Internet-Draft NTN-RF Finality August 2026
Das Expires 28 February 2027 [Page]
Workgroup:
Network Working Group
Internet-Draft:
draft-das-ntn-rf-execution-finality-00
Published:
Intended Status:
Informational
Expires:
Author:
S. Das
Independent Inventor

RF Enable Is Not Transmit Authority: Finality for LEO/NTN and Inter-Satellite Control

Abstract

A LEO constellation computer can compute a transmit burst, a beam command, an inter-satellite forward, or a user-terminal PA enable faster than any ground reviewer can see it. Today those acts become RF because the scheduler selected them, the command link authenticated, or the flight process had the radio device open. Authentication of TT&C, 3GPP NTN registration, and operator allowlists decide who may talk to the vehicle. They do not decide whether this burst, on this beam, to this next hop, over this territory, in this mission epoch, may leave the aperture.

Radiation is not reversible. An ISL hop is not a log line. A phased-array user terminal that is already pointed is one register write away from radiating. If the enable line trusts the last ground "go," a stale, substituted, or autonomy-generated command becomes sky-facing consequence.

This document specifies a radio-side execution-finality profile for NTN and mega-constellation control. A proposed RF, ISL, beam, gateway, or payload act remains a Candidate Act. A Protected Enforcement Domain binds vehicle, beam, frequency class, duration, next hop, overflight or jurisdiction epoch, and intended sink, then issues scoped non-bearer authority. The Finality Sink sits at the PA enable, ISL switch, beam driver, feeder gateway, or UT transmit path and verifies that authority immediately before energy leaves the system. RF enable is not transmit authority.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 28 February 2027.

Table of Contents

1. Introduction

Mega-constellation and 3GPP NTN stacks now sit on a short path:

scheduler / flight software / NTN CU
        -> command or grant
        -> onboard or UT radio control
        -> PA / ISL / beam enable
        -> radiated or forwarded effect

The fourth arrow is the one this document controls. The computer is allowed to compute. The aperture is not allowed to treat that computation as a capability. A proposed service-link burst, feeder-link burst, UT uplink, ISL forward, beam steer, handover-coupled transmit, or payload RF enable remains non-effective until act-specific authority is verified at the component that would actually radiate or forward.

This profile uses the two-boundary execution-finality chain in [I-D.das-6g-finality]. It does not specify PHY, waveform, or a named operator's flight code. It specifies the predicates a constellation or NTN implementation must bind before radiation or ISL forward: vehicle identity, beam or cell, frequency class, duration or slot set, next-hop, overflight epoch, command provenance, and sink identity.

Public LEO systems with electronically steered user terminals, optical or RF inter-satellite links, and gateway-fed service links — including the class of system operated as Starlink and peers such as OneWeb, Kuiper, and Telesat Lightspeed — are the motivating deployment. Vendor names in this document are informative examples of topology, not claims about unpublished internals.

2. Requirements Language

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.

Failure to establish current RF or ISL authority MUST NOT be converted into permission to enable the aperture or forward the hop.

3. Problem Space

Satellite command fails in a different place than terrestrial session control. A denied 5G PDU session is quiet. A wrongly enabled SSPA, TWTA, or phased-array panel is an ITU event, a neighbor-cell event, and in some bands a safety event. The model's — or the flight computer's — next output is energy.

The practical failures look like this:

In each case some upstream control was satisfied: the vehicle authenticated, the UT registered, the NOC user had the console, or the flight process had device access. The missing question is the one asked at the aperture: may this exact act become RF or ISL now.

4. Existing Solutions and What They Do Not Bind

Constellation and NTN stacks already contain important controls. This profile consumes them. It does not replace waveform security or ITU coordination.

4.1. TT&C Authentication and CCSDS Command Links

Authenticated telecommand establishes that a ground system may speak to a vehicle. CCSDS Space Data Link and related command-authentication profiles bind frames to a key and often to a counter. They do not, by themselves, bind beam_id, EIRP class, overflight epoch, or the particular PA that will fire. A valid command session can still carry the wrong payload act.

