Skip to content
Saharsh Engineering Log
Back to CubeSat Solar X-Ray Flare Payload — Rev A

Technical notes

CubeSat Solar X-Ray Flare Payload — Rev A

Rev A is a design-stage schematic and a design review. Nothing here has been fabricated, measured or flown, so every number on this page is a proposed engineering target or a requirement rather than a result. These notes hold the mission definition, the subsystem architecture, the per-function logic and the Rev B change list behind the case study.

01

Mission objective

The satellite's objective is to detect and characterise solar flares by measuring changes in solar soft-X-ray irradiance. It would observe the Sun whenever orbital and attitude conditions permit, measure X-ray intensity, and identify the beginning, peak and end of an event, recording how quickly intensity rises and falls and estimating flare strength from calibrated measurements.

Supporting measurements attach context: visible light for Sun-presence and pointing checks, local magnetic field as space-environment data, and time, position, attitude and temperature on every record. Measurements are stored until they can be transmitted, and compared afterwards with established space-weather observations.

The payload does not predict a flare. It detects and characterises one after its X-ray output begins increasing.

02

Science measurement concept

A flare appears first as a rise in soft X-rays above a slowly varying background, so the instrument watches one band continuously and looks for departures from that background rather than for an absolute level.

A possible initial measurement band is approximately 0.1 to 0.8 nm, which is the band conventionally used for solar-flare classification. This is a starting target, not a specification: the real spectral range will be set by whichever detector and filter combination is eventually chosen.

03

Detector requirements

The primary payload is a solar X-ray detector. It is required, and it is not present in the Rev A schematic. A practical assembly is a stack of parts rather than a single component, and the requirements below are targets to design against.

A silicon PIN photodiode, silicon-drift detector, SiC photodiode or other suitable X-ray detector. Not yet selected.
Thin, X-ray transmitting, and intact after launch vibration.
Optical and ultraviolet blocking, passing the selected X-ray band.
Sun-facing, with a field of view wide enough to absorb spacecraft pointing error.
Low-noise transimpedance or charge-sensitive amplifier, plus pulse-processing or current-measurement electronics.
An ADC, with saturated readings flagged rather than silently clipped.
A temperature sensor at the detector, and calibration circuitry.
Sensitive enough for the weakest targeted event, without saturating on the largest; dark current below the minimum useful signal.
04

Supporting sensors

Neither supporting sensor measures the science quantity. Both exist to say whether an X-ray measurement should be believed.

Confirms the Sun is in the general field of view, detects eclipse entry and exit, supports coarse pointing checks, monitors visible-light contamination, and helps identify a sensor-cover or aperture problem.
Will not independently identify or classify a flare. Needs optical attenuation if direct sunlight would saturate it, and its readings must be synchronised with the X-ray series to be useful as a quality flag.
Local three-axis magnetic field, supporting spacecraft orientation estimates, magnetic-field context, identification of interference from the payload's own electronics, and correlation with the local space environment.
Selectable from plus or minus 4 to plus or minus 16 gauss, 16-bit digital output, per the ST datasheet.
Does not measure the magnetic field at the Sun. Needs hard-iron and soft-iron correction, and placement away from magnetic hardware and large current loops.
05

Subsystem architecture

Every subsystem the payload needs, and where it stands in Rev A. Four rows are required additions that the schematic does not contain, and four more depend on spacecraft services the payload does not provide for itself.

SubsystemHardwarePurpose
X-ray detectorRequired additionConvert incoming solar X-rays into an electrical signal
X-ray aperture and filtersRequired additionAdmit the selected X-ray band while blocking visible light, ultraviolet light and unwanted particles
X-ray analog front endRequired additionAmplify the very small detector current or pulses
Radiation threshold detectorU4 LMV331 comparatorDetect when the conditioned radiation signal crosses a selected threshold
Ambient-light subsystemVEML7700Measure visible-light level and support Sun-presence checks
Magnetic-field subsystemU3 LIS3MDLMeasure the local three-axis magnetic field
Payload computerU1 2.4 GHz MCURead sensors, process measurements, detect events and control operating modes
Data storageCARD1 microSDStore science measurements, event records and health data
Power regulationU2 AP2112K-3.3Produce a regulated 3.3 V supply
USB protectionD1 USBLC6-2SC6Protect USB data lines against electrostatic-discharge events
Input protectionF1 resettable fuseLimit excessive current
Spacecraft interfaceH2 payload-bus headerReceive power and exchange commands and data with the satellite computer
Expansion interfaceCN1 Qwiic / I2C connector and H1Connect additional sensors or development equipment
Development interfaceUSB-CProgram, debug and test the payload on the ground
User interfaceSW1-SW3 and LEDsSupport reset, boot, test and status indication
Flight softwareMCU firmwareAcquire data, detect flares, control storage and respond to faults
Time and orbit serviceSpacecraft bus, requiredProvide accurate time and spacecraft position
Attitude-control interfaceSpacecraft ADCS, requiredDetermine whether the detector is correctly pointed at the Sun
Thermal monitoringTemperature sensors requiredMeasure detector and electronics temperature for correction and protection
CommunicationsSpacecraft radio requiredTransmit stored measurements to the ground station
06

Top-level requirements

Fourteen requirements the payload is designed against. The numerical values are proposed initial engineering targets, not verified performance — none of them has been measured, because there is no hardware to measure.

