Network Working Group S. Das Internet-Draft Independent Inventor Intended status: Informational 27 August 2026 Expires: 28 February 2027 RF Enable Is Not Transmit Authority: Finality for LEO/NTN and Inter- Satellite Control draft-das-ntn-rf-execution-finality-00 Abstract A LEO constellation computer can compute a transmit burst, a beam command, an inter-satellite forward, or a user-terminal PA enable faster than any ground reviewer can see it. Today those acts become RF because the scheduler selected them, the command link authenticated, or the flight process had the radio device open. Authentication of TT&C, 3GPP NTN registration, and operator allowlists decide who may talk to the vehicle. They do not decide whether this burst, on this beam, to this next hop, over this territory, in this mission epoch, may leave the aperture. Radiation is not reversible. An ISL hop is not a log line. A phased-array user terminal that is already pointed is one register write away from radiating. If the enable line trusts the last ground "go," a stale, substituted, or autonomy-generated command becomes sky-facing consequence. This document specifies a radio-side execution-finality profile for NTN and mega-constellation control. A proposed RF, ISL, beam, gateway, or payload act remains a Candidate Act. A Protected Enforcement Domain binds vehicle, beam, frequency class, duration, next hop, overflight or jurisdiction epoch, and intended sink, then issues scoped non-bearer authority. The Finality Sink sits at the PA enable, ISL switch, beam driver, feeder gateway, or UT transmit path and verifies that authority immediately before energy leaves the system. RF enable is not transmit authority. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Das Expires 28 February 2027 [Page 1] Internet-Draft NTN-RF Finality August 2026 Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 28 February 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 3 2. Requirements Language . . . . . . . . . . . . . . . . . . . . 4 3. Problem Space . . . . . . . . . . . . . . . . . . . . . . . . 4 4. Existing Solutions and What They Do Not Bind . . . . . . . . 5 4.1. TT&C Authentication and CCSDS Command Links . . . . . . . 5 4.2. 3GPP NTN Registration and NAS Security . . . . . . . . . 5 4.3. Operator Flight Allowlists and Safe Modes . . . . . . . . 5 4.4. Link Encryption and Gateway ACLs . . . . . . . . . . . . 5 4.5. ITU Filings and National Gateways . . . . . . . . . . . . 5 4.6. What This Profile Adds . . . . . . . . . . . . . . . . . 6 5. Industrial Relevance and Constellation Cases . . . . . . . . 6 5.1. Phased-Array User Terminal Uplink . . . . . . . . . . . . 6 5.2. Service-Link Radiation on the Vehicle . . . . . . . . . . 6 5.3. Optical or RF Inter-Satellite Forward . . . . . . . . . . 7 5.4. Gateway Feeder and Pointing . . . . . . . . . . . . . . . 7 5.5. Beam Steer and Handover-Coupled Transmit . . . . . . . . 7 5.6. Hosted Payload and Secondary Emitters . . . . . . . . . . 8 5.7. Faded Command Link and Onboard Autonomy . . . . . . . . . 8 5.8. What a Constellation Team Should Measure . . . . . . . . 8 6. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 8 7. Architecture . . . . . . . . . . . . . . . . . . . . . . . . 9 8. Enable-Path Pseudocode . . . . . . . . . . . . . . . . . . . 10 8.1. Scheduler or Flight Output to Candidate Act . . . . . . . 10 8.2. PED Validation . . . . . . . . . . . . . . . . . . . . . 10 8.3. Sink: Verify Then Enable . . . . . . . . . . . . . . . . 11 Das Expires 28 February 2027 [Page 2] Internet-Draft NTN-RF Finality August 2026 9. Load-Bearing Bindings . . . . . . . . . . . . . . . . . . . . 12 10. Alternate-Path Closure . . . . . . . . . . . . . . . . . . . 13 11. JSON Interoperability Profile . . . . . . . . . . . . . . . . 13 11.1. SatelliteCandidateAct . . . . . . . . . . . . . . . . . 13 11.2. Authority and Sink Verify . . . . . . . . . . . . . . . 16 11.3. Informative Starlink-Class Transaction . . . . . . . . . 17 12. Hot Path, Autonomy Envelope, and Failure . . . . . . . . . . 18 13. Security Considerations . . . . . . . . . . . . . . . . . . . 18 14. Privacy and Sovereignty Considerations . . . . . . . . . . . 19 15. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 19 16. Intellectual Property Note . . . . . . . . . . . . . . . . . 19 17. Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . 