Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
8-LAYER CDTDigital Twin Architecture

The Cyber Digital Twin Eight-Layer Architecture: Mathematical Formalization, Inter-Layer Transition Physics, and Quantitative Process Zone Hardening

100% Complete & Untruncated 13 min read
Return to Research Tracks

J. McKenney

This paper belongs to the Digital Twin Architecture working group and to no series of its own. A companion paper in the same group sets out the same eight-layer graph beside the McKenney-Lacan calculus that occupies its human layer, and states the four dynamical equations run over it. Two others take single sections of this one further: one treats the decision latency that section 5.1 states as an asymmetry, against a thermal cliff measured in tens of seconds, and one treats tier classification, redundancy topologies and common-mode failure. The five-part Fooled by Best Practice series in the same group argues in ordinary language why a distribution rather than a score is the right thing to report.

Licence: CC BY 4.0. 14 June 2026.

Executive Abstract#

The Cyber Digital Twin models critical infrastructure as one coupled dynamical system on a multi-relational knowledge graph, binding equipment thermodynamics, network conduits, firmware, operator cognition and economic signals. Its eight layers read the same for an executive, an auditor, an underwriter and a graph engine, and the foundational split between plant and controllers is load-bearing.

The architecture is built for the traversal between layers: an attack is a path across layers, its probability the product of each step. Two numbers place the facility, whether lateral code dies out or sustains itself and whether the plant rests in a stable basin or at the edge of a fold.

The paper runs this on a chemical process zone modeled twice, once as commonly built and once with a one-way optical link and write-dropping conduit, a pneumatic line from transmitter to blowdown valve bypassing software, and cold-boot firmware attestation. End-to-end probability falls from 45.04 percent to two parts in ten million. Severity does not move, the same equipment destroyed and the same 45-day outage; only frequency does, and annual loss expectancy falls from thirteen point two million dollars a year to single dollars, against a three-year cost under six hundred fifteen thousand dollars.

Abstract#

The Cyber Digital Twin is formalized as a coupled dynamical system over a multi-relational knowledge graph in eight layers: L1 facility and equipment catalog, L2 equipment, systems and networks, L3 software, SBOM and exposure surface, L4 threats and adversary manifold, L5 human and psychometric dynamics, L6 telemetry and geopolitical drivers, L7 economic and actuarial, and L8 predictive and temporal dynamics by Hawkes point processes. Transitions follow a calibrated Markov chain, so an attack path of length k carries an end-to-end probability equal to the product of its conditional transitions. Two parameters are tracked: the network reproduction number, the adjacency spectral radius times the transmission-to-recovery ratio, and the Seldon Crisis Parameter, a normal-form bifurcation whose sign decides stability. Applied to an autoclave polymerization zone at ATQ 88.4, the baseline composes to 45.04 percent at spectral radius 2.74. With the two external transitions fixed, applying unidirectional telemetry, a read-only hardware conduit, a hardwired pneumatic interlock and cold-boot attestation, it falls to 2.227x10^-7 at spectral radius 0.29. Single loss expectancy holds at $24.5 million while annual loss expectancy falls from $13.2 million to single dollars, the rational spend bounded by Gordon-Loeb. Three constraints close the paper: the physics-cognitive latency asymmetry (a 12-45 s runaway against a 65-180 s operator), heuristic reconstruction of legacy drawings with per-node confidence, and an air-gapped island mode under four invariants.


1. Platform Taxonomy: The L1-L8 Layer Model#

The model organizes facility operations into eight functional layers for risk governance, audit reporting, and executive decision-making:

