Technical evaluation · for defense communications engineers
Tamper-evident comm logs for contested environments.
For RF / PHY engineers at defense primes and government laboratories evaluating performance and forensic posture in contested-spectrum operations. We extract the channel state M t in real time, seal it into a transition hash chain bound to an FPGA-resident PUF key, and replay the verified prior under jamming and CSI degradation. The chain is the audit-grade record of the link. Every figure on this page was produced by the reproducible Python pipeline; channel models are ITU-R and 3GPP conformance profiles — no service-classified data, no proprietary captures.
Request technical briefing Read the whitepaper
§0 · Reader's note — what is and is not claimed
Two independent value props on this page. Evaluate them separately.
(1) Link resilience under jamming / CSI degradation (§3 – §6). Channel-aware reception under partial-band jamming and protocol spoofing on ITU-R / 3GPP conformance profiles. This is well-trodden comms-theory territory — Kalman / RLS / MMSE-LE equalizers under realistic interference are the production baseline in fielded SDRs (STANAG 4539 HF, Link 16, MUOS). The contribution here is the integrity-gated recursive smoother — the receiver's reliance on past M t collapses automatically when the chain detects tampering, never degrading below the memoryless single-shot baseline. Pilot integration with a real fielded waveform stack is where service-relevant numbers come from.
(2) After-action / coalition evidence chain (§7 – §8). The FPGA-PUF sealed transition hash chain + multi-party offline verification (XC4) is the standalone licensable asset. Coalition partners verify the same M t history offline without trusting each other or a central custodian — a neutral basis for shared post-action findings, EW forensics, and investigation. Survives compromise of the recording node. Applies regardless of which receiver produced M t upstream.
A service program sceptical of (1) on well-known-reception grounds can still adopt (2) standalone — the chain primitive is waveform-agnostic.
⚡ Signal / Data Restoration
Jammed / spoofed channel → original signal anchored to verified prior.
Patent core claim: "recover original modal information from broken received signal via medium forward model + integrity-anchored prior" . Under partial-band jamming and protocol-level spoofing, the M t recursive smoother reconstructs intent from the last verified chain link — forensic timeline pinpoints spoof/jam onset to 1-frame resolution. Independent parties verify offline without custodian comms (XC4).
§1 · Why a defense program should read this
Two value axes: link resilience, and after-action evidence.
Channel-aware reception under jamming and CSI degradation is well-known communications-theory territory; the difference here is the second product — a per-snapshot signed record of channel state, chained to an FPGA-resident PUF key, that survives compromise of the recording node. The signed chain provides forensic-grade evidence for after-action review, coalition data-sharing, and incident investigation in spectrum-contested operations.
Link survivability
Channel-aware reception recovers usable BER on degraded multipath / partial-band jammed channels (§3 / §4).
After-action review
Replay the channel state history with cryptographic guarantee that no node — friendly or hostile — rewrote the record.
Coalition evidence
Independent parties can verify the same M t chain offline with the public verification key — neutral basis for shared findings.
EW forensics
The chain attests when the channel state changed. Drift, spoof attempts, and sudden CSI shifts are all on the immutable record.
GPS Chimera composition (§4.5)
US Air Force's pre-deployment Chimera anti-spoof (~30 s TTFAF) vs Axowl 20 ms = ~1,500× faster . Axowl composes on top of Chimera-authenticated GPS — sealing the full mission record (GPS + radar + EW + comms) on a tactical platform.
Alt-PNT + Iridium STL comparison (§4.6)
Iridium STL (~60–90 s TTFAF, commercial subscription) vs Axowl 20 ms = ~3,000–4,500× faster . Foundry-PUF root-of-trust alternative (8" CMOS) for the alt-PNT mission — no constellation-subscription dependency.
Tactical aircraft M t -rail (§4.7)
Civil-aviation M t -rail rescaled to 3-D, 0.5-s, 6-DOF fighter dynamics. AESA + IRST + IMU sensor fusion. One kernel covers contested-EM operation, multi-sensor fusion, real-time atmospheric rail, and sealed autonomy.
§2 · Experimental setup
SISO QPSK over standardized multipath profiles — no service-specific waveform.
Deliberately neutral baseband chain: SISO, QPSK, no spreading, no FH (frequency hopping), no MIMO. The result in §3 / §4 isolates the channel-state-aware reception primitive (Subsystem B of the underlying patent) from the application-layer waveform. Production integration into a fielded SDR — STANAG 4539 HF, Link 16, MUOS tactical waveforms — is separate work; the same M t chain primitive (§5) attaches to any waveform.
Modulation
QPSK, Gray-coded, unit symbol energy
Channel models
ITU-R Rec. M.1225 Vehicular-A / Pedestrian-A; 3GPP TS 36.101 Annex B EPA / EVA (delay spreads representative of urban / vehicular / pedestrian environments)
Sample rate
10 Msps (100 ns sample period)
Noise
Complex AWGN, identical realization for both receivers within each trial (no partial-band jammer modeled here — see §8)
Sample size
200,000 bits per E b /N 0 per channel
Receiver A — no M t
Coherent QPSK with single-tap carrier recovery (no equalization)
Receiver B — with M t
Frequency-domain MMSE-LE, full channel response (perfect CSI assumed in §3 — relaxed in §4)
Theoretical bound
QPSK AWGN: P b = Q(√(2 E b /N 0 ))
§3 · Results · multipath conformance channels
Channel-aware reception removes the ISI floor — standard equalization gain.