IDRequirement
TR-01Measure solar soft-X-ray irradiance using a dedicated X-ray detector.
TR-02Detect the onset, peak and end of solar-flare events.
TR-03Distinguish genuine X-ray increases from pointing errors, eclipses, detector noise and temperature drift.
TR-04Measure over a target irradiance range of roughly 1e-7 to 1e-3 W/m2, subject to detector validation.
TR-05Produce X-ray measurements at a cadence of one second or faster during science operation.
TR-06Associate every measurement with time, spacecraft position, attitude, detector temperature and quality flags.
TR-07Confirm Sun visibility using the ambient-light sensor and spacecraft attitude information.
TR-08Measure local magnetic-field conditions as supporting context data.
TR-09Store science and housekeeping information until it can be downlinked.
TR-10Communicate reliably with the spacecraft computer.
TR-11Autonomously enter a high-rate observation mode after detecting a possible flare.
TR-12Detect internal electrical, thermal, sensor, memory and software faults.
TR-13Survive launch vibration, vacuum, radiation and the expected orbital temperature range.
TR-14Produce science data calibrated and comparable with measurements from established solar-monitoring spacecraft.
07

Flare-onset logic

Onset detection is a change detector, not a threshold on absolute intensity. The software maintains a running estimate of the background X-ray level, and a trigger requires both a minimum increase above that background and a minimum persistence time, so a single high sample cannot start an event.

The trigger settings are adjustable rather than fixed, and eclipse transitions and loss of pointing must not produce a flare alert — both look like a large, fast change in the raw series.

The targets to design against: flare mode begins within 10 seconds of the trigger condition being met, at least 95 per cent of validation events above the selected threshold are detected, and false alarms stay below the mission limit. These are acceptance criteria for a future test campaign, not results.

08

Peak and end logic

Once an event is open the software records the largest valid X-ray value, and keeps the event open until the signal has stayed below an ending threshold for a defined time. Closing on the first sample below threshold would split one flare into several.

Multiple peaks within an event are retained rather than collapsed, because a flare with two maxima is a different observation from two flares. Each event record carries onset, peak, end, duration and maximum intensity.

Validation is by replaying single-peak and multi-peak profiles, slow and rapid decays, and interrupted observations, and comparing against independent analysis software.

09

Sun visibility and pointing

Two independent things have to be true before a measurement counts: the Sun must be present, and the detector must be pointed at it.

Presence comes from the VEML7700, kept inside its measurement range with optical attenuation if direct sunlight would saturate it, and synchronised with the X-ray samples. Its output is a quality check. Visible light alone never constitutes flare evidence.

Pointing comes from the spacecraft. The detector axis is measured relative to the spacecraft coordinate frame, the ADCS supplies timestamped attitude, and a measurement is valid only when the Sun is inside the detector field of view, with attitude uncertainty carried into the quality information. Off-axis measurements are marked invalid or reduced quality rather than discarded silently.

10

Magnetic context

The magnetometer records the local three-axis field, synchronised with the flare observations. Calibration coefficients correct hard-iron and soft-iron effects, and out-of-range readings are flagged.

The harder problem is the payload itself. The MCU, the microSD card, the LEDs, the regulator and any radio all generate magnetic fields, so payload-generated interference has to be measured rather than assumed small, and the sensor placed away from magnetic hardware and large current loops. Planned verification runs a Helmholtz coil and known rotations against an independent magnetometer with all of that hardware active, because testing a quiet board proves nothing about a working one.

11

Temperature compensation

Detector gain and offset move with temperature, and in orbit the temperature moves a great deal. A sensor sits near the X-ray detector, gain and offset are characterised across temperature, and the correction coefficients are stored in memory. Measurements taken outside the calibrated temperature range are flagged rather than corrected with coefficients that do not apply.

The targets: temperature known to within 1 degree Celsius, corrected readings repeatable within 5 per cent for identical inputs, and calibration drift below 10 per cent after environmental testing. These are the limits the design has to meet, established by thermal-chamber testing that has not been carried out.

12

Timing and orbit context

A flare measurement that cannot be placed in time cannot be compared with anyone else's. Absolute time comes from the spacecraft, with a target accuracy of 100 milliseconds or better, and every record carries spacecraft-position information alongside it.