19 18. Normative References . . . . . . . . . . . . . . . . . . . . 19 19. Informative References . . . . . . . . . . . . . . . . . . . 20 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 20 1. Introduction Mega-constellation and 3GPP NTN stacks now sit on a short path: scheduler / flight software / NTN CU -> command or grant -> onboard or UT radio control -> PA / ISL / beam enable -> radiated or forwarded effect The fourth arrow is the one this document controls. The computer is allowed to compute. The aperture is not allowed to treat that computation as a capability. A proposed service-link burst, feeder- link burst, UT uplink, ISL forward, beam steer, handover-coupled transmit, or payload RF enable remains non-effective until act- specific authority is verified at the component that would actually radiate or forward. This profile uses the two-boundary execution-finality chain in [I-D.das-6g-finality]. It does not specify PHY, waveform, or a named operator's flight code. It specifies the predicates a constellation or NTN implementation must bind before radiation or ISL forward: vehicle identity, beam or cell, frequency class, duration or slot set, next-hop, overflight epoch, command provenance, and sink identity. Public LEO systems with electronically steered user terminals, optical or RF inter-satellite links, and gateway-fed service links — including the class of system operated as Starlink and peers such as OneWeb, Kuiper, and Telesat Lightspeed — are the motivating deployment. Vendor names in this document are informative examples of topology, not claims about unpublished internals. Das Expires 28 February 2027 [Page 3] Internet-Draft NTN-RF Finality August 2026 2. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. Failure to establish current RF or ISL authority MUST NOT be converted into permission to enable the aperture or forward the hop. 3. Problem Space Satellite command fails in a different place than terrestrial session control. A denied 5G PDU session is quiet. A wrongly enabled SSPA, TWTA, or phased-array panel is an ITU event, a neighbor-cell event, and in some bands a safety event. The model's — or the flight computer's — next output is energy. The practical failures look like this: * A ground operator session was valid at T0. At T1 the vehicle has handed over beams and is over a different administration. The old "transmit OK" is still sitting in a command queue. * Onboard autonomy recomputes a burst while the command link is faded. The radio stack treats "we usually transmit here" as authority. * An ISL switch forwards a packet to a next hop that was not the hop bound in the grant, because the mesh route moved and the grant did not. * A user terminal already has network attachment. The modem writes the PA enable for a grant that was issued to a different beam or duty cycle. * A hosted payload computer is allowed to talk on the spacecraft bus. That path is used to enable a sensor RF or a secondary emitter the service-link scheduler never authorized. * A replayed beam-steer command points the array at a gateway or region that is no longer in the current epoch. In each case some upstream control was satisfied: the vehicle authenticated, the UT registered, the NOC user had the console, or the flight process had device access. The missing question is the one asked at the aperture: may this exact act become RF or ISL now. Das Expires 28 February 2027 [Page 4] Internet-Draft NTN-RF Finality August 2026 4. Existing Solutions and What They Do Not Bind Constellation and NTN stacks already contain important controls. This profile consumes them. It does not replace waveform security or ITU coordination. 4.1. TT&C Authentication and CCSDS Command Links Authenticated telecommand establishes that a ground system may speak to a vehicle. CCSDS Space Data Link and related command- authentication profiles bind frames to a key and often to a counter. They do not, by themselves, bind beam_id, EIRP class, overflight epoch, or the particular PA that will fire. A valid command session can still carry the wrong payload act. 4.2. 3GPP NTN Registration and NAS Security Rel-17/18 NTN gives a UE a satellite-aware cell and a secured NAS. That answers "this UT may be on this network." It does not hash the burst the scheduled grant will radiate, and it does not sit in the UT PA enable or the satellite service-link enable. A registered UT can still transmit on a grant that is stale relative to beam or timing advance. 