Skip to content
Saharsh Engineering Log
Back to CubeSat Storm-Time Radiation Belt Mapper — Rev A

Technical notes

CubeSat Storm-Time Radiation Belt Mapper — Rev A

This project is currently a Rev A electronics schematic and design review. Aperture, shielding and absorber geometry are not defined as flight hardware; Rev A does not yet demonstrate four complete independent science channels; and no PCB has been fabricated, calibrated or radiation-tested. Numerical values in these notes are design targets, requirements or future verification criteria unless explicitly identified otherwise.

01

Mission objective

Measure how energetic-particle radiation around Earth changes during geomagnetic storms.

The intended 1U CubeSat would travel through regions influenced by Earth's radiation belts, detect energetic electrons, protons and other charged particles, record when and where radiation levels rise and fall, compare measurements from differently shielded detector channels, combine those with position, time, temperature, attitude and magnetic field, send the result to the ground, and produce maps showing radiation intensity along the orbit.

The source states the limit in the same breath as the objective, and it belongs here too: a single satellite would create an along-track radiation map, not an instantaneous map of the entire radiation belt. Complete global coverage would require repeated orbits or several satellites.

02

Radiation-belt and space-weather context

Earth's magnetic field traps energetic charged particles in regions that are neither uniform nor static. During geomagnetic storms the trapped populations are energised, redistributed and sometimes emptied, and the boundaries of the affected regions move.

For a spacecraft this is an engineering environment before it is a science subject. Energetic particles degrade solar cells, deposit total ionising dose in electronics, and cause single-event upsets in memory and logic. A mission that records what the environment actually did along a real orbit, with its uncertainty attached, produces something useful to anyone designing the next spacecraft.

Which regions a given satellite samples is a function of its orbit rather than of the instrument. The source names the South Atlantic Anomaly, radiation-belt regions and high-latitude particle precipitation as the candidates. No orbit has been selected, so nothing in these notes assumes a particular sampling pattern.

03

Along-track mapping concept

The instrument measures a count rate at a point. The map is what emerges when those points are placed on a trajectory.

Each accepted interval has to carry enough with it to be placed: the radiation level, the time, the spacecraft's position, its attitude and therefore where each aperture was pointing, the local magnetic field, the temperature, the detector state, and quality information covering live time, saturation and missing context. Strip any of those and the sample becomes a number that cannot be located, oriented or trusted.

What results is a profile along the path the spacecraft actually flew. It is a record of what the spacecraft encountered along its trajectory, not a snapshot of the entire radiation belt at once — the belt is a volume and the orbit is a line through it. Repeated passes build up coverage of the regions the orbit crosses; regions it does not cross are not sampled at all.

The ground requirement follows from that. Every map value traces back to calibrated source data, maps include uncertainty and quality flags, and invalid, saturated and missing intervals are clearly identified rather than interpolated over.

04

Detector measurement concept

A BPW34 is a silicon PIN photodiode. An energetic charged particle crossing its depletion region deposits energy and frees charge, and that charge appears as a brief current pulse — the same mechanism that makes it a light sensor, applied to a different kind of ionising input.

The chain that follows is short and every stage matters. The pulse is converted to a voltage by a transimpedance amplifier, shaped so its amplitude can be assessed, compared against a programmable threshold by a discriminator, and recorded by the microcontroller with its channel identity and time. Counting those events over an interval gives a count rate.

Three things convert a count rate into a measurement. The geometry, which says what volume of sky and what particle population the channel was exposed to. The calibration, which says what fraction of the particles arriving actually produced a recorded event. And the context, which says where and when the count was taken. Rev A addresses the third, partially addresses the electronics, and does not yet address the first two.

05

Four-channel architecture

The source requires four independent BPW34 detector channels, and is specific about what "channel" means: each shall have its own bias, return path, amplifier, comparator and microcontroller input, with a shaping stage and a calibration-injection point, and with channel identity preserved through to the ground.

The acceptance criteria attach to independence rather than to count: all four channels operate independently; injecting a signal into one produces less than 1 per cent response in another; and failure of one detector does not disable the others. Verification injects a calibrated electrical pulse into one channel at a time, measures all four outputs, then disconnects or shorts one channel and confirms the rest keep working.

Inspecting the Rev A sheet rather than counting symbols gives a clear answer, and it is the same conclusion the case study reaches. Rev A shows four detector devices but does not yet demonstrate four complete independent science paths. The four BPW34s — LED1 through LED4 — sit on a shared net rather than on four separate bias and return paths. The analog side carries three op-amp sections and three comparators, one of which drives a status LED rather than an event input. The per-channel elements the source names — feedback resistor, feedback capacitor, shaping network, injection point, four times over — are not present; the sheet's entire discrete complement is four resistors and three capacitors.

Why that matters is not bookkeeping. Four identical or incompletely separated paths do not automatically create four independent measurements. If the detectors share a bias or a return, a disturbance on that shared node appears on every channel at once, which is indistinguishable from a real multi-channel event — so coincidence, the technique that is supposed to identify penetrating particles, becomes the technique most vulnerable to the sharing. And if the channels cannot be differentiated by shielding, comparing them yields nothing anyway. Independence is the precondition for both of the things four channels are for.

06

Detector aperture and geometry

An aperture is the opening through which a channel is allowed to see the environment, and it fixes two quantities: the effective detector area presented to arriving particles, and the solid angle accepted.

Those two together are what later becomes the geometric factor. They are also what makes a count rate comparable between channels, between orbits and between missions — without them, a higher count could mean a more intense environment or simply a larger opening.