4.2. 3GPP NTN Registration and NAS Security

Rel-17/18 NTN gives a UE a satellite-aware cell and a secured NAS. That answers "this UT may be on this network." It does not hash the burst the scheduled grant will radiate, and it does not sit in the UT PA enable or the satellite service-link enable. A registered UT can still transmit on a grant that is stale relative to beam or timing advance.

4.3. Operator Flight Allowlists and Safe Modes

Flight software typically refuses unknown command opcodes and can enter a safe mode that drops payload RF. Those are class-level interlocks. They do not consume single-use authority for one burst, and they do not stop a well-formed, in-allowlist command that is wrong for this epoch.

Feeder and service-link encryption protect confidentiality. Gateway ACLs protect who may inject traffic. Encrypted wrong radiation is still radiation. An ACL on the gateway does not control the satellite PA when the vehicle is serving through another gateway or through ISL only.

4.5. ITU Filings and National Gateways

Coordination and landing-rights constrain where a system is allowed to operate. They are not a per-burst gate. Overflight changes faster than paper. A vehicle that crossed a boundary mid-queue needs an epoch check at the enable line, not a reminder in the license file.

4.6. What This Profile Adds

  • the radio command remains a Candidate Act after the scheduler or flight computer emits it;
  • beam, frequency class, duration, next-hop, and overflight epoch are bindings, not telemetry;
  • authority is non-bearer, sink-bound, and consumed at PA, ISL, beam driver, gateway, or UT TX;
  • onboard autonomy and faded command links fail closed or escalate rather than inherit the last "go";
  • a payload or bus path that can enable an emitter is in scope; and
  • the profile does not change PHY. It makes effectuation non-completable without the sink check.

5. Industrial Relevance and Constellation Cases

These cases are written in the topology a LEO operator already has: user terminal, space vehicle with service and crosslinks, gateway, and a ground or onboard scheduler. Starlink-class systems are the existence proof that this topology is no longer experimental.

5.1. Phased-Array User Terminal Uplink

A consumer or maritime UT has already acquired, is tracking a moving vehicle, and has a scheduler grant. The modem is one enable away from radiating on Ku or Ka. NTN or proprietary attachment says the terminal is in-network. Injected or stale grant data — wrong duty cycle, wrong beam, wrong vehicle — must not become PA enable.

The sink is UT_TX_ENABLE. Authority binds vehicle_id or serving cell, frequency class, grant digest, duration, and epoch. A grant computed for vehicle A at epoch 41 MUST fail on vehicle B or epoch 42. This is the satellite analogue of argument-digest binding in [I-D.das-agentic].

The satellite scheduler (onboard or ground-computed and uplinked) selects a panel, beam, slot, and user set. The irreversible step is enabling the service-link PA or beamformer path. A compromised or merely stale onboard process that can write that register is the incident.

The sink is SAT_RF_ENABLE. Authority binds satellite_id, beam_id, frequency class, EIRP class, slot or duration, and overflight_epoch. Autonomy MAY propose the Candidate Act. Autonomy MUST NOT complete enable without current authority. That is the sentence a flight-software reviewer can test.

5.3. Optical or RF Inter-Satellite Forward

Once a constellation has a mesh, a packet can leave the planet's regulatory picture without touching a gateway. Route computation is cheap. The hop is not. A forward toward a vehicle that will next serve a restricted administration, or a hop that extends a flow the grant did not include, is a consequence class of its own.

The sink is ISL_FORWARD. Authority binds this_vehicle, next_hop_id, flow or grant digest, and the epoch in which that next hop is still the intended hop. Mesh churn without epoch advance is how a correct grant becomes a wrong sky path.

