Technical evaluation · satellite / launch / ground-segment / constellation
Five space-domain primitives, one PUF-anchored chain.
For satellite operators, launch providers, ground-segment engineers, and constellation architects evaluating signal integrity, command authentication, and forensic posture. Five reproducible Python scenarios: (1) LEO L-band link recovery under scintillation + jamming + station tamper, (2) GPS / GNSS spoofing detection, (3) launch-vehicle telemetry forensic time-pinpoint, (4) 21-satellite constellation Byzantine fault tolerance, and (5) anti-jam recovery across five jamming waveforms. Headline: 99.7 % GPS spoof detection at +10 dB spoofer advantage (Wilson 95 % CI [99.5 %, 99.8 %], N = 5,000), 75 × sharper launch-anomaly pinpoint , 28.6 % constellation Byzantine tolerance , 178× faster Moon auth + 18,000–134,000× at Mars vs. NASA DSN ground-correlation (light-time independent spacecraft-side seal).
Request engineering briefing Read the whitepaper
§0 · Reader's note — what is and is not claimed
Two independent value props across five scenarios. Evaluate them separately.
(1) Per-scenario domain accuracy (S1 – S5). Each scenario instantiates the same primitive (modal decomposition + verified-prior recursive smoother) in a different threat model — L-band link, GNSS spoofing, launch forensic, Byzantine consensus, anti-jam waveforms. Headline metrics ("100% spoof detection at +10 dB", "75× sharper launch pinpoint", "28.6% Byzantine tolerance") are simulation under stated channel models with explicit Monte Carlo counts and seeds. Production deployments need pilot validation against real Galileo OS-NMA hardware, NASA DSN telemetry recordings, and operational constellation consensus logs.
(2) PUF-anchored chain primitive (cross-cutting). The FPGA-PUF sealed transition hash chain + multi-party offline verification (XC4) + N=5 odd-N quorum (XC9) is the standalone licensable asset that appears in every scenario. It is the same primitive, instantiated at five different frame rates and consensus structures. A space partner sceptical of any individual scenario's hypothesis can still adopt the chain primitive standalone — it is the substrate, the scenarios are demonstrations.
Five scenarios, one primitive. Each scenario answers "does the primitive hold in this threat model?" — not "is this number production-ready tomorrow?". See §11 limitations.
⚡ Signal / Data Restoration
One primitive: modal decomposition + verified-prior smoother + PUF-anchored chain.
Patent core claim — "recover original modal information from broken received signal via medium forward model + integrity-anchored prior" — applies identically to L-band downlink (scenario 1), GNSS authentication (scenario 2), launch telemetry forensic (scenario 3), constellation consensus (scenario 4), and anti-jam across waveform families (scenario 5).
§1 · Why a satellite / launch / ground-segment team should read this
Anti-jam, anti-spoof, audit-grade — across five independent scenarios.
Each scenario isolates one threat or one operational requirement. All five share the same underlying primitive — only the channel model, the metric, and the consensus structure change. This is the structural advantage of the cross-cutting claim set: one Python kernel, five independent space-domain instantiations.
S1 · L-band link recovery
GISM-class ionospheric scintillation (Knepp / WBMOD / Conker channel model). Across 3 in-scope regimes (mid-lat 37° N / auroral G1–G2 storm / equatorial bubble) under 5-receiver fair-test ablation (R0 textbook / A+ real 1-D Kalman per Anderson-Moore 1979 / B− real 32-mode Chladni modal / R1 std / R1+AI dispatch per Vilà-Valls 2020 NAVIGATION 67(3) §3 — KF + R-weighted for moderate, Particle filter per Closas 2012 for strong S4≥0.7), R0→R1+AI BER reduction = 83 % – 99 % range (typical mid-lat / auroral ≥ 95 %, equatorial S4=1 ≥ 80 % with Particle-filter dispatch — see §11 honest-limits for run-to-run variance). The 4th regime — NOAA G3+ super-storm (Kp ≥ 7) — is explicitly excluded from the baseline mean per honest-statistics principle; it triggers a chain-only ALARM (no Rail). Jamming-window BER recovers to 0 , tamper detected within 1 frame .
S2 · GPS / GNSS spoofing
At +10 dB spoofer advantage, R0 memoryless correlator locks onto the spoof 99.2 % of trials (95 % CI [98.9 %, 99.4 %]); R1 PUF-chain detects the forgery 99.7 % of trials (95 % CI [99.5 %, 99.8 %]) at 0.1 % false-alarm rate (95 % CI [0.06 %, 0.18 %]) under authentic-only — N = 5,000 Wilson. Cold-start authentication latency vs Galileo OS-NMA: 56× – 17,500× faster depending on OS-NMA mode × Axowl source rate (full matrix in §6.5).
S3 · Launch-vehicle forensic
1st-stage chamber-pressure anomaly at T+45.000 s. R0 raw-CSV post-flight pinpoint ≈ 1 500 ms. R1 chain-anchored pinpoint = 20 ms (75 × sharper) . Tamper-evident against OEM-side rewrite.
S4 · 21-satellite Byzantine tolerance
PBFT-style consensus with PUF-anchored per-satellite identity. Constellation survives up to 28.6 % compromised satellites (6 of 21). No-chain baseline collapses below 10 % Byzantine.
S5 · Five jamming waveforms
Partial-band / CW / swept / pulsed / full-band noise. R1 reduces consensus BER 41 – 79 % across all five — including against full-band 20 dB noise (the hardest case).
Radiation-tolerant payload
Same primitive runs on AWS F2 FPGA in ground lab today; production target is a rad-tolerant FPGA (Microchip RTG4, AMD/Xilinx KU060-class) for on-orbit payload integrity.
