Secure Adaptive Fusion Environment
A five-layer zero-knowledge proof architecture for trustless coalition sensor fusion. This report provides a comprehensive overview of the prototype's capabilities, data flows, simulation architecture, and research evidence outputs.
Prototype Notice: Cryptographic functions are simulated with calibrated timing. Results reflect modelled behaviour within the prototype environment, not production cryptographic execution. ZK proof generation, trusted setup, and recipient hash binding are explicitly simulated — not real cryptographic operations.
System components, data flow, and research question mapping
Can ZK-SNARKs meet tactical timing and bandwidth constraints?
Does policy-score gatekeeper outperform proof-check baseline under adversarial conditions?
Does recipient binding + Bloom lineage enable adequate cross-domain provenance?
How does SAFE perform in a realistic 20-minute maritime coalition ISR scenario?
Circuit design, constraint counts, and per-protocol performance
| Protocol | Prove (ms) | Verify (ms) | Proof Size | Passes 100ms? | Notes |
|---|---|---|---|---|---|
| PLONK | 65 | 8 | 400 B | Yes | Universal SRS, recommended for production |
| GROTH16 | 90 | 6 | 200 B | Yes | Smallest proof, per-circuit trusted setup |
| STARK | 250 | 4 | 45 KB | No | Post-quantum, no trusted setup, 45 KB proof |
| BULLETPROOF | 500 | 50 | 700 B | No | No trusted setup, logarithmic proof size, slow prove |
/rq1 — ZKP Benchmarking Engine
| Scenario type | 5 scenarios (Benign, Mixed Quality, Replay/Stale, Data Incest, Adversarial) |
| ZK protocols | PLONK, GROTH16, STARK, BULLETPROOF (multi-select) |
| Circuits | tier_check_linear (baseline) or tier_check_norm (realistic norm-based) |
| Sensor types | Surface Radar, Volume Radar, EO/IR, ESM, Acoustic (multi-select) |
| Runs per combo | 1–500 (default 30). Total = protocols × sensors × runs |
| Identity proofs | Optional Layer 3 (2048-constraint Merkle circuit) + classification level |
| Link conditions | Nominal, Degraded, Poor — sets BER, drop rate, latency |
| Experiment label | Human-readable ID for export and replay reference |
| Random seed | Explicit seed for deterministic reproducibility |
| Real-time feed | Streamed track events with protocol, sensor, prove/verify, bytes, success flag |
| Protocol stats table | Mean/P95 prove time, verify time, proof size vs. RQ1 thresholds |
| Layer breakdown chart | Per-layer prove time contribution (L1–L5) per protocol |
| Proof bytes chart | Per-layer circuit output bytes (STARK KB vs. PLONK bytes) |
| Activity feed | Chronological track log with pass/fail indicators |
| Bandwidth analysis | Link preset effects on message loss and effective throughput |
| Experiment report | Configurable HTML/Markdown report with methodology section |
| Historical replay | Re-run any prior experiment using saved random seed |
/rq2 — Policy-Driven Fusion Control
| Factor | α Weight | Gold (best) | Silver | Bronze (worst) | Measures |
|---|---|---|---|---|---|
| wFidelity | 0.35 | 1.0 | 1.4 | 2.0 | ZKP-verified sensor quality tier |
| wAge | 0.1 | 1.0 | 1.2 | 2.5 | Track freshness (age in seconds) |
| wLineage | 0.1 | 1.0 | 1.2 | 3.0 | Lineage depth + Bloom incest flag |
| wOutlier | 0.2 | 1.0 | 1.5 | 2.5 | Positional plausibility check |
| wLink | 0.25 | 1.0 | 1.4 | 2.0 | BER + drop rate + latency of data link |
Optimal Kalman fusion — high confidence track
Covariance Intersection — conservative fusion
Track rejected — does not enter fuser
| Live feed | Per-track decisions with layer L1–L5 status, policy score, CI reason |
| Comparison summary | Baseline vs. SAFE KALMAN/CI/REJECT rates side-by-side |
| Track map | Geospatial truth position + baseline estimate + SAFE estimate + error ellipse |
| CI reason chart | Pie of incest_detected, aged_track, low_fidelity_bronze, link_quality_degraded, outlier_position |
| RMS summary | Mean/max position error per tier (Gold/Silver/Bronze) × mode (Baseline/SAFE) |
| Gatekeeper audit log | Filterable per-track table with policyScore, topFactor, rejectReason |
| Policy score viz | Score vs. RMS scatter, mean score by decision, weight factor bars |
| Fusion quality | NEES tracking, RMS trend over time |
| Save Run | Persists to sim_runs + sim_events tables; accessible from Exports page |
/rq3 — Cross-Domain Policy Enforcement
| Scenario | Benign, Mixed, Replay, Incest, Adversarial, Degraded |
| Topology | Chain3, Chain5, Mesh (fully connected), Ring |
| Auth mix | Uniform (all Unclass), Mixed (U+S), Multi-tier (U+S+TS) |
| Seeds per scenario | 1–50 seeds for statistical robustness |
| Tracks per seed | 10–500 (total = seeds × tracks) |
| Architecture mode | SAFE only, CDS (baseline guard) only, or Comparison (both) |
| CDS parameters | Guard latency, block rate, downgrade rate, compute cost/msg |
| SAFE parameters | ZKP verify ms, Bloom check ms, recipient check ms, freshness ms |
| Fusible track % | Tracks passing incest + freshness + proof checks |
| Incest handled % | Bloom filter detections successfully quarantined to CI |
