Link Sentinel
LINK

Link Sentinel

Protecting teleoperation links, mission control and on-board software from interference and attack.

A robot on Mars is only as safe as the link that commands it. Link Sentinel defends the whole chain — mission control, ground stations, the uplink and downlink across the 4–24 minute delay, and the software running on every unit — against jamming, spoofing, intrusion and supply-chain manipulation, keeping units controllable even while an attack is in progress.

  • Authenticated commanding and verified telemetry
  • Real-time jamming and spoofing detection
  • Signed, verifiable on-board software updates with rollback
  • Post-quantum key exchange and rehearsed incident playbooks

On-unit intelligence

The AI also protects the data path itself: events are classified on board and only verified, signed alerts leave each unit. If a link is degraded, on-board intelligence keeps assessing locally and synchronises its reasoning with mission control once contact is restored.

Link integrity

Every command is authenticated and every telemetry frame verified. Anomalous signal behaviour — power, timing or modulation that does not fit the expected pass geometry through the relay network — is detected in real time and separated into interference, jamming and spoofing.

Mission-control defence

Mission control networks, scheduling systems and data archives are monitored for lateral movement, privilege escalation and unusual command sequences. Segmentation and least-privilege access keep an intrusion in one system from reaching the command path.

On-board software assurance

Robot software updates are signed, staged and verified before execution, with rollback to a known-good image. On-board monitors watch for memory, timing and behavioural deviations that indicate corruption, whether caused by an attacker or by radiation.

Post-quantum key management

Command and payload links move to post-quantum-safe key exchange with regular rotation, so that traffic recorded today cannot be decrypted by future computing capability.

Incident response

If an attack is confirmed, the programme executes a rehearsed playbook: switch to an alternate relay path, raise authentication strength, isolate the affected segment and preserve forensic evidence — without losing control of the affected unit.