Abstract
The attack surface has exploded. Every device, every protocol, every management plane an organisation operates is observable, fingerprinted, and exploitable if it stays static long enough. The reconnaissance cycle — Observe, Map, Model, Stage, Exploit — applies identically whether the target is a web server, a Nutanix Prism Central management plane, a Siemens S7 PLC, a 5G Access and Mobility Management Function, or a national power grid SCADA controller. The vulnerability is universal: the surface is static, and static surfaces can be mapped.
This paper maps the ACSE protection model across six waves of coverage — from production IT infrastructure available today, through HCI and storage fabrics, cloud-native and container orchestration, OT/ICS/SCADA, telecom and 5G core, to national critical infrastructure. For every surface in every wave it identifies the appropriate mutation profile, the specific patent claim enforced, and the exact attacker capability defeated.
Indian Patent Published · IN202641070690 · 19/06/2026 · Inventor: Arul Raj · Classification: Strategic Vision & Surface Mapping — Post-Patent Filing
The Kali Invariant is surface-agnostic. F(S, t+1) is cryptographically independent of F(S, t) regardless of what S is — a session token, a management API credential, a storage controller fingerprint, a SCADA HMI identifier, or a 5G network function endpoint. One mathematical property. Six waves. Every surface.
1. The Universal Surface Problem
Every cyberattack begins with reconnaissance. The attacker observes the target, builds a model of its surface, and stages an exploit against what they found. This cycle succeeds because the surface observed today is the surface that will still exist when the exploit fires — hours, days, or months later. This assumption holds in every environment without exception.
A Nutanix Prism Central API token is static by default. A Siemens S7 management password might not change in years. A 5G AMF service endpoint is registered in the NRF with a stable fingerprint by design. A national power grid SCADA controller has been running the same management credentials since deployment. Nobody designed these systems to rotate their observable identity continuously. That gap is universal, and it is the gap ACSE was built to close.
Observe → Map → Model → Stage → Exploit. The cycle applies identically to a Kubernetes API server, a SCADA HMI, a FC fabric controller, and a national railway signalling system. Remove stability at stage one and every subsequent stage fails. ACSE removes it at stage one — on every surface.
2. The Six-Wave Framework
ACSE's coverage expands in six waves. The waves are not product lines — they are a single engine (the Polymorphic Mutation Engine) applied to progressively broader surface categories as connectors are added. The Kali Invariant at the centre is identical in every wave.
| Wave | Coverage | Status | Key Profiles |
|---|---|---|---|
| Wave 1 | IT Infrastructure — web, identity, payments, databases, COLO, transport | ✅ Live — v0.2.0 | AnglerShield · KrakenNet · NautilusVault · TorpedoRay · ElectricEelGrid · GlassFrog |
| Wave 2 | HCI & Storage Fabrics — Nutanix, Cisco UCS, VMware, Pure, NetApp, FC SAN | 🔵 Roadmap — v2 | KrakenNet · NautilusVault · LeviathanGrid · TorpedoRay |
| Wave 3 | Cloud-Native & Containers — Kubernetes, Istio, HashiCorp Vault, AWS/Azure/GCP | 🔵 Roadmap — v2 | ChameleonNet · NautilusVault · KrakenNet · TorpedoRay |
| Wave 4 | OT / ICS / SCADA — Siemens S7, Modbus, DNP3, DCS, PI Historian | 🔵 Roadmap — v3 | MantisNet · KrakenNet · NautilusVault · TorpedoRay · KaliCoreTarget |
| Wave 5 | Telecom & 5G — AMF, SMF, UPF, SIP, SS7, O-RAN, Diameter | 🔵 Roadmap — v3 | LeviathanGrid · KrakenNet · TorpedoRay · ChameleonNet |
| Wave 6 | National Critical Infrastructure — power grid, railway, aviation, water, national PKI | 🔵 Strategic | KaliCoreTarget · LeviathanGrid · NautilusVault |
3. Wave 1 — IT Infrastructure (Production-Ready)
Wave 1 is live in ACSE v0.2.0. The eleven domain profiles cover the full spectrum of enterprise IT surfaces, each tuned to its specific threat model and enforcing the Kali Invariant at sub-millisecond speeds.
