← Research WP-10 · SURFACE MAP CISOs · Architects · Procurement · Defence

Every Surface. Every Profile. Every Claim.

ACSE protects every observable surface across six waves — from production IT infrastructure today, through HCI, storage fabrics, cloud-native, OT/ICS/SCADA, telecom and 5G, to national critical infrastructure. One invariant. One patent. Every surface protected.

Abstract

The attack surface has exploded. Every device, every protocol, every management plane an organisation operates is observable, fingerprinted, and exploitable if it stays static long enough. The reconnaissance cycle — Observe, Map, Model, Stage, Exploit — applies identically whether the target is a web server, a Nutanix Prism Central management plane, a Siemens S7 PLC, a 5G Access and Mobility Management Function, or a national power grid SCADA controller. The vulnerability is universal: the surface is static, and static surfaces can be mapped.

This paper maps the ACSE protection model across six waves of coverage — from production IT infrastructure available today, through HCI and storage fabrics, cloud-native and container orchestration, OT/ICS/SCADA, telecom and 5G core, to national critical infrastructure. For every surface in every wave it identifies the appropriate mutation profile, the specific patent claim enforced, and the exact attacker capability defeated.

Patent & Classification

Indian Patent Published · IN202641070690 · 19/06/2026 · Inventor: Arul Raj · Classification: Strategic Vision & Surface Mapping — Post-Patent Filing

The Core Claim of This Paper

The Kali Invariant is surface-agnostic. F(S, t+1) is cryptographically independent of F(S, t) regardless of what S is — a session token, a management API credential, a storage controller fingerprint, a SCADA HMI identifier, or a 5G network function endpoint. One mathematical property. Six waves. Every surface.

1. The Universal Surface Problem

Every cyberattack begins with reconnaissance. The attacker observes the target, builds a model of its surface, and stages an exploit against what they found. This cycle succeeds because the surface observed today is the surface that will still exist when the exploit fires — hours, days, or months later. This assumption holds in every environment without exception.

A Nutanix Prism Central API token is static by default. A Siemens S7 management password might not change in years. A 5G AMF service endpoint is registered in the NRF with a stable fingerprint by design. A national power grid SCADA controller has been running the same management credentials since deployment. Nobody designed these systems to rotate their observable identity continuously. That gap is universal, and it is the gap ACSE was built to close.

The Reconnaissance Cycle — Universal

Observe → Map → Model → Stage → Exploit. The cycle applies identically to a Kubernetes API server, a SCADA HMI, a FC fabric controller, and a national railway signalling system. Remove stability at stage one and every subsequent stage fails. ACSE removes it at stage one — on every surface.

2. The Six-Wave Framework

ACSE's coverage expands in six waves. The waves are not product lines — they are a single engine (the Polymorphic Mutation Engine) applied to progressively broader surface categories as connectors are added. The Kali Invariant at the centre is identical in every wave.

ACSEKaliCore · PMEWAVE 1IT INFRASTRUCTUREWeb · AD · Payments · Databases · COLO · TLSWAVE 2HCI & STORAGE FABRICSNutanix · Cisco UCS · Pure Storage · NetApp · FC SANWAVE 3CLOUD-NATIVE & CONTAINERSKubernetes · Istio · HashiCorp Vault · AWS · Azure · GCPWAVE 4OT / ICS / SCADASiemens S7 · Modbus · DNP3 · DCS · PI HistorianWAVE 5TELECOM & 5G5G AMF/SMF/UPF · SIP · SS7 · O-RANWAVE 6NATIONAL CRITICAL INFRAPower Grid · Railway · Aviation · Water · National PKI✔ LIVE IN v0.2.0ACSE Surface Protection — Six Waves of CoveragePatent IN202641070690 · Inventor: Arul RajOne Kali Invariant · One Patent · Every Surface
Figure 1: ACSE Surface Protection — Six Waves of Coverage. Wave 1 is live in v0.2.0. Waves 2–6 are on the roadmap. One engine. One invariant. Every surface.
WaveCoverageStatusKey Profiles
Wave 1IT Infrastructure — web, identity, payments, databases, COLO, transport✅ Live — v0.2.0AnglerShield · KrakenNet · NautilusVault · TorpedoRay · ElectricEelGrid · GlassFrog
Wave 2HCI & Storage Fabrics — Nutanix, Cisco UCS, VMware, Pure, NetApp, FC SAN🔵 Roadmap — v2KrakenNet · NautilusVault · LeviathanGrid · TorpedoRay
Wave 3Cloud-Native & Containers — Kubernetes, Istio, HashiCorp Vault, AWS/Azure/GCP🔵 Roadmap — v2ChameleonNet · NautilusVault · KrakenNet · TorpedoRay
Wave 4OT / ICS / SCADA — Siemens S7, Modbus, DNP3, DCS, PI Historian🔵 Roadmap — v3MantisNet · KrakenNet · NautilusVault · TorpedoRay · KaliCoreTarget
Wave 5Telecom & 5G — AMF, SMF, UPF, SIP, SS7, O-RAN, Diameter🔵 Roadmap — v3LeviathanGrid · KrakenNet · TorpedoRay · ChameleonNet
Wave 6National Critical Infrastructure — power grid, railway, aviation, water, national PKI🔵 StrategicKaliCoreTarget · LeviathanGrid · NautilusVault

