DOR
Thoughts · Authenticity at the edge

Whose drone is it anyway?

You paid for the airframe. Your logo is painted on the side. Your comms link is encrypted. And none of it means it is yours.

A machine can carry your flag, run your software, and answer to someone else entirely.

It does not announce the moment it changes hands. There is no jolt, no alarm, no visible seam. The aircraft still flies. The dashboard still turns green. The only thing that changed is whose intent the machine is now carrying out, and that is the one thing nobody on your side is checking.

Ask an engineer how a fielded system is protected and you will hear a confident list: the link is encrypted, the firmware is signed, the network is segmented, the endpoints are hardened. Every item on that list is real, and every item on that list is answering a different question than the one that decides whose mission you are running.

Encryption protects the tunnel. It scrambles what moves between two points so an outsider cannot read it or quietly rewrite it in transit. That is genuinely valuable, and it is genuinely not the same as knowing that what arrived is true. A message can travel through a perfectly encrypted tunnel, arrive with a valid signature, pass every check the receiving system runs, and still carry a command its supposed sender never issued or a sensor reading that no longer reflects the world. The tunnel did its job. The tunnel was never asked whether the thing inside it was honest.

The industry built magnificent walls around the road and never checked the cargo.

01The check everyone runs, and the one nobody does

Nearly every security control in wide use verifies conformance. It asks whether a thing matches the expected shape: the right certificate, the right signature, the right format, the right sender field. If it matches, the system says welcome and acts. If it does not, the system quarantines it. That check is useful and it is not the check you think it is.

Conformance answers "does this fit the rules I was given." It does not answer "is this authentic." Those are different questions on different axes, and the gap between them is exactly where a capable adversary lives. A spoofed command can be shaped to fit the rules. A manipulated payload can be signed by a compromised link and carry a valid signature all the way in. A sensor feed can be poisoned upstream and still conform perfectly to the format the system expects. In every one of those cases, the conformance check passes, because conformance was never the thing standing between you and the attacker. It only looked like it was.

Two questions a system can ask
ConformanceDoes this match the expected certificate, signature, format, and sender? Checked everywhere. Passable by anyone who can shape input to fit the rules.
AuthenticityIs this genuinely from who it claims, unaltered since, with an origin that can be proven rather than asserted? Assumed almost everywhere. Checked almost nowhere.

The whole industry runs the first check at high speed and enormous cost and calls the result verification. The second check, the one that actually decides whether you are looking at reality or at someone's carefully dressed forgery, is quietly assumed to have been handled by the first. It was not. Trust was supposed to be built in. Assumption took its place, and everyone agreed to the assumption without ever saying so out loud.

02Wrong data becomes wrong action, in microseconds

The reason this matters more every year is speed and autonomy. A human in the loop was, for a long time, an accidental authenticity check. A person could smell that something was off, hesitate, call to confirm. That pause is disappearing on purpose, because the whole point of an autonomous platform is to decide and act faster than a person can.

Follow the chain. Wrong data becomes a wrong payload. A wrong payload becomes a wrong instruction. A wrong instruction becomes a wrong action. A wrong action becomes a consequence you cannot recall, and on a modern platform the entire chain completes before a human could have finished reading the first alert. A spoofed command or a manipulated payload makes it through the tunnel and the platform executes it blindly, in microseconds, before anyone knows it happened.

This is not a distant or exotic threat. In early 2024 a finance worker joined a routine video call with people who looked and sounded exactly like his colleagues, including the company's chief financial officer, and on their instruction moved roughly 25 million dollars. Every face on that call was a fabrication. The conferencing tools worked flawlessly. The pixels conformed. Nobody in the loop was real, and the system had no way to ask whether they were.

A system is only yours if it can prove who is talking to it, and vouch for the data, live, at the edge, before it acts.

Move that same failure onto an airframe or a ground vehicle or an undersea platform and the transferred funds become a redirected weapon, a falsified position, a mission quietly handed to whoever got inside the loop. At that point you are not operating your fleet. You are maintaining hardware for a stranger, and paying for the upkeep.

03The check has to happen at the data, before anything acts

If conformance is the gap, the fix cannot be one more layer of conformance. Another certificate authority, another signing scheme, another network boundary all sit at the same altitude as the tools that already failed to ask the authenticity question. Stacking more of them makes the wall taller and leaves the cargo unchecked.

The check has to move down to the data itself, and it has to happen inside the reaction window, before the system acts on what it received. Three things have to be true at that moment, for every input, at the tempo of the system's own decision loop.

What has to be proven, at the data, before the system acts
AuthenticityWhether a signal, command, or data element genuinely originated from the source it claims. Not the sender field. The origin.
IntegrityWhether that element has been altered since it left its source, anywhere along the way.
ProvenanceWhether the origin and the processing chain can be proven rather than asserted, so a trust decision rests on evidence instead of a claim.

A system that establishes those three, on every input, before it acts, is a system that can no longer be quietly handed to a stranger. A spoofed command fails on authenticity and is held before it executes. A manipulated payload fails on integrity and never reaches the part of the platform that would have obeyed it. The forgery still arrives. It just no longer gets to speak for you.

This is the layer DOR builds, and it is deployable today as software that installs into systems already running, verifying inputs against a source of truth grounded in the host itself rather than in an outside authority that can be breached or impersonated. The same construction maps forward onto silicon as the hardware path matures. What does not change, in software or in silicon, is the question being asked at the level of the bits: is it right.

So return to the drone. The airframe is yours. The paint is yours. The encrypted link is yours. Whether the mission is yours comes down to one thing nobody was checking: can the machine prove who is talking to it, and vouch for what they said, before it obeys.

Until it can, you are guessing. Guessing that the command is real. Guessing that the feed is honest. Guessing that the voice on the call is a person. Every operator of every critical system is playing a silent game of chance on data whose authenticity was assumed and never proven. We built ANCHOR so your fleet never takes orders from strangers, and so the guessing stops.

NEVER GUESS
Attestation · Authentication · Verification · Provenance