Technical notes
CubeSat VLF Lightning Wave Receiver — Rev A
This project is currently a Rev A receiver schematic and design review. No PCB has been fabricated or tested. Numerical values in these notes are design targets, requirements, or future verification criteria unless explicitly identified otherwise.
Mission objective
Detect and study very-low-frequency electromagnetic waves produced by lightning.
The intended satellite would measure VLF magnetic signals from 3 to 30 kHz initially, detect lightning-generated radio pulses and possible whistler signals, record the waveform and frequency spectrum of each event, attach an accurate time and orbital position to every measurement, transmit the measurements to a ground station, compare its detections against ground-based lightning records, and from all of that investigate how lightning-generated VLF energy travels into the ionosphere and magnetosphere.
This is a receiver mission, not primarily a transmitter mission. The distinction runs through the whole design and is the reason two devices on the schematic needed explaining rather than accepting.
VLF science context
A lightning stroke is a large, brief current in a conductor several kilometres long, and it radiates strongly at very low frequencies. That energy does not stay below the ionosphere. Some of it propagates upward, and a portion travels along geomagnetic field lines, arriving at the far hemisphere dispersed in frequency — the higher components arriving before the lower ones, which is what makes a whistler a whistler.
An instrument above the atmosphere samples that energy along a path ground receivers cannot reproduce. Measuring the waveform and the spectrum of what arrives, with a known time and position attached, is what makes it possible to ask how the energy got there.
Receiver measurement concept
The measurement is of the magnetic component of the wave. A search coil in a changing magnetic field produces a voltage proportional to the rate of change of flux through it, which is small — the design case is a 10 microvolt RMS signal at the coil connector.
Everything after that connector exists to get that voltage into a digital record without adding to it or losing it: amplify it enough to use the converter's range, restrict it to the band being measured so nothing outside can masquerade as something inside, centre it so a bipolar waveform fits a single-supply converter, sample it fast enough and steadily enough that a frequency means what it says, and then decide in flight which few seconds out of a continuous stream are worth keeping.
Search-coil sensor
The search coil is the science sensor. Everything else on the board is conditioning and acquisition.
It does not appear on the schematic. H1, a two-pin connector, is where it attaches, and that is the whole of its representation in Rev A. The coil's geometry — turns, area, core, whether it is a simple air coil or has a permeable core — is undefined, and so is its sensitivity.
That sensitivity is the constant that turns a measured voltage back into a magnetic field, expressed in volts per tesla or volts per nanotesla. Without it there is no calibrated measurement, only a number of ADC counts. It has to be measured rather than calculated: the coil goes inside a calibrated field-generation coil, known signals are driven from 3 to 30 kHz, the output voltage is measured, and the sensitivity is calculated at every test frequency. The requirement is that the response stays within 3 dB of its calibrated value across the band, and the whole test is repeated at different temperatures, because a coil's resistance and its core's permeability both move with temperature.
Mounting is part of the sensor specification, not a packaging detail. The coil must sit away from major spacecraft noise sources and away from high-current wiring. A coil placed conveniently next to the power harness measures the harness.
No coil design is proposed here. Defining one is Rev B work, and it is the first item on that list.
Analog preamplifier
U4, a TLV9062 dual op-amp, amplifies the coil voltage before digitisation.
The requirement that sizes it: a 10 microvolt RMS input at the coil connector should produce at least 10 dB signal-to-noise ratio. The amplifier must not clip at the maximum expected input, and its gain must stay within 5 per cent of its specified value.
One fixed gain is unlikely to serve the whole range. The review suggests three settings — 1x for strong signals, 10x for normal ones, 100x for weak ones — because a gain chosen to resolve the weakest targeted signal will saturate on a nearby stroke, and a gain chosen to survive the strong case throws away the weak one.
Verification is by injecting calibrated sine waves at the coil connector at minimum, nominal and maximum amplitude, repeating across frequency and across every gain setting, and checking distortion and clipping on an oscilloscope.