  • L1 Facility & Equipment Catalog: Physical plant topology, piping, vessels, rotating machinery, and containment envelopes, held against the reference model of the same plant so that the designed facility and the operating facility are separate objects. Ingests computer-aided design artifacts, including DEXPI 2.0 and ISO 15926-4 Proteus XML exports.
  • L2 Equipment, Systems & Networks: Industrial control networks, routing tables, fieldbuses (Modbus, OPC-UA, DNP3, PROFINET), firewalls, VLANs and jumpboxes, and the controllers on them: PLCs, RTUs, distributed control systems (DCS), safety instrumented systems, and human-machine interfaces, each carried at serial-number granularity.
  • L3 Software, SBOM & Exposure Surface: CycloneDX 1.6+ software bills of materials and their transitive dependencies, firmware images, and VEX and CSAF advisory streams, together with the active exposures across the software and hardware stack, continuously updated with 30-day Exploit Prediction Scoring System (EPSS) velocity vectors and CISA Known Exploited Vulnerabilities (KEV) catalogs without active scanning.
  • L4 Threats & Adversary Manifold: Adversary registry profiling 389 state and criminal groups. Ingests the TACAM 7-dimensional spectral matrix (77,279 relational edges) and computes a cardinal Actor Threat Quotient (ATQ∈[0,100]\text{ATQ} \in [0, 100]) measuring adversary tool weaponization and sector affinity.
  • L5 Human & Psychometric Dynamics: Operator and defender state under load: cognitive load, arousal, and decision latency on the recognition-primed model, together with the organizational governance and policy frameworks that set who may act and how quickly. Section 5.1 states the constraint this layer exists to measure.
  • L6 Telemetry & Geopolitical Drivers: Sensor time series, Modbus registers, and alarm and event streams, correlated against external risk drivers: regional conflict datasets (ACLED), geopolitical tension indices, supply chain bottlenecks, and energy market stress indicators that alter adversary campaign frequency.
  • L7 Economic & Actuarial: Bottom-up physical vulnerability coupled with top-down adversarial pressure. Executes 50,000 Monte Carlo runs to produce Annual Loss Expectancy (ALE), Value at Risk (VaR99.5\text{VaR}_{99.5}), Loss Exceedance Curves, and Gordon-Loeb investment boundaries [2].
  • L8 Predictive & Temporal Dynamics: Forward-looking risk projections computed via self-exciting Hawkes point processes, identifying temporal clustering in campaign preparation up to 90 days before execution.

2. Database Ontological Schema: The L1-L8 Graph Engine#

Under the hood of the Seldon graph engine, the Neo4j knowledge graph (comprising 3.2 million nodes and 85 million edges) carries the same eight layers as a registry, splitting the physical asset at the foundation from the equipment and controllers that act on it:

Graph LayerDomainCore EntitiesIngestion Standards
L1Facility & Equipment CatalogBuildings, reactors, pumps, heat exchangers, pipesDEXPI 2.0 XML, ISO 15926-4, P&ID [4]
L2Equipment, Systems & NetworksFirewalls, VLANs, jumpboxes, network interfaces, PLCs, RTUs, SIS safety logic, HMIs, DCS loopsPCAP, NetBox, LLDP, ARP tables
L3Software, SBOM & Exposure SurfaceFirmware images, packages, transitive dependencies, active exposuresCycloneDX 1.6, SPDX, CSAF 2.0
L4Threats & Adversary ManifoldState and criminal groups, campaigns, techniques, weaponized exploitsTACAM cluster tables, MITRE ATT&CK for ICS
L5Human & Psychometric DynamicsOperator cognitive load, alert fatigue, stress response, suppliers, contractors, policy frameworksSweller CLT, Klein RPD Model [1], IEC 62443-2-1, NIS2 Article 21 [3]
L6Telemetry & Geopolitical DriversSensor series, alarm streams, state actors, sanctions, critical resource flowsACLED, GPR Index, trade data
L7Economic & ActuarialALE, single loss expectancy, insurance deductiblesLloyd's Bull. Y5381, SEC 8-K [5]
L8Predictive & Temporal DynamicsHawkes arrival rates, EPSS velocity, degradation curvesTime-series materialized views

3. Inter-Layer Causal Transition Dynamics#

The core differentiator of the CDT architecture is that layers do not operate as isolated silos. Attack trajectories traverse between layers following calibrated Markov transition probabilities.

