The Storage-First
Energy Platform
Platform Whitepaper (0.2.8)
1. Abstract & Introduction
The CitizenSolar platform formalizes a storage-first Energy-as-a-Service framework. This white paper outlines a system for community-governed energy deployment, moving beyond extractive legacy-utility models toward a resilient, auditable Energy Commons.
Traditional electrical grids rely on monolithic, top-down control systems that are inherently fragile to cyber-physical disruption. CitizenSolar is presented here as a storage-first distributed energy platform that combines hardware-rooted trust, trusted telemetry, Community Energy Bank architecture, and operator software for resilient local and regional coordination.
Key_Architectural_Pillars
Hardware Finality: Silicon-rooted trust prevents telemetry spoofing via post-quantum enclaves.
Commercial Discipline: Storage, software, services, and Community Energy Bank operations remain the primary value surface; SSRL stays secondary as constrained utility infrastructure.
Ethical Anchoring: The ζπθ filter applies participation and governance rules through auditable community logic.
Autonomous Resilience: Swarm-based solvers ensure local mesh stability during regional grid blackouts.
| Term | Definition |
|---|---|
| cVPP | Community Virtual Power Plant – A multi-actor DER network governing energy flows via local sub-consensus. |
| DFT | Distributed Frontier Technology – The hardware-software standard for sovereign physical infrastructure. |
| zk-Telemetry | Privacy-preserving energy metadata verified through recursive SNARK/STARK circuits. |
| ζπθ | Zeta-Pi-Theta: The programmable ethical logic gate controlling governance participation and utility eligibility. |
2. Hardware Architecture
The physical layer of CitizenSolar is defined by the SolarEye hardware family. These are secure grid-edge controllers and telemetry anchors for storage, DER, and community-energy operations. Each node is provisioned with a secure element that supports device-level signing and trusted operating identity for audit-oriented telemetry workflows.
SolarEye 100
SE100Deployment Class: EDGE
Hardware Trust Primitives
Technical Specifications
Architecture Components
- ARM Cortex-M85
- NXP EdgeLock SE050F
Supported Protocols
SolarEye 1000
SE1000Deployment Class: AGGREGATOR
Hardware Trust Primitives
Technical Specifications
Architecture Components
- Intel Xeon D-2800
- TPM 2.0 (ECC)
Supported Protocols
Silicon Root of Trust (RoT)
CitizenSolar is designed to reduce telemetry spoofing risk by utilizing Physical Unclonable Functions (PUF). Every SolarEye node has a unique hardware-derived identity anchor, helping operators distinguish genuine field devices from cloned or emulated endpoints.
Cryptographic Hardware Anchors
Our hardware roadmap includes ML-KEM-1024-class post-quantum migration paths so identity anchors can remain viable across long-lived energy-infrastructure deployments.
3. Software & Intelligence Layer
The CitizenSolar software layer is designed to coordinate storage assets, DER telemetry, and operator workflows across distributed-energy deployments. This operating layer turns field telemetry into actionable operational visibility, control, and planning support.
The Operational Trust Stack
CitizenSolar implements a layered trust strategy to mitigate cyber-physical risks. The stack is intended to help sites maintain observability, controlled updates, fallback behavior, and audit-oriented telemetry even when individual edge devices or links are degraded.
Operational Trust Stack
Platform architecture 0.2.8
The Autonomous Swarm (MAS)
The platform model includes a set of specialized software agents for forecasting, anomaly detection, and operating guidance. These components are intended to support local optimization, reserve-state modeling, and site-level control without overstating current autonomous market participation.
"Detects anomalous telemetry patterns, validates proof expectations, and raises operator-visible integrity alerts."
"Tracks capital state and aligns capital movement with verified deployment milestones and quorum-approved policy."
"Balances operator participation and energy-routing priorities to preserve resilience during changing demand conditions."
"Turns platform events into legible audit trails for operators, capital partners, and governance reviewers."
"Bridges platform state with human operators so deployment, maintenance, and escalation remain synchronized."
4. Security Architecture & Trust Controls
The attack surface of a distributed-energy platform is multi-dimensional, ranging from physical device tampering to firmware and telemetry compromise. CitizenSolar treats infrastructure security as a foundational design requirement, using a defense-in-depth model anchored in hardware identity and controlled operations.