The requirement is that every channel shall have a measured active area, field of view, absorber thickness and light-tight enclosure. The acceptance criteria are dimensional: aperture area within 5 per cent of the design, and detector alignment within 5 degrees. Verification measures apertures and absorbers with precision tools and checks alignment against an optical reference.

Alignment tolerance is a measurement requirement rather than an assembly nicety. A channel pointing 5 degrees away from where the model assumes is sampling a different part of the pitch-angle distribution, and in a structured environment that is a systematic error in the result, not a cosmetic one.

No aperture dimension is proposed here. None is in the source, and none can be chosen before the orbit and the target populations are.

07

Differential shielding and absorbers

Four channels are only informative if they differ, and shielding is how they are made to differ deliberately.

An absorber placed in front of a detector attenuates arriving particles, and it does so more strongly at lower energies. A thicker absorber therefore generally suppresses lower-energy particles more strongly than a thinner one, so two channels that are identical apart from their absorbers respond differently to the same environment. Comparing calibrated channels with deliberately different absorber responses can provide coarse penetration information.

The source is careful about how far that goes, and so is this page. REQ 2 asks that the channels provide at least coarse particle-penetration information. It does not ask for species identification, and it states the precondition directly: without shielding and calibration, four photodiodes cannot reliably determine particle energy or type. Penetration is a statement about how much material the arriving flux got through. Turning that into "these were electrons of such-and-such energy" requires assumptions about the incident population that a four-point penetration curve does not supply on its own.

What has to be established per channel is effective area, solid-angle acceptance, and the response of the shielding and absorber combination — all of which feed the calibration described later.

No absorber material, thickness or cutoff energy is proposed here. The source proposes none, and inventing one would put a number into the response model that nothing supports.

08

Light-tight detector design

A BPW34 is a photodiode, and it responds to visible light far more readily than to the particles this instrument is built to count. An enclosure that leaks light produces a count rate that looks like radiation and tracks the orbit's day-night cycle.

Blocking visible light is therefore the first job the source assigns to the shielding subsystem, and it has its own acceptance criterion: bright visible light does not produce a statistically significant radiation count. Verification compares detector counts in complete darkness and under bright light, and inspects the enclosure for gaps.

The requirement also appears at the top level. REQ 8 covers contamination control, and lists visible light alongside electrical noise, magnetic interference and channel crosstalk as things that shall not be mistaken for particle events. Grouping them is the right instinct: they are four different physical mechanisms with one shared failure mode, which is a count that was never a particle.

09

BPW34 detector channels

The sheet carries four BPW34 devices, drawn with the designators LED1 through LED4. The designator is a schematic-capture artefact rather than a claim about the part; the source is unambiguous that these are the radiation detectors.

What the device brings to the measurement is a depletion region of fixed thickness and area. That geometry sets how much energy a crossing particle is likely to deposit, and therefore how large the resulting pulse is relative to the amplifier's noise. It also sets the intrinsic upper bound on what the detector can distinguish: a photodiode of this kind reports that energy was deposited, not what deposited it.

The devices need an independent bias and return per channel, which is the first half of the independence requirement. The bias itself is generated on the sheet by U6, a detector-bias boost converter.

Nothing here is characterised. Detector efficiency, dark current at the operating bias and temperature, and the relationship between deposited energy and pulse amplitude are all calibration outputs that do not exist yet.

10

Charge and analog front end

The signal leaving a BPW34 after a particle crossing is a small, brief packet of charge. The analog front end's job is to turn that into a voltage pulse large enough and clean enough to discriminate.

The source specifies the elements per channel: a transimpedance amplifier, a feedback resistor, a feedback capacitor, a pulse-shaping stage, a comparator or discriminator, and a calibration-injection point. The feedback resistor sets the conversion gain and is also the dominant noise contributor; the feedback capacitor stabilises the stage against the detector's own capacitance, which would otherwise produce a peak in the response and a tendency to oscillate.

The requirement is a stable low-noise transimpedance amplifier and pulse-shaping network per channel. The acceptance criteria are that measured gain agrees with the circuit model within 10 per cent, the amplifier does not oscillate, noise remains below the event threshold, and gain remains usable across the operating temperature range.

The noise criterion is the one that couples to everything else. Noise below the event threshold is what keeps the false-trigger rate down; raise the threshold to escape noise and the channel stops counting the smallest real events, which changes its efficiency and therefore its calibration.

Verification simulates the circuit before construction, injects calibrated charge pulses, measures gain, noise, pulse width and settling time, and repeats at minimum, normal and maximum temperature. The simulation step is listed first deliberately: it is the cheapest place to find out that a feedback network does not do what was assumed.

11

Pulse shaping

Shaping sits between the amplifier and everything that makes a decision, and it does two jobs that pull against each other.

It gives the pulse a defined, repeatable shape so that a threshold crossing means the same thing every time, and so that an amplitude can be assessed at a known point. And it limits bandwidth, which reduces noise. The tension is that a longer shaping time reduces noise but lengthens the interval during which the channel is busy, which raises dead time and lowers the rate the instrument can handle before it starts losing events.

That trade is why shaping appears in the dynamic-range discussion as well as here: the shaping time chosen for a quiet orbit may not survive a storm. The source does not fix a shaping time, and neither do these notes.

Rev A does not contain a per-channel shaping network. The sheet's discrete complement is four resistors and three capacitors in total, which is not enough for one shaping stage per channel, let alone four with their feedback networks.

