Technical notes
CubeSat Exoplanet Transit Photometer — Rev A
This project is currently a Rev A electronics schematic and design review. The telescope, baffle, optical filter, detector mounting, fine-pointing hardware and detector-temperature sensing are not represented as complete flight hardware, and no PCB has been fabricated or tested. Numerical values in these notes are design targets, requirements or future verification criteria unless explicitly identified otherwise.
Mission objective
Measure the brightness of selected nearby stars over several hours and attempt to detect the repeatable reduction in brightness caused by a known transiting exoplanet.
The intended mission would point a small telescope at a selected bright star, focus its light onto the BPW34 photodiode, measure brightness every few seconds, maintain stable pointing and detector temperature, observe before, during and after a predicted transit, produce a light curve showing brightness against time, correct that curve for temperature, pointing and electronic drift, compare the measured transit time and depth with published predictions, and store the measurements onboard for return to Earth.
The source identifies the easiest realistic targets as bright stars with large hot-Jupiter planets, which produce relatively deep transits. It does not name one, and no target has been selected here.
Transit photometry context
A planet crossing in front of its star blocks part of the light reaching us. The fraction blocked is roughly the ratio of the planet's area to the star's, which for a Jupiter-sized planet around a Sun-like star is around one per cent and for smaller planets is very much less. That fraction is the entire signal.
What the measurement produces is a light curve: brightness against time, flat before the transit, falling through ingress, roughly flat at the bottom, rising through egress, flat again afterwards. The depth of the floor says something about the size of the planet relative to its star. The timing of the midpoint says something about the orbit, and is what allows a measurement to be checked against a published ephemeris.
Two consequences follow for the instrument. The first is that the baseline matters as much as the dip — without stable measurements before and after, there is nothing to measure the dip against. The second is that a one per cent signal demands an instrument whose own behaviour is stable to very much better than one per cent over several hours, which is the problem the rest of these notes are about.
Measurement concept
Starlight enters a telescope, passes a baffle that rejects everything not coming from the target direction, passes an optical filter that defines the wavelength band, and lands on the BPW34 photodiode. The photodiode produces a small current proportional to the light falling on it. A transimpedance amplifier converts that current into a voltage, analog filtering removes high-frequency noise, and the ADS1115 digitises the result to 16 bits. The payload computer samples, averages, timestamps and stores. Ground software turns the stored numbers into a calibrated light curve and fits a transit to it.
The central engineering problem is that the science signal is a small fractional change in stellar brightness, and the same fractional change can be produced by the instrument itself.
A measured dip can come from pointing motion across a detector whose response is not uniform; from a change in focus; from a change in detector temperature; from amplifier drift; from ADC drift; from a change in stray light or background; from a change in the calibration state; or from samples that went missing or arrived corrupted. All of those produce a decrease in the recorded number, and none of them is a planet.
So transit detection does not rest on resolving small ADC changes — sixteen bits resolves them easily. It rests on measuring and correcting the systematics well enough that what remains can only be the star. Every requirement in these notes exists to make one of those alternative explanations testable.
Target selection and photon budget
TR-01 requires the telescope to collect and focus sufficient light, and the function-level requirement makes that concrete: the payload will use a telescope sized through a photon-budget calculation for the selected target star.
A photon budget is the chain from the star to the noise floor. Stellar brightness sets how many photons per second arrive at the top of the aperture. Telescope collecting area scales that by how much of the wavefront is intercepted. Optical throughput removes what the optics absorb or scatter. Filter transmission removes everything outside the chosen band. Detector responsivity converts the surviving photons into current. Integration time multiplies the rate into a count per sample. And the noise sources — photon shot noise, detector dark current, amplifier noise, converter noise, and whatever the systematics contribute — set how large a fractional change can be distinguished from nothing.
The acceptance criteria attach to that calculation rather than to a component: telescope aperture and focal length documented, at least 80 per cent of the target image inside the intended detector area, the predicted photon count supporting the required photometric precision, and focus remaining acceptable across the operating temperature range.
No aperture, focal length, target star or photon count is proposed here. The source requires the sizing to follow from the target, and no target has been selected. Everything downstream — what precision is achievable, what integration time is needed, whether the signal fits the converter range — waits on that choice.
Telescope and optical geometry
The telescope, the lens or mirror system and the detector mounting are science-instrument components. They are absent from the EasyEDA schematic, which draws only the electronics that read the detector, but they are not packaging around the electronics — they decide what the electronics are reading.
Function 2 states the geometry requirement: the telescope will produce a focused or intentionally defocused stellar image that remains entirely within the BPW34 active area. Deliberate defocus is a real technique in photometry, because spreading the image over more of the detector averages out local non-uniformity in its response; the source leaves the choice open, and so do these notes.
The acceptance criteria are that at least 90 per cent of the measured stellar signal remains on the detector, that focus drift does not change brightness by more than 0.05 per cent per hour after correction, and that mechanical alignment is repeatable. Verification uses an artificial star, moves the source across the field of view, measures signal against source position, and performs focus and thermal sweeps.
The third of those criteria is the one that is easy to underrate. An alignment that is correct once but not repeatable means every disassembly changes the instrument, and every calibration taken before a disassembly stops applying afterwards.
Stray-light control
A photometer pointed at a faint target in orbit has three bright things to avoid: the Sun, the sunlit Earth and the Moon. Light from any of them reaching the detector adds to the measured signal, and light that varies as the spacecraft moves along its orbit adds a varying amount — which is a slow change in brightness with no astronomical cause.
The coherent requirement in the source is an optical one: the telescope will have a blackened baffle with internal vanes and a defined Sun-avoidance angle. The subsystem description adds the purpose — a blackened tube and internal vanes, blocking sunlight, Earthshine and Moonlight.