3. Wave 1 — IT Infrastructure (Production-Ready)

Wave 1 is live in ACSE v0.2.0. The eleven domain profiles cover the full spectrum of enterprise IT surfaces, each tuned to its specific threat model and enforcing the Kali Invariant at sub-millisecond speeds.

SurfaceProfileLatency p50Crown Jewel
Web / API serversAnglerShield 0x0631.67µs4-lure deception + real endpoint hidden. Attacker self-identifies at 3-probe threshold.
Active Directory / IdentityKrakenNet 0x0528.56µsLSASS credentials stale in 28.56µs. AD lateral movement map permanently invalid.
Payment / transaction APIsSquidShield 0x0315.94µs100% fingerprint uniqueness at 76.1k tx/s. PCI-DSS audit trail per cycle.
Zero-trust gateways / mTLSChameleonNet 0x0423.15µsZero mutual information between attacker and ally channels.
Databases / data vaultsNautilusVault 0x0737.96µs5× Fibonacci protection gradient. O(1) siphuncle verify at 8.024µs.
Healthcare / HIPAA surfacesGlassFrog 0x0856.84µsPer-cycle HIPAA/GDPR cryptographic compliance proof. DPDP Act aligned.
COLO / data centre nodesElectricEelGrid 0x0958.33µsOnly product defending power side-channel in COLO. 0.03% correlation.
Elastic / auto-scaling infraJellyNet 0x0212.90µsMVS guarantee at all load levels. Calm→critical transition: 1.09µs.
IDS/IPS / intrusion responseMantisNet 0x0110.31µs107/107 Forced Twitch detections. Fastest profile in the stack.
TLS / TCP transport channelTorpedoRay 0x0BJA3/JA3S defeat per session. p0f defeat. Linkability L=0.181 — below random floor.
Nation-scale topologyLeviathanGrid 0x0A143.9µs16-node simultaneous rotation + full topology rewire. O(1) grand hash.
Maximum protectionKaliCoreTarget 0xFF<200µs estateAll profiles simultaneously. Estate-wide rotation in under 200 microseconds.

4. Wave 2 — HCI & Storage Fabrics

HCI management planes and storage fabric controllers carry catastrophic blast radii. A single set of Nutanix Prism Central credentials gives an attacker access to every VM in the cluster. A compromised Pure Storage FlashArray management token gives access to every volume. A Brocade FC fabric login gives access to every SAN zone. These surfaces have historically been completely static — no vendor has addressed this until now.

The Change Healthcare breach exposed 192.7 million patient records partly because storage-level credentials remained valid long enough for a 6TB exfiltration pipeline to be established. The Stryker-Handala wiper destroyed 200,000+ devices across 79 countries after gaining access to management consoles. ACSE would have expired both management surfaces before either attack could execute.

The HCI Management Plane Problem

A Nutanix Prism Central API token is the crown jewel of an HCI estate — access to every VM, every cluster, every storage pool. Under ACSE/KrakenNet, that token is cryptographically independent of what it was 28.56µs ago. The attacker's harvested credential is stale before they can act on it.

