. Fighter validation requires 6-DOF flight-dynamics integration (JSBSim / X-Plane / OpenAerial / a Tier-1's proprietary 6-DOF sim) — that is a pilot-phase deliverable, not a current demo result. (2) AESA / IRST sensor models are stubs ; pilot work needs raw radar tensor + IRST output from an actual Tier-1 / OEM. (3) Fuel / CEP / pilot-fatigue numbers are hypotheses grounded in physics — quantitative validation needs flight-test data. (4) This section is the " this engine can also fly into fighter programs " narrative — the heavy lifting (6-DOF sim, real sensor data, flight test) is pilot scope, not demo scope. (5) M t -rail applicability — restricted scope. A combat sortie's adversarial / dynamic mission profile cannot be pre-mapped — the M t -rail framing in this §4.7 applies only to fixed-route training, transit, CAP, or ferry profiles where the route is known in advance. For unpredictable air-to-air engagement or contested-zone penetration the Rail prior is not applicable, and only the chain primitive + per-frame sensor fusion (no pre-laid environment) carry over. The pad-fixed F-35B STOVL vertical landing case — where the environment can be pre-laid — is the subject of §4.8 below.

§4.8 · F-35B STOVL · vertical-landing M t -rail · methodology

Pad-fixed environment = Rail-applicable sub-scope.

Where the §4.7 combat sortie is not Rail-applicable (adversarial / dynamic mission), the F-35B's STOVL vertical landing onto a known amphibious / carrier pad is the opposite — the landing environment (ship CAD geometry, sea-state- conditioned 6-DOF motion statistics, hot-exhaust CFD map) can be pre-laid as a rail. This section is methodology only — there is no flight-test data — but it identifies (A) the four published challenges, (B) the current Tier-1 state of the art (Rolls-Royce LiftSystem + F-35B IFPC + NAVAIR MAGIC CARPET + Royal Navy SRVL), and (C) where the Axowl Rail + AI dispatch + chain primitive plugs in.

A. Why F-35B vertical landing is hard

Challenge

Mechanism

Published source

Hot-exhaust ground effect

F135 exhaust at ~3,600 °F — deck warping, re-ingestion risk; Thermion (ceramic + Al) coating mitigates only partially

USS Gerald R. Ford deck thermal stress reports (USNI / National Security Journal, 2026); Wasp-class Thermion coating program (military.com 2011)

Pad 6-DOF motion

Ship heave / pitch / roll at sea state; SRVL trials demonstrated approaches with wind-over-deck (WOD) at 40 – 50 knots

Royal Navy / F-35 ITF, HMS Queen Elizabeth Oct 2018 trials

Superstructure wind shear

Bridge + FLYCO tower turbulence interacts with low-altitude approach; pilot relies on inertial reference + HMD-projected deck velocity vector

P. Wilson / Royal Navy 2018, SRVL test campaign

Touchdown precision

NAVAIR MAGIC CARPET (F-35C, CATOBAR carrier) has demonstrated ~50 % touchdown-dispersion reduction; F-35B STOVL pad-spot precision is the open problem

USNI News 2016 & 2021, NAVAIR Precision Landing Mode program

B. Current Tier-1 / production state of the art

System

Function

Reference

Rolls-Royce LiftSystem (ILFPS)

LiftFan (29,000 hp, contra-rotating, 1.27 m diameter) + 3-Bearing Swivel Module (3BSM) thrust-vectoring rear nozzle + roll-post wing nozzles. Collier Trophy 2001.

Rolls-Royce LiftSystem product page (rolls-royce.com)

F-35B IFPC

Integrated Flight Propulsion Control — single-pilot-input autohover; simultaneous control of LiftFan inlet area, 3BSM angle, and roll-post bypass flow to balance lift, pitch, roll and yaw with constant total lift

Lockheed Martin F-35 Air Vehicle Technology Overview (2018)

NAVAIR MAGIC CARPET / PLM

"Maritime Augmented Guidance with Integrated Controls for Carrier Approach and Recovery Precision Enabling Technologies" — auto-throttle + glideslope lock for CATOBAR carrier landing (F-35C, F/A-18E/F). ~50 % touchdown-dispersion reduction. No analogous F-35B STOVL pad-precision system fielded.

USNI News 2016 / 2021, NAVAIR Precision Landing Mode

SRVL (Royal Navy)

Shipborne Rolling Vertical Landing — 57-knot forward speed + lift-fan + wing lift; +7,000 lbs all-up-weight margin over pure vertical recovery. Pilot fuses inertial reference with HMD-projected ship-referenced velocity vector.

