The empirical hardness side of the Reality Kernel: measured, not proven, and checked by physics and by a group of instruments rather than by trust.
P.I.G.M.I.E. Filing 1 · patent pendingA Reality Kernel records light under committed controls. Assurance is the question of why that record is hard to forge, and how a disagreement is confirmed by physics and by a group of instruments rather than by trust in one device.
To commit a reading is to bind it, at the moment of capture, so that it cannot later be back-filled, substituted, or reordered. The digital Truth Beam does this with a hash chain anchored to public time references; that commitment is demonstrated and recomputable, and is documented at truthbeam.com. The analogue kernel does it by the filing's mechanism: a cross-witness record written over minimum-latency physical paths, so that a competing reading would have to complete inside the same physical budget the honest signal uses. A single unwitnessed analogue capture can attest that its own record is internally consistent with the committed controls; on its own it cannot place itself in time against the outside world - that is what public anchors, or a witness mesh of co-observing instruments, add. This mechanism is enabled in the filings, with the physical envelope still being characterised.
The mechanism is physical, and it operates on a single capture. As it records, the controller commits to a control sequence, the scan law, the focus, and the timing, that an attacker cannot anticipate. The scene, and any reactor in the path, respond to that sequence physically; where a reactor is present, its response depends on memory, nonlinearity, and manufacturing microstructure that are hard to reproduce without the device itself. To produce a capture that a meter accepts, a forger must therefore either hold the physical instrument or out-predict both the committed control sequence and the reactor's response to it. That is what the hardness below measures.
Hardness is empirical. It is measured against a stated attacker and a stated budget. It is not a formal proof. It is not a zero-knowledge guarantee.
Filing 1 makes the indexing operational: attacker families are graded by resource scale - for example parameter count, compute, wall-clock time, query budget, or training-data budget - so a hardness statement names the class of attacker it holds against, and is re-measured as that class grows.
A forgery claim is therefore indexed. It says that, for a given attacker, a given budget, and a declared threshold, producing a capture that passes is hard. The claim must be re-evaluated as attackers improve.
The demonstrated and recomputable case is the digital Truth Beam. It is evaluated against one trained forger on one rig. That case is documented separately at truthbeam.com.
A meter is a learned test that decides whether a capture matches the committed controls. It does not make the capture. It scores the relation between the capture and the controls.
A meter envelope, or meter family, is the declared set of admissibility bounds a run must stay inside: limits on brightness, colour, exposure, latency, and related quantities. The meter scores a capture; the envelope says which runs are admissible in the first place.
A meter is trained on examples. It is scored on held-out data, which is data not used for training. It is then tested against better forgers as they appear. This forms a repeated meter game.
A meter that continues to separate genuine captures from forged captures remains useful. A meter that stops separating them is retired. It is not defended by assumption.
Temporal order means the order of events inside one record and across participating instruments. In the analogue kernel, ordering comes from mutual analogue timestamping.
Mutual analogue timestamping means that instruments observe timing structure in each other and in the shared scene. The timestamp is carried by physical behaviour, not by trust in a single clock.
No discrete component is required for this ordering claim. The discrete digital layer is optional; the Truth Beam is its demonstrated realisation, documented separately at truthbeam.com.
A discrepancy is a measured difference between expected device behaviour and observed device behaviour. It is confirmed by re-running the physical challenge, not by trusting the reporting device.
A shared predictive model, called Q, learns what device behaviour should look like. It is trained across the fleet on confirmed-genuine runs, so a single deviating device shows up as a residual rather than retraining the baseline; only an independently re-executed, reproduced residual updates Q. A residual is the observed result minus the result predicted by Q.
When a device runs a challenge and the residual exceeds a declared threshold, it submits a method-object tuple. A method-object tuple is a reproducible recipe. It specifies the procedure and the object or condition to be tested.
An independent device then re-executes the same challenge. If the residual reproduces, the anomaly is confirmed. Q is updated to include the new finding.
The difficulty is physical. The confirmation is a second real physical run. A confirmed discrepancy is therefore an empirical finding.
Discovery need not be accidental. An agent may hold a private predictive model that outperforms Q in some region, and design a challenge it believes Q will fail - a hypothesis pre-registered with its metric and stopping rule before the run (Filing 2). The protocol does not care how a discrepancy was found. Every submission is confirmed the same way, by independent physical re-execution. Model error is treated as a resource: the fleet learns fastest from whoever can best predict where it is wrong, and the Eve stance institutionalises exactly this hunting, by consent. One asymmetry is stated plainly: an attacker who finds such a blind spot may hoard it rather than submit it. The defences - diversity of probing agents, trust-weighting by track record, consented red-teaming to shrink the private pool - are mitigations, not eliminations.
A witness mesh is a group of Reality Kernels that observe with bounded-latency fast loops and independent, non-overlapping or partially overlapping views.
The mesh strengthens empirical hardness. A forgery must satisfy many coupled witnesses at once. It must not only fool one camera.
Across the mesh, a transitive proof-of-projection lets a node's committed projection be checked by other nodes against their own observations and challenges. A committed projection is the node's declared view of what its controls and observations imply.
Trust in the mesh is weighted by track record. It is not assumed.
This primitive stands in a named lineage, and Filing 1 cites it: the distance-bounding protocols of Brands and Chaum (1993) and their successors, which bound a prover's distance by timing a single cryptographic round trip. The filing distinguishes the witness mesh on four grounds. The objective is the joint physical evolution of multiple coupled witnesses across an entire evidence window, not one prover's distance from one verifier. The scope is a continuous-analogue joint trace verified at sample level, not bit-level challenge rounds. And the witnessing requirement - each response bound to an observation of physical reality - has no counterpart in distance-bounding at all. Finally, the record is intrinsically multi-witness: mutually recursive joint-reproduction constraints across the whole coupling graph, where distance-bounding is one prover and one verifier, with multi-party forms as add-ons. The architectural keystone is the minimum-latency mutual connection: frame-free, buffer-free analogue paths between modules, bounded by carrier propagation plus front-end latency, with no digital re-representation in the live path - so any intervention must complete inside the same physical budget the honest signal uses. The security claim derives from the latency budget, the witnessing requirement, and the joint-trace verifier together, never from the latency bound alone.
These are empirical claims, not formal proofs. A proof-of-projection is a calibrated attestation, not a proof system with soundness and completeness, and its transitive form is not a composable formal proof. Its strength is contingent on declared assumptions: how many witnesses an attacker can compromise or collude with, resistance to spun-up false witnesses, and the separate threat of an attacker who controls the scene itself. The research sets out the protocol; the adversary model has to be stated for any given deployment, not assumed away.
The Truth Beam, the verification case, is the demonstrated and recomputable instance, evaluated against one trained forger on one rig. The witness mesh and the proof-of-discrepancy protocol are described and enabled in Filing 1 as part of the research project - not a claim of demonstration - with the physical envelope still being characterised.
The Reality Kernel · the apparatus and formalism.
Regimes, stances, and yoked operation · the three objectives.
truthbeam.com · Truth Beam, the demonstrated verification instance.