This section is intentionally unsurprising. MMSE-LE with perfect CSI on the standard channel profiles gives the expected gain over unequalized reception. We reproduce these textbook numbers to ground every claim that follows in figures any link-level engineer can replay from the published Python pipeline.
Channel
Receiver A — BER
Receiver B — BER
Δ E b /N 0 to BER 10⁻³
ITU-R Pedestrian-A
0.30 %
0.0025 %
Receiver A never reaches 10⁻³
3GPP EPA
0.32 %
0.0025 %
Receiver A near 3 ⋅ 10⁻³ floor
3GPP EVA
13.92 %
0.058 %
Receiver A bounded above 10⁻¹
ITU-R Vehicular-A
21.55 %
0.31 %
Receiver A bounded above 0.2
Numbers at E b /N 0 = 10 dB. The point of this table is not the equalization gain — it is that the table is reproducible bit-for-bit by anyone running the published pipeline. The audit primitive in §5 is what makes the same table verifiable across nodes and across time.
§4 · Time-varying CSI · contested-environment proxy
When CSI is degraded, the verified-past prior wins.
In a contested-spectrum operation the channel estimate ĥ t is degraded by partial-band noise, brief jammer dwell, terminal motion, and limited pilot budget. Below we model a slow AR(1) drift channel (ρ = 0.97) with realistic per-tap CSI noise (σ ε = 0.18) — a first-order proxy for those impairments, in a regime where there is no service-specific waveform to confuse the result. Three receivers compete at fixed E b /N 0 = 10 dB over 24 channel updates.
h t = ρ·h t−1 + √(1−ρ²)·ν t (slow channel drift) ĥ t = h t + ε t (per-snapshot CSI estimation noise) M̂ t = (1 − w) · ρ · M̂ t−1 + w · ĥ t (recursive smoother — uses verified past)
Receiver
Avg BER (24 steps)
Worst step
Best step
A — no M t (carrier recovery only)
15.30 %
29.89 %
2.77 %
B — memoryless M t (per-step noisy CSI)
4.67 %
12.70 %
0.39 %
C — M t with verified-past memory hop
2.76 %
7.60 %
0.33 %
The memory-hop receiver wins by 1.69 × on average BER and — more relevant for tactical links — its worst-step BER is roughly halved. Worst-step behavior dominates burst-error patterns and FEC failure modes. The trust in the past prior is what §5 secures.
§4.5 · Head-to-head with GPS Chimera (US Air Force L1C anti-spoof)
Pre-deployment Chimera ~30 s TTFAF · Axowl 20 ms · ~1,500× faster.
GPS Chimera is the US Air Force Research Lab (AFRL) initiative to add cryptographic authentication to the GPS L1C civil signal. TESLA-style delayed-key disclosure + ECDSA P-256 root signing per flight. Status: 2023 – 2024 test campaigns at Holloman / White Sands; expected operational deployment ≥ 2027 . Spec target: TTFAF ~ 30 s with full chain (faster than Galileo OS-NMA Reduced mode ~ 100 s, due to dual-band cross-auth and pre-cached ECDSA root).
This comparison matters for any platform that will encounter Chimera-authenticated GPS in the late-2020s. Axowl's spacecraft- /platform-side chain composes on top of Chimera rather than replacing it.
Pre-deployment caveat. Chimera TTFAF estimates below are from published AFRL / Mitre presentations and academic papers (Anderson et al. 2017 onward) — not from measured field operations. Numbers may shift ± 30 % once operational test data is published. The qualitative ranking (Chimera faster than OS-NMA, slower than Axowl frame-rate seal) is robust regardless of those adjustments.
Authentication latency vs. GPS Chimera (3-mode × 2-rate matrix)
Chimera operational mode
Estimated TTFAF
Axowl 50 Hz (20 ms)
Axowl 1.25 Hz (800 ms)
Cold-start (no cache) first power-up, no TESLA history
≈ 60 s
≈ 3,000×
≈ 75×
Standard (single-sat) typical operational mode
≈ 30 s
≈ 1,500×
≈ 38×
Aggressive (cached ECDSA root) warm-start with sideband update
≈ 10 s
≈ 500×
≈ 12×
How to read. Chimera's steady-state per-subframe authentication (after TTFAF elapses) is ~ 6 s per new MACK. Axowl 50 Hz frame = 20 ms. Steady-state speedup ≈ 300× at 50 Hz, ≈ 7× at 1.25 Hz. Both systems eventually reach cryptographic security — Axowl's advantage is when authentication becomes available.