Vanes are the part worth explaining, because a plain blackened tube is not enough. Light entering at a shallow angle can reflect off the tube wall, even a black one, and still reach the detector. Vanes are annular baffles inside the tube that interrupt those grazing paths, so that light arriving from outside the acceptance angle has to scatter several times before it can reach the focus, losing most of its energy at each bounce.
The Sun-avoidance angle is an operational constraint rather than a component: it is the minimum angle between the telescope axis and the Sun at which the baffle is designed to work, and it constrains when a given target can be observed at all.
Background also appears downstream, in the ground pipeline's background-subtraction step and in the validation requirement that background changes must not explain a candidate dip. Nothing here has been designed. A baffle geometry, a vane count and spacing, and a Sun-avoidance angle are all Rev B work.
Optical filter
Function 4 requires a documented optical filter to define the detector's wavelength range.
Two jobs. The first is limiting background: the narrower the band, the less unwanted light reaches the detector from everything that is not the target. The second is making the measurement mean something. A BPW34 is sensitive across a broad range extending into the near infrared, and a star's brightness is not the same in every part of that range. Without a defined band, "brightness" is an unweighted mixture over whatever the detector happened to respond to, which is not a quantity another observatory can compare against.
The acceptance criteria are that filter transmission agrees with its specification, that out-of-band transmission remains below a selected limit, and that the filter response is included in the photometric model. That last one is what connects the component to the analysis: the filter curve and the BPW34 spectral response multiply together to give the instrument's effective bandpass, and that is what a published transit depth has to be interpreted against.
Verification measures filter transmission with a spectrometer, tests the complete detector using LEDs at different wavelengths, and compares the result against the predicted BPW34 spectral response.
No filter has been selected, and no band has been chosen.
BPW34 photodiode
The BPW34 is a silicon PIN photodiode. It converts incident light into a current proportional to the optical power falling on its active area. It is the science detector.
The schematic annotates it as "BPW34 = LED", and the designator on the sheet is LED2. The source is explicit that the BPW34 must be correctly identified as a photodiode, not an LED — it appears as a success criterion under Function 5. The artefact is published as drawn and the discrepancy is recorded as a finding; the PDF has not been edited. It is a labelling defect rather than a circuit error, but on a drawing that someone else has to build from, a component labelled as the wrong class of device is a real hazard.
Function 5 requires the BPW34 to operate in a documented photovoltaic or reverse-biased photoconductive mode. The two differ in ways that matter here: photovoltaic mode has no dark current from an applied bias and lower noise, while reverse bias reduces junction capacitance and gives faster response at the cost of added dark current. For a measurement integrating over seconds, speed is not the constraint and noise is, but the source documents the choice as open rather than settling it.
The characterisation requirements are all future work: detector response linear within 0.1 per cent across the science range, dark current measured, saturation not occurring on the selected target, and the response repeated at multiple temperatures. Verification illuminates it with calibrated optical power, sweeps light intensity, records output current and dark current, and repeats across temperature.
Transimpedance amplifier
U3 is an MCP6002 dual op-amp. Function 6 requires one channel to operate as a transimpedance amplifier with a clearly defined feedback resistor and capacitor.
A transimpedance amplifier holds the photodiode at a fixed voltage and converts its current into a voltage across a feedback resistor. The resistor sets the gain — volts out per amp in — and for a photodiode reading a star that resistor is large, which is why R9 on the sheet is 1M. A large feedback resistor is also the dominant noise source in the stage and interacts with the photodiode's capacitance to create a peak in the frequency response, which is what the feedback capacitor is for: C10 at 22pF sits across the feedback path to damp that peak and keep the amplifier stable rather than oscillating.
The acceptance criteria are gain agreeing with simulation within 1 per cent, output stable and not oscillating, input-referred noise meeting the photometric-noise budget, and output staying inside the ADS1115 input range. Verification simulates the amplifier, injects calibrated current, measures gain, noise and bandwidth, and repeats at minimum and maximum temperature.
"Meets the photometric-noise budget" is the criterion that cannot be evaluated yet, because the budget comes from the photon budget, which comes from the target star. The amplifier's noise has to be small compared with the photon noise of the signal it is amplifying; how small depends on how bright the star is.
None of this has been simulated or measured. The feedback network is drawn; its values have not been justified against a requirement.
Analog filtering
Function 7 requires the analog and digital filters to reduce high-frequency noise without distorting transit signals.
The tension in that sentence is the whole design problem. Filtering harder reduces noise, and a photometer would like as much of that as it can get. But a transit has structure in time — ingress and egress are the sloped shoulders where the planet is partly across the disc — and a filter with a long settling time smears those shoulders, which is where the duration and midpoint information lives.
The acceptance criteria hold both ends: noise decreases as predicted, filter settling time is documented, transit ingress and egress are preserved, and filter settings are recorded in the science data. The last is a reproducibility requirement — a light curve filtered with unknown settings cannot be reanalysed, because nobody downstream knows what was removed.
Verification injects a stable DC signal with added noise, introduces small step changes, compares filtered against unfiltered data, and measures settling time. The step test is the direct analogue of an ingress: if the filter rounds a step, it will round a transit edge the same way.
ADS1115 digitisation
U4 is an ADS1115, a 16-bit delta-sigma converter on I2C with a programmable gain amplifier. Function 8 requires it to sample the detector output using a documented gain and sampling rate.
Sixteen bits is comfortable for the signal in question — the resolution is not the limiting factor, which is a point worth making explicitly because it is the intuitive place to look for precision. What limits the measurement is stability: the converter's reference, its linearity and its own temperature coefficient all sit directly in the measured brightness.
The acceptance criteria are that no clipping occurs, that ADC linearity meets the photometric-noise allocation, that missing samples are flagged, and that ADC gain and rate settings are stored. Verification applies calibrated voltages, sweeps the input range, compares against a precision multimeter, and tests every required gain setting.