Royal Navy / F-35 ITF, HMS Queen Elizabeth Oct 2018; SRVL Wikipedia / Flight Global

C. Axowl Rail + AI dispatch + chain — methodology (this is where the engine plugs in)

Layer

What plugs in

Where it would help

Pre-laid pad rail

Ship CAD prior (Wasp-class / America-class / HMS Queen Elizabeth / ITS Cavour / JS Izumo) + nominal 6-DOF motion profile conditioned on sea state + CFD-derived hot-exhaust ground-effect map

Approach planning starts from the known pad geometry — IMU + AESA + DAS only refine, never bootstrap from zero

Multi-sensor fusion

Ship IMU + AESA wind sensor + DAS 360° optical + F135 telemetry + HMD inertial reference (all already on the F-35B)

Per-frame consensus of all sensors against the pre-laid rail; sensor disagreement triggers dispatch instead of voting an unsafe approach

AI dispatch trigger

WOD > 50 kts → switching pipeline (lateral SRVL drift) · pad pitch > 3° / heave > 2 m → adaptive pipeline (motion-locked descent) · hot-exhaust re-ingestion signature → abort + climb-out

Same architectural pattern as Space §S1.7 (S4 < 0.25 / 0.25 – 0.7 / ≥ 0.7 + Kp ≥ 7 outlier) — regime classifier + per-regime pipeline + explicit out-of-scope alarm

Chain-anchored integrity

Every IMU / AESA / DAS / IFPC telemetry frame is PUF-chain authenticated at the 20 ms cycle; jamming or sensor spoof → chain fail → fall back to optical / inertial-only

Per-frame integrity = real-time safety. Sealed approach record = post-incident accident-investigation primitive (the same §5 chain).

Sub-scope — where this Rail applies. ✅ Amphibious / STOVL carrier platforms with a known CAD geometry and a multi-sortie motion archive (Wasp-class, America-class, HMS Queen Elizabeth, ITS Cavour, JS Izumo conversion). ❌ Land-based VTOL on an unknown ground (improvised combat-zone pad, downed-aircraft recovery) — environment cannot be pre-laid; only the chain primitive carries over, not the Rail. Methodology status (no flight-test data). Validation of this section requires (i) JSBSim STOVL plug-in or equivalent 6-DOF integration with the F-35B IFPC model, (ii) actual ship-trial data from a suitable amphibious-assault / carrier deck, and (iii) airframe-OEM + engine-maker + certification-authority approval for IFPC sideband integration. The current claim is " the Axowl Rail + AI + chain primitive plugs into the F-35B STOVL recovery problem in these four places " — not a touchdown-precision number. Pilot-phase deliverables are 6-DOF sim ± real sea-trial data, in partnership with a Tier-1 / OEM.

§4.9 · Submarine · ocean-medium M t -rail + AI dispatch · methodology

Ocean is the M t medium. GPS surface-skin-depth 6 mm + GNSS-R + cross-medium TARF + sealed periscope-depth handoff.

Submarine positioning is the hardest GNSS-denied case in the portfolio. The L1 1.575 GHz GPS signal has a seawater skin depth of ~6 mm (Physics Today 2022, ArduSimple) — direct sub-surface GPS reception is physically impossible. However, the ocean is a valid M t medium (sound speed profile + thermocline + halocline + surface wave state + bathymetry), and several existing technologies do use the way GPS signals interact with the ocean surface to extract state (NASA CYGNSS / Spire GNSS-R bistatic radar, MIT TARF acoustic-to-mmWave cross-medium link). This section is methodology only — there is no sea-trial data — but it identifies (A) the four published challenges, (B) the current Tier-1 / mission state of the art, and (C) where the Axowl Rail + AI dispatch + chain primitive plugs in across five independent paths.

A. Why submarine positioning + ocean communication is hard

Challenge

Mechanism

Published source

GPS skin-depth 6 mm at 1.3 – 1.6 GHz

Seawater conductivity ~5 S/m → 36.7 % amplitude loss at 6 mm, 99 % loss at ~3 cm; sub-surface direct GPS reception is physically impossible

Physics Today 75(2):42 (2022); ArduSimple analysis; arXiv 1809.06741 surface-wave underwater radio

GIB acoustic spoofing

GPS Intelligent Buoys (GIBs) relay GPS coordinates via acoustic transmissions; an adversary with a louder acoustic source can override the buoy and inject false position into the submerged receiver — a published vulnerability

Preprints.org 2020/0187 — Spoofing GNSS-like UPS; IEEE 10639769 (2024) — UW Pos/Nav attack surface analysis; MDPI 2079-9292/10/17/2089 — DUPS spoofing detection