Threat Landscape Assessment
The platform is designed for environments where edge devices may be exposed, remote links may be monitored, and firmware processes must be tightly controlled. We explicitly address:
- Telemetry Hijacking:
- Reduction of spoofing risk through signed, device-bound telemetry workflows.
- Firmware Disruption:
- Controlled update paths and approval logic to reduce unauthorized code deployment risk.
- Privacy Leakage:
- Architecture direction toward selective disclosure and privacy-preserving telemetry handling.
- Identity Abuse:
- Hardware-bound identity and operator-role controls designed to limit unauthorized participation.
Cryptographic Primitives
The CitizenSolar stack uses a tiered suite of cryptographic primitives selected for edge performance, trusted device operation, and a migration path toward post-quantum assurance.
| Term | Definition |
|---|---|
| SHA-3 / Keccak-256 | Deterministic hashing for telemetry records, integrity checks, and audit-oriented state summaries. |
| Ed25519 | Fast elliptic-curve signatures for device identity and secure session establishment. |
| Selective Proof Systems | Roadmap direction for compact attestations without exposing unnecessary raw operational data. |
| ML-KEM-1024 | Post-quantum key encapsulation candidate for future secure transport and long-lived infrastructure identity protection. |
Silicon Root of Trust (RoT)
Hardware isolation is a core trust requirement for secure energy operations. CitizenSolar SolarEye nodes implement RoT-oriented patterns via specialized secure elements, providing:
Secure Element Enclave
Keys are intended to remain inside the silicon boundary. Signing and identity-handshake logic are isolated from the main application processor.
PUF Identity
Physical Unclonable Functions generate a unique fingerprint for every chip, helping reduce mass-cloning and supply-chain spoofing risk.
Regulatory Alignment Direction
CitizenSolar is being structured with reference to frameworks such as the EU Network and Information Security Directive (NIS2) and the Cyber Resilience Act (CRA). This includes roadmap attention to SBOM transparency, coordinated vulnerability disclosure, and resilient site-level fallback behavior. It should not be read as a claim of certified compliance.
5. Governance Model
CitizenSolar is governed by a distributed, layered, and programmable sovereign model. This embeds programmable ethics, local autonomy, and identity-aware participation at every layer.
Core Parameters
- Quorum99%
- Emergency Quorum99.9%
- Multisig Threshold51
Governance Roles
| Term | Definition |
|---|---|
| Node Operator | Maintains physical grid segments and mesh telemetry integrity. |
| Platform Auditor | Verifies recursive zk-proof integrity and ethics compliance logs. |
6. SSRL Utility And Governance Logic
The Sovereign Regenerative Ledger (SSRL) token is documented in this release as a constrained utility, governance, access, and staking layer. It is not presented here as the primary public consumer settlement asset. Storage rights, reserve shares, dispatch credits, and community allocations are treated as non-speculative operating constructs within the Community Energy Bank architecture.
Economic Utility Reference
Y (Yield): Real-time verified energy generation (kWh).
E (Ethics): ζπθ compliance score [0.75 - 1.0].
R (Reputation): Historical node stability index.
V (Volatility): Grid/Market deviation factor.
This formula ensures that any modeled utility issuance remains bounded by ethical contribution and grid stability, preventing speculative decoupling.
Constrained Utility Envelope
SSRL follows a constrained utility schedule. Any modeled issuance is bound to attestation, governance, and contribution logic rather than positioned as public settlement infrastructure. The commercial center of gravity remains storage, operator software, and Community Energy Bank coordination.
Illustrative Attestation Gates
The platform models a set of gates that a contribution must clear before SSRL-related utility issuance is triggered. These are shown as governance and attestation logic, not proof of live public consumer settlement:
pledge_verifiedzk_proof_okethics_ok >= 0.92dao_quorum_finalized7. Regulatory & Compliance Framework
CitizenSolar is designed for global compliance, incorporating principles from major regulatory frameworks to ensure long-term viability and trust. Our architecture anticipates and addresses key legal and ethical considerations in data privacy, financial regulation, and AI governance.
EU: GDPR
Privacy posture is documented around minimized personal data exposure and local identity boundaries.
- Minimal personal data handling
- Local identity enclaves
EU: MiCA
Documentation notes where digital-asset and governance framing may need future legal review.
- Issuance framing discipline
- Governance accountability