Two of those criteria are bookkeeping that turns into science later. Storing gain and rate settings is what makes a stored count convertible back into a flux. Flagging missing samples is what keeps a gap in the data from being interpolated into a feature — an unflagged gap during ingress is indistinguishable from a fast change in brightness.
Sampling and averaging
Function 9 sets the cadence: the payload will sample every 1 to 10 seconds and create 30 to 60 second averaged brightness measurements.
Two timescales, two purposes. Raw samples are fast enough to catch and reject transient disturbances — a cosmic-ray hit on the detector, a momentary pointing excursion — which would be buried inside a long integration. Averaged points are the photometry: averaging reduces random noise by the square root of the number of samples combined, and a transit lasting hours is not resolved any better by one-second points than by one-minute ones.
Both are kept. The acceptance criteria require that raw and averaged values are preserved, that no samples are silently lost, and that sampling-time error stays below 1 per cent. Keeping both matters because a systematic found later can only be investigated in the raw data; an averaged point has already thrown away the evidence of what produced it.
The precision criterion is a proposed one-minute precision of 0.1 per cent for the selected bright star. That is a design objective, not an achieved result, and it is conditional on a target star that has not been chosen.
Verification applies constant illumination, records continuously for at least six hours, calculates short- and long-term stability, and verifies every timestamp. Six hours is chosen to match the observation length, because a drift that is invisible over ten minutes is exactly the kind that ruins a transit measurement.
Pointing stability
A photodiode's response is not perfectly uniform across its active area. Shine the same light on one part of it and then another and the output current differs slightly. That is a property of the device, not a fault, and for most uses it does not matter at all.
For a photometer it is the dominant instrumental error. If the stellar image moves across the detector during an observation, the measured brightness changes with it. The star has not changed; the instrument has sampled a different part of its own response curve. A slow drift in pointing over several hours produces a slow change in measured brightness over several hours, which is the exact shape the mission is looking for.
Function 10 states the requirement on the spacecraft: it will keep the star inside a defined region of the photodiode. The acceptance criteria are that target motion stays below 5 per cent of the useful detector width, that pointing information exists for at least 99 per cent of science samples, and that pointing-related brightness error is corrected below 0.05 per cent.
The second criterion is the one that makes the third possible. Correction is only available if the pointing at each sample is known, which means pointing telemetry has to be recorded alongside the photometry rather than assumed. A sample without pointing data cannot be corrected and cannot be trusted.
Verification mounts the detector on a controlled pointing platform, introduces known pointing errors, measures signal against detector position, and verifies the correction algorithm against that measured map.
The hardware that does the pointing — star tracker, reaction wheels, gyroscope, fine Sun or attitude sensors, and precise telescope alignment — belongs to the host spacecraft and appears nowhere on the payload schematic. The source cites ASTERIA, a CubeSat that attempted transit photometry of 55 Cancri e, as outside context for how demanding this is: approximately 0.5 arcsecond RMS pointing stability and around 10 millikelvin of camera thermal control. Those are another mission's figures, quoted as context only. The source is explicit that this payload does not need to match them initially, and no pointing requirement here is derived from them.
Target acquisition and verification
Function 11 requires a guide camera or the spacecraft star tracker to verify the target before science collection.
The failure this prevents is subtle and expensive: an observation of the wrong star. It produces a perfectly good light curve, correctly timestamped, fully calibrated, with no dip in it — and nothing in the data says the telescope was pointed somewhere else. Hours of observing time and the transit window are both gone, and the result looks like a non-detection.
The acceptance criteria are that the correct star is acquired in at least 95 per cent of valid attempts, that target coordinates are stored with the data, and that science collection does not begin after a failed acquisition. The third is the important one — the payload has to be willing to not observe. A system that starts collecting regardless produces data that cannot be distinguished later from a successful observation.
Verification uses artificial star fields, tests different star brightnesses and positions, introduces incorrect targets, and confirms correct abort and retry behaviour.
Temperature measurement
The source requires a temperature sensor installed near the detector and amplifier and sampled at least once per second. Three devices need covering: the BPW34, the MCP6002 and the ADS1115.
All three have temperature coefficients. Photodiode responsivity and dark current both move with temperature. Amplifier offset and bias current move with temperature. The converter's reference and gain move with temperature. Each of those appears in the output as a change in measured brightness that has nothing to do with the star, and in low Earth orbit the thermal environment changes on the orbital period — which is hours, the same timescale as a transit.
The acceptance criteria are temperature accuracy within 0.1 degrees Celsius, temperature data accompanying at least 99 per cent of photometry samples, and corrected drift below 0.05 per cent per hour. Verification compares against a calibrated thermometer, places the system in a temperature chamber, maintains constant illumination, and calculates detector response against temperature.
Constant illumination during the chamber sweep is what separates the instrument's temperature response from everything else: with the light held fixed, any change in the output is thermal by construction, and the resulting curve is the correction coefficient.
The present schematic does not contain a temperature sensor. Adding one is a Rev B item, and without it the 0.05 per cent per hour correction has nothing to work from.
Thermal drift correction
Measuring temperature is only half of it. The correction is a model that maps measured temperature to measured brightness, and it has to be derived before flight from the thermal-chamber data described above.
The structure is simple enough: for each device, a coefficient relating its temperature to a fractional change in the output; applied to the recorded temperature at each sample; subtracted from the measured brightness. What makes it delicate is that the correction is applied to the same quantity it is trying to protect. A correction derived from a noisy or poorly sampled calibration adds its own error to every point, and a correction with the wrong sign makes the drift worse while looking like it was handled.
Two protections follow from the source. The first is that temperature accompanies at least 99 per cent of samples — the correction is only defensible where the input exists. The second is the validation standard, which requires that temperature changes must not explain a candidate dip: the corrected light curve is not the end of the argument, and the engineering telemetry has to be examined alongside it.