5.4. Gateway Feeder and Pointing

Gateways are the high-power, high-duty terrestrial emitters and the usual landing-rights choke point. Operator ACLs already exist. They do not consume single-use authority when the scheduled vehicle, band, or polarization changes mid-pass.

The sink is GW_FEEDER. Authority binds gateway_id, satellite_id, band, and pass_epoch. A feeder burst for yesterday's pass MUST fail. Site diversity — moving the same traffic to another gateway — is a new Candidate Act, not reuse of the first authority.

5.5. Beam Steer and Handover-Coupled Transmit

Electronic steering is a command, not a side effect. Pointing the array at the wrong gateway, ship, or region is already the incident before the first information bit. Handover that keeps an old beam enable alive across the switch is the replay case.

The sink is BEAM_STEER, and any following RF enable MUST see a beam_id that matches the current steer authority. Handover is either a new act or an explicit epoch bump. Silent inheritance is non-conforming.

5.6. Hosted Payload and Secondary Emitters

Earth-observation, AIS, or compute payloads share the bus with the comms payload. Bus access is not radiation authority. A payload process that can toggle an emitter, a downlink modulator, or a high-rate sensor radio MUST face a PAYLOAD_CMD sink with its own consequence class. This is the spacecraft version of alternate-path closure: do not let the payload computer walk around the comms scheduler.

LEO command links fade. Operators still want the network to run. The wrong answer is "use the last approved envelope forever." The right answer is a short-lived hot-path envelope, explicitly bounded in epoch, beam set, and EIRP class, that the sink still checks. When the envelope cannot be proved, the aperture stays dark or in the last safe pattern. Timeout is not transmit.

5.8. What a Constellation Team Should Measure

The profile is live when production or hardware-in-the-loop logs show: (1) every service-link or UT PA enable has a consumed authority_id; (2) beam or vehicle mismatch is a deny, not a retry that skips the sink; (3) ISL forwards after a route change carry a new epoch; (4) payload and bus paths cannot enable an emitter the comms sink would have refused. Those four tests are more useful than a claim that TT&C is encrypted.

6. Terminology

Satellite Candidate Act
A scheduler-, flight-, NTN-, or autonomy-generated operation that would radiate, steer, forward on ISL, or enable a payload emitter, but has not been permitted to do so.
RF / ISL Finality Sink
The component that would actually enable the PA, beamformer, ISL switch, feeder chain, UT transmit path, or payload emitter. If that component can be skipped, it is not the sink.
Overflight epoch
A monotonic or attested identifier for the regulatory or mission-phase window in which the act is valid (administration under the footprint, license window, eclipse/safe-mode state, or equivalent).
Grant digest
A hash over the canonical scheduled grant or command body (vehicle, beam, band, slots, next hop, users). Changing a load-bearing field MUST change the digest.

Candidate Act, Non-Effective State, Protected Enforcement Domain (PED), Protected Validation Evidence, scoped non-bearer finality authority, and Finality Sink are used as in [I-D.das-6g-finality].

7. Architecture

A Candidate Act MUST NOT become RF or ISL merely because the scheduler selected it, TT&C authenticated, the UT registered, or onboard autonomy produced a well-formed command.

scheduler / flight / NTN CU emits command
              |
              v
   SATELLITE CANDIDATE ACT
              |
              v
        Non-Effective State
              |
              v
   Protected Enforcement Domain
      vehicle, beam, band
      grant digest, duration
      next hop / destination
      overflight / policy epoch
      command provenance
      intended RF or ISL sink
              |
              v
   evidence + scoped authority
              |
              v
   RF / ISL / UT / GW / PAYLOAD SINK
              |
      +-- PASS -> enable once, consume authority
      |
      `-- FAIL -> aperture stays non-radiating
Figure 1: Aperture-time finality

PED MAY run on the ground, in a gateway, in a UT TEE, or in a protected partition on the vehicle. The sink MUST run on the path that can prevent enable. A ground policy server that the PA does not consult is not a sink.