S2.6 · Deep-space (Moon, Mars, beyond)
Across light-time scales, ground-side auth is bound by round-trip light-time (Moon 2.56 s, Mars 6 – 44 min, Jupiter 70 min). Axowl per-frame chain at the spacecraft is light-time independent — at Moon 178× faster than NASA DSN ranging; at Mars 18,000 – 134,000× faster . Throughput today: a 7 Mbps X-band lunar downlink is operationally demonstrated (1080p live possible); NASA LLCD demonstrated 622 Mbps laser to Moon (4K multi-stream).
§2 · Experimental setup
One Python kernel, five scenarios, deterministic.
Single-file Python script under /scripts/demo_space/space.py with seed 20260513. Each scenario builds on the same primitive: modal-decomposition channel estimator + verified-prior recursive smoother + PUF-anchored HMAC chain + K-of-N consensus. Monte Carlo counts per scenario: S1 60 trials / S2 800 trials / S3 deterministic single trace / S4 600 trials / S5 40 trials per profile.
S1 Orbit / geometry
550 km LEO, semicircular pass, peak elevation 85°, 480 s total, 600 frames at 1.25 Hz
S1 RF link
1.5 GHz L-band, 1 MHz channel, BPSK uncoded, 0.5 W TX + 6 dBi patch, 20 dBi RX, 2.5 dB NF, 220 K T sys
S2 Spoofer
Sweep over −3 … +20 dB power advantage above authentic GPS, 5,000 Monte Carlo trials per power point (was 800, Option C stream 1 upgrade). R1 = Galileo OS-NMA-style per-frame signature verified against PUF-anchored authority chain
Monte Carlo counts (post Option-C stream 1)
S1 = 1,000 trials / frame · S2 = 5,000 / power point · S4 = 5,000 / Byzantine fraction · S5 = 1,000 / jam waveform · S2.5 OS-NMA = 5,000 TTFAF draws
95 % confidence intervals
Wilson score on binomial rates (lock %, detect %, alive %, false-alarm %); bootstrap percentile (n_boot = 2,000, Efron–Tibshirani) on BER means and reduction ratios; empirical 2.5 / 97.5 percentile on lognormal TTFAF samples
S3 Launch
50 Hz frame-rate telemetry, 90 s flight, 1st-stage chamber pressure with 1.5 s exponential anomaly starting at T+45.000 s. R0 = raw CSV with OEM-controlled timestamps; R1 = HMAC chain at 50 Hz seal rate
S4 Constellation
N = 21 satellites, PBFT tolerance K = ⌊(N−1)/3⌋ = 6. Sweep Byzantine fraction 0 → 50 %. R0 = simple-majority with possible impersonation; R1 = PUF-keyed per-satellite signature
S5 Jamming waveforms
Partial-band (12 dB, 55 % duty) / CW (8 dB, 95 % duty) / swept (10 dB, 50 % duty) / pulsed (15 dB, 30 % duty) / full-band noise (20 dB, 100 % duty)
Chain primitive (all scenarios)
HMAC-SHA256 with 256-bit PUF-derived key per source (station / satellite / booster), transition hash chain at the natural frame rate of each scenario
Reproducibility
seed = 20260513, fully deterministic. Single-file Python under /scripts/demo_space/space.py
§3 · Scenario 1 — LEO L-band link budget
Clean, with scintillation, with scintillation + jamming.
§3.5 · GISM-class ionospheric channel model — Option C stream 2
From analytic Nakagami → academic-grade scintillation channel.
The S1 link sits inside an ionospheric scintillation channel . Earlier iterations used a simple analytic Nakagami-m model with an empirical S4-vs-elevation curve. Stream 2 of Option C upgrades this to a GISM-class channel grounded in the published literature:
Knepp 1983 — Nakagami-m amplitude fading with m = 1/S4², the textbook mapping from scintillation index to fading severity ( IEEE Trans. Comm. ).
WBMOD (Secan et al., 1995) — the Wideband Model of Equatorial Ionospheric Scintillation, providing S4 frequency dependence (S4 ∝ f −1.5 ) and TEC-to-S4 calibration.
GISM (Conker et al., 2003) — the Global Ionospheric Scintillation Model, ESA's reference channel for satellite-receiver simulation.
ITU-R P.531 — ionospheric propagation data and prediction methods, used for obliquity factor and TEC-along-IPP geometry.
Channel parameters along the 550 km LEO pass
Channel parameter
Value along this pass
Reference / formula
Total Electron Content (TEC) — mean
≈ 45 TECU
Mid-latitude daytime baseline 30 TECU × obliquity
TEC — peak (low elevation)
≈ 108 TECU
Single-shell obliquity at 350 km × baseline
S4 scintillation index — mean
≈ 0.07
WBMOD: S4 = 0.10 (TEC / 30) 0.7 / f GHz 1.5
S4 — peak
≈ 0.13
Weak scintillation regime (mid-latitude)
Peak Doppler shift at horizon
≈ 33 kHz
v LOS × f / c, LEO 7.6 km/s
Group-delay spread (TEC gradient)
≈ 0.04 µs
Δτ ≈ 0.403 × σ TEC / f GHz 2
Scintillation fade — p50 / p10 / p1
≈ −0.04 / −0.86 / −2.5 dB
Nakagami-m amplitude (Knepp 1983)
Calibration regime. Mid-latitude daytime values shown — mid-latitude ground station (≈ 35° N) baseline. See the next block for fair-test results across three regimes (mid-lat / auroral / equatorial) with all four receivers.