INS drift 1 – 5 km / day

Submarines rely on Sperry MK 39 / Sagem Sigma / Thales Optimar INS, which accumulate position error at a fraction of a nautical mile per day — periodic external fixes are required to reset (NATO SINS index cycle 2.66 h, plus longer-period star / GPS fixes)

NATO Ships Inertial Navigation System (SINS); Sperry MK 39 IRS public spec; Sonardyne free-inertial subsea reference

Adversarial ASW jamming + counter-detection

Anti-submarine warfare environments include sonar jamming, acoustic decoys, false-track injection (e.g., towed-array attacks) and counter-detection sonobuoys — silent-running constraints prevent the submarine from emitting reliably for self-correction

Naval Post / USNI Proceedings 2021 on submarine navigation; CIMSEC AUV mine-warfare kill-chain

B. Current Tier-1 / mission state of the art

System

Function

Reference

NASA CYGNSS & Spire GNSS-R

Bistatic-radar receivers in LEO; use GPS-as-transmitter to estimate ocean surface wind speed, wave height, significant wave height (SWH), sea surface height (SSH) from Delay-Doppler Maps (DDM). CYGNSS = 8 satellites (NOAA / NASA, 2016+); Spire = follow-on CubeSat constellation (2020+).

NASA CYGNSS mission page; Soulat 2004 GRL coastal GNSS-R; Loria 2021 AGU on wind+wave retrieval; eoPortal GNSS-R overview

MIT TARF (Translational Acoustic-RF)

Submarine emits acoustic ping → ocean surface ripples at sub-mm amplitude → drone / aircraft mmWave radar detects the ripple as a translation of the acoustic signal — first cross-medium submarine-to-air wireless link, demonstrated 2018.

MIT News Aug 2018 — Adib lab; Engineering.com follow-up on 5G mmWave for submarine comms

Sperry MK 39 / Sagem Sigma / Thales Optimar INS

Production submarine inertial navigation systems with ring-laser-gyro or fiber-optic-gyro cores; NATO SINS standard. Index cycle 2.66 h (Sperry proprietary). Drift rate ≈ 0.1 – 1 NM / day depending on grade.

NATO SINS Wikipedia / rnsubs.co.uk; Sperry MK 39 IRS; Thales Optimar product page; Exail navy INS

Kongsberg HUGIN AUV (TAN)

Terrain-aided navigation via HISAS synthetic aperture sonar + EM2040 multibeam echo-sounder + Sunstone INS; 20 cm bathymetric resolution across a 750 m swath at 3.5 kt / 40 m altitude. 15-day endurance on HUGIN Endurance. Used commercially and by navies.

Kongsberg Discovery HUGIN product page; ScienceDirect S0029801823011630 — TAN underwater review

Sonardyne LBL / USBL acoustic positioning

LBL transponder arrays on the seabed give < 1 m accuracy (sometimes 1 cm) within the array footprint; USBL pole-mounted single-array on a surface vessel for shorter-range / mobile operations; DVL = bottom-tracked velocity.

Sonardyne LBL/USBL product line; EvoLogics positioning; Wikipedia underwater acoustic positioning

GIB & NOAA NDBC buoys

GPS-equipped surface buoys with submerged hydrophones; commercially available position-relay platforms for AUV / ROV tracking; NOAA National Data Buoy Center operates ~ 100 ocean-data buoys for sea state.

NOAA NDBC; Wikipedia underwater acoustic positioning §GIB; oceansciencetechnology.com supplier list

Underwater PUF authentication

PUF-based authentication has been independently proposed and prototyped for underwater wireless sensor networks (marine monitoring + naval coastal surveillance) — building block exists.

MDPI Applied Sciences 16(2):873 — Secure PUF authentication for underwater WSN; researchgate 343336193 — Merkle hash + dolphin whistle covert UW comms

C. Axowl Rail + AI dispatch + chain — methodology (5 independent paths)

Path

What plugs in

Where it would help

A · Chain-signed periscope-depth GPS fix

Each mast-up GPS fix is signed by the submarine's PUF and committed to the §5 transition-hash chain together with the INS state at the moment of reset. Until the next mast-up, the INS evolves under a sealed prior — its drift-budget evolution is itself a chain entry.

Public sources describe the procedure (Wikipedia / USNI / Naval Post) but do not describe cryptographic integrity on the GPS fix or the INS-reset transition. Adversary cannot retroactively rewrite the position-fix history during after-action review.

B · Chain-signed GIB acoustic relay

Each acoustic packet from a surface GIB carries a PUF-chain signature of (lat, lon, time, buoy ID); the submerged receiver verifies before accepting. A louder spoofing source produces a chain-invalid signature and is rejected.