Architectural comparison — Chimera and Axowl compose, not compete
Dimension
GPS Chimera (AFRL)
Axowl PUF chain
Operational status
Pre-deployment (2027+)
Simulation + AWS F2 FPGA prototype
Authentication scope
GPS L1C civil signal only
Any M t time series — GPS, telemetry, RF link, EW logs
Cryptographic primitive
TESLA delayed-key + ECDSA P-256
HMAC-SHA256 + PUF, monotonic 64-bit metering
Root of trust
USAF Ground Segment ECDSA private key
FPGA-resident PUF (8" CMOS fab option)
Cross-authentication
Dual-band L1C / L5 (when deployed)
XC4 multi-party offline N-of-K verification
Root-of-trust control
Operator-controlled ground-segment key
Vendor-independent PUF root path
Composability
Receiver-only (must be in the GPS receiver)
Wraps any sensor / telemetry / consensus output
Composition narrative. A tactical platform using Chimera-authenticated GPS can additionally seal the full mission record (GPS + radar returns + EW logs + comms) with Axowl chain. Chimera proves the GPS signal is authentic at receive time; Axowl proves the platform's entire data history is authentic at audit time. The two layers stack cleanly.
Honest limitations. (1) Chimera TTFAF estimates are pre-deployment published values — actual field numbers may differ once USAF publishes operational test data. (2) Chimera's cryptographic strength (ECDSA P-256 + TESLA) is robust; the comparison is operational latency, not security strength. (3) Axowl chain does not provide GPS / PNT functionality — it provides integrity on the data already generated. (4) Speedup ratios scale with Axowl source frame rate (50 Hz launch telemetry vs 1.25 Hz LEO downlink). (5) Axowl pitches as the data-layer wrap, not the GPS-receiver replacement.
§4.6 · Head-to-head with Iridium STL (Satellites Time & Location)
Deployed STL ~ 60–90 s TTFAF · Axowl 20 ms · ~3,000–4,500× faster.
Iridium STL (Satellite Time and Location, operated by Satelles) is the deployed PNT authentication service running on the Iridium NEXT 66-satellite LEO constellation. Commercially deployed; used by financial trading infrastructure, critical- power-grid time references, and a growing number of timing-security users.
Unlike Chimera (still pre-deployment) and OS-NMA (open-civilian), STL is commercially deployed today and the most realistic deployed alt-PNT reference for commercial-grade evaluation. Published TTFAF: 60 – 90 s typical for first authenticated fix; per-position update authenticated continuously thereafter.
Commercial-product caveat. STL internals are partially proprietary. Numbers below come from Satelles whitepapers and independent measurement studies (Fernandez-Hernandez et al. 2022, Dovis et al. 2024). Comparison is operational latency and architectural fit, not cryptographic equivalence.
Authentication latency vs. Iridium STL
STL operational regime
Published TTFAF / cadence
Axowl 50 Hz
Axowl 1.25 Hz
Cold-start (first authenticated fix)
≈ 90 s
≈ 4,500×
≈ 112×
Warm-start (cached ephemeris)
≈ 60 s
≈ 3,000×
≈ 75×
Steady-state per-fix update
≈ 2 s (per Iridium pass)
≈ 100×
≈ 2.5×
Architectural comparison — Iridium STL vs. Axowl chain
Dimension
Iridium STL
Axowl PUF chain
Operational status
Live since 2017, government-deployed
Simulation + FPGA prototype
Authentication scope
PNT (position + time) authentication only
Any M t time series
Service model
Satelles subscription service via Iridium
One-time IP license, customer-operated infrastructure
Root of trust
Satelles operations center + Iridium NOC
FPGA-resident PUF (customer-operated)
Dependency
Iridium constellation (commercial, end-of-life ≥ 2030)
None — Axowl runs on any spacecraft / platform
Geographic coverage
Global (Iridium 66-sat LEO)
Platform-local — wherever the spacecraft / receiver is
Procurement model
Iridium / Satelles subscription
One-time IP license + 8" CMOS fab PUF, customer-operated
Procurement positioning. Iridium STL is the subscription path; Axowl chain is the capex / IP-license path with a customer-operated PUF root of trust. Both can coexist: STL provides PNT today, Axowl wraps the platform's full data record. For an independent alt-PNT receiver, Axowl's spacecraft- / platform-side seal becomes the integrity layer.
Honest limitations. (1) STL is a positioning authentication service; Axowl is a data integrity layer — they solve different problems. The "latency speedup" comparison is apples-to-apples only for the auth-latency dimension. (2) Iridium 66-sat constellation is reaching end-of-life (≥ 2030 transition planned); STL's long-term roadmap depends on Iridium's next-gen deployment. (3) Axowl chain does not provide positioning — a deploying platform would still need GPS / Galileo / alt-PNT receivers for the actual fix; Axowl wraps that fix in tamper-evident chain. (4) STL subscription is operational cost (per-device / per-year); Axowl is capex (FPGA / PUF chip). Cost structures differ.
§4.7 · Fighter / tactical aircraft M t -rail
Same engine. Rescaled for high-G, 3-D, 0.5-second timescale.
The atmospheric M t -rail primitive demonstrated in the civil aviation demo (200 km en-route slab + memory-hop update, fuel + comfort optimisation for commercial operators) generalises directly to fighter / tactical aircraft with the same modal decomposition + verified-prior loop. The licensable core stays unchanged — what changes is scale, sensor stack, and dynamics.
