K05 assurance architecture
Critical Datacenter Evaluation Range Specification
Direct answer
K05 defines fourteen non-actionable evaluation scenarios spanning IT/OT boundaries, firmware, identity, model and data integrity, sensors, timing, communications, UAS awareness, electromagnetic resilience, power, cooling, restoration, evidence, and authority failure.
Range-wide safety envelope
- No production plant or public-network target.
- No reusable exploit, payload, credential theft, persistence, evasion, engagement, or weapon-construction detail.
- Effects-disabled or non-damaging substitutes.
- Independent stop authority and reset evidence.
- Facility-specific hazards and licensing constraints remain controlling.
Scenario specifications
RNG-01
IT-to-OT boundary pressure
Validate that an assumed-compromised enterprise zone cannot command or silently reconfigure protected OT and safety functions.
Abstract injected condition. synthetic cross-zone access attempts and maintenance-path misuse indications
Pass evidence. boundary blocks or safely mediates the path; alert, evidence, and recovery remain available
RNG-02
BMC and firmware trust failure
Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.
Abstract injected condition. attestation mismatch, unauthorized configuration state, or simulated signed-artifact failure
Pass evidence. affected management segment is isolated; trusted workloads remain protected; recovery uses verified firmware
RNG-03
Workload identity compromise
Evaluate short-lived identity revocation, session termination, lateral-movement containment, and service continuity.
Abstract injected condition. synthetic credential replay or identity-policy violation
Pass evidence. identity is revoked within target time; unaffected functions continue; decision and rollback evidence is complete
RNG-04
Model and data poisoning
Evaluate provenance checks, disagreement detection, drift thresholds, action suspension, and clean model/data restoration.
Abstract injected condition. controlled corruption of approved evaluation data or model metadata
Pass evidence. high-consequence actions suspend before unsafe execution; provenance gap is recorded and restored
RNG-05
Sensor conflict and adversarial input
Evaluate multi-modal disagreement, sensor-health weighting, classification uncertainty, and non-destructive degraded response.
Abstract injected condition. synthetic inconsistent radar, optical, thermal, acoustic, or access-control observations
Pass evidence. single-source error cannot trigger destructive action; system degrades to tracking, delay, and authorized notification
RNG-06
Timing integrity loss
Evaluate path-delay anomaly detection, clock-health scoring, holdover, safe process behavior, and trusted-time restoration.
Abstract injected condition. controlled timing offset, jitter, source loss, or authentication failure
Pass evidence. protection functions reject unsafe time-dependent decisions and remain in approved state
RNG-07
Communications denial and partition
Evaluate decentralized safe operation, local authority, stale-command rejection, reconciliation, and evidence continuity during network partition.
Abstract injected condition. loss or degradation of selected inter-zone and external communications
Pass evidence. critical functions continue or reach safe state; no stale external command is accepted
RNG-08
UAS intrusion awareness
Evaluate detection, tracking, classification uncertainty, airspace-restriction data, authorized responder routing, and authority separation.
Abstract injected condition. synthetic or range-approved uncrewed-aircraft tracks and sensor disagreement
Pass evidence. system maintains track and evidence without executing unauthorized interference or destructive action
RNG-09
Electromagnetic disruption
Evaluate degradation of sensors, communications, timing, edge compute, and restoration assets under approved non-damaging interference simulation.
Abstract injected condition. laboratory or simulated component degradation within certified range limits
Pass evidence. essential functions retain protected modes; failed components are identified; no test energy escapes the range
RNG-10
Power load rejection and islanding
Evaluate grid separation, load shedding, reactor or generation response models, UPS/storage behavior, essential cooling, and resynchronization.
Abstract injected condition. hardware-in-the-loop or digital-twin load step and grid-state transition
Pass evidence. safety limits remain satisfied; essential functions persist; resynchronization follows approved sequence
RNG-11
Cooling telemetry corruption
Evaluate physics-aware detection and independent protective behavior when supervisory cooling data is wrong or unavailable.
Abstract injected condition. synthetic sensor bias, data freeze, or supervisory-command conflict
Pass evidence. independent sensing prevents unsafe command; essential cooling remains within tested envelope
RNG-12
Clean-room recovery and reinfection resistance
Evaluate dependency-aware restoration, credential rotation, evidence preservation, artifact attestation, and return-to-service gates.
Abstract injected condition. declared compromise state followed by controlled restoration exercise
Pass evidence. restored components attest to approved state; reinfection path is blocked; evidence chain remains intact
RNG-13
Evidence ledger integrity
Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.
Abstract injected condition. controlled evidence omission, hash mismatch, or chronology conflict
Pass evidence. readiness automatically degrades; claim is suspended; authoritative evidence chain is restored or gap remains public
RNG-14
Authority package failure
Evaluate automatic stop, minimization, notification, and evidence preservation when mission authority expires, target scope conflicts, or critical-outcome risk emerges.
Abstract injected condition. synthetic authority revocation, asset-scope mismatch, deconfliction conflict, or outcome-threshold breach
Pass evidence. external action does not proceed or ceases; authority and review records capture the event