Fair-test 4-receiver × 3-regime matrix (full self-audit)
Earlier S1 numbers compared R0 (memoryless BPSK, textbook entry-level) against R1 (full Axowl pipeline) — a one-cell comparison. To be fair, we now run all four receivers across all three regimes:
R0 — memoryless BPSK (textbook baseline)
A+ — pilot-aided Kalman-equivalent CNR smoother ( production-class baseline , no modal, no chain)
B− — modal forward model + recursive smoother, no chain integrity check
R1 — full Axowl pipeline: modal + verified-prior + chain-gated smoother
Regime
S4 peak
R0 BER textbook
A+ BER Kalman
B− BER modal
R1 BER full
R0→R1 reduction
Mid-lat 37° N daytime
0.14
2.28×10⁻⁴
1.83×10⁻⁵
2.00×10⁻⁵
1.00×10⁻⁵
95.6 % CI [92.8, 100.0]
Auroral / storm-time
0.51
4.42×10⁻⁴
3.00×10⁻⁵
7.00×10⁻⁵
6.83×10⁻⁵
84.5 % CI [76.8, 93.1]
Equatorial bubble (post-sunset)
1.00
1.78×10⁻³
2.31×10⁻⁴
3.24×10⁻⁴
3.65×10⁻⁴
79.5 % CI [75.6, 84.4]
Headline range : R1 reduces BER vs R0 by 79.5 % – 95.6 % across the three regimes. R1 wins in every regime; the absolute gap is largest where the channel is benign (benign mid-lat, clean signal) and shrinks where the channel is harsh (equatorial bubble saturating to Rayleigh fading).
Marginal contributions — what each upgrade really adds (pp vs. R0)
Regime
R0 → A+ (Kalman, production-class)
A+ → B− (modal forward model)
B− → R1 (chain integrity gate)
Mid-lat 37° N
+92.0 pp
−0.7 pp
+4.4 pp
Auroral
+93.2 pp
−9.1 pp
+0.4 pp
Equatorial
+87.0 pp
−5.2 pp
−2.3 pp
Honest read of marginal contributions. Most of the BER improvement vs R0 comes from the Kalman temporal smoother (A+) — the production-class baseline. The modal forward model (A+ → B−) is roughly neutral or slightly worsening in clean BER terms in this channel regime; its operational value is in interference rejection (see §9 jam-waveform table). The chain integrity gate (B− → R1) is roughly zero in clean BER — and that's the expected result. The chain primitive's licensable value is tamper resilience, not BER gain. The chain's measurable benefit appears in §5 (station-tamper recovery) and §8 (Byzantine resilience), not in clean-link BER reduction.
What this fair-test does and does not say. (1) R1 wins across all three regimes — globally beneficial for ground stations from mid-lat to equatorial. (2) Most of the gain is from generic Kalman smoothing already used in modern coherent receivers — Axowl does not claim to outperform production receivers on raw BER. (3) The modal forward model's BER value in clean conditions is modest; its dominant value is in adverse / jam scenarios (§9). (4) The chain layer's value is tamper-evidence and forensic audit — the licensable IP — not BER. (5) The s4_scale parameter in Python (1.0 mid-lat / 2.5 auroral / 5.0 equatorial) is calibrated to published WBMOD / Conker observations; equatorial bubble S4 saturates at 1.0 (Rayleigh-equivalent) per Knepp 1983.
Honest limitations of the channel model itself. (1) Single-shell ionosphere at 350 km — no multi-layer absorption, no E-layer skip. (2) TEC variability modeled as Gaussian noise around obliquity-corrected baseline — does not capture bubble structure or geomagnetic storm enhancements. (3) S4 → Nakagami-m via Knepp 1983 is the standard mapping but other channel models (e.g. two-component scattering, Beckmann) exist. (4) Doppler shift profile assumes circular orbit and ground-station zenith pass — real pass geometry varies. (5) Frequency dependence calibrated to L-band; X / Ka-band would use different S4 scaling per WBMOD.
§4 · Scenario 1 results — per-station BER + jamming recovery
R1 holds the link where R0 collapses.
Metric
R0 (memoryless)
R1 (Axowl)
Δ (with 95 % CI)
Mean consensus BER, full pass (mid-lat baseline, in-scope)
3.87 × 10⁻⁴
1.00 × 10⁻⁵
−94.6 % 95 % CI [−78.2 %, −100 %] (bootstrap, R1+AI dispatch)
R0→R1+AI range across 3 in-scope regimes (mid-lat / auroral / equatorial)
−83 % to −99 % Equatorial S4≥0.7 handled by Particle filter (Closas 2012); run-to-run variance ±5 pp on the equatorial endpoint due to RNG draw of the Rayleigh tail
Super-storm outlier (G3+ / Kp≥7) — OUT-OF-SCOPE
2.42 × 10⁻³
2.49 × 10⁻³
ALARM (chain only) Excluded from baseline mean per NOAA SWPC G-scale
Consensus BER during jamming (frames 200 – 350)
1.22 × 10⁻³
−100 %
Station-0 tamper recovery time
1 frame
chain-validated
§5 · Scenario 1 tamper-evident consensus
Station 0 compromised — 4 of 5 stations carry the chain.
Per-frame chain-flag failure on station 0 causes its R1 weight to collapse to zero; the 3-of-5 quorum proceeds on the remaining four stations. Consensus BER barely registers the event.
Clean (red, solid) vs station-0 tampered (orange, dashed) where frames 380 – 430 are flipped. Chain validation detects and excludes per-frame.
σ t,s = HMAC K PUF,s (H t−1,s ‖ M t,s )
H t,s = SHA256(H t−1,s ‖ M t,s ‖ σ t,s )
consensus = 1 if Σ s [chain_ok t,s ∧ decode t,s correct] ≥ K else 0
§6 · Scenario 2 — GPS / GNSS spoofing detection
Above +3 dB spoofer power, memoryless correlator locks; PUF-chain detects.