Civil vs. tactical M t -rail — scale comparison
Dimension
Civil aviation (current demo)
Fighter / tactical
Domain
200 km along-track × 80 km cross-track, 2-D
30 – 80 km forward cone × ±30 – 60° FOV, 3-D voxel grid
Time step
5 s
0.5 – 1.0 s (high-G manoeuvre timescale)
Dynamics model
2-D point-mass, 70 t narrow-body, 240 m/s cruise
3-D, 6-DOF, roll / pitch / yaw, high-G transients
State variables
Turbulence intensity, gust index
E turb , ρ, T, ∇v, gust index, shear (5-D field)
Forward-sense stack
Forward-looking sensor cone (radar-class)
AESA radar + IRST + IMU + AoA + pitot fusion
Memory-hop weight (α)
0.30 (stable cruise)
Dynamic: ↑ in high-G (trust new), ↓ in steady (trust map)
Output to autopilot
Path-replan, fuel-optimal route
"Rail" for the next 10 – 30 s of manoeuvre
Engine reuse. The Python pipeline producing the civil-aviation §3 / §4 figures is the same kernel that would produce fighter Mt fields with the dimensions above swapped in. No new algorithm — the M t + memory-hop + chain primitive is domain-independent. What needs building is the 6-DOF simulator integration (JSBSim / X-Plane / OpenAerial) and the AESA / IRST sensor-fusion stub replacement.
Operational benefit axes for fighter / tactical platform
Benefit axis
Mechanism
Where it shows up
Manoeuvre stability
AI co-pilot pre-corrects for turbulence cores before they hit during high-G turn / pull-up / dive
Reduced trim overshoot, lower control-surface duty cycle, longer airframe life
Pilot fatigue reduction
FCS follows the Mt rail rather than reacting to disturbances
Less "fighting the aircraft" — measurable in pilot HRV / mission-end fatigue scoring
Fuel / range
Drag-equivalent turbulence avoidance on long-CAP / penetration profiles
~ single-digit % fuel savings on representative profiles (pilot validation needed)
Weapon / sensor pointing
AESA / EO / IR sight stays on target during atmospheric perturbation
Lower CEP for guided munitions, longer track-time on contact, fewer break-lock events
Sealed mission record
Every Mt snapshot + manoeuvre decision sealed via FPGA-PUF chain
Coalition / after-action / accident investigation — independent verification
Cross-domain coverage — one engine. The same primitive fuses sensing + communication + autonomy + tamper-evident trust with a single FPGA-PUF root of trust: channel-aware reception and partial-band jamming recovery (§3 / §4), multi-sensor 3-D M t fusion (AESA + IRST + IMU + pitot, this section), and sealed mission history (§5). One mathematical kernel, not four separate point solutions.
Honest limitations of the fighter framing. (1) The simulation pipeline today is the civil-aviation 2-D point-mass demo. Fighter validation requires 6-DOF flight-dynamics integration (JSBSim / X-Plane / OpenAerial / a Tier-1's proprietary 6-DOF sim) — that is a pilot-phase deliverable, not a current demo result. (2) AESA / IRST sensor models are stubs ; pilot work needs raw radar tensor + IRST output from an actual Tier-1 / OEM. (3) Fuel / CEP / pilot-fatigue numbers are hypotheses grounded in physics — quantitative validation needs flight-test data. (4) This section is the " this engine can also fly into fighter programs " narrative — the heavy lifting (6-DOF sim, real sensor data, flight test) is pilot scope, not demo scope. (5) M t -rail applicability — restricted scope. A combat sortie's adversarial / dynamic mission profile cannot be pre-mapped — the M t -rail framing in this §4.7 applies only to fixed-route training, transit, CAP, or ferry profiles where the route is known in advance. For unpredictable air-to-air engagement or contested-zone penetration the Rail prior is not applicable, and only the chain primitive + per-frame sensor fusion (no pre-laid environment) carry over. The pad-fixed F-35B STOVL vertical landing case — where the environment can be pre-laid — is the subject of §4.8 below.
§4.8 · F-35B STOVL · vertical-landing M t -rail · methodology
Pad-fixed environment = Rail-applicable sub-scope.
Where the §4.7 combat sortie is not Rail-applicable (adversarial / dynamic mission), the F-35B's STOVL vertical landing onto a known amphibious / carrier pad is the opposite — the landing environment (ship CAD geometry, sea-state- conditioned 6-DOF motion statistics, hot-exhaust CFD map) can be pre-laid as a rail. This section is methodology only — there is no flight-test data — but it identifies (A) the four published challenges, (B) the current Tier-1 state of the art (Rolls-Royce LiftSystem + F-35B IFPC + NAVAIR MAGIC CARPET + Royal Navy SRVL), and (C) where the Axowl Rail + AI dispatch + chain primitive plugs in.