Midpoint biasing
The coil signal is bipolar and the converter runs from a single 3.3 V supply, so the signal has to be shifted to sit in the middle of that range.
The requirements are that the no-signal voltage stays near 1.65 V, that the signal stays between the converter's minimum and maximum input voltages, and that the noise the bias network itself contributes stays below the receiver's noise requirement — a bias that is stable but noisy has simply moved the problem.
The acceptance criteria are that the converter sits near midscale with no input, that both the positive and negative halves of a waveform are recorded, and that normal signals do not clip at 0 V or 3.3 V. Verification terminates the input and measures the DC bias, then injects a bipolar sine wave and checks the ADC codes against an oscilloscope.
Band-limiting and anti-alias filtering
The filter is part of the measurement rather than cleanup applied afterwards.
Sampling folds energy above half the sample rate back down into the measured band, and once it has folded there is no way to tell it from a real signal. A tone at 90 kHz arriving at an 80 kSPS converter appears at 10 kHz and looks exactly like something the instrument is meant to be looking for. The filter is what prevents that, and it has to do it before digitisation, because nothing downstream can undo it.
The requirements: a passband covering 3 to 30 kHz, passband variation within 3 dB, at least 20 dB of attenuation above approximately 40 to 45 kHz, and suppression of very-low-frequency drift and DC offsets at the bottom end.
The acceptance criteria are that in-band signals pass normally, that out-of-band signals are strongly reduced, and that the converter shows no significant alias frequencies. Verification applies a constant-amplitude sweep from below 1 kHz to above 100 kHz and plots the complete response, then injects an out-of-band tone and looks for a false in-band signal appearing in the digital record.
None of this has been measured. The response has to be deliberately designed and then verified; Rev A places the network but does not establish what it does.
ADC and sampling
U5, an MCP3202, converts the conditioned waveform into 12-bit samples over SPI.
The requirements are a sample rate between 80 and 100 kSPS, 12-bit resolution, stable sample timing, and continuous measurements containing no missing or duplicated samples. The rate is set by the band: sampling at 80 kSPS or above keeps the 30 kHz top of the measurement band comfortably inside half the sample rate, which is what makes the filter's job achievable rather than impossible.
Timing stability matters as much as rate. An FFT converts sample index into frequency by assuming samples arrived at a known, even spacing; jitter in that spacing smears the result, and a dropped sample shifts everything after it.
The acceptance criteria are that a ten-minute continuous recording contains the correct number of samples, that a known tone appears at the correct digital frequency, and that no unexpected sample gaps appear. Verification injects a precision sine wave, records for ten minutes, compares expected against actual sample counts, and calculates the FFT to verify measured frequency and amplitude.
Payload processor
U6, a 2.4 GHz MCU module, controls the converter, detects possible lightning events, calculates spectra and spectrograms, and packages data for storage and transmission.
Its 2.4 GHz radio is a development convenience, along with the USB-C connector and the OLED. The source is explicit that these mainly support laboratory testing and that a flight version needs a dedicated spacecraft-computer interface and the spacecraft's own communication system. None of the three is the downlink.
The processor is also a noise source inside the band it is helping to measure, which is the subject of the interference section below.
Event detection
Acquisition is continuous; storage is not. The detector decides which few seconds are worth keeping.
The planned algorithm runs against a measured background rather than a fixed number: thresholds adjust to the noise the instrument is currently seeing, so a quiet orbit and a noisy one do not produce wildly different event rates. A candidate is an impulsive or dispersive feature crossing that threshold — impulsive for a direct stroke, dispersive for a whistler that has travelled along a field line and arrived stretched in frequency.
The acceptance criteria are targets for a future test campaign: at least 90 per cent detection probability for signals with 6 dB SNR or better, fewer than one false trigger per minute during normal spacecraft operation, and unique identification numbers on every event.
Verification generates simulated lightning and whistler waveforms, adds them to recorded noise at a range of amplitudes, replays the combined dataset through the detector, and calculates detection probability and false-trigger rate from the result.
