1. Regulatory Framework
Satellite communication operates within a layered regulatory framework that applies whether the constellation is commercial, governmental, or hybrid. At the international level, the International Telecommunication Union allocates spectrum and orbital resources through the Radio Regulations and the Master International Frequency Register; the Outer Space Treaty and the Liability Convention establish state responsibility for activities of national constellations; and the recently revised UN Long-Term Sustainability Guidelines and the IADC space-debris guidelines impose operational expectations that effectively govern routing and propagation behavior of orbital assets. At the national level, the FCC Part 25 satellite licensing rules in the United States, the Ofcom satellite filing regime in the United Kingdom, and the equivalent national regimes in major operating jurisdictions impose conditions that bind the licensee to specific operational parameters and to specific user classes.
Data-protection and locality regimes apply to satellite-borne traffic just as they apply to terrestrial. GDPR transfer obligations follow the data, not the medium; an EU resident's session relayed through an inter-satellite link transiting a satellite credentialed under a non-adequate jurisdiction is, under current EDPB enforcement posture, a transfer event. EO 14117 and the implementing DOJ rule prohibit certain bulk transfers to countries of concern regardless of whether the transfer hop is terrestrial, sub-sea, or orbital. ITAR and EAR export controls apply to controlled technical data carried by commercial satellite networks, with the exporter's compliance obligation extending to every relay path through which the data may pass.
For government and defense payloads, the framework intensifies. United States classified payloads operate under the National Industrial Security Program Operating Manual and DoD instructions, with cross-domain solutions and accreditation regimes specifying how classified data may transit, by what authority, and with what assurance. NATO STANAGs and the equivalent Five Eyes accreditation regimes apply to coalition satellite communications. Civil-government payloads, earth observation, weather, navigation augmentation, operate under data-policy regimes that may include licensee-specific conditions on user classes, latency, and integrity.
Cybersecurity overlay has accelerated. The U.S. Space Policy Directive-5, the NIST IR 8270 series on commercial satellite cybersecurity, the proposed FCC rules on satellite cybersecurity, the EU NIS2 essential-entity scope which includes space, and the UK National Cyber Security Centre guidance on space sector cybersecurity each expect demonstrable structural assurance over the routing and trust behavior of orbital assets. The trajectory is toward credentialed and lineage-recorded routing of every payload, with the assurance produced by the architecture rather than reconstructed by ground-based after-action review.
2. Architectural Requirement
The architectural requirement is dictated by the physics of space. Inter-satellite link decisions in a LEO constellation must be made in the time it takes a signal to traverse one orbital hop. Ground contact for any given satellite is intermittent, a polar-orbit satellite may have a ground station window of a few minutes per pass, and inter-satellite links among rapidly moving platforms produce a topology that changes faster than ground-based recomputation can track. The described substrate therefore supports routing and trust decisions made locally at each satellite, with governance that tolerates delay rather than depending on synchronous consultation.
A second requirement is that policy travel with payload. In the described embodiments, classification, compartmentalization, jurisdictional locality, user-class priority, and integrity expectations are available at every relay hop without round-tripping to a ground authority. The policy is authority-credentialed at origin and locally evaluable at every receiving satellite. The receiving satellite can refuse, defer, partially propagate, or admit the payload based on its own credentialed eligibility against the payload's credentialed policy.
A third requirement is closure across the constellation. Every routing decision generates an actuation-state observation, admitted, deferred, refused, partially propagated, that re-enters the substrate as input to subsequent decisions at adjacent satellites and at the ground. Without closure, the lineage of a multi-hop orbital relay terminates at each hop, and forensic reconstruction of a classification-significant or jurisdictionally-significant routing event becomes a manual cross-operator reconciliation. With closure, the lineage is the substrate.
A fourth requirement is composability across operators. Modern satellite communication is rarely single-operator end-to-end. A government payload may originate on a defense constellation, transit a commercial relay, and terminate on a coalition partner's downlink. The described substrate composes hierarchically: a satellite's local credential within an operator's credential domain within a national or coalition credential framework, with cross-recognition through published mappings. A single global root is impractical across this surface, and the described substrate operates without one.
A fifth requirement is autonomy under contested conditions. Adversarial jamming, spoofing, denial of ground links, and cyber-effects against ground infrastructure are anticipated operational conditions for both commercial and government constellations. A substrate that fails closed under loss of ground contact fails the operational availability obligation; a substrate that fails open fails the confidentiality and integrity obligations. An architecture that satisfies both is one where the policy and the trust travel with the payload, so that each satellite holds, locally, what it needs to make a defensible decision.
3. How Procedural Approaches Are Organized
The dominant approaches to satellite routing, pre-computed routing tables uploaded from ground control, ground-based traffic management, and policy enforcement at the gateway, are procedural in the same sense that ground-based control planes are procedural: the authority lives at a central location and the orbital assets execute under snapshots of that authority. The CCSDS Space Communications Protocol Specification and the DTN Bundle Protocol address the transport problem of intermittent connectivity, and governance of authority-credentialed routing in motion is organized as a separate concern above them.