A. Why F-35B vertical landing is hard
Challenge
Mechanism
Published source
Hot-exhaust ground effect
F135 exhaust at ~3,600 °F — deck warping, re-ingestion risk; Thermion (ceramic + Al) coating mitigates only partially
USS Gerald R. Ford deck thermal stress reports (USNI / National Security Journal, 2026); Wasp-class Thermion coating program (military.com 2011)
Pad 6-DOF motion
Ship heave / pitch / roll at sea state; SRVL trials demonstrated approaches with wind-over-deck (WOD) at 40 – 50 knots
Royal Navy / F-35 ITF, HMS Queen Elizabeth Oct 2018 trials
Superstructure wind shear
Bridge + FLYCO tower turbulence interacts with low-altitude approach; pilot relies on inertial reference + HMD-projected deck velocity vector
P. Wilson / Royal Navy 2018, SRVL test campaign
Touchdown precision
NAVAIR MAGIC CARPET (F-35C, CATOBAR carrier) has demonstrated ~50 % touchdown-dispersion reduction; F-35B STOVL pad-spot precision is the open problem
USNI News 2016 & 2021, NAVAIR Precision Landing Mode program
B. Current Tier-1 / production state of the art
System
Function
Reference
Rolls-Royce LiftSystem (ILFPS)
LiftFan (29,000 hp, contra-rotating, 1.27 m diameter) + 3-Bearing Swivel Module (3BSM) thrust-vectoring rear nozzle + roll-post wing nozzles. Collier Trophy 2001.
Rolls-Royce LiftSystem product page (rolls-royce.com)
F-35B IFPC
Integrated Flight Propulsion Control — single-pilot-input autohover; simultaneous control of LiftFan inlet area, 3BSM angle, and roll-post bypass flow to balance lift, pitch, roll and yaw with constant total lift
Lockheed Martin F-35 Air Vehicle Technology Overview (2018)
NAVAIR MAGIC CARPET / PLM
"Maritime Augmented Guidance with Integrated Controls for Carrier Approach and Recovery Precision Enabling Technologies" — auto-throttle + glideslope lock for CATOBAR carrier landing (F-35C, F/A-18E/F). ~50 % touchdown-dispersion reduction. No analogous F-35B STOVL pad-precision system fielded.
USNI News 2016 / 2021, NAVAIR Precision Landing Mode
SRVL (Royal Navy)
Shipborne Rolling Vertical Landing — 57-knot forward speed + lift-fan + wing lift; +7,000 lbs all-up-weight margin over pure vertical recovery. Pilot fuses inertial reference with HMD-projected ship-referenced velocity vector.
Royal Navy / F-35 ITF, HMS Queen Elizabeth Oct 2018; SRVL Wikipedia / Flight Global
C. Axowl Rail + AI dispatch + chain — methodology (this is where the engine plugs in)
Layer
What plugs in
Where it would help
Pre-laid pad rail
Ship CAD prior (Wasp-class / America-class / HMS Queen Elizabeth / ITS Cavour / JS Izumo) + nominal 6-DOF motion profile conditioned on sea state + CFD-derived hot-exhaust ground-effect map
Approach planning starts from the known pad geometry — IMU + AESA + DAS only refine, never bootstrap from zero
Multi-sensor fusion
Ship IMU + AESA wind sensor + DAS 360° optical + F135 telemetry + HMD inertial reference (all already on the F-35B)
Per-frame consensus of all sensors against the pre-laid rail; sensor disagreement triggers dispatch instead of voting an unsafe approach
AI dispatch trigger
WOD > 50 kts → switching pipeline (lateral SRVL drift) · pad pitch > 3° / heave > 2 m → adaptive pipeline (motion-locked descent) · hot-exhaust re-ingestion signature → abort + climb-out
Same architectural pattern as Space §S1.7 (S4 < 0.25 / 0.25 – 0.7 / ≥ 0.7 + Kp ≥ 7 outlier) — regime classifier + per-regime pipeline + explicit out-of-scope alarm
Chain-anchored integrity
Every IMU / AESA / DAS / IFPC telemetry frame is PUF-chain authenticated at the 20 ms cycle; jamming or sensor spoof → chain fail → fall back to optical / inertial-only
Per-frame integrity = real-time safety. Sealed approach record = post-incident accident-investigation primitive (the same §5 chain).
Sub-scope — where this Rail applies. ✅ Amphibious / STOVL carrier platforms with a known CAD geometry and a multi-sortie motion archive (Wasp-class, America-class, HMS Queen Elizabeth, ITS Cavour, JS Izumo conversion). ❌ Land-based VTOL on an unknown ground (improvised combat-zone pad, downed-aircraft recovery) — environment cannot be pre-laid; only the chain primitive carries over, not the Rail. Methodology status (no flight-test data). Validation of this section requires (i) JSBSim STOVL plug-in or equivalent 6-DOF integration with the F-35B IFPC model, (ii) actual ship-trial data from a suitable amphibious-assault / carrier deck, and (iii) airframe-OEM + engine-maker + certification-authority approval for IFPC sideband integration. The current claim is " the Axowl Rail + AI + chain primitive plugs into the F-35B STOVL recovery problem in these four places " — not a touchdown-precision number. Pilot-phase deliverables are 6-DOF sim ± real sea-trial data, in partnership with a Tier-1 / OEM.
§4.9 · Submarine · ocean-medium M t -rail + AI dispatch · methodology
Ocean is the M t medium. GPS surface-skin-depth 6 mm + GNSS-R + cross-medium TARF + sealed periscope-depth handoff.