Circular pre-trigger buffer
By the time a detector recognises an event, the beginning of it has already gone past. A circular buffer solves that by recording continuously into memory that overwrites itself, so that when a trigger fires the preceding interval is still there to be kept.
The requirements: at least one second preserved before the trigger, at least three seconds after it, and the exact trigger position recorded in the file so the two halves can be told apart.
Three seconds after is not arbitrary either. A dispersed whistler arrives spread over a fraction of a second to seconds depending on the path, and truncating the record truncates the dispersion curve that carries the information about the path.
Verification injects a pulse at a known time, opens the saved event file, and confirms it contains the required pre-trigger and post-trigger samples with no gap around the trigger.
Spectra and spectrograms
A waveform shows what arrived; a spectrogram shows how its frequency content changed over time, which for a dispersive signal is the measurement.
The requirements are that FFT settings are recorded in the metadata — window, length and overlap change what a spectrogram looks like, so a plot without them cannot be reproduced — that known tones appear in the correct frequency bins, and that spectrograms retain enough time resolution to show both impulsive and dispersive signals.
Verification injects single tones, multiple tones, impulses and frequency sweeps, and compares the calculated spectra against a laboratory spectrum analyser. A swept test signal should produce a recognisable diagonal trace in the spectrogram; that is the closest laboratory analogue to a whistler.
Timing
Timing is part of the measurement, not metadata attached to it. The final science objective is comparing these detections against independent lightning records, and a detection whose time is uncertain to more than the propagation and detection window cannot be matched to anything.
The requirements: absolute timing error within 1 ms, using GPS 1-PPS or a synchronised spacecraft clock, with loss of synchronisation recorded in the data-quality flags rather than silently tolerated.
The acceptance criteria are that recorded event times agree with a reference clock within 1 ms and that the system identifies records created without valid synchronisation. Verification sends the same electrical pulse to both the converter and the timing reference, compares the payload timestamp against calibrated laboratory equipment, and repeats over several hours to expose drift.
Neither a GPS receiver nor a spacecraft-clock interface appears as a complete subsystem in Rev A. Adding or defining one is a Rev B item.
Position and orientation context
Every event is intended to carry the spacecraft's orbital position and, where available, its orientation: latitude, longitude, altitude and spacecraft time, all referring to the same measurement period.
Position is what turns a list of detections into a map, and what allows a satellite event to be compared with a ground-based lightning location. Orientation matters because the search coil measures one vector component of the field, so what the instrument sees depends on how it is pointed.
Invalid navigation data receives a quality flag rather than being dropped or interpolated. Verification feeds simulated orbit data into the payload computer, confirms correct packet storage and ground mapping, and then deliberately supplies missing and invalid navigation messages to check that they are flagged.
Science data storage
Waveforms and their supporting information are stored until they can be downlinked.
A record contains waveform data, time, position, sample rate, gain, temperature, operating mode and a checksum. Sample rate and gain are in that list because a waveform without them is uncalibrated: the same ADC codes mean different field strengths at different gain settings.
The requirements are about failure rather than capacity. At least 99 per cent of records survive storage testing, interrupted writes do not corrupt earlier files, and corrupted records are detected automatically rather than returned as data.
Verification fills the storage system repeatedly, interrupts power during file writes, restarts the payload, examines every file, and verifies checksums and record numbering.
Spacecraft interface
The payload exchanges commands and data with the main spacecraft computer. A flight interface — UART, SPI, I2C or CAN — needs to be documented and selected; Rev A does not settle which.
Commands cover start, stop, calibrate, safe mode, status and data transfer. Communication errors are detected, invalid commands do not damage data or lock the payload, and the acceptance criterion is a 24-hour communication test with no uncorrected errors.
Downlink is the spacecraft's job, not the payload's. High-priority event summaries go first, raw waveforms follow when bandwidth allows, lost packets support retransmission, and every packet carries error detection, with at least 95 per cent of scheduled test data received directly or recovered.