12

Threshold detection

A comparator turns an analog pulse into a yes-or-no event. The requirement is that it generates a digital event when the shaped pulse crosses a calibrated threshold.

The acceptance criteria set both sides of the trade. At least 95 per cent of pulses above the defined threshold are detected — the efficiency side. The initial false-trigger target is below 0.01 event per second per channel — the noise side. And threshold values are recorded in the science data, which is what makes a count rate interpretable later: the same environment produces a different count at a different threshold, so a rate without its threshold is uncalibratable.

Verification sweeps injected pulse amplitude across the threshold and measures detection efficiency, then operates the detector in darkness for several hours to measure the false-trigger rate. The darkness run is doing two things at once — it measures electronic false triggers and it tests the light-tightness requirement from the same data.

Rev A has three comparators for four intended channels, and one of the three drives a status LED rather than a microcontroller event input.

13

Programmable threshold control

U15 is annotated on the sheet as an I2C DAC. Its role is to supply the comparator reference, so the threshold can be commanded rather than fixed by a resistor divider.

That matters operationally. A threshold appropriate for a quiet region may produce an unmanageable rate during a storm, and a threshold set for storm conditions may miss most of the quiet-time population. Commandable thresholds also make in-flight diagnosis possible: sweeping the threshold and watching the count rate is how you tell a detector problem from an environment change.

The requirement is that the DAC shall control valid threshold or calibration voltages, and that the payload shall provide electronic test-pulse injection. The acceptance criteria are that DAC output changes monotonically with the commanded value, that output never exceeds safe limits, that the selected threshold is included in telemetry, and that resetting the payload returns thresholds to a safe value.

Monotonicity and the safe-reset behaviour are both protections against the same class of failure: a commanded threshold that silently does something other than what was asked. Verification sweeps every DAC code and measures the output, sends invalid commands, resets and power-cycles the system, and runs test pulses through all four signal chains.

That last step cannot currently be performed, because the four signal chains and their injection points are not on the sheet.

14

Coincidence detection

Coincidence asks whether events in separate channels occurred within a defined timing window. In this design it is a firmware comparison: the requirement is that the microcontroller shall compare detector events within a defined coincidence window. There is no hardware coincidence gate on the Rev A sheet, and none is assumed here.

What it can help separate: multi-channel or penetrating events, where a particle energetic enough to cross more than one detector produces near-simultaneous events; single-channel events, where a particle stops in the first detector it meets; and some noise or interference cases, where a disturbance appears on several channels in a pattern a real track would not produce.

What it cannot do on its own is identify a particle species. Coincidence is a statement about how many detectors responded and when — geometry and timing — not about the identity of what passed through.

The acceptance criteria are all future targets: channel timing aligned within 1 microsecond, at least 99 per cent of known test patterns classified correctly, and accidental coincidence rates measured and documented. That last one is the honest part of the technique. At any real rate, two unrelated particles will sometimes arrive within the window by chance, and the accidental rate rises with the square of the event rate — so a technique that works in a quiet region can be dominated by accidentals during a storm. Measuring and documenting that rate is what keeps the classification meaningful.

Verification injects simultaneous pulses into multiple channels, repeats with known delays, and confirms that events inside the window are grouped while events outside it are separated.

15

Pulse height and its Rev A limitation

Three things are easy to conflate and are not the same.

Event counting says a particle crossed the detector and the pulse exceeded a threshold. It produces a rate. It requires a comparator.

Pulse-height measurement says how large the pulse was, which relates to how much energy was deposited in that detector. It produces an amplitude per event. It requires something that captures the peak and a converter fast enough to digitise it before the next event arrives.

Particle spectroscopy says what the incident particle was and what energy it had. It requires pulse-height measurement plus a calibrated response model plus assumptions about the incident population. It is not what this instrument is designed to deliver.

The source requires the payload to measure or capture the maximum amplitude of valid detector pulses, with acceptance criteria of pulse-height error within 5 per cent across the calibrated range, unreported dead time below 10 per cent at the maximum valid event rate, and saturated measurements flagged.

Rev A does not contain a valid fast pulse-height or peak-hold acquisition path. U14 is a slow 16-bit converter used for housekeeping quantities — bias, supply rails, temperature — and it is not a particle-pulse digitiser; a detector pulse is over long before a converter of that class can sample it, and nothing on the sheet holds the peak in the meantime. There is no critique of U14 here, because U14 is not being asked to do this job.

So Rev A supports event counting and, with the channels completed, coincidence. If energy information is later required, the design needs a valid pulse-height capture architecture added deliberately — a peak-hold or fast-sampling path between shaping and conversion — and until then the 5 per cent amplitude criterion has nothing to apply to.

16

Dynamic range and high-rate operation

A storm-time instrument has to work across a range of rates that differ by orders of magnitude, and the strategy the source adopts is to change what it records rather than to try to record everything.

The requirement is that the payload shall support detailed event recording at low rates and histogram or compressed-count operation at high rates. At low rates, individual events with their times and channel identities are affordable and are the most informative product. At high rates they are neither: the data volume outruns the downlink, and the instrument spends its time writing rather than counting. A histogram preserves the distribution while collapsing the per-event detail.

The acceptance criteria are about the transition, which is where this kind of scheme usually fails: the system changes acquisition mode at the intended event rate, no unreported data gaps occur during the transition, and live time, dead time and saturation are included in telemetry.

"Unreported" is the operative word. A gap that is flagged is a known hole in the coverage. A gap that is not flagged is a period of apparently low radiation, which during a storm is exactly the wrong conclusion.