| Surface | Profile | Latency p50 | Crown Jewel |
|---|---|---|---|
| Web / API servers | AnglerShield 0x06 | 31.67µs | 4-lure deception + real endpoint hidden. Attacker self-identifies at 3-probe threshold. |
| Active Directory / Identity | KrakenNet 0x05 | 28.56µs | LSASS credentials stale in 28.56µs. AD lateral movement map permanently invalid. |
| Payment / transaction APIs | SquidShield 0x03 | 15.94µs | 100% fingerprint uniqueness at 76.1k tx/s. PCI-DSS audit trail per cycle. |
| Zero-trust gateways / mTLS | ChameleonNet 0x04 | 23.15µs | Zero mutual information between attacker and ally channels. |
| Databases / data vaults | NautilusVault 0x07 | 37.96µs | 5× Fibonacci protection gradient. O(1) siphuncle verify at 8.024µs. |
| Healthcare / HIPAA surfaces | GlassFrog 0x08 | 56.84µs | Per-cycle HIPAA/GDPR cryptographic compliance proof. DPDP Act aligned. |
| COLO / data centre nodes | ElectricEelGrid 0x09 | 58.33µs | Only product defending power side-channel in COLO. 0.03% correlation. |
| Elastic / auto-scaling infra | JellyNet 0x02 | 12.90µs | MVS guarantee at all load levels. Calm→critical transition: 1.09µs. |
| IDS/IPS / intrusion response | MantisNet 0x01 | 10.31µs | 107/107 Forced Twitch detections. Fastest profile in the stack. |
| TLS / TCP transport channel | TorpedoRay 0x0B | — | JA3/JA3S defeat per session. p0f defeat. Linkability L=0.181 — below random floor. |
| Nation-scale topology | LeviathanGrid 0x0A | 143.9µs | 16-node simultaneous rotation + full topology rewire. O(1) grand hash. |
| Maximum protection | KaliCoreTarget 0xFF | <200µs estate | All profiles simultaneously. Estate-wide rotation in under 200 microseconds. |
4. Wave 2 — HCI & Storage Fabrics
HCI management planes and storage fabric controllers carry catastrophic blast radii. A single set of Nutanix Prism Central credentials gives an attacker access to every VM in the cluster. A compromised Pure Storage FlashArray management token gives access to every volume. A Brocade FC fabric login gives access to every SAN zone. These surfaces have historically been completely static — no vendor has addressed this until now.
The Change Healthcare breach exposed 192.7 million patient records partly because storage-level credentials remained valid long enough for a 6TB exfiltration pipeline to be established. The Stryker-Handala wiper destroyed 200,000+ devices across 79 countries after gaining access to management consoles. ACSE would have expired both management surfaces before either attack could execute.
A Nutanix Prism Central API token is the crown jewel of an HCI estate — access to every VM, every cluster, every storage pool. Under ACSE/KrakenNet, that token is cryptographically independent of what it was 28.56µs ago. The attacker's harvested credential is stale before they can act on it.