The causal chain links external tension directly to physical hardware failure and corporate capital impairment:

Geopolitical Shock (L6)⟶Adversary Campaign (L4)⟶Exposure Exploitation (L3)⟶Conduit Traversal and Control Logic Manipulation (L2)⟶Physical Rupture (L1)⟶Actuarial Loss (L7)\text{Geopolitical Shock } (L_6) \longrightarrow \text{Adversary Campaign } (L_4) \longrightarrow \text{Exposure Exploitation } (L_3) \longrightarrow \text{Conduit Traversal and Control Logic Manipulation } (L_2) \longrightarrow \text{Physical Rupture } (L_1) \longrightarrow \text{Actuarial Loss } (L_7)

The end-to-end traversal probability Π\Pi across an attack path of length kk is given by:

Π=∏m=0k−1P(Lm+1∣Lm)\Pi = \prod_{m=0}^{k-1} P(L_{m+1} \mid L_m)

The system measures global network stability through two parameters:

  1. Network Epidemic Threshold (R0R_0): The network reproduction number R0=βγλmax⁡(A)R_0 = \frac{\beta}{\gamma} \lambda_{\max}(A), where λmax⁡(A)\lambda_{\max}(A) is the spectral radius, the maximum eigenvalue, of the network adjacency matrix AA, β\beta is the pathogen's transmission rate per exposed connection, and γ\gamma is its recovery rate, the rate at which infected nodes are patched, isolated or otherwise cleared [6]. If R0>1.0R_0 > 1.0, the network is in a supercritical state where lateral malware propagation is self-sustaining. If R0<1.0R_0 < 1.0, outbreaks are strictly sub-epidemic and decay exponentially.
  2. Seldon Crisis Parameter (μ\mu): The normal-form bifurcation parameter governing phase transitions in control stability: dxdt=μ+x2\frac{dx}{dt} = \mu + x^2 When μ<0\mu < 0, the operational system resides within a stable basin of attraction. When μ>0\mu > 0, the equilibrium vanishes via a saddle-node bifurcation, resulting in a sudden transition to unconstrained physical damage.

4. Quantitative Process Zone Conduit Hardening (What-If Study)#

To demonstrate the multi-layer causal engine, we evaluate a simulated attack on Process Zone PZ-04 (Autoclave Polymerization Reactor & Mechatronic Exotherm Loop) in a continuous chemical processing facility.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

4.1 Asset Baseline#

  • Physical Asset (L1): Autoclave Reactor R-101, Feed Compressor C-102, Primary Cooling Loop CW-204, Pneumatic Emergency Blowdown Valve XV-101A/B, Mechanical Rupture Disc BD-101 (burst rating: 250 bar). Source: DEXPI 2.0 XML [4].
  • Control Systems (L2): Siemens S7-1500 PLC (v2.8 firmware) managing PID temperature loops; Schneider Electric Triconex Tricon SIL-3 Safety Instrumented System (SIS) managing high-pressure interlocks. Source: CycloneDX 1.6 SBOM.
  • Threat Actor (L4): Advanced persistent threat actor with verified capability against industrial control protocols (ATQ=88.4\text{ATQ} = 88.4).

4.2 Phase 1#

Baseline Architecture (Flat OT / Permissive Conduits)

In the baseline state, enterprise IT communicates with OT Level 3 through a dual-homed jumpbox without hardware conduit enforcement or deep-packet inspection (DPI).

Transition Probabilities:

  • P(L6→L4)=0.85P(L_6 \to L_4) = 0.85 (Geopolitical tension elevates targeting)
  • P(L4→L3)=0.78P(L_4 \to L_3) = 0.78 (Actor tooling matches exposed facility footprint)
  • P(L3→L2)=0.88P(L_3 \to L_2) = 0.88 (Jumpbox compromise and lateral pivot to OT subnet)
  • P(L2→L1)=0.92P(L_2 \to L_1) = 0.92 (Unauthenticated Modbus/TCP write commands injected into PLC suppress the cooling jacket setpoint)
  • P(L1→L7)=0.84P(L_1 \to L_7) = 0.84 (Thermal runaway follows; disc ruptures and the loss is realized)
Πbase=0.85×0.78×0.88×0.92×0.84=0.4504(45.04%)\Pi_{\text{base}} = 0.85 \times 0.78 \times 0.88 \times 0.92 \times 0.84 = \mathbf{0.4504 \quad (45.04\%)}

