Key Takeaways:
NASA’s lunar network will leverage Delay/Disruption Tolerant Networking to maintain signal integrity between rovers, astronauts, satellites, and more.
4G/5G LTE RF and optical inter-satellite links are both in play to transport data, but lasers are expected to gain market share as data rates reach 100 Gbps, owing to their lower vulnerability to eavesdropping and jamming.
Systems need every tool in the box to protect the data: root of trust, secure boot, measured boot, post-quantum cryptography, and over-the-air updates or programmability features such as rad-tolerant FPGAs.
The moon and Mars are becoming realistic targets for commercial mining operations, scientific exploration, and intelligence gathering, driving a swirl of activity around different communications and power options and heightening security concerns.
A race is underway to develop reliable, fast, and secure communications networks, which are essential for transferring data between satellites, spacecraft, compute centers, autonomous mobile robots and rovers (AMRs), and astronauts. Edge compute enables some of the data to be filtered and processed locally, but a lot of information is also sent back and forth to ground stations on Earth. Options include radio frequency (RF) cellular, such as 4G, 5G, and possibly 6G, along with RF GaN and lasers via optical inter-satellite links (OISLs).
NASA’s recent Artemis trip around the moon was the first step toward a forthcoming lunar landing and deployment of a lunar network, known as LunaNet. On the lunar surface, AMRs can gather samples and perform other studies, but the primary motivation is to gain a position on the moon that can provide links out to deep space missions.
“Right now, that might be defined as Mars, or other missions that may go beyond Mars or even beyond the solar system,” said Shawn Carpenter, program director for 5G/6G and space at Synopsys, which worked with NASA on the Artemis mission. “You need some place that you could base communications from where you can have stronger power conditioning systems. It’s difficult to gather enough solar energy to power a high-power amplifier for relaying. There are a number of reasons why it’s attractive to base some of that down on the moon. They’re going to get a start with that in addition to lunar surface exploration, pulling samples and looking at what’s under the cross (a light-dark optical illusion), what’s below the regolith (loose, fragmented rock, dust, and debris on the surface), and what sorts of natural resources occur there that we can reuse.”
Lunar networks will need to transmit multiple high-definition video channels, a lot of telemetry data, and other data.
“NASA’s vendor for those radios is Nokia, and they are using LTE systems that are consistent with the later 4G technology nodes,” said Carpenter. “They’re evaluating right now whether the 5G equipment is settled out well enough, and if they feel good enough about the technology to maybe upgrade the node to 5G. What they want to be able to do first is establish network communications on the moon so that NASA — and commercial companies that want to send up vehicles, landers, exploratory vehicles, and aircraft or surface craft — would be able to have surface connectivity that then connects upward to the home system and comes back to Earth.”

Fig. 1: The core network framework of LunaNet is Delay/Disruption Tolerant Networking (DTN). Source: NASA
These networks would enable astronauts to send data and download data from Earth, with the kind of delay that people were accustomed to some years ago. “They’re looking at 20-megahertz kind of bandwidths, which will support quite a bit,” said Carpenter. “Plus, you’re not competing with an awful lot of subscribers up there yet, so the bandwidth would look pretty good up there, depending on how fast the links go back to Earth. The only issue that you will have is the sheer distance from the Moon to Earth, which will create latency.”

Fig. 2: LunaNet will bring terrestrial internet capabilities to astronauts, rovers, and orbiters. Source: NASA / Reese Patillo
For now, 4G offers a more mature ecosystem than 5G. “It’s lower-risk deployment, specifically for the capabilities and the performance that would be required,” said Dana Neustadter, senior director of product management at Synopsys. “It is sufficient in terms of voice and the telecoms and telemetry. However, compared with 5G, there are some security capabilities that were added in 5G to improve the zero-trust architecture, with stronger mutual authentication. And the way that the PHYs are implemented, the way you do the network slicing, is also important for mission segmentation.”
5G millimeter wave faced challenges on Earth due to its line-of-sight requirement. “The satellite format has flipped the problem on its head,” said Shankaran Janardhanan, senior vice president of RF at GlobalFoundries. “They basically said, ‘Let me put satellites up in space and connect directly through beamforming into user terminals and user devices and networks and ground station base station terminals on the ground.”
Today’s RF satellite communication technology uses millimeter-wave phased-array systems, and the basic problem statements haven’t changed. Everybody wants higher bandwidth, higher output power, higher efficiency, and better connectivity. “That’s what RF GaN addresses,” said Janardhanan, noting that silicon photonics is also important. “Silicon photonics is spreading into the terahertz regime.”