4.3. Operator Flight Allowlists and Safe Modes Flight software typically refuses unknown command opcodes and can enter a safe mode that drops payload RF. Those are class-level interlocks. They do not consume single-use authority for one burst, and they do not stop a well-formed, in-allowlist command that is wrong for this epoch. 4.4. Link Encryption and Gateway ACLs Feeder and service-link encryption protect confidentiality. Gateway ACLs protect who may inject traffic. Encrypted wrong radiation is still radiation. An ACL on the gateway does not control the satellite PA when the vehicle is serving through another gateway or through ISL only. 4.5. ITU Filings and National Gateways Coordination and landing-rights constrain where a system is allowed to operate. They are not a per-burst gate. Overflight changes faster than paper. A vehicle that crossed a boundary mid-queue needs an epoch check at the enable line, not a reminder in the license file. Das Expires 28 February 2027 [Page 5] Internet-Draft NTN-RF Finality August 2026 4.6. What This Profile Adds * the radio command remains a Candidate Act after the scheduler or flight computer emits it; * beam, frequency class, duration, next-hop, and overflight epoch are bindings, not telemetry; * authority is non-bearer, sink-bound, and consumed at PA, ISL, beam driver, gateway, or UT TX; * onboard autonomy and faded command links fail closed or escalate rather than inherit the last "go"; * a payload or bus path that can enable an emitter is in scope; and * the profile does not change PHY. It makes effectuation non- completable without the sink check. 5. Industrial Relevance and Constellation Cases These cases are written in the topology a LEO operator already has: user terminal, space vehicle with service and crosslinks, gateway, and a ground or onboard scheduler. Starlink-class systems are the existence proof that this topology is no longer experimental. 5.1. Phased-Array User Terminal Uplink A consumer or maritime UT has already acquired, is tracking a moving vehicle, and has a scheduler grant. The modem is one enable away from radiating on Ku or Ka. NTN or proprietary attachment says the terminal is in-network. Injected or stale grant data — wrong duty cycle, wrong beam, wrong vehicle — must not become PA enable. The sink is UT_TX_ENABLE. Authority binds vehicle_id or serving cell, frequency class, grant digest, duration, and epoch. A grant computed for vehicle A at epoch 41 MUST fail on vehicle B or epoch 42. This is the satellite analogue of argument-digest binding in [I-D.das-agentic]. 5.2. Service-Link Radiation on the Vehicle The satellite scheduler (onboard or ground-computed and uplinked) selects a panel, beam, slot, and user set. The irreversible step is enabling the service-link PA or beamformer path. A compromised or merely stale onboard process that can write that register is the incident. Das Expires 28 February 2027 [Page 6] Internet-Draft NTN-RF Finality August 2026 The sink is SAT_RF_ENABLE. Authority binds satellite_id, beam_id, frequency class, EIRP class, slot or duration, and overflight_epoch. Autonomy MAY propose the Candidate Act. Autonomy MUST NOT complete enable without current authority. That is the sentence a flight- software reviewer can test. 5.3. Optical or RF Inter-Satellite Forward Once a constellation has a mesh, a packet can leave the planet's regulatory picture without touching a gateway. Route computation is cheap. The hop is not. A forward toward a vehicle that will next serve a restricted administration, or a hop that extends a flow the grant did not include, is a consequence class of its own. The sink is ISL_FORWARD. Authority binds this_vehicle, next_hop_id, flow or grant digest, and the epoch in which that next hop is still the intended hop. Mesh churn without epoch advance is how a correct grant becomes a wrong sky path. 5.4. Gateway Feeder and Pointing Gateways are the high-power, high-duty terrestrial emitters and the usual landing-rights choke point. Operator ACLs already exist. They do not consume single-use authority when the scheduled vehicle, band, or polarization changes mid-pass. The sink is GW_FEEDER. Authority binds gateway_id, satellite_id, band, and pass_epoch. A feeder burst for yesterday's pass MUST fail. Site diversity — moving the same traffic to another gateway — is a new Candidate Act, not reuse of the first authority. 