Topological and Stability Metrics:

  • Adjacency spectral radius: λmax⁡(A)=2.74>1.0\lambda_{\max}(A) = \mathbf{2.74} > 1.0 (supercritical epidemic regime)
  • Seldon Lyapunov parameter: μ=+0.34>0\mu = \mathbf{+0.34} > 0 (unstable saddle-node bifurcation)

Actuarial Baseline (50,000 Monte Carlo Iterations):

  • Single Loss Expectancy (SLE): $24,500,000\$24{,}500{,}000
    • Capital equipment destruction (R-101, piping, catalyst bed): $14,000,000\$14{,}000{,}000
    • Environmental remediation and regulatory penalties: $4,500,000\$4{,}500{,}000
    • 45-day unrecoverable plant outage: $6,000,000\$6{,}000{,}000
  • Annual Rate of Occurrence (ARO): 0.4504×1.2=0.5405 events/year0.4504 \times 1.2 = \mathbf{0.5405\text{ events/year}}
  • Annual Loss Expectancy (ALEbase\text{ALE}_{\text{base}}): ALEbase=$24,500,000×0.5405=$13,242,250/year\text{ALE}_{\text{base}} = \$24{,}500{,}000 \times 0.5405 = \mathbf{\$13{,}242{,}250 / \text{year}}
  • Value at Risk (VaR99.5\text{VaR}_{99.5}): $24,500,000\$24{,}500{,}000

4.3 Phase 2#

Targeted Countermeasure Run (IEC 62443-3-2 Conduits & SIL-3 Interlocks)

The digital twin tests a virtual architectural intervention prior to capital expenditure:

  1. IEC 62443-3-2 Conduit Enforcement: Unidirectional optical data diode for outbound telemetry; inline hardware DPI conduit restricting industrial traffic to read-only function codes (FC 03, FC 04) while dropping all write commands (FC 05, FC 06, FC 16) [3].
  2. Hardwired Physical Interlock: Analogue pneumatic bypass from transmitter PT-101 directly to blowdown valve XV-101A, bypassing software Ethernet layers entirely.
  3. Cryptographic Silicon Attestation: Hardware root of trust (TPM 2.0 / Caliptra) verifying cold-boot firmware integrity.

Recalibrated Transition Probabilities:

  • P′(L6→L4)=0.85P'(L_6 \to L_4) = 0.85 (External geopolitical tension unchanged)
  • P′(L4→L3)=0.78P'(L_4 \to L_3) = 0.78 (External adversary tooling unchanged)
  • P′(L3→L2)=0.035P'(L_3 \to L_2) = \mathbf{0.035} (Jumpbox isolated; management paths restricted to out-of-band VLAN)
  • P′(L2→L1)=0.0008P'(L_2 \to L_1) = \mathbf{0.0008} (Unauthorized writes dropped by physical DPI conduit)
  • P′(L1→L7)=0.012P'(L_1 \to L_7) = \mathbf{0.012} (Analogue SIL-3 interlock depressurizes reactor within 400ms)
Πpost=0.85×0.78×0.035×0.0008×0.012=2.227×10−7(0.000022%)\Pi_{\text{post}} = 0.85 \times 0.78 \times 0.035 \times 0.0008 \times 0.012 = \mathbf{2.227 \times 10^{-7} \quad (0.000022\%)}

Topological Transformation:

  • Adjacency spectral radius: λmax⁡(A)=0.29≪1.0\lambda_{\max}(A) = \mathbf{0.29} \ll 1.0 (sub-epidemic regime; cascades cannot propagate)
  • Seldon Lyapunov parameter: μ=−0.78<0\mu = \mathbf{-0.78} < 0 (strongly stable fixed-point attractor)