Submarine positioning is the hardest GNSS-denied case in the portfolio. The L1 1.575 GHz GPS signal has a seawater skin depth of ~6 mm (Physics Today 2022, ArduSimple) — direct sub-surface GPS reception is physically impossible. However, the ocean is a valid M t medium (sound speed profile + thermocline + halocline + surface wave state + bathymetry), and several existing technologies do use the way GPS signals interact with the ocean surface to extract state (NASA CYGNSS / Spire GNSS-R bistatic radar, MIT TARF acoustic-to-mmWave cross-medium link). This section is methodology only — there is no sea-trial data — but it identifies (A) the four published challenges, (B) the current Tier-1 / mission state of the art, and (C) where the Axowl Rail + AI dispatch + chain primitive plugs in across five independent paths.
A. Why submarine positioning + ocean communication is hard
Challenge
Mechanism
Published source
GPS skin-depth 6 mm at 1.3 – 1.6 GHz
Seawater conductivity ~5 S/m → 36.7 % amplitude loss at 6 mm, 99 % loss at ~3 cm; sub-surface direct GPS reception is physically impossible
Physics Today 75(2):42 (2022); ArduSimple analysis; arXiv 1809.06741 surface-wave underwater radio
GIB acoustic spoofing
GPS Intelligent Buoys (GIBs) relay GPS coordinates via acoustic transmissions; an adversary with a louder acoustic source can override the buoy and inject false position into the submerged receiver — a published vulnerability
Preprints.org 2020/0187 — Spoofing GNSS-like UPS; IEEE 10639769 (2024) — UW Pos/Nav attack surface analysis; MDPI 2079-9292/10/17/2089 — DUPS spoofing detection
INS drift 1 – 5 km / day
Submarines rely on Sperry MK 39 / Sagem Sigma / Thales Optimar INS, which accumulate position error at a fraction of a nautical mile per day — periodic external fixes are required to reset (NATO SINS index cycle 2.66 h, plus longer-period star / GPS fixes)
NATO Ships Inertial Navigation System (SINS); Sperry MK 39 IRS public spec; Sonardyne free-inertial subsea reference
Adversarial ASW jamming + counter-detection
Anti-submarine warfare environments include sonar jamming, acoustic decoys, false-track injection (e.g., towed-array attacks) and counter-detection sonobuoys — silent-running constraints prevent the submarine from emitting reliably for self-correction
Naval Post / USNI Proceedings 2021 on submarine navigation; CIMSEC AUV mine-warfare kill-chain
B. Current Tier-1 / mission state of the art
System
Function
Reference
NASA CYGNSS & Spire GNSS-R
Bistatic-radar receivers in LEO; use GPS-as-transmitter to estimate ocean surface wind speed, wave height, significant wave height (SWH), sea surface height (SSH) from Delay-Doppler Maps (DDM). CYGNSS = 8 satellites (NOAA / NASA, 2016+); Spire = follow-on CubeSat constellation (2020+).
NASA CYGNSS mission page; Soulat 2004 GRL coastal GNSS-R; Loria 2021 AGU on wind+wave retrieval; eoPortal GNSS-R overview
MIT TARF (Translational Acoustic-RF)
Submarine emits acoustic ping → ocean surface ripples at sub-mm amplitude → drone / aircraft mmWave radar detects the ripple as a translation of the acoustic signal — first cross-medium submarine-to-air wireless link, demonstrated 2018.
MIT News Aug 2018 — Adib lab; Engineering.com follow-up on 5G mmWave for submarine comms
Sperry MK 39 / Sagem Sigma / Thales Optimar INS
Production submarine inertial navigation systems with ring-laser-gyro or fiber-optic-gyro cores; NATO SINS standard. Index cycle 2.66 h (Sperry proprietary). Drift rate ≈ 0.1 – 1 NM / day depending on grade.
NATO SINS Wikipedia / rnsubs.co.uk; Sperry MK 39 IRS; Thales Optimar product page; Exail navy INS
Kongsberg HUGIN AUV (TAN)
Terrain-aided navigation via HISAS synthetic aperture sonar + EM2040 multibeam echo-sounder + Sunstone INS; 20 cm bathymetric resolution across a 750 m swath at 3.5 kt / 40 m altitude. 15-day endurance on HUGIN Endurance. Used commercially and by navies.
Kongsberg Discovery HUGIN product page; ScienceDirect S0029801823011630 — TAN underwater review
Sonardyne LBL / USBL acoustic positioning
LBL transponder arrays on the seabed give < 1 m accuracy (sometimes 1 cm) within the array footprint; USBL pole-mounted single-array on a surface vessel for shorter-range / mobile operations; DVL = bottom-tracked velocity.
Sonardyne LBL/USBL product line; EvoLogics positioning; Wikipedia underwater acoustic positioning
GIB & NOAA NDBC buoys
GPS-equipped surface buoys with submerged hydrophones; commercially available position-relay platforms for AUV / ROV tracking; NOAA National Data Buoy Center operates ~ 100 ocean-data buoys for sea state.