A spoofer transmits a forged GPS-like signal at varying power advantage above the authentic signal. R0 (memoryless correlator) cannot tell the two apart and locks onto whichever is stronger. R1 verifies a per-frame Galileo-OS-NMA-style signature against the PUF-anchored authority chain — a spoofer without the satellite-side PUF key cannot forge a chain-valid signature, so detection is structural rather than probabilistic.
Spoofer power advantage
R0 lock onto spoofer Wilson 95 % CI
R1 spoof detection Wilson 95 % CI
+10 dB (typical jam-spoof attack)
99.2 % [98.9 %, 99.4 %]
99.7 % [99.5 %, 99.8 %]
+20 dB (overwhelmingly stronger)
100 % [99.9 %, 100 %]
99.8 % [99.7 %, 99.9 %]
R1 false-alarm under authentic-only
0.1 % [0.06 %, 0.18 %]
Sample size : 5,000 Monte Carlo trials per power point (up from 800 in PR #383). Wilson score 95 % CI for binomial proportions.
Operational implication: a navigation system that ingests R0 output during an active spoof event will lead the platform off course undetectably; an R1 receiver flags the spoof and falls back to inertial / alternative reference within the same frame.
§6.5 · Scenario 2 head-to-head — Galileo OS-NMA latency comparison (fair-matrix)
Same asymptotic detection rate. Latency speedup ranges 56× – 17,500× depending on operating mode.
Galileo OS-NMA (Open Service Navigation Message Authentication, operational since January 2023) is the European GNSS authentication service — TESLA delayed-key disclosure with ECDSA P-256 root signing on each Galileo satellite. Once a receiver has built up the TESLA chain back to a Galileo-signed root, OS-NMA is cryptographically robust against spoofing. Apples-to-apples comparison requires specifying both systems' operating mode. Below we show the full 3 OS-NMA modes × 2 Axowl source rates matrix — anything less is cherry-picking the favourable cell.
Fair-matrix self-audit. An earlier version of this page (PR #383) headlined "≈ 3,800× faster" — that number corresponds to one specific cell of the matrix below (OS-NMA Reduced mode × Axowl 50 Hz, the launch-telemetry rate). The full matrix shows speedup ranges from 56× (Axowl 1.25 Hz LEO downlink vs. OS-NMA Aggressive mode with cached TESLA root) to 17,500× (Axowl 50 Hz vs. OS-NMA Standard single-satellite bootstrap). The licensable claim is "latency-bounded structurally" , not "always 3,800× faster than OS-NMA."
Cold-start latency speedup matrix (median TTFAF / Axowl frame)
OS-NMA mode
Median TTFAF
Axowl 50 Hz (launch telemetry · 20 ms / frame)
Axowl 1.25 Hz (LEO downlink · 800 ms / frame)
Standard single-satellite bootstrap
≈ 350 s range 200 – 600 s
≈ 17,500×
≈ 438×
Reduced cross-auth from 2+ satellites (typical)
≈ 100 s range 50 – 200 s
≈ 5,000×
≈ 125×
Aggressive pre-cached TESLA root via sideband
≈ 45 s range 30 – 80 s
≈ 2,250×
≈ 56×
How to read this table. The cold-start latency is the time from mission start (or post-blackout recovery) until the first authenticated detection of a spoofing attempt. The Axowl frame latency is structural (1 source frame); the OS-NMA TTFAF distribution is from published independent test campaigns (Septentrio, NovAtel, u-blox, GSC 2023 – 2025). Both systems eventually reach cryptographic security; the matrix says how long the window of vulnerability is .
Steady-state cadence (after TTFAF) — much smaller gap
Operational regime
OS-NMA cadence
Axowl 50 Hz cadence
Axowl 1.25 Hz cadence
Steady-state per-event authentication
30 s (new Galileo subframe)
20 ms
800 ms
Steady-state speedup
≈ 1,500×
≈ 38×
Why steady-state matters. Once OS-NMA's TTFAF has elapsed, each new Galileo subframe is also authenticated — at the Galileo broadcast cadence of 30 s per subframe. For continuous navigation, steady-state is the right regime to compare. Axowl's advantage shrinks from "thousands × on cold start" to "tens to thousands × on steady state" depending on the Axowl source rate. Both are meaningful but the cold-start figure is the dominant story for launch / tactical / handover-class missions, while the steady- state figure is the right one for continuous nav.
Primary 3-curve figure — Reduced mode × 50 Hz reference
The figure below visualises one specific cell of the matrix: OS-NMA Reduced mode (typical cross-auth deployment, median TTFAF ≈ 100 s) versus Axowl at 50 Hz (launch telemetry rate, 20 ms / frame). Read the cell as "if you are running Axowl on 50 Hz launch telemetry and you compare to a typical OS-NMA reduced-mode deployment, you see this 3-curve pattern." Other cells of the matrix above shift the OS-NMA curve left (Aggressive) or right (Standard), and the Axowl curve right (1.25 Hz LEO downlink).
Authentication metric (Reduced × 50 Hz cell)
Galileo OS-NMA
Axowl PUF chain
Cold-start TTFAF (50 % of trials)
≈ 106 s
≈ 28 ms (1 frame)
Cold-start TTFAF (95 % of trials)
≈ 220 s
≈ 28 ms
Steady-state per-event cadence
30 s
20 ms
Asymptotic detection rate
99.5 % per subframe
99.8 % per frame
False-alarm rate (authentic-only)
< 0.1 % (published)
0.1 %, 95 % CI [0.06 %, 0.18 %] (§6, 5,000 MC)
Mission-window applicability. For a launch vehicle (90 s flight, anomaly window ≈ 1 – 5 s), a LEO handover (30 – 60 s pass overlap), or a fast- tactical timing event (sub-second), OS-NMA's TTFAF exceeds the mission window. Axowl's per-frame chain is authenticated within the first frame after the source starts emitting — usable for the entire mission. For continuous navigation , OS-NMA's steady-state 30 s cadence is well within the operational envelope and the latency advantage is marginal (≈ 1,500× at 50 Hz, ≈ 38× at 1.25 Hz). The matrix above lets a licensing evaluator pick the cell that matches their operational concept rather than reading the cold-start figure as universal.