Specifically, GaN on silicon fits into the power amplifier component that goes into satellites. Gallium nitride, gallium nitride on silicon carbide, and gallium arsenide are also possible solutions, but a lot of the components that serve the power amplifier today are available only on six-inch wafers.
“GF’s gallium nitride on silicon is going to be one of the first eight-inch high-volume gallium nitride silicon technologies that’s manufactured in the U.S. This is a very important thing,” said Janardhanan. “From an overall security standpoint, the power amplifier is actually amplifying the signal, so the link between systems needs to be secure, and it’s secure if you have a closed-loop system built by technologies that are manufactured in the U.S.”
But higher bandwidth and more resilient links are only part of the equation. As space networks begin carrying more mission-critical data across RF, optical, and compute infrastructure, they also create a broader attack surface that must be secured from the hardware up.
Network and satellite security risks
Robust security measures for lunar and satellite networks are necessary to prevent sensitive information from being obtained by nation states or hackers.
“The satellite security challenge is one of high interest and importance to the U.S. government,” said Scott Best, senior technical director of silicon IP at Rambus. “There are many aspects — secure communications, secure execution, tamper resistance, etc.”
Networks are prized targets whether they connect AMRs and astronauts, or satellites and compute centers. “People will attack for all the reasons you would suspect,” said Reed Hinkel, director, strategic programs, security, processor, wireless and NVM at Synopsys. “If hackers can create a denial-of-service attack, they can charge you a nice tidy sum. They don’t care about the data as much as they care about extracting it away to ransomware your device.”
And because components in space are less physically accessible for maintenance and replacement, systems need to be designed to be future-proof through algorithms, software reinstallation, and real roots of trust to be able to factory restart.
“In risk analysis, we try to open up as wide as possible scope, and one of the first analyses is to understand that the assets — namely, satellites — have a lot of value,” said Sylvain Guilley, CTO, co-founder, and fellow at Secure-IC, a Cadence company. “They are needed for those areas on Earth that are poorly connected to the internet, but also for highly mission-critical operations. When there is value, it increases the likelihood of a threat from people who want to gain access to those assets to use them, abuse them, or destroy that advantage. The number one threat, and the most funded, most determined threats, are nation states. That’s real and is also the reason we have the CHIPS Act and other government programs. It’s not only an economic issue, but also a diplomatic and strategic one. There are tool levers to go in the same direction of power, so you need to have the technology, you need to have the control. We see that as the driving force behind cyberattacks and physical attacks that damage the system. For example, with laser beams that talk between satellites, if you increase the power a little bit, you can burn some sensors or completely destroy satellites.”
An adversary could take over a laser and use it for destructive purposes. “In free space, when you are 400 to 500 to 600 kilometers away, you’re almost outside of the atmosphere, so your lasers go almost straight,” said Guilley. “They remain extremely focused, so that’s a lot of watts per square millimeter.”
That duality makes optical links especially important to evaluate. They can reduce exposure to some RF-based attacks, but their precision, power, and line-of-sight requirements introduce a different set of security and operational tradeoffs.
Optical inter-satellite links
Laser communication is a line-of-sight technology that uses narrow, focused beams of infrared light to transmit data at up to 100X faster rates than traditional RF. Another advantage of OISLs is that they are immune to electronic interference or jamming.
“You can observe RF emissions, and for military trips, it’s important to stay silent,” said Dalius Petrulionis, CTO at Astrolight. “This is why lasers are also interesting for terrestrial applications. It can be ship-to-ship or jet-to-jet. That’s a very good application, especially for stealth jets, because then you don’t have the radio emission.”
An eavesdropper in radio can be 100 or 1,000 kilometers away and still receive the signal. “If it’s unencrypted, or they have a quantum computer and can break the encryption, that’s a problem,” said Petrulionis. “Lasers are more physically secure, because you’re only pointing the laser where you want to, and the shadowing satellite, or the shadowing drone, or whatever else shadows the communication, needs to be in direct line of sight to obstruct the laser, which means you can see if it’s behind you. It’s hard for them to track the laser, so it’s an inherently physically safer means of communication.”
Quantum communication makes lasers even safer. “We have quantum key distribution using the same optical medium, which you can’t do over RF, and we combine that with a classical channel,” he said. “In fact, you must combine it with a classical channel, so you transmit the keys, and you encrypt the classical channel with the quantum keys. The bits are sifted over the quantum link. Then you can have physically proven security. It’s physics that’s making it secure. You can see if it’s being eavesdropped. It’s all related to how precisely pointed the laser is.”
