Architecture
Two tiers, because density and evidence have different cost structures.
A node cheap enough to deploy densely is not intended, by itself, to carry the calibration, timing and evidentiary controls that forensic work requires. Splitting the fleet optimises cost, coverage and evidentiary quality together.
SCOUT and SENTINEL
SCOUT — occupancy
Swept tuner, power only, no demodulation. Answers is this channel occupied, how often, and how hard.
Cheap enough to deploy densely. Density is what makes occupancy statistics representative rather than anecdotal.
SENTINEL — evidence
Coherent IQ capture, GPS-disciplined timing, traceable calibration. Built to answer what is that emitter and where — as far as IQ analysis and node geometry allow — with records engineered to withstand a dispute.
Deployed sparsely. Each one also serves as a transfer standard.
SENTINEL acts as the transfer standard through controlled methods — co-location, direct connection, or measurement against a controlled reference source — with routine SCOUT health checks against an internal reference. The aim is what meteorological and seismic networks achieve: calibration as a per-region cost rather than per-node. The transfer method itself is subject to prototype validation before it is claimed.
Design targets
Specifications under development. These are the acceptance criteria the hardware must meet before any node is deployed.
| Parameter | Target | Why it matters |
|---|---|---|
| Frequency range | 400 MHz – 7.2 GHz | Covers TVWS through the full upper 6 GHz IMT candidate band |
| Resolution | 1 MHz, with 100 kHz zoom on innovation bands | 1 MHz bins aggregated against the applicable band and channel plans; selected bands support 100 kHz zoom |
| Full sweep time | ≤ 3 s | Sets the full-band revisit interval — the bound on which intermittent emitters the statistics can characterise |
| Noise floor | ≤ −105 dBm at 1 MHz RBW | Sensitive enough to see weak incumbents, not just strong ones |
| Dynamic range | ≥ 75 dB | Driven by co-siting. Blocking, compression and intermodulation are specified and tested separately — one number does not prove co-site survival |
| Amplitude accuracy | ± 2.5 dB after cross-calibration (Tier 1) | Occupancy grade. Evidentiary work uses Tier 2's traceable chain. |
Engineering notes
Targets are easy to publish. What follows is a sample of the analysis behind them — the constraints the design actually has to engineer its way through.
The mixer does not forgive
Placing the first IF above the local oscillator removes the classical image — and buys nothing for free. The mixer's sum product can fold densely occupied low-band spectrum directly into the IF passband; the exact image and spur map depends on the final frequency plan and is established at bench validation.
Preselection filtering ahead of the first mixer is therefore mandatory, not a refinement. A front end without it measures its own architecture instead of the band.
The noise budget is arithmetic
At about 290 K, thermal noise is about −114 dBm in a 1 MHz bandwidth before the first component is chosen. A −105 dBm input-referred target therefore implies an effective system noise figure of roughly 9 dB across the whole chain — with the displayed-floor, averaging and detection definitions stated in the test plan, because those are not interchangeable.
That is a budget, allocated component by component, not an aspiration.
Tower sites fight back
The cheapest place to mount a sensor is next to somebody's transmitter. The ≥ 75 dB dynamic-range requirement exists because a node must measure a weak rural incumbent while a co-sited base station radiates watts a few metres away.
Site selection can avoid the worst of it; the front end has to survive the rest.
ITU-R SM-series occupancy guidance and ISO/IEC 17025 calibration practice are the design references this work is being built against — reference points, not claimed compliance. Mapping the applicable recommendations onto the design is the RF lead's first task, nothing here is accredited, and every specification above is an acceptance criterion the hardware must pass before deployment, not a datasheet claim.
Density is driven by requirement, not by coverage
Blanket uniform coverage is the wrong model. Three distinct requirements drive where nodes go, and they produce different patterns:
Incumbent protection
Clustered near registered earth stations and along high-density point-to-point corridors. Targeted, not gridded.
Representative statistics
Stratified sampling across geotypes — metro core, peri-urban, industrial, rural, agricultural. Each behaves differently and needs its own baseline.
Emitter geolocation
Deliberate clusters of coherent nodes with overlapping reception, sited where interference disputes are most likely.
Data handling
At one 32-bit value per bin, 6,800 bins swept once a second would generate about 2.35 GB per day; at the ≤3 s design revisit it is about 0.78 GB per day before metadata. At fleet scale either raw stream is uneconomic to transport, so aggregation happens at the node: per-minute statistics, then change-thresholded reporting, reducing the stream by roughly two orders of magnitude without losing what the statistics describe.
What reaches the platform is retained indefinitely as a design objective, and the archive is treated as what it is — sensitive national RF observation data. Access is scoped per customer, evidence access is audited, and disclosure is contractual. Historical occupancy is the one thing in this business that cannot be bought, accelerated or recreated — a competitor starting later starts later, and stays that far behind.
Evidentiary handling
Measurements intended to support a dispute will be held in an append-only archive with per-record hash chaining and periodic anchoring to an external timestamping authority, each record carrying the calibration state of the instrument that produced it. No measurement has been taken. A reference implementation of that archive exists and recomputes its own chain offline as a self-check; external anchoring is specified and not yet in place.
The verification method and the tool that checks it will be published with the first evidentiary release, and the tool will be open source. A chain that only the operator can verify is a chain the opposing expert will challenge on exactly that basis — publishing the verifier is part of the design, not an afterthought.
The platform, as it stands today
The sensing hardware does not exist yet. The software that will receive from it does — built first, deliberately, because the evidence layer is the one component that cannot be added afterwards. Every record written before the chain exists sits outside it permanently.
It runs end to end: a frozen canonical serialisation with a conformance-vector corpus behind it, validated record models, the append-only hash-chained evidence store and its offline verifier, the node loop with a store-and-forward queue, an ingest boundary that quarantines a refused record rather than dropping it — so the gap it leaves is explained from inside the archive — and a query API that enforces subscription scope before the read and applies calibration corrections on read, while the stored record stays raw.
It runs on synthetic input. No radio has been connected to it, and it demonstrates the data path rather than any RF performance — sensitivity, dynamic range, sweep time, the 6–7.2 GHz path and measurement uncertainty are all matters for calibrated hardware on a bench, and that work is ahead of us. External timestamp anchoring, and publication of the verifier and its conformance vectors, are specified and scheduled for the first evidentiary release.
When the first calibrated measurement is taken, the record it lands in will already have been specified, built and tested against its own contract.