SurfacePlatform / APIProfileWhy this profile
Nutanix Prism CentralPrism REST API v3KrakenNet 0x05Credential surface — Prism token = access to every VM and storage pool
Cisco UCS ManagerUCS XML API / UCS Central RESTKrakenNet 0x05Service profile credentials — fabric interconnect east-west control
VMware vCenter / vSANvCenter REST APIKrakenNet 0x05VM management credential surface — vCenter = access to every VM
Azure Stack HCIAzure Arc REST APIChameleonNet 0x04Hybrid cooperative enclave boundary — Arc management surface
HPE SimpliVitySimpliVity REST APIKrakenNet 0x05OmniStack management credential surface
Dell VxRailVxRail REST APIKrakenNet 0x05Node management credential surface
Pure Storage FlashArrayPure REST API v2NautilusVault 0x07Storage management surface — array token = access to every volume
NetApp ONTAPONTAP REST API / ZAPINautilusVault 0x07SVM management — LIF identifiers and volume surface
Dell EMC PowerStorePowerStore REST APINautilusVault 0x07Array management — volume and host identifier surface
IBM FlashSystem / SpectrumIBM Storage REST APINautilusVault 0x07Array management surface at rest
HPE Nimble / AlletraNimble REST APINautilusVault 0x07Array management and volume surface
Ceph clusterCeph REST API / mgrKaliCoreTarget 0xFFMaximum protection — OSD, pool, and management surfaces simultaneously
Brocade FC SAN fabricFOS REST APILeviathanGrid 0x0AFabric topology surface — zone set and WWPN rotation
Cisco MDS FC fabricNX-APILeviathanGrid 0x0AFC topology — VSAN and zone set identifiers
iSCSI infrastructureSNMP + vendor RESTTorpedoRay 0x0BTransport channel — IQN rotation and target portal fingerprint

5. Wave 3 — Cloud-Native & Container Orchestration

Container orchestration surfaces are uniquely dangerous because they are designed for automation at scale — which means a compromised Kubernetes API server can redeploy every workload, exfiltrate every secret, and establish persistent backdoors across every namespace in a single API call. Cloud provider management planes (AWS IAM, Azure Entra, GCP IAM) carry the same risk at hyperscaler scale. The SolarWinds attack demonstrated that management plane access at this level produces dwell times measured in months — because the surface never changes.

SurfaceTechnologyProfileWhy this profile
Kubernetes API serverk8s REST + RBACChameleonNet 0x04Control plane boundary — cooperative enclave between workloads and orchestrator
Docker / containerd daemonDocker REST APITorpedoRay 0x0BTransport channel — daemon socket fingerprint rotation
HashiCorp VaultVault HTTP APINautilusVault 0x07Secrets management surface — vault token = access to every secret
Istio / Envoy service meshxDS API + mTLSChameleonNet 0x04mTLS cooperative enclave boundary — zero mutual information across service channels
ArgoCD / Flux GitOpsREST APIKrakenNet 0x05GitOps credential surface — CD token = access to every deployment
AWS IAM / management planeAWS API + SigV4KrakenNet 0x05Credential surface — access key blast radius across entire AWS account
Azure Entra / management planeAzure ARM RESTKrakenNet 0x05Credential surface — service principal = access to Azure estate
GCP IAM / management planeGCP REST APIKrakenNet 0x05Credential surface — service account key = access to GCP resources
AWS Greengrass / IoT EdgeGreengrass IPCTorpedoRay 0x0BEdge transport channel — MQTT and certificate fingerprint rotation

6. Wave 4 — OT / ICS / SCADA

Operational Technology is the most underprotected surface category on earth. The air-gap assumption was demolished by Stuxnet in 2010. The Ukraine power grid attacks in 2015 and 2016 demonstrated that OT surfaces are actively targeted by nation-state actors. What makes OT uniquely dangerous for ACSE purposes: OT management credentials are often the most static surfaces in any organisation. A Siemens S7 management password might not change in years. A SCADA HMI session token might persist indefinitely.