4.4 Phase 3#

Actuarial Comparison and Financial Return

Risk & Financial MetricBaseline (Flat OT Topology)Hardened Conduits (IEC 62443-3-2)Variance / Delta (Δ\Delta)
Spectral Radius λmax⁡(A)\lambda_{\max}(A)2.742.74 (Supercritical)0.290.29 (Sub-epidemic)−89.4%-89.4\%
Seldon Bifurcation μ\mu+0.34+0.34 (Unstable)−0.78-0.78 (Stable Attractor)Phase Transition to Safety
End-to-End Breach Probability (Π\Pi)45.04%45.04\%0.000022%0.000022\%99.99995%99.99995\% Reduction
Single Loss Expectancy (SLE)$24,500,000\$24{,}500{,}000$24,500,000\$24{,}500{,}000$0\$0 (Physical consequence static)
Annual Rate of Occurrence (ARO)0.54050.5405 events/yr0.000000270.00000027 events/yr−99.99995%-99.99995\%
Annual Loss Expectancy (ALE)$13,242,250/yr\$13{,}242{,}250 / \text{yr}$6.55/yr\$6.55 / \text{yr}−$13,242,243/yr-\$13{,}242{,}243 / \text{yr} (99.9999%99.9999\%)
Value at Risk (VaR99.5\text{VaR}_{99.5})$24,500,000\$24{,}500{,}000$0.00\$0.00−$24,500,000-\$24{,}500{,}000

Capital Allocation Optimization (Gordon-Loeb Theorem): The Gordon-Loeb theorem bounds the rational cybersecurity investment budget z∗z^* as [2]:

z∗≤1e⋅v⋅L≈0.3679×ΔALE=0.3679×$13,242,243=$4,871,821z^* \le \frac{1}{e} \cdot v \cdot L \approx 0.3679 \times \Delta\text{ALE} = 0.3679 \times \$13{,}242{,}243 = \mathbf{\$4{,}871{,}821}
  • Total 3-Year Implementation Cost: $615,000\$615{,}000 (Diode and DPI hardware $165,000\$165{,}000; SIL-3 pneumatic actuator retrofit $215,000\$215{,}000; engineering attestation $40,000\$40{,}000; annual maintenance and cryptographic audit $65,000/year\$65{,}000/\text{year}).
  • Return on Security Investment (ROSI): ROSI=ΔALE3yr−CostCost=($13,242,243×3)−$615,000$615,000=6,359%\text{ROSI} = \frac{\Delta\text{ALE}_{3\text{yr}} - \text{Cost}}{\text{Cost}} = \frac{(\$13{,}242{,}243 \times 3) - \$615{,}000}{\$615{,}000} = \mathbf{6{,}359\%}
  • Underwriting Realization: The state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 [5] requires stays in the wording; what the evidence package moves is the underwriter's frequency and severity view, which compresses the plant deductible from $5,000,000→$500,000\$5{,}000{,}000 \to \$500{,}000, and reduces operational interruption insurance premiums by $1,200,000/year\$1{,}200{,}000/\text{year}.

4.5 Graph Database Engine Traversal Query#

cypher
// Seldon 8-Layer Multi-Relational Path Traversal Query
MATCH path = (geo:GeopoliticalFactor {zone: "Petrocorridor-EU"})
  -[:AMPLIFIES]-> (actor:ThreatActor {archetype: "Volt Typhoon / Sandworm"})
  -[:WEAPONIZES]-> (vuln:Vulnerability {cve: "CVE-2024-XXXX"})
  -[:CROSSES_BOUNDARY]-> (conduit:NetworkConduit {zone_from: "IT_L3", zone_to: "OT_L2"})
  -[:INJECTS_COMMAND]-> (plc:Controller {tag: "PLC-R101-S71500"})
  -[:DRIVES_TRANSIENT]-> (equip:PhysicalAsset {tag: "R-101", standard: "DEXPI-2.0"})
  -[:TRIGGERS_LOSS]-> (loss:EconomicImpact)