NOAA NDBC; Wikipedia underwater acoustic positioning §GIB; oceansciencetechnology.com supplier list
Underwater PUF authentication
PUF-based authentication has been independently proposed and prototyped for underwater wireless sensor networks (marine monitoring + naval coastal surveillance) — building block exists.
MDPI Applied Sciences 16(2):873 — Secure PUF authentication for underwater WSN; researchgate 343336193 — Merkle hash + dolphin whistle covert UW comms
C. Axowl Rail + AI dispatch + chain — methodology (5 independent paths)
Path
What plugs in
Where it would help
A · Chain-signed periscope-depth GPS fix
Each mast-up GPS fix is signed by the submarine's PUF and committed to the §5 transition-hash chain together with the INS state at the moment of reset. Until the next mast-up, the INS evolves under a sealed prior — its drift-budget evolution is itself a chain entry.
Public sources describe the procedure (Wikipedia / USNI / Naval Post) but do not describe cryptographic integrity on the GPS fix or the INS-reset transition. Adversary cannot retroactively rewrite the position-fix history during after-action review.
B · Chain-signed GIB acoustic relay
Each acoustic packet from a surface GIB carries a PUF-chain signature of (lat, lon, time, buoy ID); the submerged receiver verifies before accepting. A louder spoofing source produces a chain-invalid signature and is rejected.
Directly addresses the published GIB-spoofing vulnerability (Preprints.org 2020/0187, IEEE 10639769, MDPI 2079-9292) — the chain is a counter to the exact attack surface those papers identified.
C · GNSS-R ocean surface M t + chain
Floating receivers (USVs, sonobuoys, or seabed-anchored stations) running a GNSS-R DDM extractor produce sea-state M t snapshots (wind, wave height, SSH); each snapshot is PUF-chain-signed and replayable downstream. Modal decomposition (Chladni 1D / 2D) separates the multipath constituents (specular vs scattered).
Composes on top of NASA CYGNSS / Spire (production GNSS-R missions) — adds tamper-evident ocean-state history that is verifiable post-hoc by coalition forces or accident investigators.
D · TARF cross-medium + chain
Submarine emits a PUF-chain-signed acoustic ping → ocean surface ripple → drone / MPA mmWave radar reads the ripple translation → drone verifies the chain signature in the demodulated bits. Modal decomposition extracts the ripple-pattern from competing wind-driven surface variance.
Composes on top of MIT TARF (2018, Adib lab) — turns a one-way acoustic→RF link into a cryptographically authenticated channel, which TARF as published does not have.
E · Sonar signal processing + modal + chain
Existing active / passive sonar transducer hardware is unchanged. The returned echo or ambient acoustic stream is processed by the §3 – §4 Chladni 1D / 2D modal decomposition (multipath separation: surface bounce + bottom bounce + thermocline scattering) + §6 verified-prior smoother + per-echo PUF-chain entry for tamper-evident track history. AI dispatch by ocean regime: shallow littoral / deep open / thermocline boundary / under-ice ALARM.
Same architectural pattern as Space §S1.7 (regime classifier + per-regime pipeline + outlier ALARM) and Defense §4.8 STOVL — XC10 cross-domain isomorphism with ocean SSP + bathymetry as the pre-laid rail.
Sub-scope — where this Rail applies. ✅ Mapped littoral / assigned operating area / harbor transit + standard sortie route / underwater pipeline + cable inspection (NOAA navigation charts / UKHO ADMIRALTY / US Naval Oceanographic Office bathymetry). 🟡 Open-ocean transit with periodic mast-up GPS fixes and / or GIB-relay anchors (partial rail — bathymetry sparse, but periodic surface-medium handoff is chain-signable). ❌ Beneath polar ice cap (no mast-up possible, no GNSS-R surface reflection in ice cover), open-ocean adversarial ASW silent-running sortie (sortie itself is unpredictable and the platform cannot emit acoustic chain pings without counter-detection) — Rail is not applicable; only the chain primitive on internal sensors carries over. Methodology status (no sea-trial data). Validation of this section requires (i) integration with an actual submarine INS stack (Sperry MK 39 / Sagem / Thales / Exail) under an OEM and navy partnership; (ii) GNSS-R receiver integration with CYGNSS-class or Spire data feeds; (iii) acoustic-channel chain-signed-ping qualification on a TARF-class transmit chain; (iv) classified-environment trials with a US-Navy or a naval submarine partner or unmanned partners (Boeing Echo Voyager XLUUV, Anduril Dive, HUGIN Endurance). The current claim is " the Axowl Rail + AI + chain primitive plugs into the submarine ocean-medium positioning problem in these five places " — not a CEP or position-error number for a specific navy stack.
§5 · Transition hash chain · forensic primitive
Each M t is signed by an FPGA-resident PUF key, then chained.
§3 and §4 are the cover story; §5 is the load-bearing claim. Every channel-state snapshot M t is HMAC-signed against the previous transition hash with a key derived inside an FPGA from a Physical Unclonable Function. The key cannot be extracted by software, by JTAG, or by side-channel. A single bit altered anywhere in the historical M t record breaks every downstream signature.
Fig. — 12-step transition chain. One bit modified in M 10 : 10 / 24 links validate (clean baseline = 24 / 24). All H t for t ≥ 10 fail.
