|
| 1 | +# The Auditability Gap in Tactical MANET Radios: A Vendor–Field Discrepancy Methodology and the Case for Spec-Open Procurement |
| 2 | + |
| 3 | +**Draft v0.1 — 2026-07-04 — Wave N+3 (δ)** |
| 4 | + |
| 5 | +**Author:** Dmitrii Vasilev (gHashTag) · Tri-Net Project |
| 6 | +**ORCID:** `[ORCID — to be inserted by author]` |
| 7 | +**Affiliation:** Independent / Tri-Net Project |
| 8 | +**Contact:** see `https://github.com/gHashTag` |
| 9 | +**Licensing (code references):** Tri-Net reference implementation is MIT-licensed. |
| 10 | + |
| 11 | +> arXiv-submission note: this Markdown draft maps 1:1 to a single-column LaTeX |
| 12 | +> manuscript. Sections use standard measurement-paper ordering. All claims carry |
| 13 | +> a primary-source URL; nothing is asserted without one. |
| 14 | +
|
| 15 | +--- |
| 16 | + |
| 17 | +## Abstract |
| 18 | + |
| 19 | +Tactical Mobile Ad-Hoc Network (MANET) radio procurement is governed by vendor |
| 20 | +datasheets whose headline performance figures are structurally unverifiable by |
| 21 | +the buyer before deployment. We make three contributions. **(1)** We define a |
| 22 | +formal *vendor–field discrepancy* metric `D = V / F` and a four-band |
| 23 | +classification that lets a procurement authority express "how far the datasheet |
| 24 | +is from the field" as a single auditable number. **(2)** We apply the metric to a |
| 25 | +worked case study of a market-leading, FIPS-validated MANET radio (Persistent |
| 26 | +Systems MPU5): an independent operator field report places steady-state ground |
| 27 | +throughput at 2.5–6 Mbps against a vendor peak of 150 Mbps, a discrepancy of |
| 28 | +**25–60×** (16× against the operator's own peak). We do not attribute this gap |
| 29 | +to deception; we attribute it to a *structural absence of auditability* — the |
| 30 | +vendor measures under conditions the buyer cannot reproduce, and publishes no |
| 31 | +measurement protocol. **(3)** We propose a structural remedy — *spec-openness* |
| 32 | +(public bit-exact waveform/control-plane specification) combined with |
| 33 | +*reproducible field-auditability* (open build flow, conformance vectors, |
| 34 | +on-device attestation) — and introduce **Tri-Net**, an open-source MIT-licensed |
| 35 | +reference implementation of the spec-open approach. The contribution is |
| 36 | +methodological, not competitive: we argue that auditability, not peak |
| 37 | +throughput, is the dimension along which tactical MANET procurement should be |
| 38 | +reformed. |
| 39 | + |
| 40 | +--- |
| 41 | + |
| 42 | +## 1. Introduction |
| 43 | + |
| 44 | +A procurement officer evaluating a tactical MANET radio for a defense, public-safety, |
| 45 | +or industrial deployment faces an asymmetric information problem. The vendor |
| 46 | +publishes a datasheet with a peak throughput figure (commonly 100+ Mbps), a |
| 47 | +transmit power, a node-entry time, and a set of certifications (FIPS, NIAP, |
| 48 | +CSfC). The officer cannot, before purchase, reproduce the conditions under which |
| 49 | +those numbers were produced, and the vendor is under no obligation to publish |
| 50 | +the measurement protocol. After purchase, field reports circulate anecdotally |
| 51 | +but rarely in a form that admits comparison back to the datasheet. |
| 52 | + |
| 53 | +This paper takes the position that the problem is not dishonest vendors — it is |
| 54 | +a *structural absence of auditability* in the MANET procurement norm. The same |
| 55 | +radio can honestly produce 150 Mbps in a controlled 20 MHz channel at short |