Nothing here has been characterised. The coefficients do not exist, because neither the hardware nor the chamber campaign does.
Calibration-light system
H1 is a two-pin header for an external star LED, intended to connect to a stabilised LED placed inside the telescope assembly. Function 13 requires it to use a stable current driver and a fixed optical path.
What it supports, from the source: checking photodiode response, measuring amplifier drift, testing the ADC, and verifying the instrument before and after observations. In one sentence, it answers whether the instrument changed between two moments.
The acceptance criteria are that calibration-light output is repeatable within 0.1 per cent, that LED current and temperature are recorded, and that calibration cannot accidentally operate during stellar observations. The last is an interlock requirement, and it exists because an LED firing mid-observation would inject a large, fast brightness change into a science light curve — a feature that nothing downstream could distinguish from an astronomical event without knowing the calibration state.
Recording LED current and temperature is what makes the reference a reference. An LED's output depends on both, so a calibration exposure whose current and temperature are unknown does not establish a known optical input, and the drift it appears to reveal might be the LED's own.
What it is not, in the source's own words, is a substitute for an actual star. It is an internal reference source. It does not arrive through the telescope's pointing, it does not carry the star's spectrum, and it does not reproduce external stray light — so it cannot validate pointing behaviour, sky background, or the detection of a transit. It can tell you the instrument moved. It cannot tell you the star did.
Verification performs repeated LED exposures, changes supply voltage and temperature, measures output over several hours, and tests the interlocks between calibration and science modes.
Dark baseline
Function 14 requires the payload to measure dark current and amplifier offset using a shutter, dark cover or reference detector.
The reason for a separate measurement is that the recorded number is not the stellar signal. It is the stellar signal plus the photodiode's dark current plus the amplifier's input offset plus any residual background, all added together into one value. Those additive terms drift with temperature and with time, and drift in an additive term is indistinguishable from a change in the star unless it is measured independently.
The acceptance criteria are that dark measurements occur before or after each observation, that dark uncertainty remains below 10 per cent of the total noise budget, and that sudden offset changes are flagged. Taking the dark next to the observation rather than once at integration is what keeps it relevant — the point is to capture the offset under the conditions that actually applied.
Verification blocks the telescope entrance, records dark values at several temperatures, introduces known amplifier offsets, and verifies dark subtraction recovers them.
The mechanism is undecided. A shutter is a moving part in a CubeSat, which brings its own reliability and mass cost; a dark cover has the same problem; a reference detector avoids moving parts but has to track the science detector closely enough to be representative. The source lists all three and selects none, and no shutter has been designed.
Gain and saturation
Function 17 requires the payload to select amplifier gain and ADC range appropriate for each target.
The reason is dynamic range. A gain chosen to make a faint star readable will drive a bright one into saturation, and a saturated sample is not a large number — it is a number that has stopped responding to light. During a transit, a saturated baseline would flatten and the dip would appear shallower than it is, or vanish.
The acceptance criteria set the working point: a normal stellar signal using approximately 20 to 80 per cent of the ADC range, no normal science samples clipping, gain changes recorded, and calibration repeated following a gain change. The 20 per cent floor exists because sitting too low wastes resolution and puts the signal nearer the amplifier's offset and noise; the 80 per cent ceiling leaves headroom for the brightest excursion the observation might contain.
Recalibrating after a gain change is not optional bookkeeping. The gain path has its own linearity and offset at each setting, so a calibration taken at one gain does not transfer to another, and a light curve spanning a gain change without recalibration has a step in it that is purely instrumental.
Verification uses artificial stars of different brightness, sweeps amplifier and ADC gain, tests saturation detection, and recalibrates after changing gain.
Observation timing
Function 15 requires the host spacecraft to provide UTC time.
The precision demanded is modest by spacecraft standards — absolute time error no greater than one second — because a transit lasts hours and its midpoint is compared against a published ephemeris with its own uncertainty. What matters more than absolute accuracy is the behaviour of the clock across an observation.
The acceptance criteria say so: absolute error within one second, sample-spacing error below 1 per cent, time remaining monotonic, and resets and synchronisation failures flagged. Monotonicity is there because a clock that steps backwards mid-observation reorders the light curve, and a transit reconstructed from misordered samples is not a transit. Sample-spacing error matters because the averaging assumes points are evenly spaced; uneven spacing biases the averages and smears the edges.
Verification compares timestamps with a GNSS reference, restarts the processor, interrupts time synchronisation, and tests counter rollover. The restart and interruption cases are the realistic ones — a payload that silently resumes timestamping with a reset clock produces data that looks fine and is wrong.
Timing is not a complete Rev A subsystem. There is no GNSS receiver on the sheet and no defined spacecraft time interface.
Full-transit scheduling
Function 16 requires each observation to include the predicted transit and stable measurements before and after it: at least one hour of pre-transit baseline, complete coverage of the predicted transit, at least one hour of post-transit baseline, and identification of any data interruptions.
The baselines are not padding. A transit is measured as a fractional decrease relative to the out-of-transit level, so the out-of-transit level has to be established on both sides. One side alone cannot separate a transit from a slow instrumental drift in the same direction — the dip and the drift look identical if there is nothing after the event to come back up to.
An hour on each side also gives the systematic corrections something to work against. A thermal or pointing trend visible in the baseline can be extrapolated across the transit; a trend only visible during the transit cannot be distinguished from the transit.
Verification runs an accelerated simulated transit schedule, verifies automatic observation startup, introduces interruptions, and confirms correct quality flags. The payload has to start on its own at the right time, because the transit will not wait for a command pass.
Data storage
CARD1 is a microSD socket. Function 18 requires storage to hold at least twice the data expected during the longest communication outage.