The OT Dwell Time Problem

In IT environments, dwell times are measured in weeks. In OT environments, they are measured in months and years. The Triton/TRISIS attack on a petrochemical facility had a dwell time of over a year before discovery. Under ACSE/MantisNet, the surface mapped at day 1 of intrusion is cryptographically invalid at day 2. The attacker's model never converges — regardless of how long they wait.

SurfacePlatform / ProtocolProfileWhy this profile
Siemens S7 PLCs / TIA PortalSnap7 API / S7commMantisNet 0x01Intrusion response — strike-and-retreat. 107/107 Forced Twitch detections.
Rockwell Allen-BradleyEtherNet/IP + CIPMantisNet 0x01Intrusion response — PLC management surface rotation
Schneider Electric EcoStruxureEcoStruxure REST APIMantisNet 0x01Intrusion response — management API surface
GE / Emerson DCSProprietary APIKaliCoreTarget 0xFFMaximum protection — DCS = entire plant control surface
OSIsoft PI / AVEVA HistorianPI Web APINautilusVault 0x07Process data surface at rest — historian = entire plant history
SCADA HMI (WinCC, FactoryTalk)OPC-UA + RESTKrakenNet 0x05Credential surface — HMI operator session token rotation
OPC-UA serversOPC-UA TCPTorpedoRay 0x0BTransport channel — OPC-UA session fingerprint rotation
Modbus/TCP surfacesModbus/TCPTorpedoRay 0x0BTransport channel — TCP fingerprint rotation at protocol boundary
DNP3 surfacesDNP3 over TCPTorpedoRay 0x0BTransport channel — DNP3 session fingerprint rotation
IEC 61850 MMS / GOOSETCP / UDP multicastLeviathanGrid 0x0ATopology surface — substation logical node identifier rotation
MQTT broker surfacesMQTT + TLSTorpedoRay 0x0BTransport channel — client ID and certificate fingerprint rotation

7. Wave 5 — Telecom & 5G

5G core network functions communicate over HTTP/2 Service-Based Interfaces (SBI). Every network function — AMF, SMF, UPF, NRF — exposes a REST API with a stable, fingerprinted identity registered in the Network Repository Function. The 5G SBI was designed for interoperability, which means it was designed to be observable. An attacker who maps the 5G core surface can interfere with access management, session handling, and user plane functions for millions of subscribers.

Legacy telecom surfaces (SS7, Diameter) are even more static. SS7 vulnerabilities have been publicly known since 2014 and remain exploitable today. The surface that enables location tracking, call interception, and SMS hijacking has never been rotated — by design or by practice. ACSE changes that.

SurfaceProtocol / InterfaceProfileWhy this profile
5G AMF (Access & Mobility Mgmt)HTTP/2 SBI + N1/N2LeviathanGrid 0x0ANation-scale topology — AMF serves millions of subscribers simultaneously
5G SMF (Session Management)HTTP/2 SBI + N4KrakenNet 0x05Session credential surface — SMF token = session control for entire PDU pool
5G UPF (User Plane Function)GTP-U / N3/N9TorpedoRay 0x0BTransport channel — GTP-U tunnel fingerprint and TEID rotation
5G NRF (Network Repository)HTTP/2 SBINautilusVault 0x07Service registry — NRF profile = discovery of entire core topology
5G PCF (Policy Control)HTTP/2 SBI + N7KrakenNet 0x05Policy credential surface — PCF token = policy for all subscriber sessions
SIP trunk surfacesSIP / TLSTorpedoRay 0x0BTransport channel — SIP dialog fingerprint and Via header rotation
SS7 signaling surfacesSS7 / SIGTRAN / M3UALeviathanGrid 0x0ATopology surface — SS7 point codes and SSN identifier rotation
Diameter protocol surfacesDiameter / TCP / SCTPTorpedoRay 0x0BTransport channel — Diameter session fingerprint rotation
O-RAN O1 / O2 / A1 interfacesHTTP/2 NETCONF/YANGChameleonNet 0x04Cooperative enclave — RAN controller to SMO boundary surface
RAN controller (gNB / CU-CP)F1-C / E1 / XnKrakenNet 0x05Control plane credential surface — gNB-DU identity rotation

8. Wave 6 — National Critical Infrastructure

National critical infrastructure represents the highest-value, highest-consequence attack surface category on earth. A successful attack on a national power grid can cause loss of life and economic damage measured in billions. A compromised national PKI invalidates the cryptographic trust chain for an entire country. These surfaces have historically received the least cybersecurity investment because they are the most difficult to reach — but nation-state adversaries have demonstrated repeatedly that reach is not the obstacle it once was.