Directly addresses the published GIB-spoofing vulnerability (Preprints.org 2020/0187, IEEE 10639769, MDPI 2079-9292) — the chain is a counter to the exact attack surface those papers identified.

C · GNSS-R ocean surface M t + chain

Floating receivers (USVs, sonobuoys, or seabed-anchored stations) running a GNSS-R DDM extractor produce sea-state M t snapshots (wind, wave height, SSH); each snapshot is PUF-chain-signed and replayable downstream. Modal decomposition (Chladni 1D / 2D) separates the multipath constituents (specular vs scattered).

Composes on top of NASA CYGNSS / Spire (production GNSS-R missions) — adds tamper-evident ocean-state history that is verifiable post-hoc by coalition forces or accident investigators.

D · TARF cross-medium + chain

Submarine emits a PUF-chain-signed acoustic ping → ocean surface ripple → drone / MPA mmWave radar reads the ripple translation → drone verifies the chain signature in the demodulated bits. Modal decomposition extracts the ripple-pattern from competing wind-driven surface variance.

Composes on top of MIT TARF (2018, Adib lab) — turns a one-way acoustic→RF link into a cryptographically authenticated channel, which TARF as published does not have.

E · Sonar signal processing + modal + chain

Existing active / passive sonar transducer hardware is unchanged. The returned echo or ambient acoustic stream is processed by the §3 – §4 Chladni 1D / 2D modal decomposition (multipath separation: surface bounce + bottom bounce + thermocline scattering) + §6 verified-prior smoother + per-echo PUF-chain entry for tamper-evident track history. AI dispatch by ocean regime: shallow littoral / deep open / thermocline boundary / under-ice ALARM.

Same architectural pattern as Space §S1.7 (regime classifier + per-regime pipeline + outlier ALARM) and Defense §4.8 STOVL — XC10 cross-domain isomorphism with ocean SSP + bathymetry as the pre-laid rail.

Sub-scope — where this Rail applies. ✅ Mapped littoral / assigned operating area / harbor transit + standard sortie route / underwater pipeline + cable inspection (NOAA navigation charts / UKHO ADMIRALTY / US Naval Oceanographic Office bathymetry). 🟡 Open-ocean transit with periodic mast-up GPS fixes and / or GIB-relay anchors (partial rail — bathymetry sparse, but periodic surface-medium handoff is chain-signable). ❌ Beneath polar ice cap (no mast-up possible, no GNSS-R surface reflection in ice cover), open-ocean adversarial ASW silent-running sortie (sortie itself is unpredictable and the platform cannot emit acoustic chain pings without counter-detection) — Rail is not applicable; only the chain primitive on internal sensors carries over. Methodology status (no sea-trial data). Validation of this section requires (i) integration with an actual submarine INS stack (Sperry MK 39 / Sagem / Thales / Exail) under an OEM and navy partnership; (ii) GNSS-R receiver integration with CYGNSS-class or Spire data feeds; (iii) acoustic-channel chain-signed-ping qualification on a TARF-class transmit chain; (iv) classified-environment trials with a US-Navy or a naval submarine partner or unmanned partners (Boeing Echo Voyager XLUUV, Anduril Dive, HUGIN Endurance). The current claim is " the Axowl Rail + AI + chain primitive plugs into the submarine ocean-medium positioning problem in these five places " — not a CEP or position-error number for a specific navy stack.

§5 · Transition hash chain · forensic primitive

Each M t is signed by an FPGA-resident PUF key, then chained.

§3 and §4 are the cover story; §5 is the load-bearing claim. Every channel-state snapshot M t is HMAC-signed against the previous transition hash with a key derived inside an FPGA from a Physical Unclonable Function. The key cannot be extracted by software, by JTAG, or by side-channel. A single bit altered anywhere in the historical M t record breaks every downstream signature.

Fig. — 12-step transition chain. One bit modified in M 10 : 10 / 24 links validate (clean baseline = 24 / 24). All H t for t ≥ 10 fail.

σ t = HMAC K PUF (H t−1 ‖ M t )

H t = SHA256(H t−1 ‖ M t ‖ σ t )

verify HMAC K PUF (H t−1 ‖ M t ) ≟ σ t   ∀ t

MAC primitive

HMAC-SHA256, 256-bit PUF-derived key

Key custody

AWS F2 FPGA (AFI agfi-085919c09c35982c3 ) in the lab today; target hardware = mil-spec FPGA / ASIC in a sealed enclosure. The 256-bit PUF root never crosses the silicon boundary.