Verification connects the payload to a spacecraft-computer emulator, exercises every command, and injects damaged packets and interruptions to confirm rejection and recovery.
Ground processing
The ground system converts raw data into calibrated waveforms, spectrograms, maps and event catalogues.
Calibration is where the coil sensitivity, the amplifier gain, the filter response and the converter's own calibration are applied to turn ADC counts back into a magnetic field. Everything that was measured during verification enters here as a coefficient, which is why an uncalibrated coil makes the whole chain uncalibrated.
Spacecraft electromagnetic interference
A VLF receiver is sensitive enough to detect the vehicle carrying it, and most of the noise it has to reject is generated a few centimetres away. This is not an integration detail; it decides whether the noise floor is low enough for the instrument to work at all.
The sources the review identifies are the ordinary contents of a CubeSat. The processor itself, switching at rates whose harmonics land in the band. The 2.4 GHz radio path. The OLED, which is a switched display with its own converter. The LEDs, whose drivers switch. Switching circuits generally, including the power supply. Unnecessary radios. And high-current wiring routed near the coil, which couples magnetically into exactly the quantity the coil is built to measure.
A clock harmonic and a lightning impulse do not look different once they have passed through the same amplifier and converter. The receiver cannot tell them apart, so the instrument has to be arranged so they do not arrive together.
The response has two halves. Operationally, Wi-Fi, the OLED, the LEDs, switching circuits and unnecessary radios are disabled during sensitive measurements rather than trusted to be quiet, and repeated spacecraft noise frequencies are identified so that they can be recognised in the data later. Physically, the coil is mounted away from high-current wiring.
The characterisation plan is the part worth writing out, because it is the only way to attribute a line in the spectrum to the thing producing it. Record with all subsystems off, to establish a baseline. Turn on each subsystem individually and record the change in the VLF spectrum. Build a spacecraft interference database from those measurements. Then repeat the whole exercise in the fully assembled satellite, because subsystems that are individually quiet can be noisy together, and the assembled vehicle has wiring the bench did not.
The acceptance criteria are that the science-mode noise floor meets the minimum signal-detection requirement and that no major processor or radio frequency dominates the VLF spectrum. Neither has been measured. There is no hardware, and the requirement behind them — that spacecraft-generated interference stays below the payload's detection threshold during science observations — is a target.
Calibration system
A receiver that cannot check itself produces numbers nobody can defend. The intended calibration system periodically injects a known test signal and uses the response to verify search-coil response, amplifier gain, filter response, ADC accuracy, and the changes all of those undergo with temperature and age.
The requirements: calibration amplitude and frequency traceable to ground measurements, the calibration signal stable within 5 per cent, and — the one that shapes the data format rather than the circuit — calibration must not be confused with a natural science event. The acceptance criteria are that the measured calibration response stays within 5 per cent of its reference and that calibration events are correctly labelled. Verification runs calibration at room temperature and repeats it at the minimum and maximum operating temperatures, comparing gain and frequency response.
Two devices on the schematic are annotated as transmitters: CID45N65MD8, a gallium-nitride part, and CI02S120C3, a silicon-carbide part. The review's reading is that they might be intended for this calibration purpose. It also says plainly that their exact connections and operating purpose will need to be clarified.
That ambiguity is not resolved here, and resolving it by picking the most plausible story would be worse than leaving it open. What can be said is what the mission is: a receiver mission, not primarily a transmitter mission. Whether these devices are the calibration injection path, something carried over from another design, or something that should not be on the board is Rev B work.
Temperature and drift
Temperature sensors monitor the coil and the analog electronics, to an accuracy of 2 degrees Celsius, with the temperature recorded alongside each event.
Coil resistance, core permeability, amplifier offset and gain, filter component values and converter reference all move with temperature. Recording it with the event is what makes a later correction possible; correcting a measurement whose temperature was never recorded is guesswork.