| Unauthorized ID leak % | Attempts to infer restricted identity that reached unauthorized node |
| Avg hop count | Mean lineage depth before fusion quality degrades |
| Attack routing | Incest/replay/sybil distribution: KALMAN vs. CI vs. REJECT |
| Auth visibility | Field access per clearance level (position, velocity, tier, ID, sensor) |
| SAFE vs. CDS comparison | Bandwidth, latency, leakage rate, fusion continuity side-by-side |
/sim/enhanced — 20-Minute Maritime ISR Coalition Scenario
| Duration | 20 minutes (1200 seconds), 1×/2×/5× speed |
| Mode | Analyst (manual seek) or Demo (auto-rotate, 2× speed) |
| Coalition ships | 4 platforms: US Destroyer (TS), UK Frigate (S), Bahrain Patrol (C), French Rafale (TS) |
| Targets | ~8 contact tracks (friendly, neutral, hostile mix) |
| Link conditions | Per-platform dynamic degradation (Nominal → Degraded → Poor) |
| View modes | Truth / Baseline / SAFE / Comparison (selectable) |
| Perspective selector | View scenario from any platform's clearance and link state |
| Map overlays | Truth contacts, Baseline tracks, SAFE tracks, BL failures, error ellipses, trails |
| Maritime map | Contact positions, platform icons, track color-coded by detection system |
| ZK pipeline panel | Per-track L1–L5 layer timing, success/fail bars, replays blocked counter |
| Gatekeeper audit trail | SAFE vs. Baseline behavioral diff, event type classification |
| Tabbed track detail | Per-contact RMS, NEES, Baseline vs. SAFE estimate comparison |
| Why SAFE summary | Counts: incest catches, freshness blocks, outlier downgrades, policy overrides |
| Narrative panel | Context-aware prose explaining gatekeeper decisions |
| Event feed | Filtered by view mode and attack type (replay, incest, spoof) |
| Timeline seek | Click progress bar to jump to any point in the 20-min scenario |
/traceability — Requirement-to-Artifact Gap Closure Matrix
| Total entries | 22 seeded requirements across RQ1, RQ2, RQ3, SIM, Dashboard, Limitations |
| Filter by RQ | RQ1, RQ2, RQ3, SIM, Dashboard, Limitation |
| Filter by status | Addressed, Partial, Stub, Out of Scope |
| Filter by evidence | UI Widget, Simulation Event, Chart, Export, Documentable Claim, Limitation |
| Search | Full-text across title, requirement, artifact path, tags |
| Expanded detail | Click row → requirement, artifact, dissertation wording bullets, limitation type |
| Visual summaries | Progress by RQ bar chart, status pie, artifact coverage heat map |
| Limitations section | Stub prover, trusted setup, hash-bound encryption, rate limiting, Byzantine scope |
/exports — Simulation Archive & Research Artefacts
All exports include generated_at timestamp, app_version, scenario name, and SIMULATION_CAVEAT header.
Schema design, RLS policies, and data flow
| Table | Rows | RLS Policy | Purpose |
|---|---|---|---|
| research_tasks | Prototype mode: anon read/insert/update | RLS enabled; SELECT/INSERT/UPDATE for anon | 37 pre-seeded tasks across RQ1/RQ2/RQ3/SIM. Status cycling with timestamps and run counts. |
| proof_runs | Prototype mode: anon read/insert/update | RLS enabled; SELECT/INSERT/UPDATE for anon | Per-track ZKP benchmark records (RQ1 and RQ2). Indexed by experiment_label, scenario_type, mode. |
| sim_runs | Prototype mode: anon read/insert/update | RLS enabled; SELECT/INSERT/UPDATE for anon | Simulation run summaries. One row per saved execution with aggregated metrics and caveats. |
| sim_events | Prototype mode: anon read/insert/update | RLS enabled; SELECT/INSERT/UPDATE for anon | Per-event telemetry linked to sim_runs via run_id. Includes layer status, policy score, CI reason. |
Explicit classification of intentional constraints
All proof generation uses calibrated timing with random hex proof strings. No real PLONK/GROTH16/STARK circuits. Requires native toolchain (circom, snarkjs, Noir).
Trusted setup is a static version string "universal-srs-v2". Real deployment requires a Powers of Tau ceremony.
Recipient binding uses deterministic hash of (value + recipientPolicyId). Production requires AES-GCM with recipient public key infrastructure.
Gatekeeper rate limiting is not implemented. Production requires token-bucket throttling per coalition node.
Replay, incest, and proof spoof attacks are modelled. Deep multi-node Byzantine collusion scenarios are out of scope.
UI audit log resets on page reload. Persistent evidence available via Exports → sim_events table.
Interpretation guidance: None of the above are software bugs. Each is an intentional prototype-scope decision. The prototype demonstrates architecture-level feasibility — that the five-layer SAFE design is coherent, measurable, and produces research-quality comparative evidence — without requiring a full production cryptographic stack.
Relative feature depth across research dimensions
SAFE Prototype — SAFE-prototype-v2.0 — Report generated 2026-05-16
Secure Adaptive Fusion Environment · SYSE 701 Research Demonstrator
Cryptographic functions are simulated/calibrated. Results reflect modelled behaviour, not production cryptographic execution.