WITH path,
     reduce(p = 1.0, r in relationships(path) | p * r.transition_probability) AS cumulative_prob,
     loss.direct_damage + loss.business_interruption AS single_loss_expectancy

RETURN 
  [n in nodes(path) | labels(n)[0] + ":" + coalesce(n.tag, n.cve, n.name, n.archetype)] AS attack_chain,
  cumulative_prob AS traversal_probability,
  single_loss_expectancy AS sle,
  cumulative_prob * single_loss_expectancy * 1.2 AS annual_loss_expectancy;

5. Architectural Extensions & Operational Constraints#

To address real-world deployment across legacy brownfield facilities, the CDT framework incorporates three operational constraints:

5.1 The Physics-Cognitive Latency Asymmetry (τphys≪τhuman\tau_{\text{phys}} \ll \tau_{\text{human}})#

Industrial safety is governed by physical time constants. In rapid runaway reactions, the physical excursion time constant satisfies:

τphys≈12−45 seconds\tau_{\text{phys}} \approx 12 - 45 \text{ seconds}

In contrast, human operators experiencing alarm flood in control rooms exhibit mean decision latencies governed by Gary Klein's Recognition-Primed Decision (RPD) model [1]:

τhuman≈65−180 seconds\tau_{\text{human}} \approx 65 - 180 \text{ seconds}

Because τhuman>τphys\tau_{\text{human}} > \tau_{\text{phys}}, human intervention during an active control-plane attack is mathematically incapable of arresting catastrophic overpressurization. This latency gap proves why software-only security fails and why hardwired, un-routable SIL-3 physical trips are mandatory.

5.2 Heuristic Reconstruction of Legacy Brownfield CAD#

Operating industrial facilities frequently lack pristine DEXPI 2.0 XML exports, relying instead on legacy scanned piping and instrumentation diagrams (P&IDs). The CDT resolves this through computer vision and symbol graph extraction:

  1. Optical character and glyph recognition extracts equipment tags, flow arrows, and valve types from scanned raster drawings.
  2. The ingestion pipeline infers conduit boundaries and creates synthetic DEXPI 2.0 graph nodes with a confidence score C∈[0,1]C \in [0, 1].
  3. Missing parameter fields inherit conservative default physics values from standard process engineering reference manuals.

5.3 Sovereign Air-Gapped Operation & Update Invariants#

For nuclear facilities, defense infrastructure, and classified environments where cloud connectivity is prohibited, the CDT runs in Island Mode:

  • The digital twin operates entirely on local, on-premise hardware without external network interfaces.
  • Threat intelligence updates (TACAM) and vulnerability feeds are transferred periodically via physical, cryptographically signed tokens.
  • The system enforces four operational invariants:
    1. Passive ingestion only: Zero packets sent to operational field networks.
    2. Write boundary isolation: No automated remote changes to PLC logic or safety interlocks.
    3. Deterministic replay: Graph simulations must produce identical state transitions from identical input seeds.
    4. Hardware attestation: Firmware images validated against silicon root of trust signatures on cold boot.

6. References#

  • [1] Klein, G. (1998): Sources of Power: How People Make Decisions. MIT Press.
  • [2] Gordon, L. A., & Loeb, M. P. (2002): "The economics of information security investment." ACM Transactions on Information and System Security, 5(4), 438-457.
  • [3] IEC 62443-3-2 (2020): Security for industrial automation and control systems, Part 3-2: Security risk assessment for system design. International Electrotechnical Commission.
  • [4] DEXPI e.V. (2025): DEXPI 2.0 Specification: Process and Plant Model Integration. Data Exchange in the Process Industry.
  • [5] Lloyd's (2022): Market Bulletin Y5381: Cyber-attack exclusions. Corporation of Lloyd's, 16 August 2022. The model wordings drafted to meet it are the Lloyd's Market Association's clauses LMA5564 to LMA5567, November 2021.
  • [6] Van Mieghem, P., Omic, J., & Kooij, R. (2009): "Virus spread in networks." IEEE/ACM Transactions on Networking, 17(1), 1-14.
Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 21,852 chars