Unsafe temperatures cause safe-mode entry. Verification places the system in a thermal chamber, compares payload readings against calibrated probes, and deliberately crosses the warning and shutdown thresholds to confirm the response.
Power and protection
Clean power matters here more than on most boards, because supply ripple at audio and low radio frequencies lands inside the measurement band.
- U3, an AP2112K-3.3, producing the 3.3 V rail.
- L1, a BLM18KG601SN1D ferrite bead between the digital and analog supply.
- A 1206L050YR polyfuse, D1 and D2 USB and power TVS diodes, D3 on the antenna input, and BAT54S clamp pairs.
- Preliminary acquisition power below 3 W.
- The 3.3 V rail stays within component limits across the bus-voltage range, and analog-supply ripple stays low enough to meet the receiver-noise requirement.
- No brownout or ADC corruption across the full bus-voltage range; consumption within allocation; a short circuit does not permanently damage the satellite power bus.
- Programmable supply at minimum, nominal and maximum bus voltage; startup, acquisition and safe-mode current measured; ripple examined on an oscilloscope.
Top-level requirements
Sixteen requirements the payload is designed against. Every numerical value is a design target — none has been measured, because there is no hardware to measure.
| ID | Requirement |
|---|---|
| TR-01 | Measure magnetic VLF signals from at least 3 to 30 kHz. |
| TR-02 | Detect a 10 microvolt RMS signal at the coil connector with at least 10 dB signal-to-noise ratio. |
| TR-03 | Digitise at 80 to 100 kSPS with 12-bit resolution. |
| TR-04 | Prevent out-of-band signals from producing false measurements in the analog front end. |
| TR-05 | Carry UTC time accurate to within 1 ms on every science record. |
| TR-06 | Carry the satellite's orbital position and payload operating state on every science record. |
| TR-07 | Identify at least 90 per cent of test signals having an SNR of 6 dB or greater. |
| TR-08 | Store at least one second before and three seconds after each event trigger. |
| TR-09 | Keep at least 99 per cent of stored science records readable and passing integrity checks. |
| TR-10 | Operate during at least 90 per cent of scheduled observation time. |
| TR-11 | Remain within a preliminary acquisition-power allocation of 3 W. |
| TR-12 | Keep spacecraft-generated interference below the payload's required detection threshold during science observations. |
| TR-13 | Recover automatically from processor lockups and temporary power interruptions. |
| TR-14 | Survive launch and the expected low-Earth-orbit thermal environment. |
| TR-15 | Produce calibrated VLF waveforms, spectra, spectrograms and event catalogues on the ground. |
| TR-16 | Compare detected events with independent lightning records whenever matching records are available. |
Full mission-function verification matrix
All twenty functions from the design review, with the requirement, the acceptance criteria and the planned test for each. Every row is planned: none has been carried out, and several need a calibrated magnetic-field source, a thermal chamber or a spacecraft-computer emulator. The table scrolls sideways on a narrow screen.