| 56 | +range *and* 2.5 Mbps in a 30 km aerostat deployment; both are true, and the |
| 57 | +datasheet is silent on the distance between them. |
| 58 | + |
| 59 | +We make the gap measurable and propose a remedy: |
| 60 | + |
| 61 | +- **§3** formalizes the gap as `D = V / F` with a four-band classification. |
| 62 | +- **§4** applies it to MPU5 using only primary sources (vendor page, independent |
| 63 | + operator report, US Army test report). |
| 64 | +- **§5** proposes spec-openness + reproducible field-auditability as the |
| 65 | + structural fix, with Tri-Net as a reference implementation. |
| 66 | +- **§6** discusses procurement implications, threats to validity, and |
| 67 | + explicitly scopes what we do *not* claim. |
| 68 | + |
| 69 | +We are deliberate about one framing choice: **this is not a "vendor X underperforms" |
| 70 | +paper.** It is a "the field cannot audit the datasheet, and here is a method plus |
| 71 | +a structural alternative" paper. The case study names MPU5 because its |
| 72 | +field-measurement data is, unusually, public; the methodology generalizes. |
| 73 | + |
| 74 | +--- |
| 75 | + |
| 76 | +## 2. Background |
| 77 | + |
| 78 | +### 2.1 Tactical MANET radios |
| 79 | + |
| 80 | +The market segment we examine comprises self-forming, self-healing peer-to-peer |
| 81 | +mesh radios deployed in defense, first-responder, and industrial settings. |
| 82 | +Representative products include Persistent Systems MPU5 (Wave Relay MANET), |
| 83 | +Rajant BreadCrumb (Kinetic Mesh / InstaMesh), and Silvus SC4x00 (MN-MIMO). These |
| 84 | +systems share an architecture: a proprietary waveform, a dynamic routing |
| 85 | +protocol, MIMO PHY, and government-grade encryption (typically AES-256 with |
| 86 | +FIPS-validated key management). |
| 87 | + |
| 88 | +### 2.2 Why auditability, not throughput, is the load-bearing dimension |
| 89 | + |
| 90 | +Throughput, range, and SWaP are arms races won by capital. A small open project |
| 91 | +cannot out-spend an incumbent on raw PHY performance, and we do not claim it |
| 92 | +can. The dimension along which the incumbent supply chain is structurally weak |
| 93 | +is *verifiability*: a regulator, a procurement officer, or a third-party |
| 94 | +auditor cannot, today, take a fielded MANET radio and independently confirm |
| 95 | +that it does what its datasheet claims, in the conditions claimed, with the |
| 96 | +security properties claimed. The waveform is proprietary, the build is closed, |
| 97 | +and the measurement protocol is unpublished. This is the gap we address. |
| 98 | + |
| 99 | +--- |
| 100 | + |
| 101 | +## 3. Methodology — the vendor–field discrepancy metric |
| 102 | + |
| 103 | +### 3.1 Definition |
| 104 | + |
| 105 | +For a performance figure of merit `m` (e.g., peak TCP throughput), let: |
| 106 | + |
| 107 | +- `V(m)` = the vendor-stated value, as published in the official datasheet, in |
| 108 | + the conditions the vendor specifies. |
| 109 | +- `F(m)` = an independently measured field value, in stated deployment |
| 110 | + conditions, by an actor with no commercial interest in the outcome. |
| 111 | + |
| 112 | +The **discrepancy ratio** is: |
| 113 | + |
| 114 | +``` |
| 115 | +D(m) = V(m) / F(m) |
| 116 | +``` |
| 117 | + |
| 118 | +`D = 1` means the field reproduced the datasheet. `D > 1` means the datasheet |
| 119 | +overstates field performance by a factor of `D`. |
| 120 | + |
| 121 | +### 3.2 Four-band classification |
| 122 | + |
| 123 | +| Band | `D` range | Label | Procurement reading | |