Verification replays artificial quiet, moderate and extreme event streams, confirms the correct mode transitions, and compares accepted counts against the number of injected events. REQ 3 states the top-level version: operate under both quiet and high-radiation conditions without unacceptable saturation, dead time or unreported data loss.

17

Payload computer

U16, an STM32F103C8T6, runs the payload. The source's list of what it does spans nearly everything in these notes: read detector events, count pulses, measure timing, read the magnetometer, IMU and temperature sensor, change detector thresholds, run self-tests, store data, communicate with the spacecraft, detect faults, and enter safe mode when necessary.

Two of those interact awkwardly and the interaction is a design constraint. Timing measurement needs to be prompt and jitter-free enough to support the 1 microsecond coincidence alignment target, while storage writes and bus transactions take time during which events can be missed. Which of those wins at any moment is what the dead-time accounting has to capture.

Fault handling is a requirement rather than a nicety. The payload shall use watchdog timers, current monitoring, communication timeouts and a safe mode, recovering from an induced software hang within five seconds, surviving three consecutive fault-and-recovery tests, recording the fault in nonvolatile memory, and switching off or isolating unsafe loads. Verification freezes the software, locks the communication bus, introduces low voltage and temporary memory errors, and confirms the watchdog resets the system and records the failure.

None of the firmware exists. Every behaviour above is a requirement on software that has not been written.

18

Magnetic context

U20, an MMC5603NJ, measures the magnetic field at the payload. That sentence needs its qualifier kept: at the payload, not of the Earth.

The distinction matters because a magnetometer bolted inside a spacecraft sees the geomagnetic field plus whatever the vehicle is producing — currents in the power harness, switching in the converters, the RS-485 driver, and the payload's own boost converters on this very sheet. A magnetic context value contaminated by the payload's own activity is worse than no value, because it will be used to interpret the radiation data.

The requirement pairs it with the IMU: the MMC5603NJ and BMI160 shall produce synchronised context measurements at least 10 times per second. The acceptance criteria are a sensor update rate of at least 10 Hz, documented sensor axes, magnetometer residual error below 5 microtesla or the stricter spacecraft limit, and — the important one — spacecraft currents producing no unexplained magnetic signals.

Verification is what makes that last criterion testable: rotate the instrument through known orientations, apply known magnetic fields where suitable equipment is available, run the power converters and communication interfaces while monitoring the magnetometer, and compare readings with a calibrated reference sensor. Running the converters deliberately, and watching what appears, is the only way to attribute a magnetic signal to its source.

Documented axes sound trivial and are not. A magnetic vector whose frame is undocumented cannot be combined with attitude to say anything about pitch angle.

19

IMU and attitude context

U19, a BMI160, measures rotation, vibration and movement of the instrument, at the same 10 Hz or better as the magnetometer.

What it contributes locally is knowledge of whether the payload was rotating or being disturbed during a measurement interval. An interval taken while the spacecraft was slewing samples a changing look direction, which for a directional instrument means the counts came from a mixture of pitch angles rather than one.

What it does not contribute is authoritative attitude. The source is explicit that position and authoritative attitude information should normally come from the host spacecraft, which has the star tracker and the attitude determination and control system. The payload IMU is a local witness to motion, not an independent attitude solution.

That division runs through the context requirement generally, and is worth stating once clearly: the payload measures its own environment — field, motion, temperature, rails — and the spacecraft supplies where and when.

20

Temperature monitoring

U21, an MCP9808, measures temperature, and U14 measures the important voltage rails. The requirement is that the payload shall measure temperature and important voltage rails at least once per second.

Temperature matters here for the ordinary reason and one specific one. The ordinary reason is that detector leakage, amplifier offset and comparator threshold all drift with it, so a threshold calibrated at one temperature is a different threshold at another — which changes the channel's efficiency, and therefore its calibration, without anything in the environment changing. The specific one is that the analog gain requirement is stated as remaining usable across the operating temperature range, and demonstrating that needs the temperature recorded alongside the data.

The source states this function's requirement and does not state success criteria or a test method for it. That is recorded as it stands in the verification matrix rather than filled in here.

21

Timing and position

U22, a DS3231 RTC, is on the sheet, and the source is careful about its role: it can provide backup time, but the host spacecraft should periodically provide a more accurate mission-time reference.

The requirement follows that division — the payload shall receive accurate time and spacecraft position from the host satellite and use the RTC as temporary backup — with acceptance criteria of payload time within 10 milliseconds of the spacecraft reference, at least 99 per cent of accepted science intervals having position and attitude information within one second of the radiation measurement, and clock resets and rollovers not corrupting data.

Ten milliseconds is modest compared with the 1 microsecond coincidence alignment, and the two are not in conflict because they are different clocks doing different jobs. Coincidence needs relative timing between channels inside the payload, measured by the microcontroller's own timers. Mission time needs absolute agreement with the spacecraft so a count rate can be attached to a position on an orbit. An instrument can have excellent relative timing and useless absolute timing, and the source requires both separately.

Verification supplies known time pulses and simulated position packets, interrupts time updates and measures RTC drift, and tests resets, month and year changes and counter rollover. Rollover testing is there because a clock that wraps mid-observation reorders the record, and a reordered along-track profile is not a profile.

22

Storage architecture

Two devices are on the sheet, U17 FRAM and U18 W25Q128 flash, and the source sketches a division: FRAM can store important recent events and status information, flash can store larger radiation datasets and histograms.

