Research question
ActiveThis project is responsible for RQ-001. The programme states that question at its full generality; this page states the narrower form this project can actually answer, and names the difference.
As this project asks it
Can a LEO access network operator, using only measurements it already takes, place a bound on how many distinct identities a single physical user terminal can present — without client cooperation, protocol change, or additional round trips?
Three qualifiers carry weight and are not decoration.
Using only measurements it already takes. Propagation delay and Doppler are formed by the gateway as a matter of course. A defence that requires new client-side instrumentation is a different and much harder proposition.
Bound, not detect. The project does not claim to identify automation. It claims to cap identity multiplicity per physical terminal, which is a weaker and more defensible statement.
Without additional round trips. This is the binding constraint in orbit. Every terrestrial challenge-response mechanism spends round trips that a LEO path cannot afford, which is why they do not transfer.
What was narrowed away
The gap between the programme question and the project question is where overclaiming happens. Named here so it can be respected in the write-up.
| Programme asks | This project answers | Difference |
|---|---|---|
| Prevent automated abuse of space edge infrastructure | Bound identity multiplicity at the access layer | Bounding identities is a prerequisite for admission control, not admission control itself |
| Detect bots | Detect that many identities share one terminal | Says nothing about whether the traffic is automated |
| Any orbital service | LEO broadband access, delay and Doppler observable | Does not cover on-orbit compute tenancy, which the access-layer bound is a prerequisite for |
| Any adversary | Adversaries constrained by what they can physically transmit | Excludes an adversary already inside a legitimate terminal |
The most important narrowing: geometry establishes where, not who or what. Automation running on a legitimate user’s own terminal at its true location is invisible to this method, and no amount of measurement precision changes that.
Success criterion
The project answers its question if all four hold.
- Terminal ground position is recoverable from delay measurements to a resolution that is stated analytically and attained empirically, rather than merely reported.
- There is a precisely stated condition under which an adversary holding one terminal cannot inflate its apparent position count, and the condition is checkable rather than assumed.
- The residual adversaries that defeat the bound are named and their cost is quantified, rather than omitted.
- The whole result is reproducible from archived inputs and a fixed seed by someone who did not write it.
All four are met. Criterion 2 is met more strongly than anticipated: the displacement is exactly zero rather than merely small, which is a structural property of the geometry matrix rather than an empirical finding.