Clock drift is characterised rather than assumed, and loss of synchronisation is flagged. The rule that follows is simple: no accepted data packet contains an unknown time.

13

Data storage

Science and housekeeping data are written to the microSD card until they can be downlinked. A record holds X-ray intensity, light level, magnetic field, temperature, time, position, attitude, operating mode and quality flags, with a checksum or CRC on each packet.

Flare data takes storage priority, and critical data is also buffered in internal flash where practical, so a card failure does not take the event with it. The design constraints are about failure rather than capacity: an interrupted write must not corrupt unrelated files, and a full card must not crash the payload.

The targets are at least 99 per cent of test records recovered correctly, corrupted data detected rather than returned, and a sudden power loss that does not destroy the whole dataset.

14

Spacecraft communications

The payload talks to the spacecraft computer, not to the ground. A method is still to be selected — UART, SPI, I2C or CAN — and commands cover modes, thresholds, calibration, data download, timing and reset. Packets carry sequence numbers and error detection, invalid commands are rejected safely rather than partially applied, and the link recovers automatically after an interruption.

One point is worth stating plainly, because the schematic invites the opposite assumption: the MCU's 2.4 GHz radio does not serve as the satellite downlink. The payload sends its data to the spacecraft computer, which controls a dedicated space-qualified radio.

15

Power and protection

The AP2112K produces the 3.3 V rail, and its input voltage has to stay above the level it needs to regulate — a Rev B verification item, not something Rev A confirms. The polyfuse limits excessive current and the USBLC6-2SC6 protects the USB data lines against electrostatic discharge.

The requirement that matters for the science is quieter: sensitive analog circuits need properly filtered power, because the eventual detector front end will be measuring a very small current while the microSD card and the radio are switching. Proposed consumption is below 2 W nominal and 3 W peak, and the intended checks include that microSD operation does not reset the processor and that power noise does not interfere with X-ray measurements.

16

Operating modes

Eight modes, each with defined entry and exit conditions. Invalid transitions are rejected, and the active mode is reported in telemetry so the ground always knows which one the payload is in.

Unpowered.
Start-up and self-check before science operation.
Reduced power, detector protected. Entered on fault.
Powered and ready, not observing.
Normal science observation of the Sun.
Increased sampling rate, entered automatically on a flare trigger.
Characterisation and correction-coefficient measurement.
Transferring stored records to the spacecraft computer.
17

Fault recovery

The aim is that no software or hardware problem permanently disables the payload. A watchdog resets frozen software, sensor communication timeouts are detected, invalid sensor readings are rejected rather than stored as data, and fault information is written to nonvolatile memory so it survives the reset that follows.

Repeated faults put the payload into safe mode, and the spacecraft can reset or power-cycle it. The condition that has to be designed against explicitly is the endless reset loop: recovering from a fault is only useful if the recovery itself terminates.

18

Environmental requirements

The payload has to survive launch and then work in orbit. The PCB and detector assembly must tolerate launcher vibration and shock, operate in vacuum, and use materials that meet outgassing limits, with every component assessed for radiation effects.

The requirement specific to this instrument is alignment. The X-ray filter and the detector alignment have to remain stable, because a detector that survives launch but is no longer pointed where the calibration assumed is not a working detector. Planned verification is vibration and shock, thermal-vacuum cycling, electromagnetic-compatibility testing and radiation analysis, with calibration repeated afterwards to measure what the testing changed.

19

Calibration

Calibration links a number the instrument produces to a physical quantity, and without it the measurements are only relative.

The intended approach is calibrated X-ray equipment at a licensed laboratory, sweeping intensity from the minimum to the maximum of the required range, repeated at several temperatures, with a separate measurement taken with the aperture blocked to characterise the dark background. The resulting correction table is validated against separate test measurements rather than against the data used to build it.

Science data is then expected to be comparable with established solar-monitoring spacecraft, allowing for the difference in spectral range between instruments.

20

Verification plan

How each mission function is intended to be shown to work. None of it has been carried out; there is no hardware to carry it out on. Writing the tests beside the requirements is what exposed the gaps in Rev A.