5.5. Beam Steer and Handover-Coupled Transmit Electronic steering is a command, not a side effect. Pointing the array at the wrong gateway, ship, or region is already the incident before the first information bit. Handover that keeps an old beam enable alive across the switch is the replay case. The sink is BEAM_STEER, and any following RF enable MUST see a beam_id that matches the current steer authority. Handover is either a new act or an explicit epoch bump. Silent inheritance is non- conforming. Das Expires 28 February 2027 [Page 7] Internet-Draft NTN-RF Finality August 2026 5.6. Hosted Payload and Secondary Emitters Earth-observation, AIS, or compute payloads share the bus with the comms payload. Bus access is not radiation authority. A payload process that can toggle an emitter, a downlink modulator, or a high- rate sensor radio MUST face a PAYLOAD_CMD sink with its own consequence class. This is the spacecraft version of alternate-path closure: do not let the payload computer walk around the comms scheduler. 5.7. Faded Command Link and Onboard Autonomy LEO command links fade. Operators still want the network to run. The wrong answer is "use the last approved envelope forever." The right answer is a short-lived hot-path envelope, explicitly bounded in epoch, beam set, and EIRP class, that the sink still checks. When the envelope cannot be proved, the aperture stays dark or in the last safe pattern. Timeout is not transmit. 5.8. What a Constellation Team Should Measure The profile is live when production or hardware-in-the-loop logs show: (1) every service-link or UT PA enable has a consumed authority_id; (2) beam or vehicle mismatch is a deny, not a retry that skips the sink; (3) ISL forwards after a route change carry a new epoch; (4) payload and bus paths cannot enable an emitter the comms sink would have refused. Those four tests are more useful than a claim that TT&C is encrypted. 6. Terminology Satellite Candidate Act A scheduler-, flight-, NTN-, or autonomy-generated operation that would radiate, steer, forward on ISL, or enable a payload emitter, but has not been permitted to do so. RF / ISL Finality Sink The component that would actually enable the PA, beamformer, ISL switch, feeder chain, UT transmit path, or payload emitter. If that component can be skipped, it is not the sink. Overflight epoch A monotonic or attested identifier for the regulatory or mission- phase window in which the act is valid (administration under the footprint, license window, eclipse/safe-mode state, or equivalent). Das Expires 28 February 2027 [Page 8] Internet-Draft NTN-RF Finality August 2026 Grant digest A hash over the canonical scheduled grant or command body (vehicle, beam, band, slots, next hop, users). Changing a load- bearing field MUST change the digest. Candidate Act, Non-Effective State, Protected Enforcement Domain (PED), Protected Validation Evidence, scoped non-bearer finality authority, and Finality Sink are used as in [I-D.das-6g-finality]. 7. Architecture A Candidate Act MUST NOT become RF or ISL merely because the scheduler selected it, TT&C authenticated, the UT registered, or onboard autonomy produced a well-formed command. scheduler / flight / NTN CU emits command | v SATELLITE CANDIDATE ACT | v Non-Effective State | v Protected Enforcement Domain vehicle, beam, band grant digest, duration next hop / destination overflight / policy epoch command provenance intended RF or ISL sink | v evidence + scoped authority | v RF / ISL / UT / GW / PAYLOAD SINK | +-- PASS -> enable once, consume authority | `-- FAIL -> aperture stays non-radiating Figure 1: Aperture-time finality PED MAY run on the ground, in a gateway, in a UT TEE, or in a protected partition on the vehicle. The sink MUST run on the path that can prevent enable. A ground policy server that the PA does not consult is not a sink. Das Expires 28 February 2027 [Page 9] Internet-Draft NTN-RF Finality August 2026 8. Enable-Path Pseudocode Procedures are normative in behavior. An implementation MAY collocate PED and sink in one protected radio-control service if evidence is committed before authority is usable and the live grant is checked immediately before enable. 