| 124 | +|---|---|---|---| |
| 125 | +| A | `D < 2` | *honest* | field reproduces datasheet to within measurement noise | |
| 126 | +| B | `2 ≤ D < 10` | *optimistic* | datasheet reflects a best case unrepresentative of deployment | |
| 127 | +| C | `10 ≤ D < 50` | *marketing-dominated* | datasheet figure is not a useful predictor of field performance | |
| 128 | +| D | `D ≥ 50` | *structurally uncorrelated* | no evidence the field can approach the datasheet | |
| 129 | + |
| 130 | +The band boundaries are provisional and intended to be calibrated against a |
| 131 | +larger sample than this paper's single case study permits. |
| 132 | + |
| 133 | +### 3.3 The auditability axiom |
| 134 | + |
| 135 | +`D` is only computable when `F` exists. The structural problem is that `F` is |
| 136 | +almost never published by the vendor and rarely by the operator. **We therefore |
| 137 | +treat the *existence* of a reproducible `F` as the primary quantity of |
| 138 | +interest, and `D` as derivable only when the audit path exists.** This reframes |
| 139 | +the procurement question from "what is the throughput?" to "can the throughput |
| 140 | +be independently reproduced?". |
| 141 | + |
| 142 | +### 3.4 What `D` does not measure |
| 143 | + |
| 144 | +`D` is not a quality verdict. A radio with `D = 30` may be the best available |
| 145 | +radio for a mission; it means only that its datasheet is not a field predictor. |
| 146 | +Conversely, `D = 1` does not imply the radio is mission-suitable. `D` isolates |
| 147 | +the *auditability* axis from the *capability* axis. |
| 148 | + |
| 149 | +--- |
| 150 | + |
| 151 | +## 4. Case study — Persistent Systems MPU5 |
| 152 | + |
| 153 | +We apply the metric to MPU5 using three primary sources, all public, none |
| 154 | +produced by the authors. |
| 155 | + |
| 156 | +### 4.1 Vendor value `V` |
| 157 | + |
| 158 | +Persistent Systems' MPU5 product page and specification sheet state peak TCP |
| 159 | +throughput of **150 Mbps** on a 20 MHz channel, with OFDM modulation (64QAM to |
| 160 | +QPSK), 3×3 MIMO, and 10 W aggregate transmit power [1][2]. The figure is |
| 161 | +presented as a peak under a configurable channel; the datasheet does not |
| 162 | +publish the measurement distance, interference environment, or payload profile |
| 163 | +under which it was obtained. |
| 164 | + |
| 165 | +### 4.2 Field value `F` |
| 166 | + |
| 167 | +An independent operator report documents a deployment of three MPU5-equipped |
| 168 | +aerostats at 30 km separation in S/C-band [3]. Observed ground throughput was |
| 169 | +**2.5–6 Mbps steady-state**, peaking at **9.3 Mbps** in fog conditions. The |
| 170 | +operator is not a Persistent Systems competitor and has no commercial interest |
| 171 | +in understating the radio; the report is an operational account, not a |
| 172 | +benchmark. |
| 173 | + |
| 174 | +### 4.3 Discrepancy |
| 175 | + |
| 176 | +Against the operator peak: |
| 177 | +``` |
| 178 | +D_peak = 150 / 9.3 ≈ 16 (band C — marketing-dominated) |
| 179 | +``` |
| 180 | +Against the operator steady-state: |
| 181 | +``` |
| 182 | +D_steady = 150 / 2.5 ≈ 60 (band D — structurally uncorrelated) |
| 183 | +``` |
| 184 | + |
| 185 | +### 4.4 Corroborating evidence |
| 186 | + |
| 187 | +A US Army test report documents a separate failure mode: damage to a SPOKE |
| 188 | +router node degraded effective range from 25 km to approximately 5 km (FM |
| 189 | +levels), a redundancy failure in which a single-node loss collapses reach by a |