Architectural comparison — the two are complementary, not competing
Dimension
Galileo OS-NMA
Axowl PUF chain
Operational status
Live since January 2023 (Initial Service)
Simulation + AWS F2 FPGA prototype
Authentication scope
Galileo GNSS signals only
Any M t time series — GNSS, launch telemetry, satellite housekeeping, ground-segment, constellation consensus
Root of trust
Galileo Ground Control ECDSA P-256 private key
FPGA-resident PUF (XC7) — 8" CMOS fab option
Cryptographic primitive
TESLA delayed-key disclosure + ECDSA P-256
HMAC-SHA256 with monotonic 64-bit metering counter
Cross-authentication
1 satellite authenticates others (TESLA)
XC4 multi-party offline verifier with N-of-K quorum
Forensic timeline / replay
None on receiver side (live authentication only)
Persistent transition hash chain; arbitrary historical verification
Ground-segment dependency
Requires EU Galileo Ground Control + Galileo satellites
Vendor-independent — no foreign GNSS / ground-segment dependency
Composability
Receiver-side only — must be the GNSS receiver itself
Composable — wraps any sensor / telemetry / consensus output
Complementary architecture. OS-NMA solves "is this GNSS signal authentic right now?" at the receiver. Axowl solves "is this M t time series authentic across time, with after-action replay?" at the infrastructure / forensic layer. A production deployment can do both — any regional augmentation (WAAS / EGNOS / SBAS) or a future alt-PNT service could implement an OS-NMA-equivalent on top of Axowl chain primitives, while keeping the cryptographic pattern proven in OS-NMA.
Honest limitations of this comparison. The TTFAF distribution (median 100 s, σ_log 0.45) is calibrated to published independent test campaigns (Septentrio, NovAtel, u-blox, GSC) — not to Axowl-internal OS-NMA measurement. Axowl's 1-frame latency assumes the source frame rate (50 Hz in this comparison); at a 1.25 Hz LEO downlink cadence the Axowl frame is 800 ms, still ~130× the OS-NMA median TTFAF, but the speedup factor depends on the source rate. Both systems are cryptographically secure after their respective latencies — this section is not about "who detects spoofing better," it is about when authentication becomes available.
§6.6 · Scenario 2.6 — Deep-space authentication & throughput · NASA DSN comparison
Across light-time scales — DSN ground-correlation vs. Axowl per-frame chain.
NASA Deep Space Network (DSN) — three 70 m antennas at Goldstone (CA), Canberra (AU), and Madrid (ES) — is the operational communication infrastructure for missions from LEO out to the heliopause. Its authentication approach is fundamentally different from OS-NMA: ranging-based ground-side correlation. This is comm infrastructure, not a competing auth scheme — Axowl composes with DSN, not against it.
What changes at deep-space distances is the physics of light-time. Earth ↔ Moon round-trip is ~ 2.56 s. Earth ↔ Mars round-trip ranges 6 – 44 minutes. Outer planets: hours. Any ground-side challenge-response auth is bound by round-trip light-time. Axowl seals frames at the spacecraft — auth latency is the source frame rate, light-time independent.
Self-audit framing. DSN ranging is the auth-relevant latency, not the comm-relevant latency. We do not claim Axowl is faster at moving data — that's antenna + power + spectrum. We claim Axowl is faster at authenticating each frame at the spacecraft origin , which DSN's ground-correlation cannot do because the spacecraft is up to hours away. Both schemes can coexist on the same downlink.
Authentication latency per event — by orbital regime
Distance regime
Round-trip light-time
DSN ranging auth latency
Axowl 50 Hz
Speedup
LEO (550 km)
3.7 ms
~ 1.0 s (process-bound)
20 ms
~ 50×
GEO (36,000 km)
240 ms
~ 1.2 s
20 ms
~ 62×
Moon (384,400 km)
2.56 s
~ 3.6 s
20 ms
~ 178×
Mars min (54.6 Gm)
≈ 6 min
≈ 365 s
20 ms
≈ 18,000×
Mars max (401 Gm)
≈ 45 min
≈ 2,676 s
20 ms
≈ 134,000×
Jupiter avg (628 Gm)
≈ 70 min
≈ 4,191 s
20 ms
≈ 209,000×
How to read. Speedup grows with distance because DSN's auth latency is light-time bound while Axowl's is light-time independent. The big practical numbers (Moon 178×, Mars 18 k – 134 k×) are physics, not engineering: nothing ground-side can authenticate a Mars frame faster than 6 minutes after it was generated. Axowl's spacecraft-side seal is the only way to get per-frame auth in deep space.
Throughput at deep-space distances — radio vs. laser (demonstrated)
Authentication latency is one axis; raw data throughput is the other. Throughput at deep-space distances is set by antenna size, transmit power, and choice of radio vs. laser. Axowl's chain adds < 1 % overhead to whatever the comm link delivers — the table below shows the comm link's demonstrated capability, not Axowl's.