8. Enable-Path Pseudocode

Procedures are normative in behavior. An implementation MAY collocate PED and sink in one protected radio-control service if evidence is committed before authority is usable and the live grant is checked immediately before enable.

8.1. Scheduler or Flight Output to Candidate Act

function ON_RADIO_COMMAND(cmd, ctx):
    act = SatelliteCandidateAct{
        candidate_act_id: fresh_id(),
        act_type: map_act_type(cmd),
        vehicle: ctx.vehicle_id,
        beam_id: cmd.beam_id,
        frequency_class: cmd.band,
        eirp_class: cmd.eirp_class,
        grant_digest: HASH(canonicalize(cmd)),
        duration: cmd.slots_or_ms,
        next_hop: cmd.next_hop,
        overflight_epoch: ctx.overflight_epoch,
        policy_state: current_epochs(),
        freshness: {nonce: fresh_nonce()},
        provenance: ctx.command_source,  # ground, onboard, ntn, payload
        finality_sink: ctx.sink,
        expires_at: now() + short_ttl
    }
    HOLD_NON_EFFECTIVE(act)
    return PED_VALIDATE(act, cmd)

8.2. PED Validation

function PED_VALIDATE(act, cmd):
    if malformed(act):
        return DENY(MALFORMED_ACT)
    if not fresh(act.freshness.nonce):
        return DENY(REPLAY_OR_STALE)
    if act.policy_state != current_epochs():
        return DENY(EPOCH_MISMATCH)
    if act.overflight_epoch != current_overflight():
        return DENY(OVERFLIGHT_MISMATCH)
    if not allowlisted(act.vehicle, act.act_type, act.frequency_class):
        return DENY(EMITTER_NOT_AUTHORIZED)
    if act.next_hop unknown and act.act_type == ISL_FORWARD:
        return ESCALATE_OR_DENY(NEXT_HOP_UNRESOLVED)
    if faded(command_link) and act.eirp_class not in HOT_ENVELOPE:
        return ESCALATE_OR_DENY(AUTONOMY_ENVELOPE)
    if act.provenance == PAYLOAD and act.act_type != PAYLOAD_CMD:
        return DENY(PATH_LAUNDERING)

    evidence = COMMIT_PROTECTED_EVIDENCE(act)
    authority = ISSUE_SCOPED_AUTHORITY(act, evidence)
    return ALLOW(authority)

8.3. Sink: Verify Then Enable

function RF_SINK_ENABLE(act, authority, live_cmd):
    live_digest = HASH(canonicalize(live_cmd))

    if authority missing or integrity_fail(authority):
        return DENY(NO_OR_INVALID_AUTHORITY)
    if HASH(act) != authority.candidate_act_digest:
        return DENY(ACT_MISMATCH)
    if live_digest != act.grant_digest:
        return DENY(GRANT_SUBSTITUTION)
    if authority.sink_id != THIS_SINK:
        return DENY(SINK_MISMATCH)
    if authority.vehicle != act.vehicle or
       authority.beam_id != live_cmd.beam_id:
        return DENY(BEAM_OR_VEHICLE_MISMATCH)
    if expired(authority) or consumed(authority):
        return DENY(STALE_OR_USED)
    if authority.overflight_epoch != current_overflight():
        return DENY(OVERFLIGHT_MISMATCH)

    ATOMICALLY:
        consume(authority)
        advance_replay_state(act.freshness.nonce)
        enable_emitter(live_cmd)
    record_sink_evidence(act, authority)
    return ENABLED

enable_emitter() is unreachable when any check fails. Logging a denial and then keying the PA is non-conforming.

9. Load-Bearing Bindings

Authority issued for SAT_RF_ENABLE / vehicle V / beam B / digest D1 MUST NOT authorize beam B' , vehicle V' , digest D2, an ISL forward, a UT PA enable, or a payload emitter. DISPLAY-equivalent mistakes in this profile are beam substitution, vehicle substitution, and grant substitution.

