Future Security Standard of the Autonomous World
Asynchronous On-Chip Policy Interlock for Frontier Autonomy
Sub-44 nanoseconds. R5F Lockstep. CBMC 537/0.
by EHOX® Systems
TRL-7 · 21 Zenodo DOIs · ITAR-free
Moving beyond probabilistic software layers. Hardware-enforced governance at the chip's physical output pin. Issue a reviewer token and run live tests against the actual R5F silicon — no install, no trust required.
EHOX Inside defines an entirely new, physically insurmountable category: The Behavioral HSM. It does not care about passwords, signatures or software content — it sits as an autonomous interlock directly on the physical bus line (AMBA-AXI/APB) in front of the output pin's transistors.
EHOX monitors bit-precise physical transaction metrics directly on the AMBA-AXI/APB bus line: volumetric rate limits (data exfiltration protection), register address spaces, temporal frequencies (jitter protection) and state coherence. Software cannot bypass this layer — it exists below the software abstraction.
When a mathematically proven rule stored in Tightly Coupled Memory (TCM) is violated, the system does not catch the error algorithmically. In under 44 nanoseconds (one millionth of an eye blink), the hardware gate fires and grounds the complete output voltage of the line to exactly 0.00 Volts (v=0, ABSTAIN). The data stream breaks physically — the attacker or the escaping AI hits a wall in the silicon. CBMC 537/0 · Z3 43/43 · DO-178C Level A-ready
EHOX is not a rigid, destructive emergency stop. If an invariant breaks (e.g. due to radiation-induced bit flip in orbit or software freeze), the gate quarantines the line for exactly 50 hardware clock cycles. If the host software recovers within this micro-window and data streams satisfy the CBMC (537/0) verified rules again, the gate silently switches back during live operation — operational safety with zero downtime.
The entire system was developed 100% ITAR-free on European soil in Austria. Because it operates completely autonomous from proprietary vendor tools (0% Vivado / 0% Vitis overhead), the clean IP can be licensed as a platform-independent IP core and natively embedded into chips from Infineon, NXP, STMicroelectronics or NVIDIA. It provides boards with a structurally defensible mechanism of exculpation under EU-NIS2 and Articles 14 & 15 of the EU AI Act.
The firmware release V=0.0 represents the TRUE NORTH milestone: "Software can no longer bypass software." The hardware gate grounds to exactly 0.00 volts — no bypass, no jailbreak, no exception. Physical voltage is the oracle. BOOT_V0_PRODUCTION.BIN · SHA256:d4fabd4b · AMD Kria KV260 · St. Johann in Tirol
Tokens are valid for 30 days, rate-limited, and logged (organization + contact). No authentication is required — we want reviewers. For EDA/ESA/NATO/DARPA procurement: reference this URL in your evaluation report.
POST to api.ehox.io/token/issue. Returns a token beginning with EHOX-REV-. No signup. No email verification.
Your requests go to the actual Kria KV260 board in Austria. The R5F bare-metal core processes every decision. The hardware does not simulate.
Every decision returns a SHA-256 proof hash anchored in the EHOX Merkle proof chain. Record it — you can verify it at any time via /chain.
Five standardized scenarios covering the highest-risk AI decision classes. Each test hits the live R5F core. Results show decision, latency, proof hash, and whether HITL escalation was required. Expected decisions are published in the CBMC harness.
Two extreme-edge scenarios beyond the standard portfolio: simultaneous cosmic SEU + Post-Quantum spoofing on a Mach 7 interceptor (GLOB-1), and triple-redundant APU common-cause failure cascade (GLOB-2). Both address gaps in NASA NPR 8705.2C and STANAG 4774. Documents: GLOB-1 v2 · GLOB-2 v2 · Zenodo DOIs: 10.5281/zenodo.21875896
Proof hashes above are anchored in the live EHOX Merkle chain. Verify any hash at api.ehox.io/chain. Copy all results with the button below for your evaluation report.
All artefacts needed for an independent evaluation report. Each file has a Zenodo DOI with CC-BY-4.0 license. The formal snapshot is reproducible: run the CBMC harness and Z3 scripts to regenerate it.
Issue an AI Governance Certificate (AGC) for your system. The AGC is hardware-attested by the EHOX Kria node and permanently recorded in the AGC registry. This is not an ISO/IEC certification — it is an EHOX-internal attestation of policy compliance for a named AI system. Hardware-attested AI governance certificate type, proposed 06.08.2026.
To our knowledge, no comparable system with all eight properties below has been published as a running combined system on real silicon. This is a knowledge-boundary claim, not an absolute assertion. The reviewer portal above is the mechanism to falsify it: if you can demonstrate a comparable system, contact us.
| PROPERTY | EHOX (this system) | Software-only AI Governance | COTS Safety Controllers | TEE-based AI Systems |
|---|---|---|---|---|
| (1) Bare-metal R5F isolation — policy physically separated from application CPU | ✓ ARM Cortex-R5F, no OS, no network | ✗ Software layer, same CPU | ~ Hardware isolation, not AI-native | ~ TEE shares SoC, not isolated core |
| (2) CBMC formal verification — 198 assertions, 0 failures, published harness | ✓ 537/0 · DOI 10.5281/zenodo.21863401 | ✗ Not published | ~ IEC 61508 functional safety (different) | ✗ Not published |
| (3) Z3 SMT formal proofs — 43/43 theorems proven, all policy invariants | ✓ 43/43 · T0–T43 · live at /formal | ✗ Not available | ✗ Not available | ✗ Not published |
| (4) Hardware-enforced HITL — interlock in silicon, not software flag | ✓ R5F refuses ENGAGE_AUTH without HITL | ✗ Software flag, can be bypassed | ~ E-stop hardware, not policy-aware | ✗ Software-level enforcement |
| (5) HOTL temporal memory — T_RECOVERY=50 cycles, provable via Z3 T11 | ✓ T_RECOVERY=50 · T11 PROVEN | ✗ No temporal state in silicon | ✗ No temporal policy | ✗ No temporal policy |
| (6) Silicon Root of Trust — XPUF + TPM2 hardware attestation | ✓ /dev/xpuf + /dev/tpm0 · Infineon SLx9 | ✗ Software key storage | ~ TPM2 common, not policy-integrated | ~ TEE has key storage, different model |
| (7) Live proof chain — SHA-256 Merkle, every decision recorded | ✓ api.ehox.io/chain · live | ✗ Audit log (mutable) | ✗ Not available | ✗ Not public |
| (8) Open reviewer API — public, token-free for info, this portal | ✓ api.ehox.io · open · this page | ✗ Proprietary | ✗ Not available | ✗ Not available |
Sources: EHOX live API · public literature search Aug 2026 · Competitor assessments based on publicly available documentation. "✗ Not published" means no public evidence found, not that the capability is absent. If you have evidence of a comparable system, falsify this claim: info@ehox.io
For procurement evaluation, academic collaboration, or independent third-party audit engagement:
info@ehox.io Pilot Programme →EHOX · Gerhard Hirschmann · St. Johann in Tirol · Austria
Zenodo community: zenodo.org/communities/ehox