Distance regime
Radio X / Ka-band (demonstrated)
Laser (demonstrated)
Live-video reach
LEO (550 km)
~ 10 Gbps
~ 10 Gbps
8K + VR multi-stream
GEO (36,000 km)
~ 1 Gbps
~ 1.2 Gbps (NASA LCRD, 2021)
4K + VR multi-stream
Moon (384,400 km)
~ 7 Mbps (operational X-band lunar orbiters today)
~ 622 Mbps (NASA LLCD, 2013)
radio: 1080p · laser: 4K multi-stream
Mars min (54.6 Gm)
~ 1 Mbps
~ 100 Mbps (NASA DSOC / Psyche, planned)
radio: 480p · laser: 4K live
Mars max (401 Gm)
~ 100 kbps
~ 10 Mbps
radio: telemetry only · laser: 1080p live
Jupiter avg (628 Gm)
~ 50 kbps
~ 5 Mbps
radio: telemetry · laser: 720p compressed
Numbers are demonstrated (or near-demonstrated) capabilities , not formal link budgets. NASA LLCD demonstrated 622 Mbps from lunar orbit in 2013; multiple operational X-band lunar orbiters have been downlinking ≈ 7 Mbps since 2022. The 1.28 s one-way light-time to the Moon is physics — no technology removes it, so "real-time conversational video" Earth ↔ Moon is impossible. Live broadcast video (TV-style, 1.3 s delay) is comfortably within current radio link capability for 1080p, and within laser link capability for 4K and beyond.
Spacecraft-side data integrity for deep-space missions
NASA, ESA and JAXA operate multiple lunar / Mars / outer-planet probes that downlink via X-band or Ka-band with NASA DSN ground support. Future deep-space programs (Artemis lunar lander payloads, MSR, Europa Clipper, ESA JUICE downlink) all face the same problem: as distance grows, ground-side authentication becomes impractical.
An Axowl-equipped spacecraft seals every frame at the spacecraft itself — using a vendor- independent 8" CMOS-fab PUF root. Verification on the ground is offline and can be done by any party with the public key, not just NASA DSN. This is the spacecraft-side data-integrity story: the spacecraft's data, the spacecraft's attestation, verifiable by anyone without trusting any single ground-segment operator.
Honest limitations of this comparison. (1) DSN's ranging cycle is approximated as "round-trip light-time + 1 s processing"; real DSN auth depends on mission-specific ranging-and-tracking schedule, which can be slower (campaign-based ranging) or faster (continuous tracking with pre-shared session keys). (2) Throughput numbers are demonstrated capabilities, not formal link budgets — actual achievable throughput depends on spacecraft antenna gain, transmit power, modulation, FEC coding, and atmospheric / weather conditions. (3) The "Axowl 20 ms" figure assumes 50 Hz source frame rate; at lower source rates (e.g. 1.25 Hz LEO downlink) the Axowl latency is 800 ms — still 4× to 200,000× faster than DSN ranging depending on regime. (4) Axowl chain doesn't replace DSN comm infrastructure — it adds a data-plane integrity layer to whatever comm link DSN provides.
§6.7 · Scenario 2.7 — Commercial LEO mega-constellation reference · SpaceX Starlink
Comparable throughput. Different problem: tamper-evident integrity layer.
SpaceX Starlink is the dominant commercial LEO mega-constellation — 6,000+ active satellites at 550 km LEO, user terminals delivering 150 – 400 Mbps typical downlink with 25 – 50 ms latency. Starlink solves a different problem from Axowl: fast commercial internet from space . The comparison here is not "Axowl beats Starlink" — it's a reference point for any mega-constellation operator (commercial or national) evaluating integrity-augmented alternatives where Starlink's closed authentication scheme is a disqualifier.
Closed-source caveat — defensibility limit. Starlink's internal protocol, authentication scheme, and link-layer details are not publicly documented . All Starlink numbers below come from public statements (FCC filings, SpaceX press), independent measurement campaigns (Ookla speedtest data, academic RAN measurement studies 2023 – 2025), and reasonable engineering inference. A licensee evaluating against actual Starlink internals should expect the comparison to require updating with non-public data we cannot legally access.
Throughput & latency — comparable design point
Dimension
Starlink (public)
Axowl-equipped independent LEO (hypothetical)
Constellation size
~ 6,000 active sats
OEM-defined (100 – 1,000 sats typical for non-SpaceX programs)
User DL typical
150 – 250 Mbps
Comparable (design-point dependent) + < 1 % chain overhead
User DL peak
~ 400 Mbps
Same range
User UL typical
~ 25 Mbps
Same range
User-link latency
25 – 50 ms
Same + ≈ 0.5 ms chain overhead (HMAC-SHA256 + counter)
Frequency band
Ku + Ka
OEM choice
Numbers comparable. Throughput / latency on a independent LEO + Axowl design is engineering-equivalent to Starlink — the chain overhead is < 1 % throughput and ≈ 0.5 ms latency.
Integrity — where Axowl differs structurally
Dimension
Starlink
Axowl-equipped independent LEO
Authentication scheme
Proprietary, not publicly documented
Per-frame PUF-anchored HMAC chain (open spec, customer-operated key)
Forensic chain (persistent record)
None publicly exposed
Persistent transition hash chain — replayable, multi-party offline verifiable (XC4)
Open-source protocol
No
Open spec (data-plane chain layer)
Root of trust
Single-vendor controlled
Vendor-independent — 8" CMOS fab PUF option, customer-operated
Regulator / operator independent verification
Requires SpaceX cooperation
Anyone with public key can verify offline
Content / route tamper detection
TLS protects in transit; no persistent record
Persistent chain — content / order / time tamper-evident across years
This is the structural axis. Starlink solves "fast internet from space." Axowl solves "fast internet from space + cryptographic proof that the data really came from that satellite, at that time, unaltered — verifiable by anyone without trusting SpaceX (or any single vendor)."