That division is plausible and is not settled. FRAM writes quickly, endures effectively unlimited write cycles and does not need erase blocks, which suits frequently updated state. Flash offers far more capacity per unit cost and area, which suits bulk science. But which records go where, what happens when one fills, and how the two are kept consistent across a power interruption are undefined in Rev A, and defining them is a Rev B item.

The capacity requirement is stated as a ratio rather than a number: nonvolatile memory shall hold at least twice the data expected during the longest planned communication outage. Doubling is margin against the case that matters — a storm-time dataset acquired while the downlink opportunity slips.

The acceptance criteria are about integrity: required capacity demonstrated, files and packets including a CRC or another error check, unexpected power loss not corrupting previously stored data, and failed memory regions detected or avoided. Verification fills the memory, performs repeated write and erase cycles, introduces simulated bit errors, and removes power during different stages of a write operation.

Flash in a radiation environment adds the reason the last criterion exists. Bits can be upset by the same particles the instrument is counting, so a stored record that is not checked is a record that may have changed since it was written.

23

Spacecraft interface

U29 MAX3485 and U28 CH340C are on the sheet. The source describes the flight interface as undecided rather than chosen: it could use RS-485, UART, SPI or another interface selected in the spacecraft interface-control document.

The CH340C is a USB-to-serial bridge and belongs to laboratory work rather than flight. Keeping that separation explicit matters for the same reason it did on the other payloads: development conveniences that look like interfaces can leave the real interface unspecified while appearing complete.

The requirement is that the communication interface shall transfer commands, science packets and health information reliably, with a link supporting at least twice the expected average science-data rate, at least 99.9 per cent of packets delivered correctly after permitted retries, and corrupted and incomplete packets rejected.

Verification connects the payload to a simulated spacecraft computer, sends normal, incomplete and corrupted packets, tests long cables, electrical noise and repeated resets, and verifies every command and response. The long-cable and noise cases are specific to a differential bus like RS-485 and are the conditions under which it earns its place over a simpler interface.

REQ 7 sits above all of this: the payload shall comply with the spacecraft's electrical, mechanical, thermal, communication, mass and electromagnetic-compatibility limits. None of those limits has been supplied yet.

24

Power and analog cleanliness

The power chain on the sheet, and what the requirements ask of it. Every figure is an allocation or an acceptance criterion.

The payload accepts the spacecraft input voltage and protects against incorrect polarity and excessive current. F1 resettable fuse, D1 TVS, D2 SS14, D3 ESD.
Stable digital, analog and detector-bias rails. U23 AP2112K 3.3 V, U24 AMS1117-5.0, U25 low-noise analog LDO, U6 detector-bias boost, U7 boost.
Main voltage rails remain within 5 per cent.
Remains within 1 per cent — the tightest electrical tolerance in the design, because bias moves detector response.
At least 20 per cent power margin remains during maximum operation.
No component exceeds its temperature limit.
REQ 8: electrical noise shall not be mistaken for particle events. The boost converters, the RS-485 driver and the digital buses all sit on the same board as a front end resolving small charge pulses.
Sweep input voltage minimum to maximum; test normal load, maximum load and temporary short circuit; monitor ripple, current and temperature; repeat inside a thermal chamber.
25

Channel crosstalk

Crosstalk is the failure mode that would quietly undermine the whole four-channel idea, which is why it gets its own acceptance criterion: injecting a signal into one channel produces less than 1 per cent response in another.

The mechanisms are ordinary. A shared bias or return path couples every channel to every other. Capacitive coupling between adjacent traces carries fast edges across. A supply rail that sags when one channel fires is seen by the rest.

What makes it particularly damaging here is the interaction with coincidence. Coincidence exists to identify events that genuinely appeared in more than one channel. Crosstalk manufactures exactly that signature from a single-channel event, and does so preferentially for large pulses — which are the ones most likely to be interesting. An instrument with crosstalk does not simply add noise; it produces a population of false penetrating events that looks like science.

REQ 8 lists channel crosstalk alongside light, electrical noise and magnetic interference as things that shall not be mistaken for particle events. Verification injects a calibrated electrical pulse into one channel at a time and measures all four outputs — a test Rev A cannot currently support, because the four independent paths and their injection points are not on the sheet.

26

Detector calibration

Calibration is what separates an instrument from a counter, and this one needs a lot of it.

The quantities that have to be established, per channel: detector efficiency, the effective or geometric factor, the threshold actually in force, angular response, the response of the shielding and absorber combination, dead time, crosstalk, coincidence timing, and — if a valid path is later added — pulse-height response. Each is a term in converting a count rate into a flux, and none can be read off the schematic.

The requirement is that every detector and absorber combination shall be characterised using simulation and controlled radiation exposure. The acceptance criteria are that simulated and measured response agree within approximately 20 per cent or a larger measured uncertainty is clearly reported; that detector thresholds, efficiency, dead time and effective area are documented; and that blind test exposures are reconstructed within the declared uncertainty.

The first criterion is unusually honest and worth keeping that way. It does not demand 20 per cent agreement; it demands either that agreement or an explicit statement of how much worse it is. An instrument that reports a large uncertainty correctly is more useful than one that reports a small one it cannot justify.

The blind test is the part that catches self-consistency masquerading as accuracy. The analysis team is given an unknown exposure and reconstructs it, and the answer is compared against the facility's value. A calibration tuned until it reproduces its own inputs will pass every other check and fail this one.

No calibration has been performed. There is no hardware, no defined geometry, and no absorber selection to characterise.

27

Geometric factor and flux

A count rate is a property of the instrument as much as of the environment. Two detectors in the same place report different rates if their apertures differ.