Pre-computed routing tables work for predictable traffic and stable orbital configurations. Their coverage is bounded by the update cadence: traffic patterns that change between updates, a satellite in a relay chain that degrades or fails, priority traffic that must be inserted, classification or jurisdictional constraints that would block a path the table assumed was available, and unavailability of the ground station that would have computed the next table each fall outside the precomputed set. Those are precisely the conditions the regulatory framework most cares about.
Ground-based traffic management of the sort employed by commercial broadband constellations addresses scaling through computation rather than through architectural redistribution of authority. As constellations grow into the thousands of satellites, the combinatorial explosion of possible routing paths overruns the upload cadence: the gap between the network's actual state and the ground station's model of it grows with constellation complexity. Engineering throughput improvements narrow that gap; the described architecture instead evaluates locally, so the decision does not depend on the ground model being current.
DTN Bundle Protocol implements store-and-forward over intermittent connectivity. A DTN node is organized around storing and forwarding; authorization to handle a particular bundle, prioritization of that bundle, and whether the next forwarding hop crosses a trust or jurisdictional boundary that should restrict propagation are governed at a separate layer. Bundle Protocol Security Specification adds confidentiality, integrity, and authentication primitives to bundles, securing the bundle against tampering in transit; the disclosed substrate adds, above that, the credentialed governance under which the bundle's routing decisions are made.
Cross-domain solutions for classified payloads are programmatic devices interposed at specific accredited boundaries. They are correct for the boundary they accredit, and their governance is scoped to that boundary; traffic admitted through it then travels through a network whose governance the accreditation presumes. As constellations integrate commercial and government payloads on shared transport, that presumption holds less well, and the cross-domain accreditation becomes a chokepoint rather than a substrate.
Procedural augmentation narrows the residual risk, and the residual that remains is structural: the binding between policy and action is a procedural binding implemented at the ground or at specific accredited boundaries, while the routing decisions that determine whether the policy is honored occur in orbit, between hops, in the time it takes light to cross a few thousand kilometers.
4. The Memory-Native Protocol Applied in Orbit
The Memory-Native Protocol disclosed in United States Patent Application 19/366,760 makes the unit of transmission a memory-bearing agent rather than a stateless packet. Each agent carries a unique identifier, a semantic payload, a transport header encoding propagation constraints such as time-to-live and trust radius, an append-only memory field holding signed lineage, access logs, and policy references, and a cryptographic signature over the whole structure. Applied to a satellite constellation, each payload relayed across inter-satellite links is carried as such an agent, so routing policy, trust scope, classification constraints, and propagation rules travel with the data and each receiving satellite evaluates them locally against its own policy without round-tripping to a ground authority.
The disclosed protocol stack supplies the mechanisms this application relies on. The dynamic routing protocol (DRP) selects the next satellite by constructing a local trust graph from the agent's access-log history, prior trace outcomes, and embedded policy references, then assigns each candidate a trust score weighed against a policy-defined threshold and against time-to-live cost. A candidate that falls below the trust threshold, that crosses a scope boundary the agent's transport header forbids, or that has expired its time-to-live is categorically excluded from the routing graph; the selected hop and its justification are appended to the agent's memory trace before forwarding. Where a payload proposes a structural change, the adaptive consensus protocol (ACP) scopes a trust-weighted quorum from the policy reference embedded in the agent and records the outcome, so that a routing or admission decision requiring agreement among satellites can be reached without a fixed validator set or globally synchronized state.
Closure across hops is load-bearing in the orbital context, and it follows directly from the append-only memory field. Each protocol layer that acts on an agent leaves a signed, hash-chained trace, so the decision made when a payload is admitted at hop N becomes recorded context that the next satellite at hop N+1 reads and weighs. Multi-hop orbital relay becomes a chain in which the cumulative lineage is verifiable at every point on the path, including the eventual ground egress where regulators, mission owners, or partner operators may require it. The substrate is delay-tolerant by construction: the disclosure states the agent carries all context needed for execution and can propagate and be validated even after long delays, so correctness does not depend on the synchronous availability of any particular authority.
The protocol is deliberately transport-agnostic. The specification describes operation atop TCP/IP, HTTP, WebRTC, mesh relay, and delay-tolerant networking without modification to the agent, with the stack operating above the transport layer and interpreting the agent as a complete operand. A memory-native agent can therefore be serialized into a DTN bundle, a CCSDS frame, or a commercial protocol payload, with the embedded governance carried in the agent structure that each surviving relay parses. Federation across operators uses the disclosed federated-zone model: each domain defines its own policies and trust models while the substrate enforces behavioral compliance through agent-carried rules and verifiable metadata, with consensus scoped locally per node and mutation eligibility enforced per policy reference. No single global root is required.
The inventive step this application draws on is the embedding of governance in the data object itself, so that routing, mutation eligibility, and consensus participation are determined by what the agent carries rather than by where it came from or by a central controller. Space-transport protocols carry classification labels, priority tags, or routing preferences as transport metadata; the disclosed substrate additionally makes those labels memory-resident policy that each receiving node evaluates locally, records a signed trace against, and passes forward as context for the next node. That memory-native closure, encapsulated in the satellite-borne transport, is the property the disclosed protocol provides and the property this orbital application enables.