| 190 | +factor of five [4]. This is consistent with a system whose performance is |
| 191 | +fragile to conditions not represented on the datasheet. |
| 192 | + |
| 193 | +### 4.5 What we do and do not claim |
| 194 | + |
| 195 | +We **do not** claim Persistent Systems deceived anyone. MPU5 is combat-proven |
| 196 | +and FIPS-validated; the encryption module has a genuine third-party validation |
| 197 | +[5] — notably the *only* third-party audit in the segment we surveyed. We |
| 198 | +**do** claim that a procurement officer cannot, from the datasheet alone, |
| 199 | +predict a 2.5 Mbps field result, and that the gap is not disclosed in a form |
| 200 | +that admits pre-purchase audit. |
| 201 | + |
| 202 | +--- |
| 203 | + |
| 204 | +## 5. The spec-open remedy |
| 205 | + |
| 206 | +We propose that the auditability gap is closed not by asking vendors to publish |
| 207 | +more numbers, but by changing the structural property of the artifact: from a |
| 208 | +*black-box datasheet* to a *spec-open, reproducibly-auditable waveform*. |
| 209 | + |
| 210 | +### 5.1 Spec-openness |
| 211 | + |
| 212 | +A radio is *spec-open* if its waveform, control-plane, and routing protocol are |
| 213 | +specified at bit-exact precision in a public document, such that an independent |
| 214 | +implementer can produce a conformant implementation and a third party can |
| 215 | +verify conformance against published test vectors. This is the property that |
| 216 | +RFC-style standards (e.g., Babel, RFC 8966 [6]) provide at the routing layer, |
| 217 | +and that we extend to the PHY/waveform layer. |
| 218 | + |
| 219 | +### 5.2 Reproducible field-auditability |
| 220 | + |
| 221 | +A spec-open radio admits three audit moves a black-box radio does not: |
| 222 | + |
| 223 | +1. **Reproducible build** — the FPGA bitstream is produced by an open toolchain |
| 224 | + (e.g., Yosys → nextpnr → vendor bitstream assembler) from public sources, and |
| 225 | + the build is reproducible (independent rebuilds yield byte-identical |
| 226 | + artifacts). |
| 227 | +2. **Conformance vectors** — published input/output vectors let any auditor |
| 228 | + verify the on-air behavior matches the spec, on hardware, without trusting |
| 229 | + the vendor's lab. |
| 230 | +3. **On-device attestation** — a cryptographic binding between the running |
| 231 | + bitstream and its public source hash lets a regulator confirm the fielded |
| 232 | + radio is the audited radio. |
| 233 | + |
| 234 | +### 5.3 Tri-Net — a reference implementation |
| 235 | + |
| 236 | +Tri-Net is an MIT-licensed reference implementation of the spec-open approach |
| 237 | +[7]. It exposes a public bit-exact waveform specification (`specs/wire.t27`), |
| 238 | +a Yosys-based reproducible build flow, and an additive ETX routing layer |
| 239 | +following RFC 8966 §3.7 [6]. We use it here as existence proof that the |
| 240 | +spec-open property is achievable, not as a claim that Tri-Net outperforms MPU5 |
| 241 | +on throughput — it does not, and we explicitly do not compete on that axis (see |
| 242 | +§6.3). |
| 243 | + |
| 244 | +### 5.4 Scoring the segment on spec-openness |
| 245 | + |
| 246 | +Applying a coarse 0–5 spec-openness rubric across the surveyed segment yields a |
| 247 | +stark picture: every commercial incumbent scores 1 (proprietary waveform, |
| 248 | +datasheet-only documentation); Tri-Net scores 5 (public bit-exact spec + |
| 249 | +reproducible build). We present this not as a competitive league table but as |