The factor of two is margin against the case that matters: the payload observes a transit, the downlink opportunity is missed or delayed, and another observation is scheduled before the first has been returned. Storage sized exactly to one outage loses data in that case, silently, by overwriting.
The acceptance criteria are about integrity rather than capacity: required capacity demonstrated, records including a CRC or another error check, previously stored data surviving interrupted writes, and a failed or full card not crashing the payload.
The interrupted-write requirement is the interesting one. Flash cards do not fail gracefully mid-write; a power interruption partway through can corrupt not only the record being written but the filesystem structure around it. A partial record that cannot be detected as partial is worse than a missing one, because it will be analysed as if it were real — which is why the CRC requirement sits next to it.
Verification fills the card, reads and verifies every record, interrupts power during writes, and removes and corrupts the card deliberately.
Spacecraft interface
Function 19 requires the main power and data connector to provide a formally defined flight interface.
Rev A does not have one. What it has is a development set: a USB-C receptacle for programming, debugging and laboratory power, an OLED header for laboratory status display, reset and boot buttons, and a status LED. None of those is a flight interface, and treating them as one would leave the real interface unspecified while appearing complete.
The acceptance criteria are a data rate at least twice the expected average requirement, at least 99.9 per cent of packets delivered correctly after retries, corrupted commands rejected, and communication loss not erasing stored data. The last is the one that protects the science: an outage has to be survivable, not destructive, which links this requirement back to the storage margin above.
Verification connects to a simulated spacecraft computer, sends valid, incomplete and corrupted packets, interrupts communication, and tests continuous maximum-rate data transfer.
Autonomous modes and fault recovery
Function 20 requires the firmware to support five modes: OFF, BOOT, NOMINAL SURVEY, BURST and SAFE.
The acceptance criteria tie the modes to the measurement. Every valid transition operates correctly; science mode requires valid time and pointing; unsafe sunlight, voltage or temperature causes safe mode; and the mode is recorded in telemetry.
Requiring valid time and pointing before science mode is a data-quality rule expressed as a state machine. It means the payload cannot produce a light curve that is missing the two things needed to interpret it, because it will not enter the mode that produces one.
Function 21 covers recovery: a watchdog, brownout detection and communication timeouts, with software-hang recovery within five seconds, three consecutive recovery trials succeeding, fault details stored, and existing science data remaining readable. Five seconds matters during an observation — a longer recovery punches a gap in the light curve, and a gap during ingress or egress removes the part carrying the timing information.
Verification freezes the firmware, locks the ADC communication bus, lowers input voltage, and simulates storage failure. None of it has been written, because there is no firmware yet.
Ground photometry pipeline
Function 22 defines what ground software does to a raw light curve before anyone is allowed to look for a planet in it. The order matters: each step assumes the ones before it have been applied.
- 01
Dark subtraction
Removes detector dark current and amplifier offset, measured separately before or after the observation.
- 02
Temperature correction
Applies the thermal coefficients to the recorded detector, amplifier and converter temperatures.
- 03
Calibration correction
Applies what the internal reference source established about instrument response and drift.
- 04
Pointing correction
Removes the brightness change caused by the star moving across a non-uniform detector, using the recorded pointing telemetry.
- 05
Background subtraction
Removes residual stray light and sky background.
- 06
Outlier identification
Flags samples inconsistent with their neighbours — particle hits, pointing excursions, dropouts. Flagged, not silently deleted.
- 07
Time conversion
Converts spacecraft timestamps to the time system the published ephemeris uses.
- 08
Flux normalisation
Scales the out-of-transit baseline to unity so depth reads as a fraction.
Systematic-error correction
The acceptance criteria on the pipeline are what make it auditable rather than a black box.
Every processed point traces back to raw data. Rejected points and corrections are documented. A simulated constant star remains stable within 0.1 per cent per minute. Injected transits are preserved.
The first two are provenance requirements. A corrected light curve is the product of a chain of models, each of which could be wrong; if a point cannot be traced to the raw sample and the corrections applied to it, then a disagreement later cannot be investigated. Documenting rejections is the same principle applied to what was removed — a pipeline that silently discards inconvenient points can manufacture a clean result.
The last two are the two ways the pipeline can fail, and they pull in opposite directions. A pipeline that does not correct enough leaves a constant star drifting, and drift is a false transit. A pipeline that corrects too aggressively flattens everything, including the transit it exists to reveal — the corrections are fitted against the light curve itself, so an over-flexible model can absorb the signal into the baseline. Testing both against synthetic data is the only way to know which side of that line the implementation sits on.
Verification generates artificial stellar datasets, adds pointing, thermal and electrical drift, processes them through the pipeline, and compares the output with the known input.
Transit detection and fitting
Function 23 requires ground software to estimate transit depth, midpoint, duration and statistical significance.
Those four are the output of the mission. Depth relates to the planet's size relative to the star. Midpoint is what is compared against a published ephemeris. Duration constrains the geometry of the crossing. Significance is the statement of how confident the measurement is, and without it the other three are numbers without error bars.
The acceptance criteria are stated against synthetic tests, because that is the only way to know the answer in advance: a transit depth of at least 0.5 per cent recovered at signal-to-noise greater than 5; midpoint agreeing with prediction within ten minutes; measured depth agreeing with the expected value within approximately 20 per cent; and non-transit data not producing significant false detections.
That last criterion is the one that keeps the rest honest. A fitting routine sensitive enough to find a 0.5 per cent dip will also find dips in pure noise if it is allowed to; measuring the false-alarm rate on data known to contain nothing is what establishes the threshold at which a detection means something.
Verification adds artificial transits to real noise, varies depth, duration and timing, uses blind test datasets, and measures detection and false-alarm rates. Blind testing is deliberate: an analyst who knows where the transit was injected will find it.
No transit has been detected, and no detection or false-alarm rate has been measured.
