Technology

Secure, trusted inference begins at the completion transaction.

Nelix engineers Joule-Bounded Inference Architecture (JBIA) on InferEdge™ — ICSM-managed completion transactions under Energy Contract, INT8/INT4 execution, checkpoint-capable recovery, and Proof-Carrying Inference outputs secured by TrustCore™.

Roadmap In Development Pre-Silicon
Honest stage Conceptual architecture complete. No Nelix silicon prototype yet — products below are roadmap targets under active design, not shipping silicon claims.
ICSM
Completion Transaction
sub-15 W
JBIA Power Envelope
INT8 / INT4
Quantized Inference
PCI
Proof-Carrying Export
01 — The Architecture Thesis

Mission-critical edge systems cannot trust unattested inference

Operators of energy, defense, industrial, and utility infrastructure need local inference that survives intermittent power, constrained connectivity, and hostile field conditions — and that can prove what ran.

Attested Infrastructure Inference (AII) is the architecture Nelix is designing toward: every completion is a managed transaction under an Energy Contract, measured by TrustCore, and exported as Proof-Carrying Inference.

Global framing, infrastructure-first — not a consulting brochure, and not a claim of shipping silicon.

Proof-Carrying Inference — result + attestation, bound by TrustCore
JBIA Completion Transaction Result + proof = one architectural transaction Roadmap Input Workload / Context Contract Joule Budget Execute ICSM / Energy Contract Prove Attest Bundle Export Proof-Carrying Inference Result Bundle TrustCore / RoT / Boundary
Fig. NX-03 — JBIA completion path Roadmap vision / Pre-silicon
05 — Architecture Philosophy

Trust begins at the silicon layer

Attested Infrastructure Inference (AII) starts where software cannot — at the silicon attestation boundary. TrustCore™ anchors the Trust Continuum on every Nelix die: PUF identity, measured boot, and proof signing before any model executes.

InferEdge™ JBIA and SecureGrid™ silicon export Proof-Carrying Inference and measurement attestation for field deployment reality — intermittent power, 55°C operation, and offline workflows that cannot wait on the cloud.

01 Applications
02 Models
03 Infrastructure
04 InferEdge · SecureGrid · TrustCore AII Silicon
05 Energy
Attestation Boundary Below Firmware
03 — Execution Architecture

Joule-Bounded Inference Architecture (JBIA)

JBIA does not treat inference as a stateless kernel call. Each request is a managed completion transaction — governed by the Inference Completion State Machine (ICSM), executed under an accepted Energy Contract, and exported as Proof-Carrying Inference when complete.

ICSM

Inference Completion State Machine owns each transaction from attested input through execute, checkpoint, complete, prove, and export — or explicit untrusted abort.

Energy Contract

Execution constraints accepted before EXECUTE — joule budget, approved model tier, clock profile, and checkpoint policy. Renegotiated at safe boundaries when infrastructure conditions change.

Checkpoint Recovery

Transactionally consistent inference recovery across power loss. Restore validates checkpoint integrity and execution-compatible Energy Contract revision before resume.

Figure 2 — JBIA Inference Completion State Machine Trust-plane via TrustCore
Proof-Carrying Inference Output Inference Result Anomaly score / class Operational payload + Attestation Bundle Digest / identity Model / contract TrustCore signature Bound at export · verified before fleet admission
The digest binds result to identity, model, contract, and trust state

Energy Contract Restore

V1 contract → EXECUTE

Grid anomaly inference runs under accepted joule budget and model tier.

CHECKPOINT binds V1

Progress committed at a safe tile boundary before power loss.

RESTORE_VALIDATE → assess energy

On return, infrastructure conditions may differ from the original contract.

V2 contract — compatible, not equal

Lower clock profile preserves committed state semantics; resume to EXECUTE.

Failure is an explicit ICSM transition — not an exception layered on a stateless kernel
04 — Security Architecture

TrustCore: the Trust Continuum from power-on

TrustCore is not secure boot alone — it is a continuous trust continuum from manufacture through cryptographic retirement. Boot ROM measures each stage, PUF derives per-die identity, firmware and models load only under PQC verification, runtime attestation never stops, and the same trust plane signs every Proof-Carrying Inference export.

TrustCore Trust Continuum Lifecycle trust from manufacture to cryptographic retirement Mfg Provision Active Fleet admit Update Suspect Retired keys destroyed · identity revoked Secure boot chain · Measure → Derive → Verify → Attest → Prove → Export Boot ROM Immutable 1st measure PUF Per-die ID Never stored Firmware PQC verify Anti-rollback Runtime Re-attest Tamper resp Prove Bind digest Sign context Export PCI Output Result + bundle Continuous re-attestation loop TrustCore Gateway ICSM · ATTEST_INPUT · CHECKPOINT AUTH · PROVE · EXPORT
Figure 6 — TrustCore Trust Continuum Boot trust gates inference completion
A device in SuspectTamper cannot return to Active without authenticated remediation

What the chain guarantees

Because identity is derived from the physics of each die rather than stored in flash, there is no key material to extract, clone, or reflash. Invasive attacks disturb the silicon structure the PUF depends on, destroying the identity they were trying to steal.

IdentityPUF-derived, per-die, never leaves silicon
CryptographyPost-quantum + classical suites, hardware-accelerated
BootMeasured and attested, anti-rollback counters
TamperActive mesh, environmental sensors, key zeroization
UpdatesSigned OTA with staged rollout and offline queueing
0x0000 [ OK ] Boot ROM integrity verified
0x01A4 [ OK ] PUF identity derived
0x03C0 [ OK ] PQC signature check — firmware stage 1
0x0788 [ OK ] Anti-rollback counters validated
0x0A10 [ OK ] Tamper mesh armed · sensors nominal
0x0D55 [ OK ] Attestation report signed
0x1000 [ >> ] Handing off to application…
TrustCore Boot Sequence
05 — Product Roadmap

Attested Infrastructure Inference, secured in silicon

These are roadmap product families under active architecture work. Status is honest: conceptual design complete, no Nelix silicon prototype yet.

InferEdge™ / JBIA

Joule-Bounded Inference Architecture: ICSM-managed completion transactions, Energy Contract scheduling, INT8/INT4 execution, and checkpoint-capable recovery in sub-15 W envelopes.

In Development / Pre-Silicon
JBIA ICSM Sub-15 W

TrustCore™ Hardware Root of Trust

Trust Continuum from manufacture to retirement. PUF identity, measured boot, signed delivery, and Proof-Carrying Inference signing — binding each result digest to its execution context.

In Development / Pre-Silicon
Trust Continuum Secure Boot Proof Signing

SecureGrid™ Infrastructure SoC

Inference Integrity Chain and Metrology Integrity Chain in one trust domain — encrypted measurement, tamper detection, signed OTA, and optional local JBIA inference.

In Development / Pre-Silicon
Secure Infrastructure Tamper Detection Signed OTA
TrustCore™ In Development / Pre-Silicon Root of trust & Trust Continuum
SecureGrid™ In Development / Pre-Silicon Infrastructure SoC & metrology
InferEdge™ In Development / Pre-Silicon JBIA inference accelerator
Nelix Compute Platform In Development / Pre-Silicon Fleet attestation plane
Engage

Ready to talk architecture?

Walk through the AII thesis, TrustCore continuum, JBIA completion model, and engineering partnership paths — honest stage, global infrastructure framing.