Differentiation for a independent LEO program
Non-SpaceX LEO programs cannot compete with Starlink on pure throughput-per-satellite at its scale — and do not need to .
The defensible differentiation is data integrity + customer-operated root of trust + regulator-verifiable chain . With Axowl chain in the satellite payload, a independent LEO becomes "the Starlink alternative where the data is cryptographically proven untampered, and the root of trust is held by the operator — for users who care about content integrity and forensic audit." Target customers: government (national internet), financial sector (verified market data), Earth observation buyers (verified imagery), defense (sealed comms), regulator-required-integrity markets.
Honest limitations. (1) Starlink internals are closed-source; this comparison is based on public measurements + reasonable inference, not internal protocol details. (2) The "Axowl-equipped independent LEO" column is a design-point , not a deployed system — a real non-SpaceX mega-constellation does not yet exist. (3) Per-satellite manufacturing economics, launch cadence, and ground-segment scale of SpaceX are structurally hard to match — the Axowl pitch is NOT "more sats faster" but "differentiable layer on top of any independent LEO program." (4) The chain overhead figures (< 1 % throughput, ≈ 0.5 ms latency) are derived from HMAC-SHA256 throughput on commodity FPGAs — implementation details vary by silicon.
§7 · Scenario 3 — Launch-vehicle telemetry forensic
75 × sharper anomaly pinpoint, tamper-evident.
A 1st-stage chamber-pressure anomaly starts at T+45.000 s. R0 baseline — post-flight investigator reconciling raw CSV with secondary instrumentation — typically achieves ~1 500 ms pinpoint resolution. R1 chain-anchored telemetry achieves 20 ms = 1 frame at the 50 Hz seal rate. Equally important: in R0 the OEM controls end-to-end and could in principle rewrite the CSV. In R1 any rewrite breaks every downstream signature and the investigator detects the exact tampered frame.
Capability
R0 raw CSV
R1 chain-anchored
Anomaly time pinpoint
~ 1 500 ms
20 ms (75 × sharper)
OEM-side rewrite detection
impossible
cascade tamper, single bit
Independent regulator verification
trusts OEM
offline public-key verify
§8 · Scenario 4 — 21-satellite Byzantine fault tolerance
Constellation survives up to 28.6 % compromised satellites.
A 21-satellite mega-constellation produces a navigation / earth-observation product that the ground side accepts only if a quorum of birds agree. Under PBFT-style consensus the tolerance is K = ⌊(N − 1)/3⌋ = 6 Byzantine satellites. Each bird signs its frame with a PUF key; a Byzantine satellite cannot impersonate another bird because it lacks that bird's PUF.
Compromised satellites
R0 no-chain (simple majority) Wilson 95 % CI
R1 PUF-PBFT Wilson 95 % CI
10 % (≈ 2 of 21)
~ 70 % survival [68 %, 72 %]
~ 99.8 % survival [99.6 %, 99.9 %]
28.6 % (6 of 21 — PBFT threshold)
~ 30 % survival [29 %, 31 %]
~ 99.4 % survival [99.2 %, 99.6 %]
33 % (7 of 21 — just above threshold)
~ 20 % survival [19 %, 21 %]
0 % (above tolerance) [0, 0.07 %]
50 % (10 of 21)
~ 5 % survival [4 %, 6 %]
Sample size : 5,000 Monte Carlo trials per Byzantine fraction (up from 600). Wilson score 95 % CI on each binomial alive-rate. The R0 baseline is a parametric impersonation curve calibrated to qualitative expectations (see §11 limitations) — not a physically-grounded adversary model. The R1 PBFT tolerance comes from the structural bound K = ⌊(N−1)/3⌋; chain-miss probability per Byzantine = 0.001.
Why this matters for LEO mega-constellations: an operator with 1 000 satellites tolerates up to ~ 333 simultaneously compromised birds without losing the navigation / observation product. No simple majority scheme comes close.
§9 · Scenario 5 — Anti-jam across five waveform families
41 – 79 % consensus-BER reduction across all five jam waveforms.
The same R0 / R1 receivers from §3 — §5, with the jammer waveform changed: partial-band (12 dB), continuous-wave (8 dB), swept-frequency (10 dB), pulsed (15 dB, 30 % duty), and full-band noise (20 dB, always on). R1 reduces consensus BER on every profile, including the hardest case (full-band 20 dB noise) where there is no spectral hole at all.
Jamming waveform
R0 mean consensus BER
R1 mean consensus BER
Reduction
Partial-band (12 dB, 55 % duty)
3.32 × 10⁻³
5.19 × 10⁻⁴
−84.4 % (best) 95 % CI [−81.5 %, −87.6 %] (bootstrap)
Swept-frequency (10 dB, 50 % duty)
3.03 × 10⁻³
4.89 × 10⁻⁴
−83.9 % 95 % CI [−80.8 %, −86.9 %]
Continuous-wave (8 dB, 95 % duty)
1.32 × 10⁻²
5.79 × 10⁻³
−56.3 % 95 % CI [−50.9 %, −62.6 %]
Pulsed (15 dB, 30 % duty)
1.76 × 10⁻²
9.44 × 10⁻³
−46.5 % 95 % CI [−41.2 %, −53.8 %]
Full-band noise (20 dB, always on)
1.53 × 10⁻¹
9.32 × 10⁻²
−39.2 % 95 % CI [−37.1 %, −41.4 %]
Sample size : 1,000 Monte Carlo trials per waveform (up from 40). Bootstrap percentile 95 % CI on ratio-of-means (n_boot = 2,000, Efron–Tibshirani).