Transit validation
Detecting a dip and having detected a planet are different claims, and Function 24 is where the second one has to be earned.
The requirement is that a detected dip will be compared with published predictions and independent observations. The acceptance criteria are three, and all three have to hold: at least two of the payload's own observations show consistent results, or one observation agrees with an independently confirmed transit; temperature, pointing and background changes cannot explain the dip; and uncertainty is reported.
The first is repeatability. A transiting planet recurs on a known period, so a real signal can be observed again; an instrumental artefact generally cannot be reproduced on someone else's schedule. Agreeing with an independently confirmed event is the alternative route to the same confidence, using another observatory's detection as the second witness.
The second is the criterion this whole instrument is built around. It says the engineering telemetry is part of the evidence, not support data — the thermal record, the pointing record and the background estimate have to be examined during the candidate event and shown not to account for it. A light curve alone cannot discharge that burden, however clean it looks.
The third is the shortest and the one most often skipped. A depth without an uncertainty cannot be compared with a published value, because there is no way to say whether a disagreement is significant.
Verification observes multiple predicted events, compares against published TESS ephemerides, examines engineering data during the transit, and conducts an independent review.
Power and noise
Function 25 and the power subsystem on the sheet. Every figure is a requirement or an allocation.
- The payload accepts the spacecraft voltage and produces a stable 3.3 V rail. U1, an AP2112K.
- Voltage remains within 5 per cent across the input range.
- At least 20 per cent power margin exists against the allocation.
- Supply ripple remains below the photometric-noise allocation — the rail is inside the measurement, not beside it.
- No component overheats under maximum load.
- F1 resettable fuse, Q1 MOSFET, D1 USBLC6-2SC6 ESD device on the USB input, and decoupling.
- Sweep input voltage; test minimum and maximum load; measure ripple and startup behaviour; operate other spacecraft loads during photometry.
Environmental qualification
Function 26 requires the payload to survive vibration, vacuum, thermal cycling, electromagnetic interference and the expected radiation exposure.
The acceptance criteria are the usual three plus one that belongs specifically to an optical instrument: no structural or electrical damage, functional tests passing afterwards, stored data remaining readable, and gain and calibration changing by less than 10 per cent — or recalibration restoring performance.
That last allowance is realistic rather than lax. An instrument whose calibration shifts during launch is not necessarily broken, provided the shift is detected and a post-environment calibration re-establishes the relationship between counts and flux. What would be fatal is a shift that goes unnoticed, which is why the test campaign ends with calibration rather than with a functional check.
The planned campaign is a vibration test, a thermal-vacuum test, an electromagnetic compatibility test, radiation assessment and testing, an optical realignment test, and post-environment calibration. The optical realignment step is the one unique to this payload: the mechanical alignment requirement from Function 2 has to still hold after the vibration, or the 90 per cent-on-detector criterion silently stops being true.
Top-level requirements
The eleven requirements the payload is designed against, with the meaning the source attaches to each. None has been demonstrated, because there is no hardware.
| ID | Top requirement | Meaning |
|---|---|---|
| TR-01 | Collect stellar light | Telescope must collect and focus sufficient light. |
| TR-02 | Maintain pointing | Star must remain in a stable position on the detector. |
| TR-03 | Measure brightness precisely | Electronics must resolve small brightness changes. |
| TR-04 | Control systematic drift | Temperature, pointing, background and electronic changes must be corrected. |
| TR-05 | Observe the entire transit | Measurements must cover before, during and after transit. |
| TR-06 | Calibrate the instrument | Detector, amplifier, ADC and calibration LED must be characterised. |
| TR-07 | Store and return data | Light curves must be preserved without silent corruption. |
| TR-08 | Operate autonomously | Payload must schedule observations, detect faults and recover. |
| TR-09 | Interface with the spacecraft | Power, timing, pointing and communication interfaces must be defined. |
| TR-10 | Survive launch and space | Payload must tolerate vibration, vacuum, temperature and radiation. |
| TR-11 | Validate the scientific result | A transit claim must be statistically significant and repeatable. |
Mission-function verification matrix
The mission functions from the design review, with the requirement, the acceptance criteria and the planned test for each. Every row is planned: none has been carried out, and several need an artificial star, a thermal chamber, a spacecraft emulator or optics that do not exist yet.
One row is marked as consolidated. The source block for stray-light control is internally inconsistent — its requirement and test text belong to a different detector technology — so that text is excluded pending source cleanup, and the row below is built only from the coherent baffle material stated elsewhere in the review. Its success criteria and test method are recorded as not available rather than invented. The table scrolls sideways on a narrow screen.
