Deterministic Enforcement of Orbit-Derived Maintenance Exclusion Windows for Vulnerability Remediation in a Simulated Satellite Ground Segment
GwangHyun Ahn, JaePil Youn, GeunSoo Son, Dongkyoo ShinSatellite ground segments run conventional, patchable software, but disruptive maintenance must be coordinated with recurring orbital visibility. We formulate vulnerability remediation as a constrained action-and-timing problem in which SGP4-propagated visibility intervals and a pre-contact guard band define protected intervals, and a deterministic gate admits or rejects each action over a recovery-aware execution envelope containing the action, its verification, and any rollback. The enforcement property is stated as a proved conditional invariant, and the experiments test conformance to it rather than operational safety. The evaluation is a public-feed-driven discrete-event simulation over 48 CISA KEV vulnerabilities, 12 propagated passes in a 24 h horizon, and MITRE D3FEND countermeasures. Across 30 paired runs, policies that did not enforce the protected intervals violated them in every run, whereas enforcing policies recorded none, with no violation in any of 270 gated runs (cluster-level 95% upper bound of 0.011 per run). Violations first appear at a schedule displacement of 120 s, about 900 km of along-track error, so schedule integrity rather than decision sophistication carries the property. Mission weighting added nothing beyond contact avoidance, which follows analytically from the hard exclusion and reverses under partial protection. Cumulative exposure is conditional on the retry budget of the reported runs, a dependence quantified analytically from the verification model rather than measured, and asset attribution rests on a simulation reference mapping rather than on adjudicated applicability.