5. Compliance Mapping
The compliance mapping is direct. ITU spectrum and orbital-resource conditions and FCC Part 25 license conditions become credentialed observations within the operator's taxonomy, with the regulator credentialed as the underlying authority. Routing decisions that would violate a license condition are structurally refused or constrained at the boundary where the violation would occur. ITAR and EAR export-controlled technical data carry classification credentials evaluated at every relay; a payload credentialed as ITAR-controlled is structurally refused at boundaries leading to satellites or ground stations not credentialed to receive ITAR-controlled material, and the refusal itself is a credentialed observation that satisfies the export-control recordkeeping obligation.
GDPR transfer obligations follow the payload through orbit. An EU resident's session credentialed under the relevant adequacy or SCC framework is evaluated at every inter-satellite hop against the receiving satellite's jurisdictional credential. EO 14117 country-of-concern restrictions are enforced structurally at orbital boundaries leading to credentialed prohibited-jurisdiction nodes. The "transfer event" is a credentialed observation with provenance, not a forensic reconstruction.
For classified and compartmentalized government payloads, the substrate's authority-credentialed and lineage properties satisfy the structural-assurance expectations that NISPOM, DoD CIO guidance, and the equivalent Five Eyes regimes are converging toward. Cross-domain transitions remain accredited at specific boundaries, but the substrate extends credentialed governance throughout the relay path so that the cross-domain solution is a participant in the chain rather than a chokepoint over an ungoverned medium. Coalition operations under NATO STANAGs and equivalent frameworks compose through published cross-recognition of national credential taxonomies.
NIS2, SPD-5, NIST IR 8270, and the proposed FCC satellite cybersecurity rules are satisfied structurally: every routing and trust decision is credentialed, lineage-recorded, and locally evaluated, which is the architectural property each of these regimes is converging toward. CCSDS and DTN compatibility is preserved; the substrate adds a closed governance chain above those transport substrates.
6. Adoption Pathway
Adoption proceeds through staged introduction compatible with existing satellite transport. The first stage attaches credentialed policy envelopes to payloads at ground ingress, with existing routing logic continuing to make decisions while the substrate records lineage in parallel. This validates the authority taxonomy, the credentialing infrastructure, and the lineage recording without changing routing behavior. It produces immediate evidentiary value for license compliance, export-control attestation, and classification audit.
The second stage introduces composite admissibility at the orbital boundaries that carry the highest regulatory or mission exposure: classification transitions, jurisdictional transitions, coalition trust-domain transitions, and priority-class transitions. At these boundaries the receiving satellite evaluates the credentialed policy locally and produces a graduated outcome. Routing within trust-homogeneous segments continues on existing logic, with the substrate observing in parallel.
The third stage extends composite admissibility throughout the constellation, with ground systems specialized to taxonomy management, credential issuance, mission-level observability, and long-term orbital prediction rather than to per-bundle routing authority. Ground stations remain operationally central; their authorial role narrows to policy and credential, while their operational role broadens to lineage consumption and forensic reconstruction.
Commercial fit is strongest where regulatory exposure, multi-operator relay, and contested-environment posture coincide: defense and intelligence constellations, civil-government earth observation and weather constellations operating under data-policy regimes, broadband constellations operating across multiple national regulatory regimes, and emerging space-data-relay providers serving heterogeneous payload classes. Substrate licensing is per-credentialed-authority, per-class, or per-mutation-rate, aligned with how regulated satellite traffic is actually consumed. The substrate does not replace existing transport, CCSDS, DTN Bundle Protocol, commercial protocols all continue, and it does not replace ground operations. It gives the orbital tier a structural credentialed-governance property produced by the architecture itself, of the kind the converging regulatory and mission-assurance frameworks increasingly look for.
Honest framing closes the analysis. Memory-native delay-tolerant governance does not eliminate ground operations; it redistributes the authorial function, policy, credential, lineage consumption, into the satellite-borne substrate while preserving the operational, mission-management, and observability functions that ground systems perform. Every payload becomes a carrier of its own governance, every satellite becomes a local authority for the payloads it handles, and the operator's compliance and mission-assurance posture becomes a structural property of the orbital architecture rather than a procedural attestation laid over it.
7. Disclosure Scope
This article is a public, dated application of the Memory-Native Protocol disclosed in United States Patent Application 19/366,760, "Cognition-Compatible Network Substrate and Memory-Native Protocol Stack." The technology it relies on, the memory-bearing agent with its append-only memory field, the dynamic routing protocol and its trust-weighted candidate scoring, the adaptive consensus protocol with trust-weighted quorum, the network health monitoring system, the transport-agnostic protocol stack, and the federated-zone deployment model, is described in that application, including its express support for asynchronous, delay-tolerant, and interplanetary deployment. The satellite constellation domain, the specific regulatory mappings, and the staged adoption pathway are deployment context for that disclosed technology and are not themselves claimed. Nothing here is to be read as enlarging the scope of the claims of United States Patent Application 19/366,760; it is published to establish enabling prior-art disclosure of applying that invention to delay-tolerant satellite routing governance.