In addition to connecting satellites, optical links could connect a rover on the moon directly to a terminal on Earth, without the need for relay satellites or huge antennas. “There’s a NASA Psyche mission that beams data from the asteroid belt, which is orders of magnitude further away, down to Earth without any intermediaries,” said Petrulionis. “But it can also beam to a satellite. There’s no inherent reason why it wouldn’t. The Artemis mission that went around the moon, for example, had optical connectivity. They transmitted huge amounts of data over that link.”
Optical space networks may also be used for specific computations of confidential terrestrial data. “When you’re in space, satellites are moving around, so it’s much more difficult to trace where the data is hopping,” said Cadence’s Guilley. “It might be another way to evade and to do some kind of furtive computation if you have some extremely critical data and you want to reduce the risk of interception or adverse manipulation, especially in the context of nation states. You want to be in a neutral space, extraterritorially, so the jurisdictions do not apply.”
GF’s Janardhanan agreed that optical connectivity will be preferred to RF when it comes to very high-speed links between satellites, and to connect GPUs within orbital data centers. “RF would still be the solution of choice when you’re connecting from the satellite to user terminals and consumer terminals to the ground, or consumer terminals to the base station — because the RF downlink signal can work well enough.”
Optical connectivity matters to ensure fast compute. “Even within that there’s really high-speed, high-performance RF that’s needed, which is silicon germanium, and a lot of SOIs (silicon on insulators) are needed,” said Janardhanan. “RF has got a new life thanks to some of these applications.”
But faster links and more distributed compute only raise the stakes for trust inside the device itself. As satellites, rovers, and orbital compute platforms become more connected and more programmable, firmware becomes one of the most important lines of defense.
Firmware security measures
Securing space networks, relay satellites, and rovers is harder than securing systems on Earth because of the harsh environment, physical inaccessibility, extreme distances, and legacy constraints of space assets.
“There are a lot of similarities to Earth,” said Synopsys’ Neustadter. “You need a strong root of trust and secure boot, and measured boot. But in space, you would need to do a very fast signature verification, because when you are a rover, you may have many incoming messages, such as beacons. You will need secure update and recovery mechanisms to be available for a longer period. Another area that may be different is how to partition between the safety controller and the communication-type stacks. It’s still something you must address on Earth as well, but as a rover, the main risks are injecting rogue commands and spoofing to compromise software, which can come from many directions. You need to act fast, but also you need to have a reliable system for the long lifecycles.”
Cadence’s Guilley agreed root of trust is essential, and that it must be based on cryptography. “The root of trust will ensure that when you update, you will load a new firmware image, and that is duly checked,” he said. “Then you’re okay to have a long mission time, because you can do this update in the field, in space. My warning is that this over-the-air capability, with the root of trust itself, needs to be based on some crypto. So you’d better have a full-fledged root of trust because you cannot update everything. The root of trust is immutable, meaning you cannot go beneath the root of trust, so it must be future-proof. It must have PQC (post-quantum cryptography) with long keys, with multiple algorithms, in case it happens that one family of algorithms happens to be weak.”
For example, China is trying to find vulnerabilities in lattice-based crypto for PQC, so designers are advised to use non-lattice-based schemes. “This is why NIST standardized another algorithm for key exchange, HQC (Hamming Quasi-Cyclic), which is not lattice-based, just to have some diversity, in case…,” said Guilley. “That is what I call future-proof root of trust — implementing an array of different algorithms so that you can do your firmware in space update using whatever crypto agility you wish.”
Further, the space environment is more prone to bit flips or single-event upsets caused by radiation or a malicious fault injection. “The challenge is that we are working with both large-scale constellations and also tiny satellites of just one liter or kilogram,” said Guilley. “Some of the satellites have minimum — if any — safety features, meaning redundancy, error, parity checks, etc., because they can reboot extremely fast. They are tiny objects.”
Mature FPGA technology also enables fast reboot. “You still have a hardware system, but it can reload the bit stream,” said Guilley. “Some of the satellites will go half an hour into the dark and basically power down in sleep mode, and then they will be in the sun, so they will get some power. They have cycles, and it’s very easy to reboot. You wouldn’t do it with an automotive chip when it is driving, but in a satellite if you need to reboot, you take it offline for one second, and that’s fine. So even though space is a harsher environment, you can continue the mission, especially when you have a complete constellation with many satellites. Space is therefore a yes and no problem.”
