UE-RES-2026-014Peer-reviewedAdviQ
Sep 2026S. Malviya, U. Wad, S. Prabhudesai, U. Sinha (external)
IEEE Transactions on Dependable and Secure Computing · doi:10.0000/uelement.2026.014
Abstract▾
Migration programmes conventionally sequence cryptographic assets by system criticality. We argue this is the wrong ordering under a harvest-now-decrypt-later threat model, and present a ranking function over data sensitivity lifetime, capture probability and re-key cost. Applied to three production financial estates totalling 5,400 hosts, the resulting order differs from criticality ranking in 38% of the top quartile, and concentrates residual risk in assets that conventional sequencing would have addressed last.
UE-RES-2026-012PreprintTRIpura
Jul 2026K. Narwade, S. Sengupta, A. Kumar
arXiv preprint · arXiv:2607.04412 · Under Review
Abstract▾
We describe the reconciliation protocol used by BoSC3 to maintain a coherent command picture across mesh partitions lasting hours to days. Rather than blocking on quorum, nodes accept locally-ordered tasking and reconcile through a causal merge with operator-visible conflict surfacing. We report reconciliation behaviour across a 72-hour denied-communications field exercise and characterise the conditions under which manual adjudication becomes necessary.
UE-RES-2026-010Standards contributionAdviQ
Jun 2026S. Malviya, C. V. Ghate
Submitted contribution · working group review
Abstract▾
A CBOM is only useful across an organisational boundary if the receiving party can interpret asset ownership and exposure claims without out-of-band context. We propose three additions to the interchange schema covering custody attestation, exposure-lifetime annotation, and a deprecation channel for algorithms withdrawn mid-programme, and discuss migration impact for institutions already producing inventories under the current draft.
UE-RES-2026-007WhitepaperStamBH
Apr 2026U. Wad, B. Shrirame, N. Randive
UElement technical whitepaper, second edition
Abstract▾
Passive monitoring is frequently sold as equivalent to active polling with fewer risks. It is not. This paper sets out precisely which OT conditions are observable from mirrored traffic across forty-one industrial protocols, which require an active query and are therefore deliberately outside our scope, and how to reason about the resulting coverage gap during a process safety review rather than after one.
UE-RES-2026-003Peer-reviewedStamBH
Feb 2026A. Kumar, B. Pancholi, U. Banerjee (external)
ACM Digital Threats: Research and Practice · doi:10.0000/uelement.2026.003
Abstract▾
Compliance evidence is typically reconstructed retrospectively from logs never designed to serve as evidence. We present an architecture in which attestable artefacts are emitted at the point of action and signed before aggregation, and evaluate storage, verification and retrieval cost against three regulatory regimes with differing retention and reporting-window requirements, including the six-hour CERT-In incident window.