| Surface | Platform / API | Profile | Why this profile |
|---|---|---|---|
| Nutanix Prism Central | Prism REST API v3 | KrakenNet 0x05 | Credential surface — Prism token = access to every VM and storage pool |
| Cisco UCS Manager | UCS XML API / UCS Central REST | KrakenNet 0x05 | Service profile credentials — fabric interconnect east-west control |
| VMware vCenter / vSAN | vCenter REST API | KrakenNet 0x05 | VM management credential surface — vCenter = access to every VM |
| Azure Stack HCI | Azure Arc REST API | ChameleonNet 0x04 | Hybrid cooperative enclave boundary — Arc management surface |
| HPE SimpliVity | SimpliVity REST API | KrakenNet 0x05 | OmniStack management credential surface |
| Dell VxRail | VxRail REST API | KrakenNet 0x05 | Node management credential surface |
| Pure Storage FlashArray | Pure REST API v2 | NautilusVault 0x07 | Storage management surface — array token = access to every volume |
| NetApp ONTAP | ONTAP REST API / ZAPI | NautilusVault 0x07 | SVM management — LIF identifiers and volume surface |
| Dell EMC PowerStore | PowerStore REST API | NautilusVault 0x07 | Array management — volume and host identifier surface |
| IBM FlashSystem / Spectrum | IBM Storage REST API | NautilusVault 0x07 | Array management surface at rest |
| HPE Nimble / Alletra | Nimble REST API | NautilusVault 0x07 | Array management and volume surface |
| Ceph cluster | Ceph REST API / mgr | KaliCoreTarget 0xFF | Maximum protection — OSD, pool, and management surfaces simultaneously |
| Brocade FC SAN fabric | FOS REST API | LeviathanGrid 0x0A | Fabric topology surface — zone set and WWPN rotation |
| Cisco MDS FC fabric | NX-API | LeviathanGrid 0x0A | FC topology — VSAN and zone set identifiers |
| iSCSI infrastructure | SNMP + vendor REST | TorpedoRay 0x0B | Transport channel — IQN rotation and target portal fingerprint |
5. Wave 3 — Cloud-Native & Container Orchestration
Container orchestration surfaces are uniquely dangerous because they are designed for automation at scale — which means a compromised Kubernetes API server can redeploy every workload, exfiltrate every secret, and establish persistent backdoors across every namespace in a single API call. Cloud provider management planes (AWS IAM, Azure Entra, GCP IAM) carry the same risk at hyperscaler scale. The SolarWinds attack demonstrated that management plane access at this level produces dwell times measured in months — because the surface never changes.
| Surface | Technology | Profile | Why this profile |
|---|---|---|---|
| Kubernetes API server | k8s REST + RBAC | ChameleonNet 0x04 | Control plane boundary — cooperative enclave between workloads and orchestrator |
| Docker / containerd daemon | Docker REST API | TorpedoRay 0x0B | Transport channel — daemon socket fingerprint rotation |
| HashiCorp Vault | Vault HTTP API | NautilusVault 0x07 | Secrets management surface — vault token = access to every secret |
| Istio / Envoy service mesh | xDS API + mTLS | ChameleonNet 0x04 | mTLS cooperative enclave boundary — zero mutual information across service channels |
| ArgoCD / Flux GitOps | REST API | KrakenNet 0x05 | GitOps credential surface — CD token = access to every deployment |
| AWS IAM / management plane | AWS API + SigV4 | KrakenNet 0x05 | Credential surface — access key blast radius across entire AWS account |
| Azure Entra / management plane | Azure ARM REST | KrakenNet 0x05 | Credential surface — service principal = access to Azure estate |
| GCP IAM / management plane | GCP REST API | KrakenNet 0x05 | Credential surface — service account key = access to GCP resources |
| AWS Greengrass / IoT Edge | Greengrass IPC | TorpedoRay 0x0B | Edge transport channel — MQTT and certificate fingerprint rotation |
6. Wave 4 — OT / ICS / SCADA
Operational Technology is the most underprotected surface category on earth. The air-gap assumption was demolished by Stuxnet in 2010. The Ukraine power grid attacks in 2015 and 2016 demonstrated that OT surfaces are actively targeted by nation-state actors. What makes OT uniquely dangerous for ACSE purposes: OT management credentials are often the most static surfaces in any organisation. A Siemens S7 management password might not change in years. A SCADA HMI session token might persist indefinitely.
In IT environments, dwell times are measured in weeks. In OT environments, they are measured in months and years. The Triton/TRISIS attack on a petrochemical facility had a dwell time of over a year before discovery. Under ACSE/MantisNet, the surface mapped at day 1 of intrusion is cryptographically invalid at day 2. The attacker's model never converges — regardless of how long they wait.
