Two Paths to Reliable Space Computing

Two Paths to Reliable Space Computing

One approach relies on BAE Systems’ RAD750 family: expensive radiation-hardened processors with a long record of service on deep-space missions. The other uses commercial processors backed by redundant computers and fault-tolerant software, as demonstrated by SpaceX.

The question is not simply which technology is more advanced. These approaches reflect two different ways of paying for reliability.

1. Path A: Built for Missions Beyond Repair

The RAD750 family’s flight history reads like a timeline of planetary exploration:

  • 2005: Deep Impact, XSS-11 and Mars Reconnaissance Orbiter were among the first missions to fly RAD750 processors.
  • 2011: Curiosity launched toward Mars.
  • 2016: Juno arrived at Jupiter, where its protected electronics supported operations in a demanding radiation environment well beyond the original mission timeline.
  • 2021: Perseverance landed on Mars.
  • 2024: Europa Clipper launched with a RAD750 V3 single-board flight computer, described in a February 2025 mission paper.

The economic premise is straightforward: missions can cost hundreds of millions or billions of dollars, and their hardware cannot ordinarily be repaired once deployed. When the value of the mission far exceeds the cost of its flight computer, paying a substantial premium for radiation-qualified electronics can be justified.

Prices frequently quoted for RAD750-based hardware run into hundreds of thousands of dollars. However, those figures should not be treated as a universal price for a bare processor: the configuration, board, qualification requirements and procurement terms all matter.

This approach emphasizes reducing the likelihood of hardware failure before launch. It still relies on shielding, redundant systems, error correction and recovery software. Radiation hardening does not eliminate every possible fault.

2. Path B: SpaceX’s Redundancy Philosophy

SpaceX’s approach to flight computing places greater emphasis on maintaining reliable operation through redundant hardware and software.

Triple redundancy: Public descriptions of Falcon 9’s flight computers identify three independent computing channels, or “flight strings,” using commercial dual-core x86 processors. Within each string, duplicate computations can be checked for consistency.

The actor–judge approach: Computing channels generate commands, while downstream control logic evaluates their outputs and determines which commands to follow. The purpose is to prevent a faulty channel from taking control of the vehicle. Describing this as requiring unanimous agreement in every situation would miss the central point of fault tolerance: the system must also function when a channel disagrees or becomes unavailable.

Recovery after an upset: A radiation-induced bit flip can corrupt data or disrupt execution. Redundant channels allow the system to detect inconsistencies and continue operating while an affected computer is isolated or recovered. SpaceX has publicly described a Dragon mission in which a radiation event temporarily disabled one flight computer while the remaining computers maintained safe operation.

A shared engineering philosophy: Redundancy and fault tolerance underpin SpaceX’s launch vehicles and spacecraft, although their specific hardware and implementations need not be identical. Crew Dragon’s touchscreen interface uses Chromium as a rendering engine, with the flight software and fault-tolerance functions outside that display boundary. Physical controls remain available for emergency commands.

The economic attraction is clear: commercial processors offer much more computing performance at a much lower component price, while familiar development tools can support faster software iteration.

Starlink’s large fleet also provides extensive operational experience with electronics in low Earth orbit. However, fleet operation alone does not establish the radiation tolerance of every commercial component or prove its suitability for a different mission.

3. Two Cost Models, Five Dimensions

Dimension Path A: Radiation-Hardened Hardware Path B: COTS with System Redundancy
Processor and computing hardware cost High; frequently quoted RAD750-based hardware prices reach hundreds of thousands of dollars, depending on configuration Commercial processors may cost hundreds of dollars, but redundant flight systems also require custom boards, testing and software
Performance Legacy RAD750 processors operate at around 200 MHz; newer radiation-hardened designs offer substantially greater capability Access to newer commercial architectures and higher performance, subject to qualification
Development cycle Often measured in years, with qualification and mission assurance shaping the schedule Software can evolve rapidly, although flight hardware validation remains demanding
Suitable environments Often favored for harsh radiation environments and long-duration missions, including GEO and deep space Attractive for short-duration flight and selected LEO missions when radiation risks are adequately controlled
Reliability emphasis Reduce susceptibility to faults and permanent damage Detect, isolate and recover from faults while maintaining system operation

The central distinction is the cost and consequence of failure.