8.1. Scheduler or Flight Output to Candidate Act function ON_RADIO_COMMAND(cmd, ctx): act = SatelliteCandidateAct{ candidate_act_id: fresh_id(), act_type: map_act_type(cmd), vehicle: ctx.vehicle_id, beam_id: cmd.beam_id, frequency_class: cmd.band, eirp_class: cmd.eirp_class, grant_digest: HASH(canonicalize(cmd)), duration: cmd.slots_or_ms, next_hop: cmd.next_hop, overflight_epoch: ctx.overflight_epoch, policy_state: current_epochs(), freshness: {nonce: fresh_nonce()}, provenance: ctx.command_source, # ground, onboard, ntn, payload finality_sink: ctx.sink, expires_at: now() + short_ttl } HOLD_NON_EFFECTIVE(act) return PED_VALIDATE(act, cmd) 8.2. PED Validation Das Expires 28 February 2027 [Page 10] Internet-Draft NTN-RF Finality August 2026 function PED_VALIDATE(act, cmd): if malformed(act): return DENY(MALFORMED_ACT) if not fresh(act.freshness.nonce): return DENY(REPLAY_OR_STALE) if act.policy_state != current_epochs(): return DENY(EPOCH_MISMATCH) if act.overflight_epoch != current_overflight(): return DENY(OVERFLIGHT_MISMATCH) if not allowlisted(act.vehicle, act.act_type, act.frequency_class): return DENY(EMITTER_NOT_AUTHORIZED) if act.next_hop unknown and act.act_type == ISL_FORWARD: return ESCALATE_OR_DENY(NEXT_HOP_UNRESOLVED) if faded(command_link) and act.eirp_class not in HOT_ENVELOPE: return ESCALATE_OR_DENY(AUTONOMY_ENVELOPE) if act.provenance == PAYLOAD and act.act_type != PAYLOAD_CMD: return DENY(PATH_LAUNDERING) evidence = COMMIT_PROTECTED_EVIDENCE(act) authority = ISSUE_SCOPED_AUTHORITY(act, evidence) return ALLOW(authority) 8.3. Sink: Verify Then Enable Das Expires 28 February 2027 [Page 11] Internet-Draft NTN-RF Finality August 2026 function RF_SINK_ENABLE(act, authority, live_cmd): live_digest = HASH(canonicalize(live_cmd)) if authority missing or integrity_fail(authority): return DENY(NO_OR_INVALID_AUTHORITY) if HASH(act) != authority.candidate_act_digest: return DENY(ACT_MISMATCH) if live_digest != act.grant_digest: return DENY(GRANT_SUBSTITUTION) if authority.sink_id != THIS_SINK: return DENY(SINK_MISMATCH) if authority.vehicle != act.vehicle or authority.beam_id != live_cmd.beam_id: return DENY(BEAM_OR_VEHICLE_MISMATCH) if expired(authority) or consumed(authority): return DENY(STALE_OR_USED) if authority.overflight_epoch != current_overflight(): return DENY(OVERFLIGHT_MISMATCH) ATOMICALLY: consume(authority) advance_replay_state(act.freshness.nonce) enable_emitter(live_cmd) record_sink_evidence(act, authority) return ENABLED enable_emitter() is unreachable when any check fails. Logging a denial and then keying the PA is non-conforming. 9. Load-Bearing Bindings Authority issued for SAT_RF_ENABLE / vehicle V / beam B / digest D1 MUST NOT authorize beam B' , vehicle V' , digest D2, an ISL forward, a UT PA enable, or a payload emitter. DISPLAY-equivalent mistakes in this profile are beam substitution, vehicle substitution, and grant substitution. Authority for UT_TX_ENABLE MUST NOT automatically authorize SAT_RF_ENABLE. Authority created under overflight epoch N MUST fail at epoch N+1. Authority for one gateway pass MUST NOT authorize site-diverse feeder radiation at another gateway. Das Expires 28 February 2027 [Page 12] Internet-Draft NTN-RF Finality August 2026 10. Alternate-Path Closure If the same radiated or forwarded effect can be produced by the comms scheduler, a payload computer, a debug bus, a ground override, or a UT test mode, each path MUST either enforce this profile or be unable to produce the effect. Moving the command from the mission scheduler to a laboratory register poke MUST NOT remove the requirement on an in-orbit or in-field emitter. 11. JSON Interoperability Profile Objects are UTF-8 JSON. Transport MAY be a spacecraft bus message, a UT driver ioctl, a gateway controller RPC, or a ground-to-board command wrapper. Transport MUST preserve integrity, sink identity, freshness, and non-bearer semantics. 