The geometric factor is what removes the instrument from the answer. It reflects the effective detector area and the solid angle accepted through the aperture and shielding, and it enters the conversion from count rate to particle flux. Divide a rate by the geometric factor and by the efficiency, correct for dead time, and the result is a flux — a property of the environment that another mission can be compared against.

Every term in that conversion is something the earlier sections had to establish. Effective area and solid angle come from the aperture and mounting geometry. Efficiency comes from the calibration campaign. Dead time comes from the rate-handling measurements. The threshold comes from the DAC setting recorded with the data. Miss any one and what comes out is a number with the instrument still baked into it.

This is also why the geometry has to be measured rather than designed. A drawing states an intended aperture; the 5 per cent area tolerance and 5 degree alignment criteria exist because the built article differs from the drawing, and it is the built article that took the data.

28

Particle-transport modelling

The response of a shielded detector to an incident particle population is not something that can be reasoned out from geometry alone. Particles scatter, lose energy gradually, generate secondaries in the absorber, and arrive from a distribution of angles.

The source proposes modelling the detector and shielding using a particle-transport program such as Geant4. That is presented here as a proposed modelling approach and nothing more — no model has been built and no simulation has been run.

What such a model would produce is the predicted response of each channel to a defined incident spectrum and angular distribution: which particles reach the depletion region, how much energy they deposit, and therefore what fraction produce a pulse above threshold. That prediction is what the controlled radiation exposure is compared against, and the agreement between them — within approximately 20 per cent, or with a larger uncertainty reported — is the acceptance criterion.

The dependency ordering is worth being explicit about, because it determines what can happen when. The model needs a defined geometry, which needs the aperture and absorber decisions, which are Rev B work. Until then there is nothing to model, and the facility exposure would have nothing to validate against.

29

Ground radiation mapping

What ground software does with the returned data before anything is called a map. The requirement is that it combines calibrated radiation measurements with time, position, attitude, magnetic field and quality information.

  1. 01

    Apply calibrated channel response

    Efficiency, threshold, dead time and geometric factor per channel, from the calibration campaign.

  2. 02

    Convert count rate to flux

    The instrument divided out, so the result is a property of the environment.

  3. 03

    Attach position and attitude

    From the spacecraft, within one second of the radiation measurement, for at least 99 per cent of accepted intervals.

  4. 04

    Attach magnetic and thermal context

    Local field and temperature, with the payload-interference characterisation applied.

  5. 05

    Preserve channel identity

    Channels with different absorbers are different measurements and are never merged.

  6. 06

    Flag invalid, saturated and missing intervals

    Identified explicitly rather than interpolated over.

  7. 07

    Build the along-track profile

    Samples placed on the trajectory, with uncertainty and quality flags carried through.

30

Top-level requirements

The nine requirements the payload is designed against. None has been demonstrated, because there is no hardware.

IDRequirement
REQ 1Radiation measurement — use four independent detector channels to measure radiation count rate along the satellite orbit.
REQ 2Calibration and particle discrimination — each detector shall have a known aperture, absorber and calibrated response, and the channels shall provide at least coarse particle-penetration information.
REQ 3Timing and dynamic range — operate under both quiet and high-radiation conditions without unacceptable saturation, dead time or unreported data loss.
REQ 4Measurement context — associate radiation measurements with accurate time, spacecraft position, temperature, magnetic field and attitude information.
REQ 5Data integrity and return — store science data safely, check it for corruption, and transfer it to the spacecraft and ground.
REQ 6Autonomous and fault-tolerant operation — detect faults, perform self-tests, recover from common failures and enter a safe operating condition when necessary.
REQ 7Spacecraft compatibility — comply with the spacecraft electrical, mechanical, thermal, communication, mass and electromagnetic-compatibility limits.
REQ 8Contamination control — visible light, electrical noise, magnetic interference and channel crosstalk shall not be mistaken for particle events.
REQ 9Environmental survival — survive launch vibration, vacuum, temperature changes and the expected radiation environment.
31

Mission-function verification matrix

All eighteen mission functions from the design review, with the requirement, the acceptance criteria and the planned test for each. Every row is planned: none has been carried out, and several need an approved radiation facility, a thermal chamber, a spacecraft emulator or a defined detector geometry that does not exist yet.

One row is incomplete by the source rather than by omission here: Function 10 states its requirement and gives no success criteria or test method, and that is recorded as it stands. The table scrolls sideways on a narrow screen.