An unrecoverable failure on a distant spacecraft can end the mission. That makes component qualification and resistance to radiation especially valuable.

A redundant system may be able to tolerate a temporary computer fault without interrupting its mission. A constellation may also accommodate the loss and eventual replacement of individual satellites.

But these are different levels of resilience. A computer restart is not a remedy for permanent radiation damage, and replacing a satellite does not restore a service immediately.

4. Path B Has Limits

Falcon 9’s experience must be understood within its operating conditions. Its powered ascent lasts minutes, giving its flight computers far less time to accumulate radiation exposure than electronics on a spacecraft operating for years.

Short exposure does not eliminate single-event effects. It does, however, change the balance between transient faults and cumulative damage.

An architecture suitable for launch cannot simply be transferred unchanged to Jupiter. Commercial processors would require a mission-specific assessment of radiation susceptibility, shielding, component selection and fault protection. Redundancy alone cannot compensate for multiple channels suffering the same destructive failure.

NASA’s High Performance Spaceflight Computing (HPSC) project illustrates the continuing importance of radiation-hardened processing. It combines a modern multicore architecture with radiation hardening and fault-tolerance features, targeting roughly two orders of magnitude more computing capability than established spaceflight processors.

Government missions have therefore not abandoned hardened hardware. They are combining it with more capable architectures and recovery mechanisms.

Path A is evolving as well. Radiation hardening by design (RHBD) can enable radiation-resistant circuits to be implemented using commercial semiconductor manufacturing processes, potentially improving access and cost.

Companies such as Apogee Semiconductor target the space between conventional commercial electronics and expensive, highly qualified space components. The two approaches increasingly meet in hybrid designs.

5. Three Lessons

Reliability Can Be Distributed Across the System

SpaceX’s contribution is not simply the use of inexpensive processors. It is the integration of those processors into an architecture designed to detect faults and preserve operation.

Reliability comes from the interaction of hardware, software, redundancy, testing and operating procedures. It cannot be assigned to the processor alone.

At the constellation level, the Space Development Agency’s emphasis on proliferated architectures reflects a related principle: mission resilience can also depend on multiple spacecraft and distributed capabilities.

The Mission Determines the Approach

LEO constellations, GEO satellites and deep-space probes face different radiation environments, operating lifetimes and consequences of failure.

They therefore require different trade-offs. Neither radiation-hardened hardware nor commercial processors with redundancy provide a universal answer.

The relevant question is whether the complete system meets the mission’s reliability requirements at an acceptable cost.

Implications for China’s Space Industry

For China’s growing satellite constellations, a hybrid approach deserves consideration: radiation-tolerant commercial processing combined with Chinese-developed space-qualified FPGAs, radiation-hardened supervisory devices and system-level fault protection.

Such combinations could balance computing capability, cost and supply-chain security. Their suitability must still be demonstrated through component testing and mission-specific analysis.

A Balanced View of the Risks

Much of the operational experience supporting commercial electronics in space comes from LEO missions with limited lifetimes. Extending satellite life or changing orbital altitude and inclination can alter both cumulative radiation exposure and the frequency of single-event effects.

Solar activity adds another variable, but the relationship is not as simple as “solar minimum is safe, solar maximum is dangerous.” Solar energetic particle events and galactic cosmic rays behave differently across the solar cycle.

Large constellations can also face correlated failures if many satellites share the same vulnerable component or design. Redundancy within a spacecraft does not automatically protect an entire fleet against a common weakness.

Long-term confidence requires radiation testing, failure analysis and operational evidence across changing environmental conditions. Fleet size is valuable evidence, but it is not a substitute for those assessments.

Conclusion

The two approaches place their spending in different parts of the reliability equation: Path A pays more to reduce hardware susceptibility; Path B invests in detecting faults and recovering from them.

Reliable space computing increasingly combines both.

For satellite developers, these trade-offs make it essential to match hardware and testing requirements to the mission’s orbit, lifetime and budget. Drawing on China’s growing satellite manufacturing capacity, STARPATH GLOBAL helps international customers access competitively priced satellite platforms, payloads and assembly, integration and test (AIT) equipment. To explore options for your mission, discuss your requirements with STARPATH GLOBAL and identify a solution that balances capability, cost and mission needs.

References to third-party companies, products, services, or projects are for informational purposes only and do not imply endorsement, affiliation, or partnership unless explicitly stated.