Telecommunications
Unmanned radio sites where energy and access are the binding constraints
Architecture specified · RTL in progress · no Nelix silicon yet
telecommunications context
The radio site is the cost centre and nobody is standing at it
Radio access network energy is among the largest operating costs a mobile operator carries, and at off-grid and hybrid sites part of it is paid in diesel delivered by road. Operators want more analysis at the site itself, for energy optimisation, equipment fault prediction and intrusion detection, but every watt added to the cabinet is drawn from the same generator, rectifier and battery budget.
Those sites are also physically exposed. Fuel siphoning, battery theft and vandalism of tower equipment are routine in many markets, and the remote monitoring unit installed to detect them is itself unattended and reachable by anyone who gets through the fence. Site controllers and passive infrastructure stay in service well past a decade, so what is specified now has to remain defensible against attacks and cryptographic expectations that are not yet in view.
Why current compute does not serve it
The constraints are structural: placement, power, connectivity and service life, not missing features on a datasheet.
-
Compute is sized for peak load, not for a joule budget
General-purpose edge servers draw power according to the workload in front of them, not according to what a battery bank and solar array can supply, so operators either oversize the plant or forbid local processing entirely.
-
Analysis sits behind the link that fails first
Centralised site analytics stop working during exactly the transport degradation and islanding events when fault and intrusion detection would be most useful.
-
Site telemetry cannot be proved
Fuel level, battery state and door contacts arrive at the network operations centre as plain values over the management channel. A spoofed or compromised controller reports a full tank indefinitely.
-
Interrupted work disappears without explanation
When a generator fails to start and the batteries deplete, compute at the site stops mid-task. Restart discards partial work, leaving a gap the operator cannot distinguish from a device fault.
Inference that fits the energy the site actually has
InferEdge is specified so that a site controller admits an inference request only against an energy contract: a joule budget, model tier, clock profile and checkpoint policy agreed before execution begins. A site running on battery reserve can accept a reduced model tier, renegotiate at a safe boundary, or refuse the request, rather than drawing the plant down partway through a decision.
TrustCore anchors what the site reports. Fuel and battery telemetry, cabinet and shelter tamper events, and the output of any local analysis are bound to per-die identity and a firmware measurement, so the operations centre can reject values from a device whose configuration does not match what was approved. Attestation bundles are sized for a narrowband management channel rather than a broadband link.
None of this has been fabricated. The architecture is published and under RTL development, FPGA validation is the next milestone, and the power figures quoted are design targets.
Specified, not measured. RTL in progress; FPGA next; no Nelix silicon yet.
- Span that closes
- Span where in and out disagree
- Attenuated light = energy unaccounted for
Where Nelix sits in this system
The site admits an inference only against an energy contract, and signs the telemetry it returns to the operations centre.
From site energy budget to a report the NOC can check
Admit, execute, attest and report inside the energy the site actually has — design intent, not a field measurement.
-
Admit
Accept work only against a joule budget the site can pay
-
Execute
Run inference at a clock profile the plant can sustain
-
Attest
Sign telemetry and results to per-die identity
-
Report
Return a narrowband bundle the NOC can verify
The mechanisms that address them
Technical mechanisms in the specification. None of these figures have been characterised in silicon.
-
Energy contract admission
A request is accepted only if the site can pay for it in joules, so analysis cannot draw down a diesel-solar plant that did not budget for it.
-
Renegotiation at safe boundaries
As supply degrades, work moves to a lower clock profile or a smaller model tier at a checkpoint boundary instead of terminating in an undefined state.
-
Attested site telemetry
Fuel, battery and tamper readings are signed against per-die identity and firmware measurement, so substituted or replayed values can be rejected on ingest.
-
Detection through transport loss
Local inference continues when backhaul is down, so intrusion and equipment faults are identified at the site rather than after the link returns.
-
Recovery across plant failure
Checkpointed execution and validated restore mean battery depletion produces a resumable state rather than a lost interval.
-
Cabinet-compatible envelope
INT8 and INT4 datapaths inside a sub-15 W envelope are the design target, so inference can share existing power and thermal headroom in a site cabinet.
What changes if the architecture delivers
Operational consequences stated as design intent, not as measured field results.
-
Local analysis without a plant upgrade
Bounded energy per inference lets processing be added within existing rectifier, battery and cooling headroom rather than after replacing the site power plant.
-
Fewer dispatches to unmanned sites
Telemetry that can be trusted reduces both the visits caused by false alarms and the visits caused by alarms nobody believes.
-
Theft and outage claims backed by evidence
A fuel loss or intrusion event carries provenance identifying the device, firmware and model that reported it.
-
Equipment that outlasts the refresh cycle
Post-quantum-capable signing and offline-queued signed update are specified for site equipment that will be in service for well over a decade.
Platform layers involved
The product family this sector is specified against. Each page states programme stage honestly.
-
Inference accelerator
InferEdge
Inference as a bounded transaction, not a kernel call
Learn more -
Root of trust
TrustCore
Continuous hardware trust, manufacture to retirement
Learn more -
Architecture class
Attested Infrastructure Inference
Verifiable completed inference under energy constraint
Learn more
What we need from this sector now
PartnershipWhat we need from operators now is site reality rather than a procurement conversation. Pre-silicon is when the behaviour of a real tower site can still change the specification.
- Energy and site-visit data from off-grid and hybrid sites
- Requirements from RAN operations and site security teams
- Tower sites for FPGA-based validation ahead of silicon
- Review of attestation formats against existing monitoring systems
Other sectors
-
Sector
Energy & Utilities
Metering and grid-edge equipment that has to be trusted from a pole
Sector detail -
Sector
Industrial Infrastructure
Condition monitoring on plant that will outlive several generations of compute
Sector detail -
Sector
Government
Compute whose provenance an institution can establish for itself
Sector detail -
Sector
Edge AI
Inference that completes on the device and proves what produced it
Sector detail -
Sector
Secure Embedded Systems
Devices that have to stay trustworthy for the next fifteen years
Sector detail