Limitations
ActiveWritten by the author, before a reviewer writes it for them. A limitation stated plainly costs a paragraph; the same limitation found by a reviewer costs a revision cycle.
Scope
What the results hold for. A LEO broadband access network in which the operator can measure arrival time to roughly 10 ns and can observe each session from at least three satellites sharing a common transmit epoch. Under those two conditions, terminal position is recoverable to about 3 m and a single-beam adversary cannot shift its apparent position at all.
What they do not hold for. Everything else, and the two conditions are not minor.
| Condition | If unmet |
|---|---|
| Simultaneous multi-satellite observation | Position and a free-running clock bias become jointly unidentifiable. The guarantee degrades to a clock-plausibility heuristic that a commodity TCXO defeats by tens of kilometres |
| Arrival time to roughly 10 ns | The resolution cell grows until legitimate neighbours are indistinguishable from a relay. At 100 ns, false positives reach 28.3% at 100 terminals per km² |
Unmitigated threats
Threats named in the methodology that were not addressed, and what that costs.
| Threat | Why not mitigated | Effect on conclusions |
|---|---|---|
| Real constellations use beam hopping, scheduling and proprietary handover logic the model omits | No access to operational scheduling behaviour | The evaluation is simulation on public ephemeris. It does not claim operational validation, and the numbers should be read as an upper bound on achievable geometry |
| No prior geometric method to compare against | The literature study that produced this project found none | The detector is characterised against its own operating envelope rather than a competitor. A reviewer may reasonably ask “compared to what?” and there is no strong answer |
| Timing precision at 10 ns is asserted as achievable, not demonstrated | Would require hardware the project does not have | The central operating condition rests on a value taken from link-budget reasoning rather than measurement |
| Estimator uses delay only | Doppler is modelled but not wired into the solve | is likely pessimistic. Since binds the false-positive envelope, the operating envelope reported may be narrower than achievable |
Claims a reader should not draw
-
That this detects bots. It does not. Geometry establishes where, not who or what. Automation running on a legitimate user’s own terminal at its true location is invisible to the method, exactly as it is to device attestation.
-
That it prevents Sybil attacks. It bounds them. An adversary willing to deploy physical terminals at distinct sites obtains identities and is not detected. The contribution is that the cost becomes linear in hardware rather than in compute.
-
That spoofing is impossible. It is impossible for a single-beam adversary. An adversary radiating independently timed phase-coherent beams, one per satellite, can synthesise any position exactly. That class is not defended against; the barrier is capability cost, not geometry.
-
That the global identity cap is meaningful. It is not, and the paper deliberately does not present one. A 100 × 100 km footprint holds roughly 1.4 million resolution cells at m; a ceiling of that magnitude is operationally vacuous. The meaningful statement is per terminal.
-
That the numbers transfer to another constellation. They were measured on Starlink elements. The method is not Starlink-specific, but the resolution and visibility figures are.
-
That 10 ns is a mild requirement. It is the binding practical constraint and it is stated as such in the abstract, not buried.
What would remove each limitation
Each limitation with a route out of it belongs in future work; each without one is a boundary of the method.
| Limitation | Removable by | Cost |
|---|---|---|
| Delay-only estimation inflates | Folding Doppler into the solve; it constrains the same unknowns independently | Low. Already modelled in the code, needs wiring and re-validation |
| No operational validation | Measurement campaign against a real terminal and gateway | High. Needs operator cooperation or instrumented hardware |
| 10 ns asserted, not demonstrated | Bench measurement of achievable arrival-time precision on representative hardware | Medium |
| No comparison baseline | Implementing an RSSI-based Sybil detector from the WSN literature as a straw baseline | Medium. Would be a weak comparison but better than none |
| Multi-beam adversary undefended | Exploiting the fact that independently timed beams still radiate from a common aperture, so their relative phase behaviour may be anomalous | High, speculative. Currently stated as future work, not claimed |
| Fixed terminals only | Extending the estimator to a motion model | Medium. Changes the estimation problem rather than extending it |
| On-terminal automation invisible | Nothing within this method. Geometry cannot distinguish a human from a script at the same location | Boundary of the method, not a gap |