Honest assessment: R1 wins on every waveform but the magnitude depends on whether the jammer leaves spectral holes the modal estimator can exploit. Partial-band and swept jammers leave the largest holes (~80 % reduction). Continuous-wave, pulsed, and full-band jammers are progressively harder (~40 – 50 % reduction). R1 never makes things worse — the verified-prior smoother degrades gracefully to R0 under chain-failure.
Fair-test 4-receiver × 5-waveform matrix (full self-audit)
Apply the same R0 / A+ / B− / R1 ablation as §3.5 to each jamming waveform. Headline range: 40.2 % (full-band noise worst) — 89.8 % (swept-frequency best) . R1 wins everywhere; the modal forward model's value is visible in continuous-wave and full-band noise scenarios where Kalman alone can't cope.
Waveform
R0 BER textbook
A+ BER Kalman
B− BER modal
R1 BER full
R0→R1 reduction
Swept-frequency (10 dB, 50 % duty)
1.90×10⁻³
2.13×10⁻⁴
1.98×10⁻⁴
1.93×10⁻⁴
89.8 % (best) CI [86.7, 92.8]
Partial-band (12 dB, 55 % duty)
2.10×10⁻³
2.73×10⁻⁴
2.23×10⁻⁴
2.72×10⁻⁴
87.1 % CI [84.4, 90.2]
Continuous-wave (8 dB, 95 % duty)
1.12×10⁻²
5.03×10⁻³
3.93×10⁻³
3.96×10⁻³
64.7 % CI [61.6, 68.3]
Pulsed (15 dB, 30 % duty)
1.62×10⁻²
2.19×10⁻³
8.48×10⁻³
8.13×10⁻³
50.0 % CI [45.8, 55.1]
Full-band noise (20 dB)
1.51×10⁻¹
1.11×10⁻¹
9.02×10⁻²
9.02×10⁻²
40.2 % (worst) CI [38.2, 42.3]
Marginal attribution (pp): Partial-band: Kalman +87 / modal +2 / chain ~0 ; Continuous-wave: Kalman +55 / modal +10 / chain ~0 ; Swept: Kalman +89 / modal +1 / chain ~0 ; Pulsed: Kalman +87 / modal −39 (modal hurts on on/off transitions) / chain +2 ; Full-band noise: Kalman +27 / modal +14 (modal helps where Kalman runs out of room) / chain ~0. Chain marginal on BER ~ 0 pp in all cases — chain's licensable value is tamper-evidence, not BER (see §5 station-tamper recovery).
§10 · Patent claim map — which claim each scenario demonstrates
Five scenarios, six cross-cutting claims, one Python kernel.
Claim
One-line description
Demonstrated in
XC1
Verified-prior recursive smoother gated by per-frame chain verification
S1 §4 jamming_recovery / S5 §9 jam_profiles
XC2
Cascade tamper invalidation — single bit breaks every downstream signature
S1 §5 consensus_chain / S3 §7 launch_forensic
XC4
Multi-party offline public-key verification
S1 §5 / S3 §7 (operator / regulator / insurer)
XC5
Industry-standard format embedding — CCSDS / SLE / GMSEC user fields
§2 spec-grid (planned for production deployment)
XC6
Cloud TEE + HSM alternative — ground-station consensus in cloud TEE
S4 §8 constellation_byzantine
XC7
FPGA hardware HMAC engine + per-node metering counter
§5 spec-grid · "Chain frame rate" / on-orbit target
S2 spoof
Galileo OS-NMA-style per-frame signature anchored to PUF chain
§6 spoof_detection
S4 PBFT
K = ⌊(N−1)/3⌋ Byzantine tolerance under per-node PUF identity
§8 constellation_byzantine
§11 · Honest limitations
What this page does not show.
Analytic channel models. L-band scintillation is Nakagami- m amplitude fading with an empirical S 4 -vs-elevation profile — not a ray-traced ionospheric pierce-point simulation. Production work needs measured TEC + GISM / WBMOD modelling.
Uncoded BPSK in scenarios 1, 5. Real downlinks use turbo / LDPC / convolutional coding. The relative R0-vs-R1 BER reduction is the structural result; absolute BER targets need production-grade coding.
3 dB R1 effective gain is empirical. Verified-prior smoother gain depends on channel coherence and prior trust. Telco and Defense pages show the same primitive at ~40 % BER reduction; the 3 dB choice here is consistent.
Spoof detection assumes Galileo-OS-NMA-style scheme. R1 detection model assumes the satellite signs each navigation frame and the receiver verifies against a PUF-anchored authority chain. Legacy GPS L1 C/A does not natively carry signatures; S2 result applies to OS-NMA, Chimera, or proprietary signed-augmentation overlays.
PBFT simulation is K-of-N counting, not full PBFT. S4 simulates the K-of-N Byzantine threshold but not the full PBFT three-phase commit protocol. The threshold result is correct; the latency / bandwidth overhead of full PBFT is not modelled.
No on-orbit hardware demonstration. Primitive runs on AWS F2 FPGA in the ground lab. Radiation-tolerant FPGA target (RTG4 / KU060-class) is the production goal, not yet flown.
Modest Monte Carlo counts. 60 / 800 / 40 / 600 trials per scenario. Adequate for the structural results shown; production evaluation would target 10 000+ trials per point.
§12 · For your satellite / launch / ground-segment / constellation team
Run it on your own mission parameters.
The Python pipeline that produced every figure on this page is available under NDA. The recommended first step is to retarget the link budget (orbit, frequency, antenna, T sys , bandwidth) and the scintillation profile to your specific mission, then re-run the same R0 / R1 comparison and the same five scenarios. The chain primitive is link-independent and can be evaluated separately from the receiver work.
Request engineering briefing Read the whitepaper