ACSE is uniquely qualified for national critical infrastructure for three reasons: the Kali Invariant is mathematical and cannot be misconfigured out of effectiveness; the Control Plane runs fully air-gapped with no internet dependency; and TEE attestation provides hardware-rooted trust that no software vulnerability can subvert.

For DRDO, CERT-In, and Defence Evaluators

ACSE can be deployed entirely on-premise with zero external dependencies. The Control Plane, PME agents, and the full SHA3-256 audit chain operate within a closed network. KaliCoreTarget (0xFF) fires all 11 profiles simultaneously across a national estate in under 200 microseconds — faster than any attacker can act on reconnaissance gathered the previous cycle.

SurfaceSectorProfileWhy this profile
Power grid SCADA (IEC 61850 substations)EnergyKaliCoreTarget 0xFFMaximum protection — substation control = grid stability for millions
Power grid EMS / DMSEnergyLeviathanGrid 0x0ANation-scale topology — EMS coordinates entire grid topology
Water treatment SCADAWaterKaliCoreTarget 0xFFMaximum protection — treatment plant control = public health
Water distribution SCADAWaterMantisNet 0x01Intrusion response — distribution control with strike-and-retreat
Railway signalling (ETCS / ERTMS)RailLeviathanGrid 0x0ATopology surface — signalling controller = movement authority for entire network
Railway interlocking systemsRailMantisNet 0x01Intrusion response — interlocking = collision prevention surface
Aviation ground systems (SWIM / ACARS)AviationLeviathanGrid 0x0ATopology surface — ground coordination network identifier rotation
ATC radar / surveillance systemsAviationKaliCoreTarget 0xFFMaximum protection — ATC surface = air safety
Port / maritime managementMaritimeKaliCoreTarget 0xFFMaximum protection — port management = national supply chain
National PKI / Root CAGovernmentNautilusVault 0x07Root of trust surface — CA key = cryptographic trust for entire country
Government identity systemsGovernmentKrakenNet 0x05 + KaliCoreTarget 0xFFCredential surface + maximum protection
Defence command and control (C2)DefenceKaliCoreTarget 0xFFMaximum protection — C2 surface = national operational capability

9. Linux & Agentless Environments

Many environments — cloud-native shops, startups, mixed estates, and OT floors — operate without Active Directory. Linux servers, containerised workloads, and cloud VMs have no domain controller. The ACSE discovery layer addresses this directly with multiple discovery methods, each producing the same result: the asset enters the catalog, receives a profile suggestion, awaits admin approval, and comes under the Kali Invariant.

Discovery MethodBest ForRequired Configuration
Agent self-registrationAny Linux/Windows server — the agent registers itself into the discovery catalog on its first push. Zero scanning, zero credentials, zero network configuration required.Install acse-pme-agent · set ACSE_CP_URL and ACSE_API_KEY
SSH-based discoveryLinux fleets without AD — the Control Plane SSHes into a target range using a service account key, retrieves hostname/OS/IP, and creates catalog entries automatically.Service account SSH key · IP range or host list in discovery source config
Cloud provider APIsAWS EC2, Azure VMs, GCP Compute — returns full Linux VM inventory with OS type, tags, and network metadata. Richest source for cloud-native environments.Read-only cloud API credentials in discovery source config
Active ICMP + TCP probeAny reachable network range — ping sweep and port scan (22, 443, 80, 161, 102) classifies live hosts by service fingerprint without credentials.CIDR range in discovery source config
DNS zone transferEnvironments where the DNS admin permits AXFR — pulls all A records, then probes each. Works without agent access.DNS server address + zone name in discovery source config
CSV importAny environment — upload a CSV of hostname, IP, device type, and OS. The simplest path for initial pilots and air-gapped estates.CSV file with headers: hostname, ip, device_type, os

