Skip to main content
Sector

Telecommunications

Unmanned radio sites where energy and access are the binding constraints

Architecture specified · RTL in progress · no Nelix silicon yet

telecommunications context

Energy is the binding constraint at an unmanned site
Energy is the binding constraint at an unmanned site
THE CHALLENGE

The radio site is the cost centre and nobody is standing at it

Radio access network energy is among the largest operating costs a mobile operator carries, and at off-grid and hybrid sites part of it is paid in diesel delivered by road. Operators want more analysis at the site itself, for energy optimisation, equipment fault prediction and intrusion detection, but every watt added to the cabinet is drawn from the same generator, rectifier and battery budget.

Those sites are also physically exposed. Fuel siphoning, battery theft and vandalism of tower equipment are routine in many markets, and the remote monitoring unit installed to detect them is itself unattended and reachable by anyone who gets through the fence. Site controllers and passive infrastructure stay in service well past a decade, so what is specified now has to remain defensible against attacks and cryptographic expectations that are not yet in view.

LIMITATIONS

Why current compute does not serve it

The constraints are structural: placement, power, connectivity and service life, not missing features on a datasheet.

  1. Compute is sized for peak load, not for a joule budget

    General-purpose edge servers draw power according to the workload in front of them, not according to what a battery bank and solar array can supply, so operators either oversize the plant or forbid local processing entirely.

  2. Analysis sits behind the link that fails first

    Centralised site analytics stop working during exactly the transport degradation and islanding events when fault and intrusion detection would be most useful.

  3. Site telemetry cannot be proved

    Fuel level, battery state and door contacts arrive at the network operations centre as plain values over the management channel. A spoofed or compromised controller reports a full tank indefinitely.

  4. Interrupted work disappears without explanation

    When a generator fails to start and the batteries deplete, compute at the site stops mid-task. Restart discards partial work, leaving a gap the operator cannot distinguish from a device fault.

Interposer stack
Interposer stack
APPROACH

Inference that fits the energy the site actually has

InferEdge is specified so that a site controller admits an inference request only against an energy contract: a joule budget, model tier, clock profile and checkpoint policy agreed before execution begins. A site running on battery reserve can accept a reduced model tier, renegotiate at a safe boundary, or refuse the request, rather than drawing the plant down partway through a decision.

TrustCore anchors what the site reports. Fuel and battery telemetry, cabinet and shelter tamper events, and the output of any local analysis are bound to per-die identity and a firmware measurement, so the operations centre can reject values from a device whose configuration does not match what was approved. Attestation bundles are sized for a narrowband management channel rather than a broadband link.

None of this has been fabricated. The architecture is published and under RTL development, FPGA validation is the next milestone, and the power figures quoted are design targets.

Specified, not measured. RTL in progress; FPGA next; no Nelix silicon yet.

Distribution Utility infrastructure
Distribution network with loss localised to one span A conceptual map of an electricity distribution feeder in three parts. Across the top, a delivered-energy profile: an expected staircase that steps down at each transformer tap, and an actual line that follows it until the second meter, then ramps away across a single span and stays low, leaving a constant unaccounted gap. In the middle, the feeder trunk leaves a substation and runs past four metering points to a head-end port, with three step-down transformers tapping off it into clusters of service pads; the span between the second and third meter is drawn in the muted status colour with attenuated light. Underneath, energy in and energy out are compared as paired bars for each span. Every span balances except that one, where the outgoing bar is short and the shortfall is left as an open outline. The loss is therefore localised to one span rather than to the whole feeder. Distribution domain Energy delivered along the feeder Expected Unaccounted Substation Feeder head Bus bars Metering macro M1 M2 M3 M4 Energy balance Energy in over energy out, span by span One span, not one feeder Closes In ≠ out Closes In Out Xfmr 1 Step-down Xfmr 2 Step-down Xfmr 3 Step-down Service points Head-end One feeder, metered end to end
  • Span that closes
  • Span where in and out disagree
  • Attenuated light = energy unaccounted for
Metering every span turns a feeder-wide loss estimate into a single span you can send a crew to. Conceptual system visualization · design intent · not measured field data
Site energy and trust boundary · design intent
POSITION

Where Nelix sits in this system

The site admits an inference only against an energy contract, and signs the telemetry it returns to the operations centre.

Reporting over a narrowband management channel
Reporting over a narrowband management channel
PATHWAY

From site energy budget to a report the NOC can check

Admit, execute, attest and report inside the energy the site actually has — design intent, not a field measurement.

  1. Admit

    Accept work only against a joule budget the site can pay

  2. Execute

    Run inference at a clock profile the plant can sustain

  3. Attest

    Sign telemetry and results to per-die identity

  4. Report

    Return a narrowband bundle the NOC can verify

CAPABILITIES

The mechanisms that address them

Technical mechanisms in the specification. None of these figures have been characterised in silicon.

  1. Energy contract admission

    A request is accepted only if the site can pay for it in joules, so analysis cannot draw down a diesel-solar plant that did not budget for it.

  2. Renegotiation at safe boundaries

    As supply degrades, work moves to a lower clock profile or a smaller model tier at a checkpoint boundary instead of terminating in an undefined state.

  3. Attested site telemetry

    Fuel, battery and tamper readings are signed against per-die identity and firmware measurement, so substituted or replayed values can be rejected on ingest.

  4. Detection through transport loss

    Local inference continues when backhaul is down, so intrusion and equipment faults are identified at the site rather than after the link returns.

  5. Recovery across plant failure

    Checkpointed execution and validated restore mean battery depletion produces a resumable state rather than a lost interval.

  6. Cabinet-compatible envelope

    INT8 and INT4 datapaths inside a sub-15 W envelope are the design target, so inference can share existing power and thermal headroom in a site cabinet.

OUTCOMES

What changes if the architecture delivers

Operational consequences stated as design intent, not as measured field results.

  1. Local analysis without a plant upgrade

    Bounded energy per inference lets processing be added within existing rectifier, battery and cooling headroom rather than after replacing the site power plant.

  2. Fewer dispatches to unmanned sites

    Telemetry that can be trusted reduces both the visits caused by false alarms and the visits caused by alarms nobody believes.

  3. Theft and outage claims backed by evidence

    A fuel loss or intrusion event carries provenance identifying the device, firmware and model that reported it.

  4. Equipment that outlasts the refresh cycle

    Post-quantum-capable signing and offline-queued signed update are specified for site equipment that will be in service for well over a decade.

What we need from this sector now

Partnership

What we need from operators now is site reality rather than a procurement conversation. Pre-silicon is when the behaviour of a real tower site can still change the specification.

  • Energy and site-visit data from off-grid and hybrid sites
  • Requirements from RAN operations and site security teams
  • Tower sites for FPGA-based validation ahead of silicon
  • Review of attestation formats against existing monitoring systems