Operating hardware in space is one of engineering’s greatest challenges. Extreme distances, harsh environmental conditions, and the inability to perform physical repairs require spacecraft to operate reliably for years, often well beyond their original design life. Few examples illustrate this better than Voyager 1 and Voyager 2. Launched in the late 1970s with an expected mission lifetime of just five years, the probes continue to operate nearly 50 years later in interstellar space, billions of kilometres from Earth, where even a simple transmission takes roughly a day to reach mission control.

What made this possible? It involved the ingenuity of several NASA teams that carefully developed and deployed software updates to help the spacecraft overcome a host of complex challenges. Over the last five decades, these updates have enabled fixes ranging from bypassing dead hardware memory chips and rewriting power management systems to mitigating thruster clogging.
The same principle underpins today’s software-defined architectures. To test whether the updates would deliver the intended results, the teams relied on simulation. By understanding how the spacecraft would behave under real-world conditions and respond to proposed changes, engineers could make informed decisions and compare various “what-if” scenarios. If software kept Voyager operating for decades, what happens when satellites are designed from the outset to be software-driven? As the space industry evolves with the rapid growth of Low Earth orbit (LEO) satellite constellations, commercial space missions, and increasing demand for real-time connectivity, satellite manufacturers are moving beyond traditional hardware-centric architectures. Software-defined capabilities enable satellites to be reconfigured, upgraded, and optimized throughout their operational lifecycle, helping organizations respond more quickly to changing mission requirements while reducing costs and improving performance.
Designing Flexible Satellite Systems
However, flexibility introduces engineering complexity. While the benefits of software-defined capabilities are promising, new challenges can arise during the prototyping and testing phases. Specifically, how can companies ensure the updates will work as expected when deployed in the real world? Considerations like microgravity, absence of viscous damping, large temperature swings, and ionizing radiation affect the satellite’s performance and must be understood prior to deployment. Because it is impossible to recreate the harsh space environment on Earth, using high-fidelity, multiphysics simulation is critical to understanding how to design, develop, and operate these satellites.
Multiphysics simulation can help engineers by defining the mission requirements and operational scenarios for the satellite, then identifying the dynamic capabilities needed at both the satellite and subsystem levels, including propulsion, sensors, communications, and other key systems. Engineers can use mission simulation software to create a virtual model of the satellite mission and test how the satellite would perform in differing operating conditions. This could include designing the insertion into the right orbit as well as attitude and orbital manoeuvres once in operation.
This mission model can be integrated in a System Architecture Framework using a Model-Based System Engineering (MBSE) approach to model potential configurations that can meet mission success objectives. In addition, the requirements and the constraints of the satellite can be tracked and evaluated with full traceability from the why (end objective) to the what (functional need) to the how (system configuration).
Engineers can then evaluate thousands of design alternatives, balancing performance, cost, coverage, power consumption, and constellation size before committing to a specific system configuration. In space applications, where systems operate in extreme environments and cannot be physically repaired once deployed, reliability, fault tolerance, and safe behavior are also essential. Subsystems such as Guidance, Navigation and Control (GNC), propulsion management, communication, flight software, and fault monitoring must be developed through a disciplined safety process.
Ensuring Reliability and Mission Success
This is where functional safety becomes important: it helps engineers identify hazards, analyze risks, define safety goals, derive safety requirements, and introduce mechanisms such as redundancy, diagnostics, fault detection, and safe-state behavior. Safety software tools need to be used to carry out studies for hazard analysis, risk assessment, safety requirement traceability, and failure mode evaluation early in the lifecycle. Historical mission failures show why these matter. The Mars Polar Lander failed in 1999 when transient signals from landing leg deployment were interpreted as touchdown, causing premature engine shutdown. Launch vehicle Ariane 5 Flight 501 failed in 1996 due to reused Ariane 4 software that encountered an unhandled arithmetic overflow in a different operating environment. This phenomenon lead to vehicle destruction about 37 seconds after liftoff. Such examples highlight the importance of safe software development practices, including requirements traceability, model-based design, formal verification, automatic code generation, rigorous testing, and validation under abnormal conditions.

Embedded software digital environments are then needed to help engineers develop deterministic, safety-certified software with predictable behaviour. Together, functional safety and robust software engineering reduce the likelihood of mission failure and improve confidence in complex space systems.
Unlocking New Capabilities through Software
One example of a software-defined subsystem in satellites is the software-defined radio (SDR) coupled with a digital beamforming (DBF) antenna, which provides great flexibility to communication systems. Take an antenna for a LEO satellite moving at 27,000 km/h. DBF allows the satellite’s beams to electronically lock onto a ground station or a moving ship, tracking it across the planet’s surface without a single moving mechanical part.
Software can instantly morph a single, broad beam covering a whole country into a grid of 50 dense, high-powered “spot beams” targeting specific cities. The main advantages of SDR for satellites center on breaking the physical limitations of hardware. By moving radio functions like modulation, filtering, and coding from fixed analog circuits into digital software, operators gain unprecedented agility. It also plays a critical role thwarting malicious interventions to avoid communication being compromised.
It is critical to simulate and verify the various functionalities and use cases of these systems to ensure they meet mission requirements, from precise pointing accuracy to high-fidelity, uninterrupted communications. Software-defined architectures are also enabling RF systems to perform both communications and radar functions with minimal hardware modifications. This convergence helps reduce the number of dedicated subsystems onboard a satellite, an important advantage in space where size, weight, and power constraints are critical. To support this level of adaptability, however, the underlying hardware must be designed to flexibly accommodate multiple operational modes and mission requirements.
Validating the Software Defined Capabilities
Before any software-defined capability is deployed, it must be extensively validated. During the early design phase, model-in-the-loop (MIL) testing enables engineers to evaluate software strategies and verify that required functionality can be achieved safely and reliably. As development progresses, software-in-the-loop (SIL) and hardware-in-the-loop (HIL) testing become increasingly important, combining physical hardware with high-fidelity physics-based models to evaluate real-world performance before launch. For example, a satellite communication system can be tested on the ground using simulated RF environments to verify that both the hardware and software perform as intended under a wide range of operational conditions.
Software-defined systems are transforming satellite design by enabling spacecraft to adapt to evolving mission requirements long after they have been deployed. Rather than being constrained by fixed hardware functionality, satellites can incorporate new capabilities, optimize performance, and respond to emerging needs through software updates across their operational lifetimes. As sensors, processors, and communications technologies continue to advance, decoupling software from hardware allows engineers to introduce enhancements in a more agile, modular, and scalable manner. Throughout this lifecycle, high-fidelity simulation serves as a foundational technology, helping engineers conceive, design, validate, and operate increasingly flexible and resilient satellite systems.