A bigger problem is obsolescence, and FPGAs also have an advantage here due to being reprogrammable. “This is an experiment we’ve been doing with one of the nanosat companies — we retrofitted some algorithms,” said Guilley. “They were taking radar photographs for intelligence, and they were signing using classical crypto. They wanted to see whether it is possible to sign with post-quantum crypto. We said, ‘It’s very simple. Your FPGA is running Linux. You use OpenSSL and retarget the algorithms to PQC.’ They re-flashed the FPGA, upgraded it, and it worked, signed with LMS (Leighton-Micali Hash-Based Signature), which is a post-quantum crypto. But if you go with an ASIC or something that is not meant to be future-proof, or upgradable, then you are a bit stuck.”
Others agree that newer satellites benefit from better security. “The early ones were less secure than the ones today, particularly around the communications,” said Synopsys’ Hinkel. “Customers are spending a lot more on the topic of security, and they’re investing a lot more heavily because they have to follow encrypted communications.”
Another aspect that’s common to most security challenges is key rolling. “This term intends to capture the idea of updating the most secure cryptographic keys on a remote device — there’s nothing more objectively remote than a satellite — even while a malicious adversary might have compromised the system and potentially be in control of it,” said Rambus’ Best.
One of the most secure means of key rolling involves physically unclonable function (PUF) key-generation circuits. “While the key material they create is not unclonable — keys are just long strings of binary digits, quite easily cloneable — PUFs are ideally suited for key-rolling purposes,” said Best. “This is because the transformation function they perform is chip-unique and unclonable, guarding the keys from compromise or replication by an adversary.”
PUFs are aimed at security resiliency and are a feature of Microchip’s radiation-tolerant FPGAs and NASA’s radiation-hardened RISC-V processors, such as in its High-Performance Spaceflight Computing – Implementation (HPSC-I). NASA also has a Rad-Hard Non-Volatile Memory for FPGA BootLoading project.

Fig. 3: NASA’s High Performance Spaceflight Computer, courtesy of Microchip. Source: NASA
Ongoing improvements to PUF technology are a result of advanced error correction that cryptographers have been able to put in place. “We benefit from a lot of the same science and mathematics as cryptography, from being able to do error correction,” said Hinkel. “Cryptographers are probably equally as good at, or better than, some of the folks that do error correction for modems and things like that.”
Assorted natural and regulatory challenges
Along with hackers and bad actors, solar ejections and nuclear attacks pose threats to space networks. Geostationary satellites, operating in higher orbit, can also suffer from exposure to high solar winds.
“Solar particle ejections are a natural thing, which are a high flux of protons,” said Helmut Puchner, fellow and vice president of Aerospace and Defense at Infineon Technologies. “Engineers are smart enough to detect it, and are always improving systems to protect the asset. But if somebody triggers a nuclear event in space, I was told it populates around the globe in space and causes an EMP (electromagnetic pulse) event that might fry all the commercial satellites. Not the government ones, because they are built to sustain those levels of radiation or stress, but the commercial ones will not survive.”
Conclusion
Both government and private companies are taking steps to ensure data security as networks in space grow more complex with more use cases.
“The investment to put something in space is high enough that they are absolutely protecting at least their part of the investment, the byproduct of which is that their signals don’t get compromised,” said Synopsys’ Hinkel. “They don’t want to lose control of their vehicle. They want to be able to update it. With some government projects, there’s a mission, and if the mission includes security, that’s great, but if the timeline doesn’t allow you to do it, they may cut corners more than a commercial company might. A commercial company may have more to lose, because they have shareholder lawsuits and product liability. There’s a ton of different things that they have that the government doesn’t really have to worry about to remain a viable entity.”
Whether in space or on Earth, companies have to prove the same kind of capabilities, reliability, and security mechanisms. “Otherwise, they would be out of business,” said Neustadter. “If they make mistakes, likely someone will be liable, and/or the business will go down the drain.”
Overall, space technology continues to benefit from nations working together, and there has not yet been a major conflict in space.
“Space inherently has to be cooperative,” said Petrulionis. “If you clutter up space, you ruin it for everybody. That’s what they call the Kessler syndrome. For example, why satellite destruction is so destructive for humanity’s endeavors is because it generates a lot of debris that’s going much faster than a bullet, and all of this debris, when it hits a satellite, generates more debris than it’s another satellite generates more debris, and you can end up with a situation in space where it’s very hard to operate there.”
Related Article
Orbital Data Centers Are Souped-Up Satellites – For Now
Satellite constellations with extra onboard compute are several steps away from handling full AI workloads for people on Earth.