← Research

LTR-2026-04 · Technical Report · July 2026

Contextual Evaluation under Encryption

Abstract

Encryption is arriving in operational technology. Protocols that historically carried control traffic in clear, from Modbus/TCP to native controller interfaces, are being superseded by authenticated, encrypted channels: OPC UA with security policies, Modbus/TLS, and vendor Web APIs over HTTPS. This shift protects the confidentiality and integrity of the channel. It does not address the question the Liscere framework was built around: whether a protocol-compliant, authorised action is appropriate to the operational context in which it occurs. A competent adversary arriving through legitimate means, now over an encrypted session, still issues commands that are individually valid, authorised, and within range, and so indistinguishable, action by action, from a legitimate operator.

This report characterises one such encrypted channel in hardware, the Web API of a Siemens S7-1200 G2 controller (JSON-RPC over HTTPS/TLS 1.3), and reports what an external observer can and cannot recover from it. The findings are specific and, in one respect, uncomfortable. Under TLS 1.3, a strictly passive observer on a mirror port, the observation architecture validated for Modbus/TCP in the preceding report, is blind to the payload: the method, the target artefact, the value, and the session token are all opaque, and the server certificate itself is encrypted. A traffic-metadata sensor that survives encryption, keyed on record sizes and timing, detects bursts of activity but is unreliable for the isolated, well-chosen write that defines the adversary Liscere is concerned with. We then establish, through a decrypted vantage used as an offline validation method only, that the process variable required for contextual evaluation is recoverable at a workable rate, that the process of the preceding report can be ported onto this channel unchanged, and that an authorised control action can be captured in two distinct operational phases.

The contribution is not a demonstration that contextual evaluation runs on this channel; it is the isolation of the problem that must be solved before it can. Passive observation of payload is physically impossible under strong transport encryption, so the observation vantage, not the evaluation core, is what an encrypted channel changes. This reframes the central dependency of the approach: the core that judges coherence is protocol-independent, while the vantage from which it draws its evidence is contingent on the channel. Stating this precisely, and grounding it in hardware measurement, is the necessary step before positioning the framework across the encrypted protocols that will dominate operational technology. The report closes by setting out the research fronts this opens: a landscape study of encrypted OT protocols, the positioning of the framework at the point of legitimate decryption, and the longer horizon of post-quantum cryptography.

Open the PDF ↗

Cite this report

@techreport{salmazo_encryption_2026,
  author      = {Bruno Salmazo},
  title       = {Contextual Evaluation under Encryption},
  institution = {Liscere},
  year        = {2026},
  month       = jul,
  number      = {LTR-2026-04},
  type        = {Technical Report},
  url         = {https://liscere.com/research/ltr-2026-04/}
}

Preview unavailable on this device. Open the full PDF.

Open full PDF ↗

Liscere 2026