| Function | Requirement | Success criteria | Test method |
|---|---|---|---|
| Detect VLF magnetic fields | Coil covers at least 3 to 30 kHz; sensitivity measured in V/T or V/nT; response within 3 dB of calibration; mounted away from major spacecraft noise sources. | A known magnetic field produces the expected voltage; signals across the band are measurable; the response is repeatable. | Coil inside a calibrated field-generation coil, driven 3 to 30 kHz; output measured and sensitivity calculated at every frequency; repeated at different temperatures. |
| Amplify the search-coil signal | A 10 microvolt RMS input produces at least 10 dB SNR; no clipping at maximum expected input; gain within 5 per cent; preferably multiple gain settings (1x, 10x, 100x). | Weak signals become clearly measurable; strong signals do not saturate; every gain setting amplifies as expected. | Calibrated sine waves injected at the coil connector at minimum, nominal and maximum amplitude, across frequencies and gain settings; distortion and clipping checked on an oscilloscope. |
| Bias the bipolar signal | No-signal voltage near 1.65 V; signal between the ADC's input limits; bias noise below the receiver noise requirement. | The ADC sits near midscale with no input; both halves of the waveform are recorded; normal signals do not clip at 0 V or 3.3 V. | Input terminated and DC bias measured; a bipolar sine wave injected and ADC codes checked against an oscilloscope. |
| Filter unwanted frequencies | Passband 3 to 30 kHz within 3 dB; at least 20 dB attenuation above approximately 40 to 45 kHz; very-low-frequency drift and DC offsets suppressed. | In-band signals pass normally; out-of-band signals are strongly reduced; the ADC shows no significant alias frequencies. | Constant-amplitude sweep from below 1 kHz to above 100 kHz with the full response plotted; an out-of-band tone injected while looking for false in-band ADC signals. |
| Digitize the waveform | 80 to 100 kSPS at 12 bits; stable sample timing; no missing or duplicated samples in continuous measurement. | A ten-minute recording has the correct sample count; a known tone appears at the correct digital frequency; no unexpected gaps. | Precision sine wave injected and recorded for ten minutes; expected and actual sample counts compared; FFT calculated to verify frequency and amplitude. |
| Detect lightning-like events | At least 90 per cent detection probability at 6 dB SNR or better; fewer than one false trigger per minute in normal operation; thresholds adapt to measured background noise. | Most injected lightning-like signals are detected; normal noise does not create excessive records; events receive unique identifiers. | Simulated lightning and whistler waveforms added to recorded noise at different amplitudes and replayed through the detector; detection probability and false-trigger rate calculated. |
| Preserve pre-trigger and post-trigger data | At least one second before the trigger and three seconds after; the record indicates the exact trigger position. | Every saved event contains the required interval; no samples missing around the trigger. | A pulse injected at a known time; the saved event file opened and checked for the required pre-trigger and post-trigger samples. |
| Calculate spectra and spectrograms | FFT settings recorded in metadata; known tones in the correct bins; spectrograms retain enough time resolution for impulsive and dispersive signals. | Laboratory tones appear at expected frequencies; a swept test signal produces the expected spectrogram pattern. | Single tones, multiple tones, impulses and frequency sweeps injected; calculated spectra compared against a laboratory spectrum analyser. |
| Time-stamp measurements | Absolute timing error within 1 ms, using GPS 1-PPS or a synchronised spacecraft clock; loss of synchronisation recorded in quality flags. | Recorded event times agree with the reference clock within 1 ms; records made without valid synchronisation are identified. | The same electrical pulse sent to the ADC and the timing reference; payload timestamp compared against calibrated laboratory equipment; repeated over several hours. |
| Record position and orientation | Position includes latitude, longitude, altitude and spacecraft time, referring to the same measurement period; invalid navigation data flagged. | Every valid event contains usable orbital information; ground software plots events along the orbit. | Simulated orbit data fed to the payload computer; packet storage and ground mapping confirmed; missing and invalid navigation messages tested. |
| Store science data | Records contain waveform, time, position, sample rate, gain, temperature, mode and checksum; at least 99 per cent survive storage testing; interrupted writes do not corrupt earlier files. | Stored files remain readable after resets and power interruptions; corrupted records are detected automatically. | Storage filled repeatedly; power interrupted during writes; payload restarted and every file examined; checksums and record numbering verified. |
| Communicate with the spacecraft computer | A flight interface such as UART, SPI, I2C or CAN documented; commands for start, stop, calibrate, safe mode, status and data transfer; communication errors detected. | All valid commands produce the correct response; invalid commands neither damage data nor lock the payload; a 24-hour test has no uncorrected errors. | Payload connected to a spacecraft-computer emulator; every command exercised; damaged packets and interruptions injected to confirm rejection and recovery. |