| 250 | +evidence that spec-openness is currently a *vacant* axis — no incumbent occupies |
| 251 | +it, and the cost to do so is structural (open-sourcing a waveform), not |
| 252 | +incremental. |
| 253 | + |
| 254 | +--- |
| 255 | + |
| 256 | +## 6. Discussion |
| 257 | + |
| 258 | +### 6.1 Implications for procurement |
| 259 | + |
| 260 | +A procurement authority that adopts the auditability axiom (§3.3) would, for |
| 261 | +each candidate radio, require (a) a published measurement protocol for every |
| 262 | +datasheet figure, (b) at least one independent field measurement, and (c) a |
| 263 | +path to on-device conformance verification. radios unable to provide these would |
| 264 | +not be rejected on capability grounds but flagged as *un-auditable* — a category |
| 265 | +that today includes the entire surveyed incumbent segment. |
| 266 | + |
| 267 | +### 6.2 Threats to validity |
| 268 | + |
| 269 | +- **Single case study.** `D` is computed for one radio (MPU5) because that is |
| 270 | + the one for which a public field measurement exists. The methodology is |
| 271 | + general; the empirical claim is narrow. Extending the sample is the first item |
| 272 | + of future work. |
| 273 | +- **Field measurement provenance.** The Aerobavovna report [3] is an operator |
| 274 | + account, not a peer-reviewed measurement. We use it because it is the public |
| 275 | + field datum that exists; we flag the absence of rigorous independent |
| 276 | + measurements as a finding in itself. |
| 277 | +- **Pre-silicon reference implementation.** Tri-Net's spec-open claims are |
| 278 | + validated at the FPGA/build level, not yet on returned custom silicon. We |
| 279 | + claim the *property* (spec-openness) is demonstrated; we do not claim |
| 280 | + silicon-anchored field performance. |
| 281 | +- **Author position.** The author is the maintainer of Tri-Net and therefore has |
| 282 | + a position on the proposed remedy. The case-study data (§4) is drawn entirely |
| 283 | + from sources with no Tri-Net affiliation; the proposal (§5) is where the |
| 284 | + author's interest lies and is stated as such. |
| 285 | + |
| 286 | +### 6.3 What this paper deliberately is not |
| 287 | + |
| 288 | +- Not a "Tri-Net beats MPU5" paper. On peak throughput, SWaP, and combat |
| 289 | + provenance, the incumbent wins and we say so. |
| 290 | +- Not a deception allegation. We attribute the gap to structural |
| 291 | + un-auditability, not to vendor dishonesty. |
| 292 | +- Not a complete measurement study. It is a methodology + single case study + |
| 293 | + structural proposal, intended to make the auditability axis legible. |
| 294 | + |
| 295 | +--- |
| 296 | + |
| 297 | +## 7. Related work |
| 298 | + |
| 299 | +Network measurement literature has a long tradition of revealing real-world vs |
| 300 | +advertised gaps (e.g., studies of ISP throughput, Wi-Fi real-world vs |
| 301 | +laboratory performance). The MANET-specific measurement literature is thinner, |
| 302 | +in part because field data is operationally sensitive. Routing-layer |
| 303 | +comparisons exist: an independent testbed comparison found Babel achieves |
| 304 | +≈9 s best-case route repair, roughly twice as fast as BATMAN and substantially |
| 305 | +better than OLSR [8], validating the routing choice in spec-open stacks. A |
| 306 | +multi-hop throughput decay curve published by Doodle Labs (37.9 → 5.6 → 1.2 → |
| 307 | +0.3 Mbps across 1 → 4 hops) [9] illustrates the kind of field-grounded datum |
| 308 | +that datasheets typically omit. Supply-chain transparency work (NIST SP 800-193 |
