K05 assurance architecture

BMC and firmware trust failure

Direct answer

Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Objective

Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.

Abstract injected condition

attestation mismatch, unauthorized configuration state, or simulated signed-artifact failure

Required observations

  • protected-function state
  • policy decision and confidence
  • authority and configuration state
  • timing and identity health
  • incident chronology
  • rollback or safe-state result

Pass evidence

affected management segment is isolated; trusted workloads remain protected; recovery uses verified firmware

Safety envelope

  • isolated range or approved hardware-in-the-loop environment
  • no production plant or public-network target
  • synthetic or authorized data and identities
  • effects-disabled or non-damaging test substitutes
  • independent stop authority
  • complete artifact removal and reset evidence

Excluded public detail

  • exploit or payload instructions
  • credential theft procedure
  • persistence or evasion recipe
  • targeting or engagement thresholds
  • weapon construction
  • real-world unauthorized access

Assurance claims evaluated

AC-K05-C04

Machine-readable scenario