| Downlink science data | High-priority event summaries transmitted first; raw waveforms when bandwidth allows; lost packets support retransmission; every packet carries error detection. | At least 95 per cent of scheduled test data received directly or recovered through retransmission; ground software reconstructs complete event files. | End-to-end payload-to-ground test with packet loss and radio interruptions introduced; retransmission and file reconstruction verified. |
| Control spacecraft interference | Wi-Fi, OLED, LEDs, switching circuits and unnecessary radios disabled during sensitive measurements; repeated spacecraft noise frequencies identified; coil mounted away from high-current wiring. | The science-mode noise floor meets the minimum signal-detection requirement; no major processor or radio frequency dominates the VLF spectrum. | Record with all subsystems off; turn on each individually and record the spectral change; build a spacecraft interference database; repeat in the fully assembled satellite. |
| Perform calibration | Calibration amplitude and frequency traceable to ground measurements; the signal stable within 5 per cent; calibration not confused with a natural science event. | The measured calibration response stays within 5 per cent of its reference; calibration events are correctly labelled. | Calibration run at room temperature and repeated at minimum and maximum operating temperatures, comparing gain and frequency response. |
| Monitor payload temperature | Temperature accuracy within 2 degrees Celsius; temperature recorded with each event; unsafe temperatures cause safe-mode entry. | Recorded temperatures match calibrated chamber sensors; the payload responds correctly to hot and cold limits. | System placed in a thermal chamber; payload readings compared against calibrated probes; warning and shutdown thresholds crossed. |
| Regulate and monitor power | Preliminary acquisition power below 3 W; the 3.3 V supply within component limits; analog-supply ripple low enough to meet the receiver-noise requirement; overcurrent protection prevents permanent damage. | No brownout or ADC corruption across the bus-voltage range; consumption within allocation; a short circuit does not permanently damage the power bus. | Programmable supply at minimum, nominal and maximum bus voltage; startup, acquisition and safe-mode current measured; ripple examined on an oscilloscope. |
| Recover from faults | A hardware watchdog monitors the processor; normal operation resumes within 60 seconds after a recoverable fault; stored data is not erased during recovery. | Forced lockups cause an automatic restart; the payload returns to a commandable safe state; previously stored files remain readable. | Firmware loops and memory errors forced; power interrupted and restored; corrupted commands sent; recovery time and stored-data integrity checked. |
| Survive launch and orbit | Mechanical connections secure after launch vibration; operation throughout the approved temperature range; radiation-related resets detected and recovered; materials suitable for vacuum. | No structural or electrical damage; calibration within allowed limits after environmental testing; a complete functional test passes afterwards. | Vibration testing, thermal-vacuum cycling, vacuum-compatible-material review, radiation analysis or component testing, with full functional tests before and after each. |
| Correlate events with lightning observations | Event time, location, frequency content and uncertainty available; the correlation window defined before analysing results; unmatched events retained rather than discarded. | Multiple satellite events match independently observed lightning; the analysis reports matching and nonmatching events; results include uncertainty and false-match estimates. | A blind dataset of known matched and unmatched events built and run through the correlation software; correct-match and false-match rates measured; repeated with real observations after launch. |
Environmental qualification
The payload has to survive vibration, temperature cycling, vacuum and the expected radiation environment, and still work afterwards.
The requirements are that mechanical connections remain secure after launch vibration, that the payload operates throughout the approved temperature range, that radiation-related resets are detected and recovered rather than left to corrupt data silently, and that materials are suitable for vacuum.
The criterion that matters most for this instrument is the second half of the acceptance test: calibration must remain within its allowed limits after environmental testing. A receiver that survives vibration mechanically but whose coil sensitivity has shifted has lost its calibration, which for a science instrument is a different kind of failure but a failure all the same. Planned qualification is vibration testing, thermal-vacuum cycling, a vacuum-compatible-material review, radiation analysis or component testing, and full functional testing before and after every environmental test.
Lightning-correlation method
The final science objective is comparing satellite detections against independent lightning records. It is also the check that the instrument measured what it claims to have measured.