11.1. SatelliteCandidateAct { "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "urn:ietf:params:json-schema:ntn-rf-finality:candidate-act:1", "title": "SatelliteCandidateAct", "type": "object", "additionalProperties": false, "required": [ "version", "object_type", "candidate_act_id", "act_type", "created_at", "expires_at", "vehicle", "grant_digest", "policy_state", "freshness", "finality_sink" ], "properties": { "version": { "type": "string", "const": "1.0" }, "object_type": { "type": "string", "const": "satellite_candidate_act" }, "candidate_act_id": { "type": "string", "minLength": 16, "maxLength": 128 }, "act_type": { "type": "string", "enum": [ "SAT_RF_ENABLE", "UT_TX_ENABLE", "ISL_FORWARD", "BEAM_STEER", "GW_FEEDER", "HANDOVER_TX", "PAYLOAD_CMD", "OTHER" ] }, Das Expires 28 February 2027 [Page 13] Internet-Draft NTN-RF Finality August 2026 "created_at": { "type": "string", "format": "date-time" }, "expires_at": { "type": "string", "format": "date-time" }, "vehicle": { "type": "object", "required": ["vehicle_id"], "properties": { "vehicle_id": { "type": "string" }, "constellation_id": { "type": "string" }, "orbit_shell": { "type": "string" } } }, "beam": { "type": "object", "properties": { "beam_id": { "type": "string" }, "cell_id": { "type": "string" }, "pointing_ref": { "type": "string" } } }, "radio": { "type": "object", "properties": { "frequency_class": { "type": "string" }, "eirp_class": { "type": "string" }, "polarization": { "type": "string" }, "duration_ms": { "type": "integer", "minimum": 0 } } }, "grant_digest": { "type": "object", "required": ["algorithm", "value", "canonicalization"], "properties": { "algorithm": { "type": "string", "enum": ["SHA-256", "SHA-384", "SHA-512"] }, "value": { "type": "string" }, "canonicalization": { "type": "string", "enum": ["JCS", "implementation-defined"] } } }, "next_hop": { "type": "object", "properties": { "hop_type": { "type": "string", Das Expires 28 February 2027 [Page 14] Internet-Draft NTN-RF Finality August 2026 "enum": ["ISL", "GATEWAY", "UT", "NONE"] }, "next_hop_id": { "type": "string" } } }, "overflight": { "type": "object", "properties": { "overflight_epoch": { "type": "integer", "minimum": 0 }, "administration": { "type": "string" }, "license_profile_id": { "type": "string" } } }, "provenance": { "type": "object", "properties": { "source_type": { "type": "string", "enum": [ "ground_noc", "onboard_scheduler", "ntn_cu", "ut_modem", "payload", "autonomy", "other" ] }, "command_digest": { "type": "string" } } }, "policy_state": { "type": "object", "required": ["policy_epoch", "revocation_epoch"], "properties": { "policy_epoch": { "type": "integer", "minimum": 0 }, "revocation_epoch": { "type": "integer", "minimum": 0 } } }, "freshness": { "type": "object", "required": ["nonce"], "properties": { "nonce": { "type": "string", "minLength": 16 }, "sequence": { "type": "integer", "minimum": 0 } } }, "finality_sink": { "type": "object", "required": ["sink_id", "sink_type"], "properties": { "sink_id": { "type": "string" }, "sink_type": { Das Expires 28 February 2027 [Page 15] Internet-Draft NTN-RF Finality August 2026 "type": "string", "enum": [ "SAT_RF_ENABLE", "UT_TX_ENABLE", "ISL_FORWARD", "BEAM_STEER", "GW_FEEDER", "PAYLOAD_CMD", "OTHER" ] } } } } } 11.2. Authority and Sink Verify { "version": "1.0", "object_type": "satellite_finality_authority", "authority_id": "sfa-11c0a4e2", "candidate_act_id": "act-sat-44b1", "scope": { "act_type": "SAT_RF_ENABLE", "vehicle_id": "sat-12041", "beam_id": "beam-17", "frequency_class": "KU_DL", "eirp_class": "NOMINAL" }, "binding": { "grant_digest": { "algorithm": "SHA-256", "value": "base64url-grant-digest" }, "nonce": "C0FFEE11DEADBEEF", "overflight_epoch": 1902, "policy_epoch": 88, "finality_sink_id": "sat-12041-pa-svc" }, "lifetime": { "issued_at": "2026-08-27T01:20:00Z", "expires_at": "2026-08-27T01:20:08Z", "single_use": true } } Das Expires 28 February 2027 [Page 16] Internet-Draft NTN-RF Finality August 2026 { "operation": "RfSinkVerify", "request_id": "rf-req-09", "decision": "ALLOW", "verification": { "authority_signature": "VALID", "grant_digest": "MATCH", "vehicle": "MATCH", "beam": "MATCH", "overflight_epoch": "CURRENT", "nonce": "FRESH", "consumption_state": "UNUSED", "sink_binding": "MATCH" }, "consumption": { "authority_id": "sfa-11c0a4e2", "status": "CONSUMED" }, "effectuation": { "permitted": true, "effect_id": "tx-slot-441" } } { "operation": "RfSinkVerify", "request_id": "rf-req-10", "decision": "DENY", "error": { "code": "EF_OVERFLIGHT_MISMATCH", "message": "Authority epoch does not match current footprint.", "retryable": false }, "effectuation": { "permitted": false } } 11.3. Informative Starlink-Class Transaction The identifiers below are examples of topology, not SpaceX protocol fields. Das