FunctionRequirementSuccess criteriaTest method
Accept and condition spacecraft powerAccept the spacecraft input voltage, protect against incorrect polarity and excessive current, and generate stable digital, analog and detector-bias rails.Main rails within 5 per cent; detector bias within 1 per cent; at least 20 per cent power margin at maximum operation; no component exceeds its temperature limit.Sweep input voltage minimum to maximum; test normal load, maximum load and temporary short circuit; monitor ripple, current and temperature; repeat inside a thermal chamber.
Control detector aperture, shielding and visible lightEvery channel shall have a measured active area, field of view, absorber thickness and light-tight enclosure.Aperture area within 5 per cent of design; detector alignment within 5 degrees; bright visible light produces no statistically significant radiation count; absorber material and thickness documented.Measure apertures and absorbers with precision tools; test alignment with an optical reference; compare counts in darkness and under bright light; inspect the enclosure for gaps.
Operate four independent detector channelsEach BPW34 shall have an independent bias, return path, amplifier, comparator and microcontroller input.All four channels operate independently; injecting a signal into one produces less than 1 per cent response in another; failure of one detector does not disable the others.Inject a calibrated electrical pulse into one channel at a time and measure all four outputs; disconnect or short one channel and confirm the rest continue operating.
Amplify and shape detector pulsesEach channel shall use a stable low-noise transimpedance amplifier and pulse-shaping network.Measured gain agrees with the circuit model within 10 per cent; the amplifier does not oscillate; noise remains below the event threshold; gain remains usable across the operating temperature range.Simulate the circuit before construction; inject calibrated charge pulses; measure gain, noise, pulse width and settling time; repeat at minimum, normal and maximum temperature.
Detect valid threshold eventsA comparator shall generate a digital event when the shaped pulse crosses a calibrated threshold.At least 95 per cent of pulses above the defined threshold are detected; the initial false-trigger target is below 0.01 event per second per channel; threshold values are recorded in the science data.Sweep injected pulse amplitude across the threshold and measure detection efficiency; operate the detector in darkness for several hours and measure the false-trigger rate.
Measure pulse heightThe payload shall measure or capture the maximum amplitude of valid detector pulses.Pulse-height error within 5 per cent across the calibrated range; unreported dead time below 10 per cent at the maximum valid event rate; saturated measurements flagged.Inject pulses with known amplitudes; increase the pulse rate gradually; compare measured and commanded amplitudes; record where saturation and missed events begin.
Perform coincidence detectionThe microcontroller shall compare detector events within a defined coincidence window.Channel timing aligned within 1 microsecond; at least 99 per cent of known test patterns classified correctly; accidental coincidence rates measured and documented.Inject simultaneous pulses into multiple channels; repeat using known delays; confirm events inside the window are grouped and events outside it are separated.
Control thresholds and run self-testsThe DAC shall control valid threshold or calibration voltages, and the payload shall provide electronic test-pulse injection.DAC output changes monotonically with the commanded value; output never exceeds safe limits; the selected threshold is included in telemetry; resetting the payload returns thresholds to a safe value.Sweep every DAC code and measure the output; send invalid commands; reset and power-cycle the system; run test pulses through all four signal chains.
Measure magnetic field and motionThe MMC5603NJ and BMI160 shall produce synchronised context measurements at least 10 times per second.Sensor update rate at least 10 Hz; sensor axes documented; magnetometer residual error below 5 microtesla or the stricter spacecraft limit; spacecraft currents produce no unexplained magnetic signals.Rotate the instrument through known orientations; apply known magnetic fields where suitable equipment is available; run power converters and communication interfaces while monitoring the magnetometer; compare with a calibrated reference sensor.
Monitor temperature and electrical healthThe payload shall measure temperature and important voltage rails at least once per second.Not stated in the source for this function.Not stated in the source for this function.
Synchronise time and spacecraft positionReceive accurate time and spacecraft position from the host satellite and use the RTC as temporary backup.Payload time within 10 milliseconds of the spacecraft reference; at least 99 per cent of accepted science intervals have position and attitude information within one second of the radiation measurement; clock resets and rollovers do not corrupt data.Supply known time pulses and simulated position packets; interrupt time updates and measure RTC drift; test resets, month and year changes and counter rollover.
Adapt to quiet and storm-time event ratesSupport detailed event recording at low rates and histogram or compressed-count operation at high rates.The system changes acquisition mode at the intended event rate; no unreported data gaps occur during the transition; live time, dead time and saturation are included in telemetry.Replay artificial quiet, moderate and extreme event streams; confirm the correct mode transitions; compare accepted counts with the number of injected events.
Store science and health dataNonvolatile memory shall hold at least twice the data expected during the longest planned communication outage.Required storage capacity demonstrated; files and packets include a CRC or another error check; unexpected power loss does not corrupt previously stored data; failed memory regions are detected or avoided.Fill the memory to capacity; perform repeated write and erase cycles; introduce simulated bit errors; remove power during different stages of a write operation.
Exchange commands and telemetryThe communication interface shall transfer commands, science packets and health information reliably.The link supports at least twice the expected average science-data rate; at least 99.9 per cent of packets delivered correctly after permitted retries; corrupted and incomplete packets rejected.Connect to a simulated spacecraft computer; send normal, incomplete and corrupted packets; test long cables, electrical noise and repeated resets; verify every command and response.
Detect faults and recover automaticallyUse watchdog timers, current monitoring, communication timeouts and a safe mode.Recovery from an induced software hang within five seconds; three consecutive fault-and-recovery tests survived; a fault recorded in nonvolatile memory; unsafe loads switched off or isolated.Freeze the software; create a communication-bus lock; introduce low voltage and temporary memory errors; confirm the watchdog resets the system and records the failure.
Calibrate the particle responseEvery detector and absorber combination shall be characterised using simulation and controlled radiation exposure.Simulated and measured response agree within approximately 20 per cent, or a larger measured uncertainty is clearly reported; thresholds, efficiency, dead time and effective area documented; blind test exposures reconstructed within the declared uncertainty.Model the detector and shielding using a particle-transport program such as Geant4; expose the instrument to calibrated electron or proton sources at an approved radiation facility; repeat at different particle energies and incident angles; give the analysis team an unknown exposure and compare its result with the facility value.
Produce radiation-belt mapsGround software shall combine calibrated radiation measurements with time, position, attitude, magnetic field and quality information.Every map value traces back to calibrated source data; maps include uncertainty and quality flags; invalid, saturated and missing intervals clearly identified; synthetic test datasets produce the correct known map.Generate a simulated orbit with predetermined radiation regions; process the synthetic data through the complete ground pipeline; compare the reconstructed map with the original truth data; compare flight trends with independent space-weather measurements when available.
Survive launch and the space environmentThe completed instrument shall survive the mission vibration, vacuum, temperature, electromagnetic and radiation environments.All environmental tests completed without physical damage; important measurements remain within 10 per cent of calibrated pre-test values; no unsafe electrical condition occurs; radiation-related failures detected and recovered where possible.Vibration testing; thermal-vacuum cycling; electromagnetic compatibility testing; total-dose and relevant single-event radiation testing; repeat the detector calibration and functional tests afterward.
32

Environmental qualification

REQ 9 requires the payload to survive launch vibration, vacuum, temperature changes and the expected radiation environment. The function-level requirement adds electromagnetic compatibility.