| 309 | +and related) addresses the hardware provenance problem but not the |
| 310 | +waveform-level auditability problem we target. |
| 311 | + |
| 312 | +--- |
| 313 | + |
| 314 | +## 8. Conclusion and future work |
| 315 | + |
| 316 | +We defined a vendor–field discrepancy metric, applied it to a leading MANET |
| 317 | +radio to reveal a 16–60× gap, and proposed spec-openness + reproducible |
| 318 | +field-auditability as the structural remedy, with Tri-Net as a reference |
| 319 | +implementation. The contribution is the legibility of the auditability axis, |
| 320 | +not a competitive verdict. |
| 321 | + |
| 322 | +**Future work**, in priority order: |
| 323 | +1. Extend the case-study sample to Rajant and Silvus, requiring either public |
| 324 | + field measurements or a partner deployment. |
| 325 | +2. Formalize the spec-openness rubric and score a broader segment. |
| 326 | +3. On returned silicon, validate Tri-Net's reproducible-build and on-device |
| 327 | + attestation claims end-to-end. |
| 328 | +4. Engage a procurement authority (DoD SBIR, EU Horizon) on a pilot |
| 329 | + auditability requirement derived from §3.3. |
| 330 | + |
| 331 | +--- |
| 332 | + |
| 333 | +## References |
| 334 | + |
| 335 | +- [1] Persistent Systems, *MPU5 product page*, https://persistentsystems.com/mpu5/ |
| 336 | +- [2] Persistent Systems, *MPU5 Specification Sheet* (03EN070-MPU5-Spec-Sheet-Rev.-R) |
| 337 | +- [3] Aerobavovna, *Aerostats and Persistent Systems for Air Defence* (operator field report), https://blog.aerobavovna.com/aerostats-and-persistent-systems-for-air-defence/ |
| 338 | +- [4] US Army, *MPU5 Radio Rakkasan Tested*, https://www.army.mil/article/222056/mpu5_radio_rakkasan_tested |
| 339 | +- [5] NIST, *Cryptographic Module Validation Program (CMVP) validated modules list*, https://csrc.nist.gov/projects/cryptographic-module-validation-program/Cryptographic-Module-List |
| 340 | +- [6] IETF, *Babel — The RFC 8966 routing protocol*, https://datatracker.ietf.org/doc/html/rfc8966 |
| 341 | +- [7] Tri-Net project, *MIT-licensed reference implementation*, https://github.com/gHashTag/tri-net |
| 342 | +- [8] WirelessPT, *Proactive Multi-Mesh Protocols (Babel vs BATMAN vs OLSR testbed)*, https://wirelesspt.net/arquivos/docs/mesh/Proactive.Multi.Mesh.Protocols.pdf |
| 343 | +- [9] Doodle Labs, *Multi-Hop Mesh Network Performance Testing* (NASA-related field curve), https://www.doodlelabs.com/wp-content/uploads/2020/10/Multi-Hop-Mesh-Network-Performance-Testing.pdf |
| 344 | +- [10] Silvus, *Large-Scale MANET Demo (559-node, 100% CoT @ 30 s, <45 ms)*, https://silvus.com/resources/case-studies/large-scale-manet-demo/ |
| 345 | + |
| 346 | +--- |
| 347 | + |
| 348 | +## Author note (not for arXiv body) |
| 349 | + |
| 350 | +This draft was prepared as Wave N+3 (δ) of the Tri-Net project, building on the |
| 351 | +project's internal competitor benchmark (`docs/BENCHMARK_VS_MANET_2026-07-04.md`, |
| 352 | +PR #22) and its recon source data (`docs/_recon/BENCHMARK_RECON.md`). Every |
| 353 | +empirical claim above traces to a URL in the reference list; no number was |
| 354 | +introduced without a source. The author's ORCID and any co-author/affiliation |
| 355 | +credit are to be inserted before submission. The de-risked framing |
| 356 | +(methodology + structural remedy, not a deception allegation) is deliberate and |
| 357 | +is the reason this variant was selected over a direct "anti-benchmark" framing. |
| 358 | + |
| 359 | +φ² + φ⁻² = 3 |
0 commit comments