| Function | Requirement | Success criteria | Test method |
|---|---|---|---|
| Collect light from the target star | A telescope sized through a photon-budget calculation for the selected target star. | Aperture and focal length documented; at least 80 per cent of the target image inside the intended detector area; predicted photon count supports the required precision; focus acceptable across the operating temperature range. | Measure aperture and focal length; observe an artificial star at a long distance; measure the focused spot size; repeat at different temperatures; compare light collection with the optical model. |
| Focus the star on the BPW34 | A focused or intentionally defocused stellar image remaining entirely within the BPW34 active area. | At least 90 per cent of the measured stellar signal remains on the detector; focus drift changes brightness by no more than 0.05 per cent per hour after correction; mechanical alignment is repeatable. | Use an artificial star; move the source across the field of view; measure signal versus source position; perform focus and thermal sweeps. |
| Control stray light (consolidated) | A blackened baffle with internal vanes and a defined Sun-avoidance angle, blocking sunlight, Earthshine and Moonlight. | Not available — the source block for this function is internally inconsistent and is excluded pending cleanup. | Not available — see above. A stray-light test campaign is Rev B work. |
| Limit the optical wavelength band | A documented optical filter defining the detector wavelength range. | Filter transmission agrees with specification; out-of-band transmission below the selected limit; filter response included in the photometric model. | Measure filter transmission with a spectrometer; test the complete detector using different LED wavelengths; compare with the predicted BPW34 spectral response. |
| Convert stellar light into current | The BPW34 operates in a documented photovoltaic or reverse-biased photoconductive mode. | Detector response linear within 0.1 per cent across the science range; dark current measured; no saturation on the selected target; the BPW34 correctly identified as a photodiode, not an LED. | Illuminate with calibrated optical power; sweep light intensity; record output current and dark current; repeat at multiple temperatures. |
| Amplify photodiode current | One MCP6002 channel as a transimpedance amplifier with a clearly defined feedback resistor and capacitor. | Gain agrees with simulation within 1 per cent; output stable and not oscillating; input-referred noise meets the photometric-noise budget; output stays inside the ADS1115 input range. | Simulate the amplifier; inject calibrated current; measure gain, noise and bandwidth; repeat at minimum and maximum temperature. |
| Filter electronic noise | Analog and digital filters reduce high-frequency noise without distorting transit signals. | Noise decreases as predicted; filter settling time documented; transit ingress and egress preserved; filter settings included in the science data. | Inject a stable DC signal with added noise; introduce small step changes; compare filtered and unfiltered data; measure settling time. |
| Digitize brightness | The ADS1115 samples the detector output using a documented gain and sampling rate. | No clipping occurs; ADC linearity meets the photometric-noise allocation; missing samples are flagged; ADC gain and rate settings are stored. | Apply calibrated voltages; sweep the ADC input range; compare with a precision multimeter; test every required gain setting. |
| Record the light curve | Sample every 1 to 10 seconds and create 30 to 60 second averaged brightness measurements. | No samples silently lost; sampling-time error below 1 per cent; proposed one-minute precision of 0.1 per cent for the selected bright star; raw and averaged values preserved. | Apply constant illumination; record continuously for at least six hours; calculate short- and long-term stability; verify every timestamp. |
| Maintain target pointing | The spacecraft keeps the star inside a defined region of the photodiode. | Target motion below 5 per cent of the useful detector width; pointing information exists for at least 99 per cent of science samples; pointing-related brightness error corrected below 0.05 per cent. | Mount the detector on a controlled pointing platform; introduce known pointing errors; measure signal versus detector position; verify the pointing-correction algorithm. |
| Identify the target star | A guide camera or spacecraft star tracker verifies the target before science collection. | Correct star acquired in at least 95 per cent of valid attempts; target coordinates stored; science collection does not begin after failed acquisition. | Use artificial star fields; test different star brightnesses and positions; introduce incorrect targets; confirm correct abort and retry behaviour. |
| Measure detector temperature | A temperature sensor installed near the detector and amplifier, sampled at least once per second. | Temperature accuracy within 0.1 degrees Celsius; temperature data accompany at least 99 per cent of photometry samples; corrected drift below 0.05 per cent per hour. | Compare with a calibrated thermometer; place the system in a temperature chamber; maintain constant illumination; calculate detector response versus temperature. |
| Produce calibration light | The external calibration LED uses a stable current driver and fixed optical path. | Calibration-light output repeatable within 0.1 per cent; LED current and temperature recorded; calibration cannot accidentally operate during stellar observations. | Perform repeated LED exposures; change supply voltage and temperature; measure output over several hours; test interlocks between calibration and science modes. |
| Measure the dark baseline | Dark current and amplifier offset measured using a shutter, dark cover or reference detector. | Dark measurements occur before or after each observation; dark uncertainty below 10 per cent of the total noise budget; sudden offset changes flagged. | Block the telescope entrance; record dark values at several temperatures; introduce known amplifier offsets; verify dark subtraction. |
| Time-stamp measurements | The host spacecraft provides UTC time. | Absolute time error no greater than one second; sample-spacing error below 1 per cent; time remains monotonic; resets and synchronisation failures flagged. | Compare timestamps with a GNSS reference; restart the processor; interrupt time synchronisation; test counter rollover. |
| Observe the complete transit | Each observation includes the predicted transit and stable measurements before and after it. | At least one hour of pre-transit baseline; complete predicted transit covered; at least one hour of post-transit baseline; data interruptions identified. | Run an accelerated simulated transit schedule; verify automatic observation startup; introduce interruptions; confirm correct quality flags. |
| Control gain and saturation | Amplifier gain and ADC range selected appropriately for each target. | Normal stellar signal uses approximately 20 to 80 per cent of ADC range; no normal science samples clip; gain changes recorded; calibration repeated following a gain change. | Use artificial stars of different brightness; sweep amplifier and ADC gain; test saturation detection; recalibrate after changing gain. |
| Store the observation | MicroSD storage holds at least twice the data expected during the longest communication outage. | Required capacity demonstrated; records include a CRC or another error check; previously stored data survive interrupted writes; a failed or full card does not crash the payload. | Fill the card; read and verify every record; interrupt power during writes; remove and corrupt the card. |