The acceptance criteria are the usual three plus one that belongs specifically to a calibrated instrument: all environmental tests completed without physical damage, no unsafe electrical condition, stored data remaining readable, and important measurements remaining within 10 per cent of their calibrated pre-test values.

That last one is why the campaign ends with recalibration rather than a functional check. A detector assembly that survives vibration mechanically but whose aperture alignment has shifted will still count — it will simply be counting a different solid angle than the calibration assumed, and nothing in a functional test would reveal it.

Radiation testing has a doubled meaning on this payload. Total-dose and single-event testing are qualification activities like any other, but the environment being qualified against is the same one the instrument exists to measure. The particles that upset the memory storing a radiation record are the record.

The planned campaign is vibration, thermal-vacuum cycling, electromagnetic compatibility, total-dose and relevant single-event radiation testing, then repeated detector calibration and functional tests. None has been performed.

33

Rev A design review

What the drawing settles, and what it does not.

It settles a coherent supporting payload. A payload computer, a threshold DAC, a housekeeping converter, FRAM and flash, magnetometer, IMU and temperature sensor, an RTC, a detector-bias supply with regulated digital and analog rails and input protection, and both a differential flight-candidate interface and a laboratory one. As a board that supports a particle instrument, most of it is present.

What it does not settle is the instrument. The four detector devices are not four independent channels: they share a net, there are three op-amp sections and three comparators for four intended channels, one comparator drives a status LED, and the per-channel feedback, shaping and injection elements are absent — the sheet's full discrete complement is four resistors and three capacitors.

Nor does it settle what the channels are for. Aperture, field of view, absorber thickness and the light-tight enclosure are not defined anywhere, so the channels have no basis for differing and no known geometry for calibration.

Then the measurement paths. There is no fast pulse-height capture path; U14 is a slow housekeeping converter and is not being asked to digitise particle pulses. Coincidence exists as a firmware concept with a 1 microsecond alignment requirement and no verification behind it. Threshold behaviour across the DAC range is uncalibrated.

Then the context. The magnetometer, IMU and temperature sensor need synchronisation at 10 Hz or better, and the magnetometer needs characterising against the payload's own converters. Spacecraft time, position and authoritative attitude come from the host and are not settled here.

Then the housekeeping of the data. FRAM and flash roles are undefined, as is the integrity strategy. The flight power, command and telemetry interface needs formal definition rather than a development connector.

And running underneath all of it, REQ 8: light, electrical noise, magnetic interference and crosstalk all have to be kept out of the count, on a board carrying two boost converters, a differential driver and several digital buses.

Nothing in this review has been resolved by testing. There is no board and no shielding.

34

Rev B required changes

What the next revision has to settle before a board is worth fabricating, with the source basis for each. The order runs from the instrument outward.

AreaRequired changeSource basis
Channel architectureComplete and document four independent channels: detector, bias, return, amplifier, shaping, comparator, MCU input and injection point, with preserved channel identity.Detector subsystem; analog front-end subsystem; Function 3.
Apertures and geometryDefine and document measured active area, field of view and alignment per channel.Shielding and aperture subsystem; Function 2.
Differential absorbersSelect and document absorber materials and thicknesses that give the channels deliberately different responses.Shielding and aperture subsystem; REQ 2.
Light tightnessDesign the light-tight enclosure and demonstrate no significant count under bright light.Shielding and aperture subsystem; Function 2; REQ 8.
Analog front endSimulate and verify per-channel gain, noise, shaping and stability across temperature.Function 4.
ThresholdsCalibrate threshold behaviour across the DAC range and record the setting in telemetry.Function 8.
CoincidenceDefine and verify the coincidence window and channel timing alignment, and measure accidental rates.Function 7.
Pulse heightAdd a valid fast peak-hold and conversion path if energy information is required.Function 6.
CrosstalkDemonstrate under 1 per cent response in adjacent channels with per-channel injection points.Function 3; REQ 8.
Context synchronisationSynchronise magnetometer, IMU and temperature at 10 Hz or better and document sensor axes.Function 9.
Magnetic cleanlinessCharacterise payload and spacecraft interference in magnetometer data with converters running.Function 9.
Timing and positionDefine the host time and position interface, with the RTC as backup and rollover handling proven.Timing subsystem; Function 11.
StorageDefine FRAM and flash roles, capacity margin and the integrity strategy.Data-storage subsystem; Function 13.
Flight interfaceSelect and document the flight power, command and telemetry interface in the spacecraft ICD.Communication subsystem; Function 14; REQ 7.
Calibration campaignBuild the particle-transport model and the controlled-radiation exposure plan, including a blind test.Function 16.
Ground pipelineBuild and test the mapping pipeline against synthetic orbits with known radiation regions.Function 17.