Authority for UT_TX_ENABLE MUST NOT automatically authorize SAT_RF_ENABLE. Authority created under overflight epoch N MUST fail at epoch N+1. Authority for one gateway pass MUST NOT authorize site-diverse feeder radiation at another gateway.

10. Alternate-Path Closure

If the same radiated or forwarded effect can be produced by the comms scheduler, a payload computer, a debug bus, a ground override, or a UT test mode, each path MUST either enforce this profile or be unable to produce the effect. Moving the command from the mission scheduler to a laboratory register poke MUST NOT remove the requirement on an in-orbit or in-field emitter.

11. JSON Interoperability Profile

Objects are UTF-8 JSON. Transport MAY be a spacecraft bus message, a UT driver ioctl, a gateway controller RPC, or a ground-to-board command wrapper. Transport MUST preserve integrity, sink identity, freshness, and non-bearer semantics.

11.1. SatelliteCandidateAct

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "urn:ietf:params:json-schema:ntn-rf-finality:candidate-act:1",
  "title": "SatelliteCandidateAct",
  "type": "object",
  "additionalProperties": false,
  "required": [
    "version", "object_type", "candidate_act_id", "act_type",
    "created_at", "expires_at", "vehicle", "grant_digest",
    "policy_state", "freshness", "finality_sink"
  ],
  "properties": {
    "version": { "type": "string", "const": "1.0" },
    "object_type": {
      "type": "string",
      "const": "satellite_candidate_act"
    },
    "candidate_act_id": {
      "type": "string",
      "minLength": 16,
      "maxLength": 128
    },
    "act_type": {
      "type": "string",
      "enum": [
        "SAT_RF_ENABLE", "UT_TX_ENABLE", "ISL_FORWARD",
        "BEAM_STEER", "GW_FEEDER", "HANDOVER_TX",
        "PAYLOAD_CMD", "OTHER"
      ]
    },
    "created_at": { "type": "string", "format": "date-time" },
    "expires_at": { "type": "string", "format": "date-time" },
    "vehicle": {
      "type": "object",
      "required": ["vehicle_id"],
      "properties": {
        "vehicle_id": { "type": "string" },
        "constellation_id": { "type": "string" },
        "orbit_shell": { "type": "string" }
      }
    },
    "beam": {
      "type": "object",
      "properties": {
        "beam_id": { "type": "string" },
        "cell_id": { "type": "string" },
        "pointing_ref": { "type": "string" }
      }
    },
    "radio": {
      "type": "object",
      "properties": {
        "frequency_class": { "type": "string" },
        "eirp_class": { "type": "string" },
        "polarization": { "type": "string" },
        "duration_ms": { "type": "integer", "minimum": 0 }
      }
    },
    "grant_digest": {
      "type": "object",
      "required": ["algorithm", "value", "canonicalization"],
      "properties": {
        "algorithm": {
          "type": "string",
          "enum": ["SHA-256", "SHA-384", "SHA-512"]
        },
        "value": { "type": "string" },
        "canonicalization": {
          "type": "string",
          "enum": ["JCS", "implementation-defined"]
        }
      }
    },
    "next_hop": {
      "type": "object",
      "properties": {
        "hop_type": {
          "type": "string",
          "enum": ["ISL", "GATEWAY", "UT", "NONE"]
        },
        "next_hop_id": { "type": "string" }
      }
    },
    "overflight": {
      "type": "object",
      "properties": {
        "overflight_epoch": { "type": "integer", "minimum": 0 },
        "administration": { "type": "string" },
        "license_profile_id": { "type": "string" }
      }
    },
    "provenance": {
      "type": "object",
      "properties": {
        "source_type": {
          "type": "string",
          "enum": [
            "ground_noc", "onboard_scheduler", "ntn_cu",
            "ut_modem", "payload", "autonomy", "other"
          ]
        },
        "command_digest": { "type": "string" }
      }
    },
    "policy_state": {
      "type": "object",
      "required": ["policy_epoch", "revocation_epoch"],
      "properties": {
        "policy_epoch": { "type": "integer", "minimum": 0 },
        "revocation_epoch": { "type": "integer", "minimum": 0 }
      }
    },
    "freshness": {
      "type": "object",
      "required": ["nonce"],
      "properties": {
        "nonce": { "type": "string", "minLength": 16 },
        "sequence": { "type": "integer", "minimum": 0 }
      }
    },
    "finality_sink": {
      "type": "object",
      "required": ["sink_id", "sink_type"],
      "properties": {
        "sink_id": { "type": "string" },
        "sink_type": {
          "type": "string",
          "enum": [
            "SAT_RF_ENABLE", "UT_TX_ENABLE", "ISL_FORWARD",
            "BEAM_STEER", "GW_FEEDER", "PAYLOAD_CMD", "OTHER"
          ]
        }
      }
    }
  }
}

