background gif
ENI6MA

Attacks · By business pattern

Patterns overview

How attack families show up across product and ops patterns. Each pattern page names which conversion steps matter - ambient harvest, replay, relay, tamper, phish - and links into Channel, Credentials, and Replay families with mechanism-first dual plates, not residual-risk sidebars.

~5 min readContinue: APIs & workloads

Opening

What the attacker wants

Patterns are lenses, not separate cryptosystems. Buyers arrive with a deployment context - API keys, agents, human login, certificates, air-gaps, content backends, regulated reviews - and need to know which attack families dominate that context and which mechanisms deny the conversion from surface observation into lasting authority.

How it works today

Ambient deployments teach the wrong lesson: every pattern looks like “protect the secret store.” ENI6MA patterns instead name defined conversion steps - ambient bearer harvest, replay of spent envelopes, relay of unbound tokens, post-mint request tamper, phishing of reusable factors - and deep-link the family pages that deny each step at the gate or on the channel.

Why it fails against one-shot proofs

Use the hub plate to pick a context, then read the linked families for dual-plate teaching: ambient success path versus mechanism denial. Residual Limits essays stay deferred; keep honesty language on Technology Claims when reviewers ask for walls and claim IDs.

Patterns hub

How to read: each pattern card names the families that dominate that estate. Takeaway: patterns are lenses, not new cryptosystems.

Each card is a buyer context - not a new protocol - naming the families that matter there.

Attack family map

How to read: scan Channel, Credentials, Replay/relay columns then mechanism badges. Takeaway: family-level mechanism denial, not a stage dump.

Return to the family map when you need mechanism detail instead of estate language.

Where it shows up

Watch it fail

Go deeper