Skip to main content
Infrastructure SoC

SecureGrid

Measurement and inference inside one trust domain

Infrastructure SoC for metering and industrial equipment. Metrology, tamper detection, and optional local inference share one TrustCore anchor, reading and decision share chain of custody.

Architecture defined Pre-silicon
FPGA development board

FPGA development board

Distribution Utility infrastructure
Distribution network with loss localised to one span A conceptual map of an electricity distribution feeder in three parts. Across the top, a delivered-energy profile: an expected staircase that steps down at each transformer tap, and an actual line that follows it until the second meter, then ramps away across a single span and stays low, leaving a constant unaccounted gap. In the middle, the feeder trunk leaves a substation and runs past four metering points to a head-end port, with three step-down transformers tapping off it into clusters of service pads; the span between the second and third meter is drawn in the muted status colour with attenuated light. Underneath, energy in and energy out are compared as paired bars for each span. Every span balances except that one, where the outgoing bar is short and the shortfall is left as an open outline. The loss is therefore localised to one span rather than to the whole feeder. Distribution domain Energy delivered along the feeder Expected Unaccounted Substation Feeder head Bus bars Metering macro M1 M2 M3 M4 Energy balance Energy in over energy out, span by span One span, not one feeder Closes In ≠ out Closes In Out Xfmr 1 Step-down Xfmr 2 Step-down Xfmr 3 Step-down Service points Head-end One feeder, metered end to end
  • Span that closes
  • Span where in and out disagree
  • Attenuated light = energy unaccounted for
Metering every span turns a feeder-wide loss estimate into a single span you can send a crew to. Conceptual system visualization · design intent · not measured field data
SecureGrid · architecture, design intent
ARCHITECTURE

Read the architecture

Each state is entered explicitly, failure is a defined transition rather than an absence, and what is drawn is specified rather than measured.

While running Runtime verification
Continuous runtime verification A conceptual die floorplan for continuous measurement. An always-on measurement engine occupies the left of the die, with a four-phase cycle beneath it: sample, hash, extend, compare. To its right a recessive band shows workload activity in three lanes of uneven task footprints. A sample bus runs under the band and a comb of taps drops from it into a digest chain of linked cells, one per epoch, which the light extends from left to right. One epoch is flagged and re-measured. Beneath the chain the measured history stacks downward in rows that fade as they age, and the chain has no entry from its left end, so the record can only be extended and never rewound. Fresh evidence leaves through a port on the right edge. Operating die · power on Measure engine Always on Sampler Hash macro Every epoch not only at boot Sample Hash Extend Compare Workload activity L0 L1 L2 Sample bus Rolling digest E0 E1 E2 E3 E4 E5 E6 No rewind Re-measure Measured history E6 E5 E4 E3 Fresh quote Measurement continues for as long as the device runs
  • Measured epoch
  • Flagged for re-measure
  • Light = the digest being extended
Boot-time proof goes stale, so measurement continues while the device works and the evidence an operator asks for is always current.
Mechanism context · design intent
MECHANISMS

What holds, and why

  1. Metrology integrity

    Encrypted and attested at capture, not after a board-level transfer

  2. Inference integrity

    Local decisions inherit the provenance of the reading

  3. Tamper as trust state

    Enclosure and electrical events persist across power cycles

  4. Outage-tolerant operation

    Log, queue, and resume across the interruptions these networks see

Semiconductor die macro
Semiconductor die macro
DESIGN TARGETS

Specification

Pre-silicon. Architecture specified; RTL in progress; FPGA next. Figures are design targets, not measured silicon results.

SecureGrid design targets
Status Architecture defined
Target applications Metering, distribution, industrial monitoring
Trust anchor Integrated TrustCore
Measurement Encrypted and attested at capture
Local inference Optional InferEdge datapath
Connectivity Intermittent, narrowband
Target service life 10-20 years
Where it fits
  • Smart meters
  • Feeder automation
  • Industrial sensors
  • Outage-tolerant telemetry
  • Constrained backhaul sites