10. Universal Profile Selection Guide

10.1 Decision Framework

Profile Selection — In Order of Priority

1. Maximum protection required (C2, root CA, power grid, aviation ATC)? → KaliCoreTarget 0xFF
2. Nation-scale or topology coordination surface (grid EMS, SS7, FC fabric, railway signalling)? → LeviathanGrid 0x0A
3. Credential or identity surface (AD, cloud IAM, HCI management plane, SCADA HMI, 5G SMF)? → KrakenNet 0x05
4. Data or storage surface at rest (database, storage array, secrets vault, historian, NRF)? → NautilusVault 0x07
5. Transport or protocol surface (TLS, TCP, SIP, Modbus, iSCSI, GTP-U)? → TorpedoRay 0x0B
6. Cooperative enclave or mTLS boundary (Kubernetes, service mesh, zero-trust gateway, O-RAN)? → ChameleonNet 0x04
7. Public-facing API or deception target? → AnglerShield 0x06
8. OT intrusion response surface (PLC, DCS, ICS)? → MantisNet 0x01
9. Compliance-regulated surface (HIPAA, GDPR, DPDP)? → GlassFrog 0x08
10. Elastic or auto-scaling infrastructure? → JellyNet 0x02
11. COLO / data centre power surface? → ElectricEelGrid 0x09

10.2 Master Surface-to-Profile Table

SurfaceWaveProfileHexPatent Claim
Web / API server1AnglerShield0x06A — surface fingerprint independence
Active Directory / Identity1KrakenNet0x05A — credential surface independence
Payment / transaction API1SquidShield0x03A — transaction metadata independence
Zero-trust gateway / mTLS1ChameleonNet0x04A — cooperative channel independence
Database / data vault1NautilusVault0x07A — data surface independence
Healthcare / HIPAA / DPDP1GlassFrog0x08A + compliance proof per cycle
COLO / data centre node1ElectricEelGrid0x09A — power side-channel independence
Elastic / auto-scaling infra1JellyNet0x02A — elastic surface independence
IDS / IPS / intrusion response1MantisNet0x01A — intrusion response surface
TLS / TCP transport channel1TorpedoRay0x0BA + B (JA3 defeat) + C (session token) + D (Torpedo)
Nation-scale topology1LeviathanGrid0x0AA — topology surface independence
Nutanix Prism Central2KrakenNet0x05A — HCI credential surface independence
Cisco UCS Manager2KrakenNet0x05A — fabric interconnect credential surface
VMware vCenter / vSAN2KrakenNet0x05A — VM management credential surface
Pure Storage FlashArray2NautilusVault0x07A — storage management surface independence
NetApp ONTAP2NautilusVault0x07A — SVM/LIF surface independence
Dell EMC PowerStore / IBM FlashSystem2NautilusVault0x07A — array management surface independence
Brocade / Cisco MDS FC fabric2LeviathanGrid0x0AA — fabric topology surface independence
iSCSI infrastructure2TorpedoRay0x0BA + B + C — IQN and transport surface
Ceph cluster2KaliCoreTarget0xFFA — all management surfaces simultaneously
Kubernetes API server3ChameleonNet0x04A — control plane enclave boundary
HashiCorp Vault3NautilusVault0x07A — secrets surface independence
AWS / Azure / GCP IAM plane3KrakenNet0x05A — cloud credential surface independence
Istio / Envoy service mesh3ChameleonNet0x04A — mTLS cooperative enclave boundary
Siemens S7 / Allen-Bradley PLC4MantisNet0x01A — OT intrusion response surface
SCADA HMI (WinCC, FactoryTalk)4KrakenNet0x05A — OT operator credential surface
OSIsoft PI / AVEVA Historian4NautilusVault0x07A — process data surface independence
Modbus/TCP / DNP3 / OPC-UA4TorpedoRay0x0BA + C — OT transport channel surface
IEC 61850 MMS / GOOSE4LeviathanGrid0x0AA — substation topology surface
GE / Emerson DCS4KaliCoreTarget0xFFA — entire plant control surface
5G AMF5LeviathanGrid0x0AA — 5G access and mobility topology surface
5G SMF / PCF5KrakenNet0x05A — 5G session credential surface
5G UPF / GTP-U5TorpedoRay0x0BA + B + C — user plane transport surface
5G NRF5NautilusVault0x07A — service registry surface independence
SS7 / Diameter signaling5LeviathanGrid0x0AA — telecom topology surface
O-RAN interfaces5ChameleonNet0x04A — RAN cooperative enclave boundary
Power grid SCADA (IEC 61850)6KaliCoreTarget0xFFA — national energy surface, all profiles
Railway signalling (ETCS)6LeviathanGrid0x0AA — national rail topology surface
National PKI / Root CA6NautilusVault0x07A — root of trust surface independence
Government identity / Defence C26KaliCoreTarget0xFFA — national credential surface, all profiles