| Communicate with the spacecraft | The main power/data connector provides a formally defined flight interface. | Data rate at least twice the expected average requirement; at least 99.9 per cent of packets delivered correctly after retries; corrupted commands rejected; communication loss does not erase stored data. | Connect to a simulated spacecraft computer; send valid, incomplete and corrupted packets; interrupt communication; test continuous maximum-rate transfer. |
| Operate autonomously | Firmware supports OFF, BOOT, NOMINAL SURVEY, BURST and SAFE modes. | Every valid transition operates correctly; science mode requires valid time and pointing; unsafe sunlight, voltage or temperature causes safe mode; mode recorded in telemetry. | Exercise every transition; send invalid commands; remove pointing and timing inputs; create electrical and temperature faults. |
| Recover from faults | The processor uses a watchdog, brownout detection and communication timeouts. | Software-hang recovery within five seconds; three consecutive recovery trials succeed; fault details stored; existing science data remain readable. | Freeze the firmware; lock the ADC communication bus; lower input voltage; simulate storage failure. |
| Process the raw light curve | Ground software performs dark subtraction, temperature correction, calibration correction, pointing correction, background subtraction, outlier identification, time conversion and flux normalisation. | Every processed point traces back to raw data; rejected points and corrections documented; a simulated constant star remains stable within 0.1 per cent per minute; injected transits preserved. | Generate artificial stellar datasets; add pointing, thermal and electrical drift; process them through the pipeline; compare output with the known input. |
| Detect and fit a transit | Ground software estimates transit depth, midpoint, duration and statistical significance. | A transit depth of at least 0.5 per cent recovered at S/N greater than 5; midpoint agrees with prediction within ten minutes; measured depth agrees with the expected value within approximately 20 per cent; non-transit data produce no significant false detections. | Add artificial transits to real noise; vary depth, duration and timing; use blind test datasets; measure detection and false-alarm rates. |
| Validate the transit | A detected dip is compared with published predictions and independent observations. | At least two of the payload observations show consistent results, or one agrees with an independently confirmed transit; temperature, pointing and background changes cannot explain the dip; uncertainty is reported. | Observe multiple predicted events; compare with published TESS ephemerides; examine engineering data during the transit; conduct an independent review. |
| Regulate electrical power | The payload accepts the spacecraft voltage and produces a stable 3.3 V supply. | Voltage remains within 5 per cent; at least 20 per cent power margin exists; ripple remains below the photometric-noise allocation; no component overheats. | Sweep input voltage; test minimum and maximum load; measure ripple and startup behaviour; operate other spacecraft loads during photometry. |
| Survive the mission environment | The payload survives vibration, vacuum, thermal cycling, electromagnetic interference and expected radiation exposure. | No structural or electrical damage; functional tests pass afterward; gain and calibration change by less than 10 per cent, or recalibration restores performance; stored data remain readable. | Vibration test; thermal-vacuum test; electromagnetic compatibility test; radiation assessment and testing; optical realignment test; post-environment calibration. |
Rev A design review
What the drawing settles, and what it does not.
It settles the acquisition electronics. A photodiode position, a transimpedance stage around an MCP6002 with its feedback network, a 16-bit converter on I2C, a payload processor, microSD storage, a calibration-light header, a regulated supply with protection, and a development interface. As a board that reads a photodiode and writes the result to a card, it is coherent.
What it does not settle starts with the instrument. There is no telescope, no lens or mirror system, no baffle, no optical filter and no optical mounting. Nothing on the sheet collects light, and the source is explicit that these are essential rather than optional.
Then the missing measurements. There is no temperature sensor near the BPW34, the MCP6002 or the ADS1115, and all three drift. Fine pointing depends on host-spacecraft systems — star tracker, reaction wheels, gyroscope, attitude sensors — none of which is on the payload schematic. Timing has to come from the spacecraft or GNSS and is not a complete subsystem here. The dark-baseline mechanism is undecided.
Then the interfaces. The flight power and data connector needs formal definition; USB-C, the OLED header and the buttons are development conveniences and are not it.
Then the drawing itself. The photodiode is annotated "BPW34 = LED" and carries the designator LED2. The source requires it to be correctly identified as a photodiode. The artefact is published as drawn and the discrepancy is recorded rather than quietly fixed.
Finally the unverified analog. Transimpedance gain, noise, stability and bandwidth are unsimulated and unmeasured. ADC gain, sampling rate and linearity are undefined. The calibration LED driver and its optical path need characterisation. And the photon budget that would justify any of those numbers waits on a target star.
Nothing in this review has been resolved by testing. There is no board and no telescope.
Rev B required changes
What the next revision has to settle before a board is worth fabricating, with the source basis for each. The order runs from the instrument outward.
| Area | Required change | Source basis |
|---|---|---|
| Optical system | Define telescope aperture, focal length and optical layout from a photon budget for a selected target. | Function 1; the primary-payload component list. |
| Baffle | Design a blackened baffle with internal vanes and a defined Sun-avoidance angle for sunlight, Earthshine and Moonlight rejection. | Consolidated from the Function 3 success criterion and the optical-baffle subsystem row. |
| Filter | Select and characterise the optical passband, and include its response in the photometric model. | Function 4. |
| Detector mount | Define BPW34 alignment, the focus or defocus strategy, and mechanical repeatability. | Function 2. |
| Detector labelling | Correct the schematic annotation so the BPW34 is identified as a photodiode rather than an LED. | Function 5 success criteria. |
| Temperature | Add sensing near the BPW34, the MCP6002 and the ADS1115, sampled at least once per second. | The thermal-monitoring payload section and the temperature-monitoring function. |
| Pointing | Define the host attitude-telemetry interface, the stability requirement, and the pointing-correction method. | Functions 10 and 11; the fine-pointing payload section. |
| Analog front end | Simulate and verify transimpedance gain, noise, bandwidth and stability, and justify the feedback network against the noise budget. | Function 6. |
| ADC | Define gain and sampling strategy, calibrate linearity, and store the settings with the data. | Function 8. |
| Calibration LED | Stable current driver, fixed optical path, recorded current and temperature, and an interlock against science mode. | Function 13. |
| Dark baseline | Select and design the shutter, dark-cover or reference-detector strategy. | Function 14. |
| Timing | Define the UTC source and the timestamp behaviour, including reset and synchronisation flagging. | Function 15. |
| Flight interface | Define the spacecraft power and data connector and protocol, separate from the development interfaces. | Function 19. |
| Ground segment | Build and test the photometry pipeline and the transit-fitting analysis against synthetic data. | Functions 22, 23 and 24. |