The requirements make the comparison honest rather than flattering. Event time, location, frequency content and uncertainty all have to be available. The correlation window — how close in time and space a ground record has to be before it counts as the same event — is defined before mission results are analysed, not chosen afterwards to maximise matches. And unmatched events stay in the dataset rather than being discarded automatically: an event with no ground counterpart may be a false detection, or it may be a signal that propagated from somewhere the ground network does not cover, and deleting it removes the evidence either way.
The acceptance criteria are that multiple satellite events match independently observed lightning, that the analysis reports both matching and nonmatching events, and that results include uncertainty and false-match estimates. Verification builds a blind dataset containing known matched and unmatched events, runs the correlation software against it, and measures correct-match and false-match rates before the same pipeline is used on real observations.
No correlation has been performed. There is no instrument and no data.
Rev A design review
The review compared the schematic against the sixteen top-level requirements and the twenty mission functions, asking of each whether Rev A could contribute to it.
The receiver core is present, and that distinguishes this design from one that has only its support electronics: coil connector, preamplifier, conditioning network, converter, processor, power, protection and the interfaces for bench work are all drawn. Signal in at H1 and digital samples out is a path the drawing describes.
What is missing is the sensor. The search coil is external and not shown, so its geometry, its sensitivity and its calibrated response are undefined — and TR-01 and TR-02 both depend on them. What is unresolved is precision: gain unverified against the 10 microvolt requirement and probably needing multiple settings, filter response to be designed and measured rather than assumed, midpoint bias unchecked, and sampling stability unverified.
What is absent as flight capability is everything past the processor. UTC within a millisecond needs GPS 1-PPS or a spacecraft clock. Science storage with 99 per cent integrity is required. A flight command and data interface has to be documented. USB-C, the OLED and the 2.4 GHz path are development conveniences and none of them is the downlink.
And two devices are annotated as transmitters on a receiver. Whether they serve the calibration system or something else is not established.
None of that makes the drawing wrong. It is the distance between a circuit that would work on a bench and an instrument whose measurements would mean something in orbit.
Rev B required changes
The review's priorities in one list. The main page carries the same eleven; this is where the reasoning for each sits beside it.
| # | Change | Why |
|---|---|---|
| 01 | Define the physical search coil. | Geometry, sensitivity in V/T, mounting away from noise sources and calibration across frequency and temperature. TR-01 and TR-02 have no hardware behind them until this exists. |
| 02 | Validate or add selectable analog gain. | One fixed setting is unlikely to serve both a 10 microvolt signal and a nearby strong stroke; the review suggests 1x, 10x and 100x. |
| 03 | Design and verify the filter. | 3 to 30 kHz within 3 dB, at least 20 dB above roughly 40 to 45 kHz. Out-of-band energy that folds into the band cannot be removed afterwards. |
| 04 | Verify the midpoint bias. | 1.65 V with a bipolar waveform fitting between the converter's limits, and bias noise below the receiver requirement. |
| 05 | Verify ADC sampling. | Rate, timing stability, reference and noise, over a recording long enough for missing or duplicated samples to show. |
| 06 | Add or define timing synchronisation. | GPS 1-PPS or a synchronised spacecraft clock for UTC within 1 ms, without which correlation against lightning records is not possible. |
| 07 | Define flight science storage. | Records with checksums and the strategy behind the 99 per cent integrity requirement, surviving interrupted writes. |
| 08 | Define the flight spacecraft interface. | A documented UART, SPI, I2C or CAN link with a defined command set, replacing the development assumptions. |
| 09 | Add a science-mode interference strategy. | Shutdown of noisy subsystems during measurement, plus the measured interference database that says which subsystem produces which line. |
| 10 | Clarify calibration and the GaN and SiC devices. | The injection path has to be defined, and the purpose of the two devices annotated as transmitters established. |
| 11 | Define coil and analog temperature monitoring. | Accuracy within 2 degrees Celsius, recorded with each event, so drift can be corrected rather than guessed at. |