The Single-Satellite Coverage Problem
A single low-Earth-orbit satellite at 500 to 600 km altitude has a maximum visible horizon distance from any ground point of roughly 2,500 km. A pass over a city at that altitude lasts 8 to 15 minutes, depending on whether the pass is directly overhead or at a lower elevation angle. For a satellite optimized for QKD, the usable window where link quality is sufficient for secure key generation is typically the middle 5 to 10 minutes of that pass, when the elevation angle is highest and atmospheric path length is shortest.
Over a 24-hour period, a single LEO satellite makes 14 to 16 orbits of Earth, but the ground track shifts westward with each orbit (approximately 24 degrees per orbit for a 600 km altitude). For a ground station at a given latitude, the satellite passes overhead between 1 and 3 times per day depending on the orbital inclination. Useful QKD windows: perhaps 10 to 30 minutes total per day. That is a sharply limited key generation capacity window for any ground station pair.
Key buffer management can extend the coverage from a single satellite by pre-generating and storing key material during pass windows for use during the much longer inter-pass periods. But the buffer capacity is bounded by the key generation rate during passes (which is itself bounded by link quality) and the key consumption rate of the applications being served. For high-frequency key refresh requirements, a single satellite per orbital plane cannot provide the generation rate needed to sustain continuous operations.
How Constellations Change the Math
A constellation of satellites in multiple orbital planes changes the coverage geometry fundamentally. Consider a Walker Delta constellation, which is the standard architecture for LEO broadband constellations: satellites are distributed in multiple orbital planes, each plane containing multiple satellites spaced evenly. For QKD applications, the key property is the revisit time: the interval between successive visible passes at any given ground station.
With a 6-plane constellation of 6 satellites per plane (36 total) at 60-degree inclination, the revisit interval at temperate latitudes drops to roughly 30 to 45 minutes between usable passes. With a 12-plane constellation of 8 satellites per plane (96 total), revisit intervals drop to 10 to 20 minutes. At that revisit rate, a ground station can maintain key buffers continuously under most atmospheric conditions: the inter-pass buffer drawdown period is short enough that reasonable buffer sizes can bridge it.
This changes the operational model from "QKD generates key material during infrequent pass windows, stored in large buffers" to "QKD is a near-continuous key source, with buffers sized for short bridge intervals." The security architecture implications of these two models are different: the first requires large, carefully managed key stores with extended key lifetimes; the second allows shorter key lifetimes and more frequent key refresh, which is the more desirable security property.
Inter-Satellite Links and Trusted Relay
A constellation provides coverage continuity, but it introduces a new architectural question: how does key material generated at one satellite pass get reconciled with key material from a later satellite pass at the same or different ground station pair?
For QKD relay across geographic distances using a constellation, the most discussed approach is the trusted node relay: a satellite generates a key with ground station A, generates a correlated key with ground station B during the same or a near-simultaneous pass, and the satellite itself serves as the trusted relay that holds both keys long enough to XOR them into a combined key for ground-to-ground relay. This is the approach used in the Micius satellite experiments conducted by the Chinese QUESS program, which achieved intercontinental QKD relay.
The trusted relay approach has a security limitation that is worth stating clearly: the satellite itself is a trusted node. If the satellite is compromised, the key material it relayed is exposed. This is a different security property from the ground-to-ground QKD ideal where the relay is fully untrusted. For satellite QKD relay constellations, the security assumption is that the satellites themselves are trustworthy, typically because they are under the operational control of the network operator or a trusted national agency.
Entanglement distribution, the alternative that eliminates the trusted relay assumption, is the subject of active research. In E91-style protocols, the satellite distributes entangled photon pairs to two ground stations simultaneously, and the key is derived from measurement correlations without ever existing on the satellite in extractable form. This approach is more technically demanding and requires more precise optical alignment than prepare-and-measure BB84-based approaches, but it provides a stronger security guarantee. Current satellite QKD deployments are mostly prepare-and-measure; entanglement distribution at global scale is an active research and engineering challenge.
Coverage Geometry for South and Southeast Asia
For a regional constellation serving South and Southeast Asia at latitudes between 5 and 35 degrees north, orbital inclinations in the 45 to 55 degree range provide good coverage at those latitudes with manageable satellite counts. A 6-plane constellation at 50 degrees inclination provides near-continuous coverage (sub-60-minute revisit intervals) across the region with 30 to 40 satellites, depending on altitude.
The atmospheric environment at tropical latitudes is relevant. Monsoon cloud cover, tropical convection, and high humidity all reduce free-space optical QKD link quality. Ground station placement is particularly important in tropical regions: stations near the coasts face higher humidity and cloud frequency than stations on elevated terrain or in drier inland locations. A multi-station network for a city like Bengaluru or Colombo benefits from geographic diversity of ground stations to improve the statistical likelihood that at least one station has usable link conditions during each satellite pass.
This is a pattern we have worked through in our Bengaluru deployment planning: placing ground stations at multiple sites across the metropolitan area, with different atmospheric exposure profiles, so that cloud cover that degrades one station's link often leaves others usable in the same time window. The adaptive routing layer then allocates key generation capacity to the stations with the best current link quality rather than treating all stations as interchangeable.
Network Architecture at Scale
A constellation serving multiple cities creates a network topology that looks more like a mesh of key distribution points than a simple hub-and-spoke. Each ground station pair that shares a satellite pass can establish shared key material. The number of node pairs that can be simultaneously served in a single pass window is limited by the satellite's optical aperture and key generation capacity: current satellite QKD prototypes typically serve one or two ground station pairs per pass.
At the key management layer, the network architecture needs to handle key routing: getting key material from the node where it was generated to the application endpoint that needs it. In a city-scale deployment where ground stations and application servers are co-located at data centers, this is straightforward. In a national deployment where ground stations are at geographic points that do not coincide with the major network endpoints, there is an additional distribution hop: key material moves from the ground station to the application endpoint via a classical encrypted channel. The security of that hop matters: it should use ML-KEM or existing quantum-safe key exchange for the bootstrap, and ideally be short enough in hop count and distance that it does not introduce significant latency.
The full picture of a constellation-based national QKD network: satellites generate key material in pass windows, deliver it to ground stations, the ground stations forward it to key management servers, the routing layer distributes it to application endpoints on demand. Each step in this chain has latency and availability characteristics that the network design must account for. We are not arguing that this architecture is simple to deploy. It is not. It is the architecture that provides continuous QKD coverage at national scale, which is what the threat model demands for high-sensitivity communications.