Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
26 techniques
Cryptography and key management mandates that the spacecraft cannot disable cryptography on TT&C — directly defeating crypto-mode obfuscation that selects 'crypto off' or null cipher profiles.
Cryptography and key management denies the keys needed to forge cryptographically-authenticated traffic, but DE-0004 masquerades across multiple layers: RF-fingerprint imitation (Doppler, polarization, timing, and framing), insider-derived credentials that already pass authentication, and metadata or identifier spoofing for false attribution. Crypto interdicts one vector, not the dominant multi-layer masquerade scope, so the relationship is addresses.
Cryptography and key management — counter rotation, anti-replay windows, and authenticated encryption — denies replayed traffic acceptance.
Cryptography and key management — anti-replay counters and key rotation — turns previously-captured commands into stale, unaccepted traffic.
Bus-level authenticated encryption raises the cost of bus replay but does not interdict EX-0001.02's dominant scope. Many bus subsystems act on the latest message or on message rate rather than on uniqueness, and time-triggered buses resist anti-replay, so replayed well-formed frames can still drive resource exhaustion and determinism abuse. Cryptography and key management is in-domain but is not the operative interdiction of this technique, so at the Cryptography and Crypto Key Management control the relationship is addresses, not mitigates.
Cryptography and key management mandates that the spacecraft cannot disable cryptography on the TT&C link (no crypto-bypass mode), the named defense against EX-0006.
Cryptography and key management governs the cryptographic foundation relevant to replay defense, but the generic rules excerpt does not itself provide the active anti-replay mechanism.
Use of only approved cryptographic algorithms governs the cryptographic domain that timing attacks (EXF-0002.04) target; the excerpt does not itself assert constant-time/timing-resistant implementation, so the relationship is relevance-level.
Cryptography and key management with authenticated encryption renders intercepted bitstreams as ciphertext to the adversary.
Cryptography and key management on uplink command sessions with anti-replay counters renders intercepted uplink content non-readable and time-stale.
Cryptography and key management mandates uplink/downlink encryption to prevent eavesdropping; unprotected downlink content is the precise EXF-0003.02 target.
Cryptography and key management for code-signing keys denies the stolen-signing-key vector, but IA-0001.02's dominant scope is supply-chain manipulation across the pipeline: altering source before build, version rollback to re-introduce known weaknesses, and update-metadata subversion, all of which yield artifacts that are then legitimately signed. Crypto covers one non-dominant vector, so the relationship is addresses.
Cryptography and key management explicitly mandates ISL encryption — the named defense against compromised-neighbor crosslink injection.
Cryptography on uplink/downlink is relevant to protecting the backup receive path, but the eavesdropping-prevention excerpt does not actively defend against command exploitation of the backup receiver.
Key-update-frequency and key-length governance is relevant to limiting the value of keys exposed via emanations, but does not actively defend against the side-channel extraction itself.
Cryptography and key management on signing keys denies forging an update package without the key, but IA-0007.01's dominant scope is pre-signing pipeline compromise: substituting or modifying artifacts at source repositories, build and packaging steps, and staging areas, which are then signed and promoted through normal procedures. Crypto does not reach the dominant pre-signing scope, so the relationship is addresses.
Cryptography and key management restricts encryption keys to authorised endpoints, so a rogue ground station cannot issue accepted commands without compromised keys.
Cryptography and key management explicitly mandates ISL encryption — the canonical defence against constellation-hopping via crosslink.
Cryptography and key management governs the uplink-key lifecycle (handling outside on-board software, key restrictions, rotation cadence, anomaly review) that PER-0004 attempts to subvert.
Cryptography and key management denies adversary-built ground equipment the keys to issue accepted commands, but RD-0001.01's defining act is the acquisition and assembly of an RF ground stack, which crypto does not interdict; the equipment retains passive-collection and active-probing utility. Crypto blunts the downstream commanding use rather than the technique's defining vector, so the relationship is addresses.
Cryptography and key management interdicts a partial set of RD-0003.02's key-acquisition routes (onboard key handling and the telecommand-read restriction) and limits the lifetime of obtained keys through rotation, but the dominant acquisition routes are ground-side and non-crypto: compromised ground systems and laptops, misconfigured repositories, memory and core dumps, and contractor or human channels. Crypto covers the minority of routes, so the relationship is addresses.
Cryptography and key management directly governs the algorithms, key types, lifecycles, counters, and anti-replay rules that REC-0001.03 attempts to enumerate.
Cryptography and key management governs the authentication scheme (keys, counters, anti-replay windows) REC-0003.02 studies and reduces the value of what is learned, but it does not actively prevent the reconnaissance itself, so addresses rather than mitigates.
Cryptography and key management protects TT&C keys, link-encryption keys, and counters — exactly the credential families REC-0003.04 targets in space and ground.
Cryptography and key management provides the encryption that turns wideband recordings into ciphertext for the eavesdropping adversary.
Encryption on the uplink/downlink to prevent eavesdropping is mandated under cryptography and key management.