σ t = HMAC K PUF (H t−1 ‖ M t )
H t = SHA256(H t−1 ‖ M t ‖ σ t )
verify HMAC K PUF (H t−1 ‖ M t ) ≟ σ t ∀ t
MAC primitive
HMAC-SHA256, 256-bit PUF-derived key
Key custody
AWS F2 FPGA (AFI agfi-085919c09c35982c3 ) in the lab today; target hardware = mil-spec FPGA / ASIC in a sealed enclosure. The 256-bit PUF root never crosses the silicon boundary.
Compromised-node tolerance
A captured / destroyed recording node cannot retroactively rewrite history; verification keys can be held off-platform (command, ground station, escrow).
Coalition verification
Public verification key shared with independent parties enables offline chain audit without sharing the PUF root.
Tamper sensitivity
1 bit flipped at step k → 100 % of links from k to T reject (demonstrated on T = 24)
§6 · Operational scenarios
Where the primitive lands in a force-on-force timeline.
After-Action Review
Replay the channel-state record of a contested engagement with cryptographic guarantee against unit-level tampering — both friendly and adversary.
EW incident reconstruction
The signed M t drift is the immutable record of when, where, and how the channel state changed. Jammer attribution from a chain is far stronger than from a node log.
Coalition data sharing
Independent units exchange verified chain segments with shared public keys. No party trusts the other's log; both trust the chain.
LPI / LPD posture
The chain attests when CSI was observed, not the content. Compatible with low-probability-of-intercept waveforms — the chain layer is content-neutral.
Cryptographic provenance
Channel-state records survive node capture; the FPGA-resident PUF root cannot be exfiltrated by software or by physical disassembly without destroying the key.
Replay attack resistance
Each H t binds to its predecessor; replayed CSI from an earlier moment fails to validate against the current chain head.
Multi-domain transport integration
The chain is waveform-agnostic and small (≪1 kB per snapshot). Sealed channel-state records can transit any multi-domain transport.
Mil-spec porting target
The current AWS F2 FPGA AFI is a development target. Production target = rad-hard FPGA (e.g. Microsemi RTG4 class) or ASIC; PUF + HMAC-SHA256 primitives port directly.
§7 · Integration paths
Three deployment shapes. Pick the one that fits the platform.
In-radio / SCA component
Modal extraction co-located with channel estimator block of an existing JTRS / SCA-compliant radio; HMAC sign per CSI snapshot. Tightest latency. FPGA / ASIC implementation.
Network-appliance form factor
Sealed CSI records produced by a side-car appliance from radio KPI exports. No radio-cert impact; suitable for retrofit of fielded waveforms.
Ground-station log signer
CSI snapshots emitted by deployed units are countersigned at the ground station / HQ. Defense-in-depth for forensic chain on long-duration missions.
Licensing model
Per-radio IP block (FPGA / ASIC), per-platform software license, or government-purpose-rights configuration negotiated through the program office.
Export control
HMAC-SHA256 + SHA-256 are not export-controlled per current US/EU regimes. PUF + RTL is subject to standard reviews depending on jurisdiction and end-use.
§8 · Honest limitations
What this page does not show.
No jammer model in §3 / §4. We use commercial multipath profiles and AWGN. Partial-band jammers, follower jammers, and reactive jammers all require explicit modeling and are out of scope for this page. The chain primitive is jammer-agnostic; the receiver-side gain depends entirely on which equalizer wraps it.
SISO baseband only. No spread-spectrum (DSSS / FH), no MIMO, no anti-jam waveform features. Production waveforms (HAVE QUICK, SINCGARS, MUOS, Link 16) add their own gains; the M t chain attaches independently.
Perfect CSI in §3, simplified CSI noise in §4. Real fielded radios estimate CSI from a pilot budget that varies by waveform. The §4 noise level is a single operating point, not a sweep.
FPGA is software-emulated for the chain in this demo. The 24-step chain in §5 was computed in Python against the same PUF-derived key constant the FPGA uses. A separate program of work has the same HMAC running on a real AWS F2 FPGA AFI. Mil-spec hardware (rad-hard FPGA, ASIC) is the production target.
Chain content vs chain attestation. The chain attests when M t was observed and when it changed. It does not encrypt M t nor attest to unit identity. Classification guards, COMSEC keying, and identity binding are separate layers.
No FH / hopset coordination in this model. Frequency-hopping waveforms require chained extraction of a per-dwell M t ; the page does not yet demonstrate this. The primitive scales directly — each dwell is one chain link — but the latency budget per dwell needs measuring in hardware.
Sample-size-limited measurements. 200,000 bits per E b /N 0 caps measurable BER at ~5 × 10⁻⁶. We report "0 errors in N" rather than extrapolating.
§9 · For your evaluation team
Run it on your own waveform.
The Python pipeline that produced every figure on this page is available under appropriate non-disclosure for a defense evaluation. The recommended first step is to repeat §3 / §4 on your service-specific channel sounding (HF, VHF, UHF SATCOM, MUOS, Link 16) and report the same table against the program's reference receiver. The chain primitive is waveform-independent and can be evaluated independently of the receiver work.
Request technical briefing Read the whitepaper