OSI-ORB-F1 · Version 0.9 Draft

Many ORBs. One network.

A single ORB covers a site. Some sites are bigger than one ORB: a 40 km highway corridor, a mine with three pits, a wind farm across two ridgelines, a disaster area spanning a county. Federation is how units become one coverage domain, one policy plane, one ledger, and one management view, while each unit stays fully autonomous.

Doctrine

Federation is additive.

Every capability here layers on top of a unit that is complete by itself. The loss of any unit, link, or coordination service degrades the federation gracefully back toward independent operation, never below it. Three design rules are normative.

Rule one

No controller

There is no master node, no election whose failure stalls the site, and no external orchestrator required for any federated behavior. Coordination state converges through peer-to-peer replication.

Rule two

No new hardware

Federation uses only the radios, transport links, and management channels already specified in ORB-1 and ORB-C1. Nothing is added to the crate to make units work together.

Rule three

No configuration

Units federate because they share a site identity delivered through provisioning, not because anyone drew a topology. The topology is discovered, and it changes as units arrive and leave.

Discovery

Three channels, in parallel.

Federation forms under any connectivity condition a real site presents. Mutual authentication in all three channels chains to the provisioned device identity: a unit that cannot prove membership in the site identity is a neighbor to be coexisted with, never a peer to be joined.

Federation discovery channels
ChannelCarried onWhat it covers
Management planeLTE-M provisioned identity and site assignmentUnits learn their siblings' existence, keys, and last-known positions before they can hear each other. A unit still in its crate already knows the federation it will join.
Transport tier5.8 GHz PtP, wireless fiber, or wired interconnectA peer discovery and authentication exchange runs on link-up, which is how chains and rings self-assemble as dishes are aimed.
Over the airNR+ coordination beaconing and shared ledger stateUnits within radio range detect sibling identity directly, covering two units deployed within earshot before any transport link exists.

Synchronization

Six coordination domains.

What actually synchronizes between units, and what the operator sees as a result.

The six coordination domains
DomainWhat replicatesBehavior
SpectrumSAS grant state, channel and power plans, TVWS channel sets, Wi-Fi and AFC plansSectors of adjacent units interlock rather than collide. TDD phase alignment comes free from the common GNSS base, and the uplink-heavy frame structure is applied federation-wide.
MobilityHandover context, slice membership, QoS policy, ledger identityA haul truck driving 15 km transits five ORBs as one continuous attachment, make-before-break across both the CBRS and TVWS tiers. Nothing re-authenticates at a coverage boundary.
WANPooled path set across every unit in the chainOne fibered handoff at the south end and one LEO terminal at the north end serve the whole corridor. A chain of N units needs one or two WAN subscriptions, not N.
The ledgerAppend-only, identity-signed grant, attachment, and position recordsEach unit writes locally and replicates peer-to-peer. Any single unit answers an audit query for the whole site, and records merge on rejoin with nothing to reconcile, only to interleave.
Policy and tenancySlice definitions, authentication, QoS class, WAN policy, accountingA tenant defined on one unit exists on all units. A subcontractor's devices work identically at either end of a corridor and their accounting aggregates site-wide.
Compute and contentClass A edge workloads, site caches, plans, models, firmware imagesCapture workloads process on the nearest unit with capacity and caches replicate, so the site feels identical everywhere on it.

Topologies

Chains, rings, stars, clusters.

Topology is descriptive, not configured: the federation is whatever the discovered link graph says it is, and it changes as dishes are aimed, units arrive, and units leave.

Federation topologies and failure behavior
TopologyFormed byFitsFailure behavior
ChainSequential 5.8 GHz or wireless fiber hopsCorridors: highways, pipelines, rail, transmission linesA broken hop splits the chain into two federations, each fully functional; WAN re-pools per side
RingChain closed back on itself, or dual-homed endsLarge area sites wanting hop redundancyAny single hop loss leaves the ring connected; no split
StarSpoke units on transport links to one anchorA central pit or yard with satellite work areasSpoke loss isolates one unit into autonomous operation; anchor loss reverts all spokes to autonomy
ClusterOverlapping coverage, with or without transport linksDense sites, staged deployments, disaster surgesDegrades continuously; any subset of units federates among itself

Multi-site fleets federate one level up through the management plane, which provides fleet-wide views and policy without ever sitting in the data or coordination path. The management plane can see every federation and is required by none of them.

Architecture

Small, slow, mergeable state.

That is what permits the no-controller rule. Convergence is eventual and bounded, and correctness never depends on it.

  • Coordination state is small, slow, and mergeable: signed, append-only or last-writer-wins entries over any available inter-unit path.
  • The transport tier is preferred, the access tiers are usable, and the LTE-M management channel is the path of last resort for state too important to wait, such as revocations.
  • Every coordinated decision is also independently lawful: SAS, PAWS, and AFC obligations are satisfied by a unit's own grants regardless of federation state.
  • The worst consequence of stale peer state is transient inefficiency, never a compliance violation.
  • Real-time behaviors bypass replication entirely: TDD phase rides GNSS, safety signaling rides the NR+ mesh, and handover context passes directly between the two units involved.

Partition behavior

Splitting is a supported state.

Partition behavior follows from the same design. Nothing about a severed link is exceptional.

  • A federation that splits continues as two federations.
  • A unit that loses every peer continues as a complete ORB.
  • Every rejoin is a merge of append-only state rather than a negotiation.
  • No state in the platform stops service when synchronization is lost, which is the formal version of the doctrine that federation is additive.

The operator's view

Four sentences.

Commissioning discipline is unchanged from a single unit: place it, power it, aim the dish if there is one, and the unit finds its site, its siblings, and its role.

Coverage

Coverage tiles instead of colliding

Every added unit extends the site rather than fighting the last one. Adding a unit adds capacity, which is the opposite of what uncoordinated equipment does.

Devices

Devices roam without noticing

A machine, a phone, or a camera works identically across the whole deployment, at vehicle speed, across as many units as the ground takes.

Economics

The WAN is shared

One fiber handoff or one LEO terminal serves the corridor. WAN pooling is the largest single economic effect of federating a deployment.

Operations

The site remains one thing

One ledger, one tenant list, one management view, however many units it takes to cover the ground.

Conformance

Verified as a member, and as the last unit standing.

The federation profile extends the ORB-1 conformance suite. A unit claiming ORB-F1 conformance passes the suite in both roles.

  • Discovery and mutual authentication over each of the three channels independently.
  • Interlocking spectrum plans on CBRS, TVWS, and Wi-Fi, with measured absence of inter-unit self-interference.
  • Session continuity for a CPE transiting at least three units at vehicle speed.
  • WAN pooling with failover across units.
  • Ledger convergence after a forced partition and rejoin, with a whole-site audit query answered correctly from each unit.
  • Slice consistency across units, including accounting aggregation.
  • Chain-split behavior in which both halves of a severed chain independently pass the single-federation cases.

Cover ground that needs more than one unit.

Tell us the corridor, the pits, or the county. We will lay out the chain, the transport hops, and the WAN handoffs, or send the federation specification for engineering review.