FunctionPlanned verification
Receive solar X-raysFilter transmission measured at an X-ray calibration facility; visible-light rejection under a solar simulator; filter inspected before and after vibration; payload rotated around a simulated Sun.
Detect solar X-raysCalibrated X-ray equipment at a licensed laboratory; measurement with the aperture blocked; intensity swept minimum to maximum; repeated at several temperatures.
Amplify the detector outputCalibrated currents injected; gain, linearity, noise, bandwidth and recovery time measured, with the MCU and microSD active, at minimum and maximum temperature.
Digitise the signalCalibrated voltages applied and compared against a precision meter; normal and high-speed sampling exercised; signals applied slightly above ADC range to confirm the saturation flag.
Detect flare onsetHistorical solar X-ray data replayed with artificial flares of varying strength, plus noise, eclipse transitions and missing data, against manually verified event times.
Determine peak and endSingle-peak and multi-peak profiles replayed, with slow and rapid decays and interrupted observations, compared against independent analysis software.
Verify Sun visibilityCalibrated solar simulator swept through light levels; attenuation filters tested; eclipse and off-Sun conditions simulated.
Confirm Sun pointingPayload on a rotation table with a simulated Sun source and injected spacecraft-attitude messages, including near the edge of the field of view.
Measure the local magnetic fieldHelmholtz coil and known rotations, with MCU, microSD, LEDs, regulator and radio operating, compared against an independent magnetometer.
Correct for temperatureThermal chamber, identical detector input at multiple temperatures, correction table built and then validated on separate measurements.
Timestamp and locatePrecisely timed electronic signal compared against a laboratory reference; clock drift measured across temperature; timing input disconnected and restored.
Store dataCard filled and read; power interrupted during selected writes; deliberately corrupted records inserted; long-duration maximum-rate run.
Communicate with the spacecraftSpacecraft-computer simulator sent valid, invalid, repeated and corrupted commands; interface disconnected and restored; sustained at maximum planned data rate.
Regulate and protect powerSupply voltage swept; current, ripple, startup behaviour and regulator temperature measured; analog noise recorded with microSD and radio active; controlled transient and overcurrent applied.
Control operating modesEvery valid transition exercised and invalid ones attempted; low-power, high-temperature, sensor-failure and communication-loss conditions injected.
Detect and recover from faultsFirmware frozen deliberately; sensors disconnected; corrupt memory responses, undervoltage and overtemperature simulated; repeated resets performed.
Survive launch and orbitVibration and shock, thermal-vacuum cycling, electromagnetic-compatibility testing, radiation analysis, and calibration repeated afterwards.
Validate detected flaresHistorical reference datasets replayed before launch; in-orbit measurements compared with NOAA or other solar-monitoring observations; missed and false detections examined.
21

Mission success criteria

Four levels, defined in advance so that success is not decided after the fact. All four are objectives for a mission that has not been built.

The payload powers on in orbit; the MCU, microSD, light sensor, magnetometer and spacecraft interface operate; the X-ray detector produces measurements above its dark background; the satellite transmits science and health data.
Calibrated solar X-ray measurements; Sun-pointed, off-Sun and eclipse conditions distinguished; at least one solar X-ray variation agreeing with independent observations; uncertainty and quality information on every measurement.
At least one suitable solar flare detected when an observable event occurs, with onset, peak, ending, duration and relative intensity recorded alongside visible-light, magnetic, temperature, attitude, orbit and timing context, agreeing with an independent source.
Multiple flares across different intensity levels; timing and relative intensity agreeing with established observations; calibration stable throughout; a scientifically reusable dataset.
22

Rev A design review

The review compared the schematic against the eighteen mission functions and the fourteen top-level requirements, and asked of each one whether Rev A could contribute to it at all.

What is present: the payload computer, the 3.3 V regulation chain, input and ESD protection, microSD storage, the two context sensors, a comparator, the USB-C and Qwiic development interfaces, the expansion and payload-bus headers, and the buttons and LEDs. That covers the housekeeping half of the instrument and a useful amount of the context half.

What is absent is the measurement. There is no detector, no aperture, no filter, no low-noise front end and no ADC path, which means TR-01 through TR-05 — the requirements that make this a science instrument rather than a development board — have no hardware behind them. The LMV331 is labelled a radiation pulse comparator, but with no conditioned signal reaching its input and no defined threshold at the other, it cannot perform that function as drawn.

The review also flagged several items that are not missing subsystems but unfinished connections: an absent pull-up on the comparator output, unverified regulator input voltage, magnetometer placement close to current-carrying electronics, unlabelled payload-bus connections, and no test points on the analog path that does not exist yet.

23

Rev B changes

The full list from the design review, in the order it was written. The main page carries the eleven that decide whether the next revision becomes an instrument; these are the rest of them.

#Change
01A dedicated X-ray detector.
02A Sun-facing X-ray aperture.
03X-ray-transmitting and visible-light-blocking filters.
04A low-noise radiation-detector amplifier.
05An ADC, or an assigned MCU ADC input.
06A detector temperature sensor.
07A defined comparator threshold circuit.
08A pull-up resistor for the LMV331 comparator output.
09Attitude and timing inputs from the spacecraft.
10Optical attenuation for the VEML7700.
11Better physical separation between the magnetometer and current-carrying electronics.
12Clearly labelled payload-bus connections.
13Test points for the detector and analog signal path.
14Verified AP2112K input voltage.
15Internal-flash backup for critical microSD data.
16Radiation and environmental review of all components.
17Clear analog and digital grounding.
18Watchdog and safe-mode support.