| Surface | Platform / Protocol | Profile | Why this profile |
|---|---|---|---|
| Siemens S7 PLCs / TIA Portal | Snap7 API / S7comm | MantisNet 0x01 | Intrusion response — strike-and-retreat. 107/107 Forced Twitch detections. |
| Rockwell Allen-Bradley | EtherNet/IP + CIP | MantisNet 0x01 | Intrusion response — PLC management surface rotation |
| Schneider Electric EcoStruxure | EcoStruxure REST API | MantisNet 0x01 | Intrusion response — management API surface |
| GE / Emerson DCS | Proprietary API | KaliCoreTarget 0xFF | Maximum protection — DCS = entire plant control surface |
| OSIsoft PI / AVEVA Historian | PI Web API | NautilusVault 0x07 | Process data surface at rest — historian = entire plant history |
| SCADA HMI (WinCC, FactoryTalk) | OPC-UA + REST | KrakenNet 0x05 | Credential surface — HMI operator session token rotation |
| OPC-UA servers | OPC-UA TCP | TorpedoRay 0x0B | Transport channel — OPC-UA session fingerprint rotation |
| Modbus/TCP surfaces | Modbus/TCP | TorpedoRay 0x0B | Transport channel — TCP fingerprint rotation at protocol boundary |
| DNP3 surfaces | DNP3 over TCP | TorpedoRay 0x0B | Transport channel — DNP3 session fingerprint rotation |
| IEC 61850 MMS / GOOSE | TCP / UDP multicast | LeviathanGrid 0x0A | Topology surface — substation logical node identifier rotation |
| MQTT broker surfaces | MQTT + TLS | TorpedoRay 0x0B | Transport channel — client ID and certificate fingerprint rotation |
7. Wave 5 — Telecom & 5G
5G core network functions communicate over HTTP/2 Service-Based Interfaces (SBI). Every network function — AMF, SMF, UPF, NRF — exposes a REST API with a stable, fingerprinted identity registered in the Network Repository Function. The 5G SBI was designed for interoperability, which means it was designed to be observable. An attacker who maps the 5G core surface can interfere with access management, session handling, and user plane functions for millions of subscribers.
Legacy telecom surfaces (SS7, Diameter) are even more static. SS7 vulnerabilities have been publicly known since 2014 and remain exploitable today. The surface that enables location tracking, call interception, and SMS hijacking has never been rotated — by design or by practice. ACSE changes that.
| Surface | Protocol / Interface | Profile | Why this profile |
|---|---|---|---|
| 5G AMF (Access & Mobility Mgmt) | HTTP/2 SBI + N1/N2 | LeviathanGrid 0x0A | Nation-scale topology — AMF serves millions of subscribers simultaneously |
| 5G SMF (Session Management) | HTTP/2 SBI + N4 | KrakenNet 0x05 | Session credential surface — SMF token = session control for entire PDU pool |
| 5G UPF (User Plane Function) | GTP-U / N3/N9 | TorpedoRay 0x0B | Transport channel — GTP-U tunnel fingerprint and TEID rotation |
| 5G NRF (Network Repository) | HTTP/2 SBI | NautilusVault 0x07 | Service registry — NRF profile = discovery of entire core topology |
| 5G PCF (Policy Control) | HTTP/2 SBI + N7 | KrakenNet 0x05 | Policy credential surface — PCF token = policy for all subscriber sessions |
| SIP trunk surfaces | SIP / TLS | TorpedoRay 0x0B | Transport channel — SIP dialog fingerprint and Via header rotation |
| SS7 signaling surfaces | SS7 / SIGTRAN / M3UA | LeviathanGrid 0x0A | Topology surface — SS7 point codes and SSN identifier rotation |
| Diameter protocol surfaces | Diameter / TCP / SCTP | TorpedoRay 0x0B | Transport channel — Diameter session fingerprint rotation |
| O-RAN O1 / O2 / A1 interfaces | HTTP/2 NETCONF/YANG | ChameleonNet 0x04 | Cooperative enclave — RAN controller to SMO boundary surface |
| RAN controller (gNB / CU-CP) | F1-C / E1 / Xn | KrakenNet 0x05 | Control plane credential surface — gNB-DU identity rotation |
8. Wave 6 — National Critical Infrastructure
National critical infrastructure represents the highest-value, highest-consequence attack surface category on earth. A successful attack on a national power grid can cause loss of life and economic damage measured in billions. A compromised national PKI invalidates the cryptographic trust chain for an entire country. These surfaces have historically received the least cybersecurity investment because they are the most difficult to reach — but nation-state adversaries have demonstrated repeatedly that reach is not the obstacle it once was.
ACSE is uniquely qualified for national critical infrastructure for three reasons: the Kali Invariant is mathematical and cannot be misconfigured out of effectiveness; the Control Plane runs fully air-gapped with no internet dependency; and TEE attestation provides hardware-rooted trust that no software vulnerability can subvert.
