Downlink Duty-Cycle Ceiling
also called Airtime Budget Ceiling, Gateway Transmit Budget
The regulatory cap on how long a radio may transmit in a given period - which bounds how fast commands and configuration can reach a fleet, and makes a synchronous fleet-wide instruction physically impossible.
An operations lead asks for a button that pushes a new setpoint to 40,000 sub-GHz sensors. The platform can compute the change in a millisecond. The radio cannot send it, because the limit is legal rather than technical. In the European 868 MHz band, ETSI EN 300 220-2 (V3.2.1, 2018) caps a transmitter's duty cycle per sub-band - commonly 0.1%, 1% or 10% depending on the sub-band - and 1% means 36 seconds of transmit time per hour, around 864 seconds a day, for the gateway as much as for the device.
Divide the fleet by that budget and the answer is uncomfortable. At roughly 150 ms of airtime per downlink frame, one gateway can send about 240 frames an hour. Sixty gateways give 14,400. A one-frame-per-device campaign with retries needs around 56,000, which is four hours of perfect use of the entire budget, and the budget also has to carry join accepts and acknowledgements for normal traffic. Plan on half a day to several days, not a progress bar.
Why it matters
It converts a product requirement into a physics question. "Remote stop", "instant configuration" and "confirm every device has the new value within the hour" are not slow on this link; they are unavailable. A team that discovers this after launch has usually built a command-and-control platform whose central abstraction - the synchronous command - cannot be delivered.
The ceiling also explains why well-designed low-power fleets are pull-shaped. A device that fetches desired state on its own uplink schedule costs one short downlink at a moment the radio is already awake, which is the cheapest possible use of a budget measured in seconds per hour.
Implementation patterns
- Reconcile, do not command. Store desired state per device with a version, let the device report what it has applied, and send deltas in the receive window that follows its next uplink.
- Budget accounting as a first-class metric. Track airtime consumed per gateway per sub-band against the limit, and alert at 70%. Without it, a campaign silently starves routine traffic including join accepts, and the symptom is devices that cannot rejoin.
- Spend the budget on the smallest payload that works. Frame sizes are discrete, so a 24-byte delta may fit where a 60-byte full configuration needs an extra frame - a 2x change in campaign duration from a schema decision.
- Choose the fastest data rate the link budget allows. Airtime varies by roughly an order of magnitude across spreading factors, which dominates every other lever.
- Cohort and pace campaigns deliberately, reserving a stated fraction of the budget - 30% is a reasonable default - so normal operation survives the rollout.
- Fail safe locally. Any behaviour that must happen quickly in the physical world has to be a decision the device makes from its own sensing, with a default it falls back to when it has heard nothing for a defined period.
Industry example
LoRaWAN's Class A design is a direct expression of the ceiling: a device transmits when it chooses, and the network may reply only in the two short receive windows that follow, so downlink capacity is a function of uplink frequency rather than of network capacity. The Things Network's documentation converts the ETSI percentages into the daily airtime figures above, and network operators commonly apply a fair-use policy stricter than the regulation - a published figure of around 30 seconds of uplink airtime per device per day is typical of community networks. Regulations differ by region: the United States 915 MHz band substitutes dwell time and frequency-hopping rules for a duty cycle, so the same product has different command economics on two continents.
Failure scenarios
- A fleet campaign starves joins. The config push consumes the gateway's budget, join accepts cannot be sent, and devices that reboot during the window cannot come back. The outage looks like a device fault and is a scheduling fault.
- A command queue with no expiry. Instructions issued hours ago are finally delivered to a device whose situation has changed, and it acts on them. Every queued command needs a validity window.
- Retry amplification. Unacknowledged downlinks are retried, retries consume the budget that acknowledgement needed, and the campaign converges more slowly the harder it is pushed.
- A dashboard that shows percent-sent. Operators read it as percent-applied, and a regulator or a customer is later told the fleet was updated when a third of it never heard the message.
Trade-offs
Accepting the ceiling buys a decade of battery life, licence-free spectrum and gateway costs an order of magnitude below cellular. It pays with command latency measured in hours, no reliable interactive control, and a hard cap on bidirectional features.
Escaping it means a different radio. Cellular LPWAN removes the duty cycle and replaces it with a per-device data plan, a power budget that no longer supports years on a primary cell for chatty designs, and a platform whose constraint becomes connection count rather than airtime.
When not to use it
Do not carry duty-cycle thinking into a cellular, Wi-Fi or wired fleet as though it were a law of nature. There the binding constraints are connection count, reconnection storms and data-plan cost, and a push-based command path is perfectly reasonable. The pull-shaped instinct usually still wins, but for different reasons, and sizing it with airtime arithmetic will produce a design that is cautious in the wrong places. Equally, if a use case genuinely needs sub-second actuation, do not design around the ceiling - choose a different link, or put the decision on the device.
Interview question
Q: Operations wants a button that pushes a configuration change to 40,000 sub-GHz devices and reports when every unit has it. What do you tell them, and what do you build instead?
What a strong answer covers: the duty-cycle arithmetic and the resulting multi-hour to multi-day figure; that Class A downlink is bounded by uplink frequency, so per-device latency is the reporting interval; a reconciliation design with versioned desired state, deltas and device-reported generations; a reserved fraction of airtime for routine traffic; version-distribution reporting over days instead of a progress bar; and the statement that anything needing to happen in seconds must be a local decision with a safe default.
Quick check
Quiz: A 1% duty cycle applies to a gateway serving 600 devices. How much transmit time does that allow per hour, and what does it rule out? About 36 seconds per hour per sub-band, which rules out any synchronous fleet-wide command and forces pull-based reconciliation.
Flashcard: Why does adding gateways not fix slow fleet-wide configuration? Each gateway gets its own airtime budget, so capacity rises linearly while the campaign still competes with joins and acknowledgements - and in Class A the per-device latency is set by its uplink interval, which no gateway count changes.