Compromised-node tolerance

A captured / destroyed recording node cannot retroactively rewrite history; verification keys can be held off-platform (command, ground station, escrow).

Coalition verification

Public verification key shared with independent parties enables offline chain audit without sharing the PUF root.

Tamper sensitivity

1 bit flipped at step k → 100 % of links from k to T reject (demonstrated on T = 24)

§6 · Operational scenarios

Where the primitive lands in a force-on-force timeline.

After-Action Review

Replay the channel-state record of a contested engagement with cryptographic guarantee against unit-level tampering — both friendly and adversary.

EW incident reconstruction

The signed M t drift is the immutable record of when, where, and how the channel state changed. Jammer attribution from a chain is far stronger than from a node log.

Coalition data sharing

Independent units exchange verified chain segments with shared public keys. No party trusts the other's log; both trust the chain.

LPI / LPD posture

The chain attests when CSI was observed, not the content. Compatible with low-probability-of-intercept waveforms — the chain layer is content-neutral.

Cryptographic provenance

Channel-state records survive node capture; the FPGA-resident PUF root cannot be exfiltrated by software or by physical disassembly without destroying the key.

Replay attack resistance

Each H t binds to its predecessor; replayed CSI from an earlier moment fails to validate against the current chain head.

Multi-domain transport integration

The chain is waveform-agnostic and small (≪1 kB per snapshot). Sealed channel-state records can transit any multi-domain transport.

Mil-spec porting target

The current AWS F2 FPGA AFI is a development target. Production target = rad-hard FPGA (e.g. Microsemi RTG4 class) or ASIC; PUF + HMAC-SHA256 primitives port directly.

§7 · Integration paths

Three deployment shapes. Pick the one that fits the platform.

In-radio / SCA component

Modal extraction co-located with channel estimator block of an existing JTRS / SCA-compliant radio; HMAC sign per CSI snapshot. Tightest latency. FPGA / ASIC implementation.

Network-appliance form factor

Sealed CSI records produced by a side-car appliance from radio KPI exports. No radio-cert impact; suitable for retrofit of fielded waveforms.

Ground-station log signer

CSI snapshots emitted by deployed units are countersigned at the ground station / HQ. Defense-in-depth for forensic chain on long-duration missions.

Licensing model

Per-radio IP block (FPGA / ASIC), per-platform software license, or government-purpose-rights configuration negotiated through the program office.

Export control

HMAC-SHA256 + SHA-256 are not export-controlled per current US/EU regimes. PUF + RTL is subject to standard reviews depending on jurisdiction and end-use.

§8 · Honest limitations

What this page does not show.

No jammer model in §3 / §4. We use commercial multipath profiles and AWGN. Partial-band jammers, follower jammers, and reactive jammers all require explicit modeling and are out of scope for this page. The chain primitive is jammer-agnostic; the receiver-side gain depends entirely on which equalizer wraps it.

SISO baseband only. No spread-spectrum (DSSS / FH), no MIMO, no anti-jam waveform features. Production waveforms (HAVE QUICK, SINCGARS, MUOS, Link 16) add their own gains; the M t chain attaches independently.

Perfect CSI in §3, simplified CSI noise in §4. Real fielded radios estimate CSI from a pilot budget that varies by waveform. The §4 noise level is a single operating point, not a sweep.

FPGA is software-emulated for the chain in this demo. The 24-step chain in §5 was computed in Python against the same PUF-derived key constant the FPGA uses. A separate program of work has the same HMAC running on a real AWS F2 FPGA AFI. Mil-spec hardware (rad-hard FPGA, ASIC) is the production target.

Chain content vs chain attestation. The chain attests when M t was observed and when it changed. It does not encrypt M t nor attest to unit identity. Classification guards, COMSEC keying, and identity binding are separate layers.

No FH / hopset coordination in this model. Frequency-hopping waveforms require chained extraction of a per-dwell M t ; the page does not yet demonstrate this. The primitive scales directly — each dwell is one chain link — but the latency budget per dwell needs measuring in hardware.

Sample-size-limited measurements. 200,000 bits per E b /N 0 caps measurable BER at ~5 × 10⁻⁶. We report "0 errors in N" rather than extrapolating.

§9 · For your evaluation team

Run it on your own waveform.

The Python pipeline that produced every figure on this page is available under appropriate non-disclosure for a defense evaluation. The recommended first step is to repeat §3 / §4 on your service-specific channel sounding (HF, VHF, UHF SATCOM, MUOS, Link 16) and report the same table against the program's reference receiver. The chain primitive is waveform-independent and can be evaluated independently of the receiver work.

Request technical briefing Read the whitepaper