ACSE can be deployed entirely on-premise with zero external dependencies. The Control Plane, PME agents, and the full SHA3-256 audit chain operate within a closed network. KaliCoreTarget (0xFF) fires all 11 profiles simultaneously across a national estate in under 200 microseconds — faster than any attacker can act on reconnaissance gathered the previous cycle.
| Surface | Sector | Profile | Why this profile |
|---|---|---|---|
| Power grid SCADA (IEC 61850 substations) | Energy | KaliCoreTarget 0xFF | Maximum protection — substation control = grid stability for millions |
| Power grid EMS / DMS | Energy | LeviathanGrid 0x0A | Nation-scale topology — EMS coordinates entire grid topology |
| Water treatment SCADA | Water | KaliCoreTarget 0xFF | Maximum protection — treatment plant control = public health |
| Water distribution SCADA | Water | MantisNet 0x01 | Intrusion response — distribution control with strike-and-retreat |
| Railway signalling (ETCS / ERTMS) | Rail | LeviathanGrid 0x0A | Topology surface — signalling controller = movement authority for entire network |
| Railway interlocking systems | Rail | MantisNet 0x01 | Intrusion response — interlocking = collision prevention surface |
| Aviation ground systems (SWIM / ACARS) | Aviation | LeviathanGrid 0x0A | Topology surface — ground coordination network identifier rotation |
| ATC radar / surveillance systems | Aviation | KaliCoreTarget 0xFF | Maximum protection — ATC surface = air safety |
| Port / maritime management | Maritime | KaliCoreTarget 0xFF | Maximum protection — port management = national supply chain |
| National PKI / Root CA | Government | NautilusVault 0x07 | Root of trust surface — CA key = cryptographic trust for entire country |
| Government identity systems | Government | KrakenNet 0x05 + KaliCoreTarget 0xFF | Credential surface + maximum protection |
| Defence command and control (C2) | Defence | KaliCoreTarget 0xFF | Maximum protection — C2 surface = national operational capability |
9. Linux & Agentless Environments
Many environments — cloud-native shops, startups, mixed estates, and OT floors — operate without Active Directory. Linux servers, containerised workloads, and cloud VMs have no domain controller. The ACSE discovery layer addresses this directly with multiple discovery methods, each producing the same result: the asset enters the catalog, receives a profile suggestion, awaits admin approval, and comes under the Kali Invariant.
| Discovery Method | Best For | Required Configuration |
|---|---|---|
| Agent self-registration | Any Linux/Windows server — the agent registers itself into the discovery catalog on its first push. Zero scanning, zero credentials, zero network configuration required. | Install acse-pme-agent · set ACSE_CP_URL and ACSE_API_KEY |
| SSH-based discovery | Linux fleets without AD — the Control Plane SSHes into a target range using a service account key, retrieves hostname/OS/IP, and creates catalog entries automatically. | Service account SSH key · IP range or host list in discovery source config |
| Cloud provider APIs | AWS EC2, Azure VMs, GCP Compute — returns full Linux VM inventory with OS type, tags, and network metadata. Richest source for cloud-native environments. | Read-only cloud API credentials in discovery source config |
| Active ICMP + TCP probe | Any reachable network range — ping sweep and port scan (22, 443, 80, 161, 102) classifies live hosts by service fingerprint without credentials. | CIDR range in discovery source config |
| DNS zone transfer | Environments where the DNS admin permits AXFR — pulls all A records, then probes each. Works without agent access. | DNS server address + zone name in discovery source config |
| CSV import | Any environment — upload a CSV of hostname, IP, device type, and OS. The simplest path for initial pilots and air-gapped estates. | CSV file with headers: hostname, ip, device_type, os |
10. Universal Profile Selection Guide
10.1 Decision Framework
1. Maximum protection required (C2, root CA, power grid, aviation ATC)? → KaliCoreTarget 0xFF