11.2. Authority and Sink Verify

{
  "version": "1.0",
  "object_type": "satellite_finality_authority",
  "authority_id": "sfa-11c0a4e2",
  "candidate_act_id": "act-sat-44b1",
  "scope": {
    "act_type": "SAT_RF_ENABLE",
    "vehicle_id": "sat-12041",
    "beam_id": "beam-17",
    "frequency_class": "KU_DL",
    "eirp_class": "NOMINAL"
  },
  "binding": {
    "grant_digest": {
      "algorithm": "SHA-256",
      "value": "base64url-grant-digest"
    },
    "nonce": "C0FFEE11DEADBEEF",
    "overflight_epoch": 1902,
    "policy_epoch": 88,
    "finality_sink_id": "sat-12041-pa-svc"
  },
  "lifetime": {
    "issued_at": "2026-08-27T01:20:00Z",
    "expires_at": "2026-08-27T01:20:08Z",
    "single_use": true
  }
}
{
  "operation": "RfSinkVerify",
  "request_id": "rf-req-09",
  "decision": "ALLOW",
  "verification": {
    "authority_signature": "VALID",
    "grant_digest": "MATCH",
    "vehicle": "MATCH",
    "beam": "MATCH",
    "overflight_epoch": "CURRENT",
    "nonce": "FRESH",
    "consumption_state": "UNUSED",
    "sink_binding": "MATCH"
  },
  "consumption": {
    "authority_id": "sfa-11c0a4e2",
    "status": "CONSUMED"
  },
  "effectuation": { "permitted": true, "effect_id": "tx-slot-441" }
}
{
  "operation": "RfSinkVerify",
  "request_id": "rf-req-10",
  "decision": "DENY",
  "error": {
    "code": "EF_OVERFLIGHT_MISMATCH",
    "message": "Authority epoch does not match current footprint.",
    "retryable": false
  },
  "effectuation": { "permitted": false }
}

The identifiers below are examples of topology, not SpaceX protocol fields.

{
  "step_1_scheduler": {
    "emitted": "service_downlink_burst",
    "vehicle": "sat-12041",
    "beam": "beam-17",
    "status": "NON_EFFECTIVE"
  },
  "step_2_candidate_act": {
    "act_type": "SAT_RF_ENABLE",
    "vehicle": { "vehicle_id": "sat-12041", "constellation_id": "leo-mesh-a" },
    "beam": { "beam_id": "beam-17" },
    "radio": { "frequency_class": "KU_DL", "eirp_class": "NOMINAL", "duration_ms": 5 },
    "next_hop": { "hop_type": "UT", "next_hop_id": "ut-dish-88" },
    "overflight": { "overflight_epoch": 1902, "administration": "IN" },
    "provenance": { "source_type": "onboard_scheduler" },
    "finality_sink": {
      "sink_id": "sat-12041-pa-svc",
      "sink_type": "SAT_RF_ENABLE"
    }
  },
  "step_3_authority": { "authority_id": "sfa-11c0a4e2", "single_use": true },
  "step_4_sink": { "decision": "ALLOW", "authority_consumed": true },
  "step_5_effect": "service PA enabled for digest-bound 5 ms burst only"
}