11. Patent Coverage Across All Surfaces

Patent Application IN202641070690 covers a single mathematical property — the Kali Invariant — and four specific claims derived from it. None of these claims are surface-specific. They apply to any observable surface S at any time t, in any wave, on any protocol.

Claim A — Surface Fingerprint Independence: For every protected surface S and every access event at time t, the observable fingerprint F(S, t+1) is cryptographically independent of F(S, t). The Hamming distance between successive fingerprints averages 128 bits. This claim covers every surface in every wave without amendment.

Claim B — Transport Channel Fingerprint Defeat: The observable transport channel fingerprint (JA3/JA3S, p0f, cipher suite order) changes on every session such that passive fingerprinting cannot link successive sessions. Applies to TorpedoRay surfaces in any wave — from iSCSI in Wave 2 to GTP-U in Wave 5 to any TCP/TLS surface in any wave.

Claim C — Session Token Independence: Session tokens, credentials, and access identifiers are rotated such that a valid token at time t is invalid at t+1. Applies across all profiles — AD credentials (Wave 1), HCI management tokens (Wave 2), cloud IAM keys (Wave 3), SCADA operator sessions (Wave 4), 5G SMF session identifiers (Wave 5), and government access tokens (Wave 6).

Claim D — Torpedo Mechanism: When the EWMA anomaly score reaches 0.70, a disruptive full-surface rotation executes without terminating the legitimate session. Applies to any surface running TorpedoRay or KaliCoreTarget — from a payment API to a 5G UPF to a national power grid SCADA controller.

One Patent. Six Waves. Every Surface.

No amendment to the patent is required to extend coverage to any new surface category. The Kali Invariant is already claimed at the mathematical level. Adding a Wave 4 OT connector or a Wave 5 5G adapter is a new application of the existing patented property — not a new invention. The breadth of protection established by IN202641070690 covers every surface described in this paper.

12. Conclusion

The surface explosion is accelerating. Every new cloud-native deployment adds Kubernetes API surfaces. Every HCI deployment adds management planes with catastrophic blast radii. Every OT modernisation adds SCADA surfaces that have been static for decades. Every 5G rollout adds SBI surfaces that are observable by design. Every critical infrastructure programme adds national-consequence surfaces that have historically received the least cybersecurity investment.

ACSE is the only architecture designed from first principles to address this at every layer. The Kali Invariant does not care what the surface is. F(S, t+1) is cryptographically independent of F(S, t) whether S is a payment API, a Nutanix cluster, a Siemens PLC, a 5G AMF, or a national power grid SCADA controller.

Six waves. One invariant. One patent. Every surface protected.

Further Reading

WP-00: Master Technical Whitepaper — full ACSE stack reference · WP-02: PME Engineering — the 3-line integration API · WP-04: The Dasa Mahavidya Profiles — all 11 profiles in depth · WP-09: The ACSE Control Plane — management layer and Auto-Discovery

Patent Status

Application No. IN202641070690 · Indian Patent Office · Inventor: Arul Raj · Published 19/06/2026 · Journal No. 25/2026 · Expedited examination (Form 18A) · Early publication (Form 9) · Publicly searchable on the Indian Patent Office portal.

Part of the ACSE Research Series:

Master Whitepaper ← All Papers