2. Nation-scale or topology coordination surface (grid EMS, SS7, FC fabric, railway signalling)? → LeviathanGrid 0x0A
3. Credential or identity surface (AD, cloud IAM, HCI management plane, SCADA HMI, 5G SMF)? → KrakenNet 0x05
4. Data or storage surface at rest (database, storage array, secrets vault, historian, NRF)? → NautilusVault 0x07
5. Transport or protocol surface (TLS, TCP, SIP, Modbus, iSCSI, GTP-U)? → TorpedoRay 0x0B
6. Cooperative enclave or mTLS boundary (Kubernetes, service mesh, zero-trust gateway, O-RAN)? → ChameleonNet 0x04
7. Public-facing API or deception target? → AnglerShield 0x06
8. OT intrusion response surface (PLC, DCS, ICS)? → MantisNet 0x01
9. Compliance-regulated surface (HIPAA, GDPR, DPDP)? → GlassFrog 0x08
10. Elastic or auto-scaling infrastructure? → JellyNet 0x02
11. COLO / data centre power surface? → ElectricEelGrid 0x09
10.2 Master Surface-to-Profile Table
| Surface | Wave | Profile | Hex | Patent Claim |
|---|---|---|---|---|
| Web / API server | 1 | AnglerShield | 0x06 | A — surface fingerprint independence |
| Active Directory / Identity | 1 | KrakenNet | 0x05 | A — credential surface independence |
| Payment / transaction API | 1 | SquidShield | 0x03 | A — transaction metadata independence |
| Zero-trust gateway / mTLS | 1 | ChameleonNet | 0x04 | A — cooperative channel independence |
| Database / data vault | 1 | NautilusVault | 0x07 | A — data surface independence |
| Healthcare / HIPAA / DPDP | 1 | GlassFrog | 0x08 | A + compliance proof per cycle |
| COLO / data centre node | 1 | ElectricEelGrid | 0x09 | A — power side-channel independence |
| Elastic / auto-scaling infra | 1 | JellyNet | 0x02 | A — elastic surface independence |
| IDS / IPS / intrusion response | 1 | MantisNet | 0x01 | A — intrusion response surface |
| TLS / TCP transport channel | 1 | TorpedoRay | 0x0B | A + B (JA3 defeat) + C (session token) + D (Torpedo) |
| Nation-scale topology | 1 | LeviathanGrid | 0x0A | A — topology surface independence |
| Nutanix Prism Central | 2 | KrakenNet | 0x05 | A — HCI credential surface independence |
| Cisco UCS Manager | 2 | KrakenNet | 0x05 | A — fabric interconnect credential surface |
| VMware vCenter / vSAN | 2 | KrakenNet | 0x05 | A — VM management credential surface |
| Pure Storage FlashArray | 2 | NautilusVault | 0x07 | A — storage management surface independence |
| NetApp ONTAP | 2 | NautilusVault | 0x07 | A — SVM/LIF surface independence |
| Dell EMC PowerStore / IBM FlashSystem | 2 | NautilusVault | 0x07 | A — array management surface independence |
| Brocade / Cisco MDS FC fabric | 2 | LeviathanGrid | 0x0A | A — fabric topology surface independence |
| iSCSI infrastructure | 2 | TorpedoRay | 0x0B | A + B + C — IQN and transport surface |
| Ceph cluster | 2 | KaliCoreTarget | 0xFF | A — all management surfaces simultaneously |
| Kubernetes API server | 3 | ChameleonNet | 0x04 | A — control plane enclave boundary |
| HashiCorp Vault | 3 | NautilusVault | 0x07 | A — secrets surface independence |
| AWS / Azure / GCP IAM plane | 3 | KrakenNet | 0x05 | A — cloud credential surface independence |
| Istio / Envoy service mesh | 3 | ChameleonNet | 0x04 | A — mTLS cooperative enclave boundary |
| Siemens S7 / Allen-Bradley PLC | 4 | MantisNet | 0x01 | A — OT intrusion response surface |
| SCADA HMI (WinCC, FactoryTalk) | 4 | KrakenNet | 0x05 | A — OT operator credential surface |
| OSIsoft PI / AVEVA Historian | 4 | NautilusVault | 0x07 | A — process data surface independence |
| Modbus/TCP / DNP3 / OPC-UA | 4 | TorpedoRay | 0x0B | A + C — OT transport channel surface |
| IEC 61850 MMS / GOOSE | 4 | LeviathanGrid | 0x0A | A — substation topology surface |
| GE / Emerson DCS | 4 | KaliCoreTarget | 0xFF | A — entire plant control surface |
| 5G AMF | 5 | LeviathanGrid | 0x0A | A — 5G access and mobility topology surface |
| 5G SMF / PCF | 5 | KrakenNet | 0x05 | A — 5G session credential surface |
| 5G UPF / GTP-U | 5 | TorpedoRay | 0x0B | A + B + C — user plane transport surface |