Expires 28 February 2027 [Page 17] Internet-Draft NTN-RF Finality August 2026 { "step_1_scheduler": { "emitted": "service_downlink_burst", "vehicle": "sat-12041", "beam": "beam-17", "status": "NON_EFFECTIVE" }, "step_2_candidate_act": { "act_type": "SAT_RF_ENABLE", "vehicle": { "vehicle_id": "sat-12041", "constellation_id": "leo-mesh-a" }, "beam": { "beam_id": "beam-17" }, "radio": { "frequency_class": "KU_DL", "eirp_class": "NOMINAL", "duration_ms": 5 }, "next_hop": { "hop_type": "UT", "next_hop_id": "ut-dish-88" }, "overflight": { "overflight_epoch": 1902, "administration": "IN" }, "provenance": { "source_type": "onboard_scheduler" }, "finality_sink": { "sink_id": "sat-12041-pa-svc", "sink_type": "SAT_RF_ENABLE" } }, "step_3_authority": { "authority_id": "sfa-11c0a4e2", "single_use": true }, "step_4_sink": { "decision": "ALLOW", "authority_consumed": true }, "step_5_effect": "service PA enabled for digest-bound 5 ms burst only" } 12. Hot Path, Autonomy Envelope, and Failure Repeated bursts inside a fixed envelope — same vehicle, beam set, band, EIRP class, and overflight epoch — MAY use cached policy and short-lived authority. The sink check remains mandatory. New beams, new next hops, payload provenance, unknown administrations, or command-link fade outside the envelope SHOULD escalate. Timeout is not enable. Illustrative codes: EF-002 NO_FINALITY_AUTHORITY, EF-005 AUTHORITY_ALREADY_USED, EF-006 REPLAY_DETECTED, EF-020 NEXT_HOP_UNRESOLVED, EF-023 OVERFLIGHT_MISMATCH, EF-040 SINK_MISMATCH, EF-041 BEAM_OR_VEHICLE_MISMATCH, EF-070 AUTONOMY_ENVELOPE, EF-080 FAIL_CLOSED. 13. Security Considerations Threats the sink is intended to make non-completable without current authority include: replay of a prior grant, beam or vehicle substitution, ISL next-hop substitution, gateway site-diversity laundering, payload-bus path around the comms scheduler, stale overflight, faded-link default-open, and ground-session reuse after revocation. Das Expires 28 February 2027 [Page 18] Internet-Draft NTN-RF Finality August 2026 The scheduler and the flight computer are not trusted to police these. The property is mechanical: enable_emitter() does not run. Residual risk remains if an unclassified analog path (a strap, a test coupler, an unmodeled amplifier) can radiate. Implementations MUST treat those as profile failures. This document does not describe how to disable, jam, or commandeer a satellite. It describes how an operator's own enable path can refuse an unauthorized act. 14. Privacy and Sovereignty Considerations Grant descriptors can reveal serving beams, gateways, and user- terminal associations. Implementations SHOULD hash raw user maps on untrusted paths and SHOULD treat overflight_epoch as a sovereignty input, not only a radio input. The profile does not create landing rights. It keeps radiation non-completable when those rights, as encoded in the current epoch, say no. 15. IANA Considerations This document requests no IANA actions. 16. Intellectual Property Note Certain concepts are associated with pending applications in the DAS Protocols family, including PCT/IB2026/055615 and follow-on NTN- related filings. IETF disclosure should follow BCP 79 [RFC8179]. 17. Conclusion The constellation computer may compute a burst. That computation is not sky-facing authority. RF, ISL, beam, gateway, UT, and payload enable start only after the Candidate Act is validated, evidence is committed, scoped authority is issued, and the aperture-side sink verifies the live grant. RF enable is not transmit authority. 18. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, May 2017, . Das Expires 28 February 2027 [Page 19] Internet-Draft NTN-RF Finality August 2026 [RFC8179] Bradner, S. and J. Contreras, "Intellectual Property Rights in IETF Technology", BCP 79, RFC 8179, May 2017, . 19. Informative References [I-D.das-6g-finality] Das, S., "Execution-Finality for AI-Native 5G/6G and O-RAN", Work in Progress, Internet-Draft, draft-das-ai- native-6g-execution-finality-01, August 2026, . [I-D.das-agentic] Das, S., "Tool Selection Is Not Execution: Finality for Agentic Tool Dispatch", Work in Progress, Internet-Draft, draft-das-agentic-execution-finality-01, August 2026, . Author's Address Sangam Das Independent Inventor Balasore 756001 Odisha India Email: info@sangamdas.com Das Expires 28 February 2027 [Page 20]