The machine clock.
Every month there are more agents that move on their own: robotaxis, USVs, drones, delivery robots, autonomous machinery. Each one has to interact with infrastructure it does not own.
R2I Protocol · Robot-to-Infrastructure
Signed identity, authorization and evidence between the agents that move — vehicles, robots, drones, machines, accredited people — and the infrastructure that receives them: doors, barriers, cranes, docks, lifts, charging points.
A barrier opens because someone opens it. A crane receives an order and does not ask where it came from. A truck enters because its plate is on a list. An autonomous vehicle arrives at a facility that does not know who it is, who operates it or what it is authorized to do. For decades that was enough, because there was always a person on the other side. Now there is not always one.
The question is no longer “does it have a badge?”, but “who or what is requesting this action, who answers for it, is it authorized here and now, and how do we prove it afterwards?”.
Every month there are more agents that move on their own: robotaxis, USVs, drones, delivery robots, autonomous machinery. Each one has to interact with infrastructure it does not own.
eIDAS2 brings verifiable identity to Europe; NIS2 and IEC 62443 harden critical infrastructure. Machine identity stops being an integration detail.
Insurers, regulators and customers no longer accept reconstructions: they require proof of who did what. Evidence stops being desirable and becomes mandatory.
Issuer and node verify each other's identity with professional cryptography (mTLS 1.3, ECDSA P-256 signatures). A copied, lent or spoofed credential stops working.
The node checks that whoever authorizes is whoever is actually there. No authorization by list, and none at a distance.
Person or machine, role, zone, time window, evaluated against the live state of the facility. Whatever falls out of scope is rejected at the door, not discovered in the report.
The lost credential, the finished assignment, the declared incident: revoked across the whole facility in seconds, enforced by every node.
The decision is evaluated locally and cannot be overridden from outside. On failure or silence, the node falls back to the safe state the operator defines — with one absolute exception: no emergency exit is ever made conditional.
Post-quantum resistance for evidence that has to last years · defence against tampered agents · offline mode to operate without a network.
The information systems (management, planning, ERP, TOS, PCS). Their raw material is data; when they fail, information is lost. They are updated every week.
Cranes, barriers, locks, pumps, PLCs, actuators. Their raw material is physical fact; when they fail, someone gets hurt. Twenty-five-year-old equipment, slow change, historically separated networks.
Of the two is the great industrial ailment of the decade (NIS2, IEC 62443): every point where the world that knows touches the one that moves is a door — and today it is crossed on trust.
URBANODE is neither IT nor OT: it is the verifiable border between the two. Never inside the control loop; always at the crossing, signing it.
Automatic, signed settlement of the energy session is validated end to end in production. Every vehicle, robot or machine charges against a signed identity, and the session is settled attributably to its owner, its function or its customer. This is not a laboratory promise: it is the circuit that already works.