12. Hot Path, Autonomy Envelope, and Failure

Repeated bursts inside a fixed envelope — same vehicle, beam set, band, EIRP class, and overflight epoch — MAY use cached policy and short-lived authority. The sink check remains mandatory. New beams, new next hops, payload provenance, unknown administrations, or command-link fade outside the envelope SHOULD escalate. Timeout is not enable.

Illustrative codes: EF-002 NO_FINALITY_AUTHORITY, EF-005 AUTHORITY_ALREADY_USED, EF-006 REPLAY_DETECTED, EF-020 NEXT_HOP_UNRESOLVED, EF-023 OVERFLIGHT_MISMATCH, EF-040 SINK_MISMATCH, EF-041 BEAM_OR_VEHICLE_MISMATCH, EF-070 AUTONOMY_ENVELOPE, EF-080 FAIL_CLOSED.

13. Security Considerations

Threats the sink is intended to make non-completable without current authority include: replay of a prior grant, beam or vehicle substitution, ISL next-hop substitution, gateway site-diversity laundering, payload-bus path around the comms scheduler, stale overflight, faded-link default-open, and ground-session reuse after revocation.

The scheduler and the flight computer are not trusted to police these. The property is mechanical: enable_emitter() does not run. Residual risk remains if an unclassified analog path (a strap, a test coupler, an unmodeled amplifier) can radiate. Implementations MUST treat those as profile failures.

This document does not describe how to disable, jam, or commandeer a satellite. It describes how an operator's own enable path can refuse an unauthorized act.

14. Privacy and Sovereignty Considerations

Grant descriptors can reveal serving beams, gateways, and user-terminal associations. Implementations SHOULD hash raw user maps on untrusted paths and SHOULD treat overflight_epoch as a sovereignty input, not only a radio input. The profile does not create landing rights. It keeps radiation non-completable when those rights, as encoded in the current epoch, say no.

15. IANA Considerations

This document requests no IANA actions.

16. Intellectual Property Note

Certain concepts are associated with pending applications in the DAS Protocols family, including PCT/IB2026/055615 and follow-on NTN-related filings. IETF disclosure should follow BCP 79 [RFC8179].

17. Conclusion

The constellation computer may compute a burst. That computation is not sky-facing authority. RF, ISL, beam, gateway, UT, and payload enable start only after the Candidate Act is validated, evidence is committed, scoped authority is issued, and the aperture-side sink verifies the live grant. RF enable is not transmit authority.

18. Normative References

[RFC2119]
Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, , <https://www.rfc-editor.org/info/rfc2119>.
[RFC8174]
Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, , <https://www.rfc-editor.org/info/rfc8174>.
[RFC8179]
Bradner, S. and J. Contreras, "Intellectual Property Rights in IETF Technology", BCP 79, RFC 8179, , <https://www.rfc-editor.org/info/rfc8179>.

19. Informative References

[I-D.das-6g-finality]
Das, S., "Execution-Finality for AI-Native 5G/6G and O-RAN", Work in Progress, Internet-Draft, draft-das-ai-native-6g-execution-finality-01, , <https://datatracker.ietf.org/doc/html/draft-das-ai-native-6g-execution-finality-01>.
[I-D.das-agentic]
Das, S., "Tool Selection Is Not Execution: Finality for Agentic Tool Dispatch", Work in Progress, Internet-Draft, draft-das-agentic-execution-finality-01, , <https://datatracker.ietf.org/doc/html/draft-das-agentic-execution-finality-01>.

Author's Address

Sangam Das
Independent Inventor
Balasore 756001
Odisha
India