| 5G NRF | 5 | NautilusVault | 0x07 | A — service registry surface independence |
| SS7 / Diameter signaling | 5 | LeviathanGrid | 0x0A | A — telecom topology surface |
| O-RAN interfaces | 5 | ChameleonNet | 0x04 | A — RAN cooperative enclave boundary |
| Power grid SCADA (IEC 61850) | 6 | KaliCoreTarget | 0xFF | A — national energy surface, all profiles |
| Railway signalling (ETCS) | 6 | LeviathanGrid | 0x0A | A — national rail topology surface |
| National PKI / Root CA | 6 | NautilusVault | 0x07 | A — root of trust surface independence |
| Government identity / Defence C2 | 6 | KaliCoreTarget | 0xFF | A — national credential surface, all profiles |
11. Patent Coverage Across All Surfaces
Patent Application IN202641070690 covers a single mathematical property — the Kali Invariant — and four specific claims derived from it. None of these claims are surface-specific. They apply to any observable surface S at any time t, in any wave, on any protocol.
Claim A — Surface Fingerprint Independence: For every protected surface S and every access event at time t, the observable fingerprint F(S, t+1) is cryptographically independent of F(S, t). The Hamming distance between successive fingerprints averages 128 bits. This claim covers every surface in every wave without amendment.
Claim B — Transport Channel Fingerprint Defeat: The observable transport channel fingerprint (JA3/JA3S, p0f, cipher suite order) changes on every session such that passive fingerprinting cannot link successive sessions. Applies to TorpedoRay surfaces in any wave — from iSCSI in Wave 2 to GTP-U in Wave 5 to any TCP/TLS surface in any wave.
Claim C — Session Token Independence: Session tokens, credentials, and access identifiers are rotated such that a valid token at time t is invalid at t+1. Applies across all profiles — AD credentials (Wave 1), HCI management tokens (Wave 2), cloud IAM keys (Wave 3), SCADA operator sessions (Wave 4), 5G SMF session identifiers (Wave 5), and government access tokens (Wave 6).
Claim D — Torpedo Mechanism: When the EWMA anomaly score reaches 0.70, a disruptive full-surface rotation executes without terminating the legitimate session. Applies to any surface running TorpedoRay or KaliCoreTarget — from a payment API to a 5G UPF to a national power grid SCADA controller.
No amendment to the patent is required to extend coverage to any new surface category. The Kali Invariant is already claimed at the mathematical level. Adding a Wave 4 OT connector or a Wave 5 5G adapter is a new application of the existing patented property — not a new invention. The breadth of protection established by IN202641070690 covers every surface described in this paper.
12. Conclusion
The surface explosion is accelerating. Every new cloud-native deployment adds Kubernetes API surfaces. Every HCI deployment adds management planes with catastrophic blast radii. Every OT modernisation adds SCADA surfaces that have been static for decades. Every 5G rollout adds SBI surfaces that are observable by design. Every critical infrastructure programme adds national-consequence surfaces that have historically received the least cybersecurity investment.
ACSE is the only architecture designed from first principles to address this at every layer. The Kali Invariant does not care what the surface is. F(S, t+1) is cryptographically independent of F(S, t) whether S is a payment API, a Nutanix cluster, a Siemens PLC, a 5G AMF, or a national power grid SCADA controller.
Six waves. One invariant. One patent. Every surface protected.
WP-00: Master Technical Whitepaper — full ACSE stack reference · WP-02: PME Engineering — the 3-line integration API · WP-04: The Dasa Mahavidya Profiles — all 11 profiles in depth · WP-09: The ACSE Control Plane — management layer and Auto-Discovery
Application No. IN202641070690 · Indian Patent Office · Inventor: Arul Raj · Published 19/06/2026 · Journal No. 25/2026 · Expedited examination (Form 18A) · Early publication (Form 9) · Publicly searchable on the Indian Patent Office portal.