CCSDS Space Data Link Security
CCSDS-355.0-S02

Authentication

Description

Assurance that a received data-link frame came from the legitimate peer and was not altered on the way, produced by attaching a message authentication code computed over the frame. A monotonic sequence number carried under the same protection lets the receiver detect and reject replayed or reordered frames, which is what defends a command link against capture-and-resend.

Mapped SPARTA techniques

8 techniques

  • EX-0001ReplayST0004
    addresses
    moderate

    SDLS anti-replay interdicts replay on the space link and SDLS-protected crosslinks, but the technique also covers internal-bus replay (SpaceWire, MIL-STD-1553) outside SDLS scope, so it governs the link portion.

  • EX-0001.01Command PacketsST0004
    mitigates
    moderate

    SDLS anti-replay, monotonic sequence numbering bound under the frame MAC, rejects a re-sent telecommand whose counter is below the receiver's high-water mark; the adversary cannot refresh the counter without the key, so the replayed command is interdicted.

  • EXF-0001ReplayST0008
    addresses
    low

    SDLS anti-replay rejects the replayed commands that trigger a data dump, but the technique's dominant scope is the downlink capture itself, which is owned by encryption, so authentication addresses only the enabling trigger.

  • SDLS crosslink authentication limits which peers a vehicle trusts, but a compromised neighbor holding valid keys produces authentic frames SDLS cannot reject, so it governs the trust boundary without interdicting the compromised-peer vector.

  • IA-0008Rogue External EntityST0003
    addresses
    moderate

    SDLS authentication rejects forged command frames from an unkeyed rogue transmitter, but this umbrella technique also spans jamming, relay of legitimately-keyed traffic, and other foothold vectors SDLS does not interdict, so it governs the command-injection sub-vector.

  • IA-0008.01Rogue Ground StationST0003
    mitigates
    moderate

    A rogue ground station transmitting mission-compatible signals cannot produce a valid frame MAC without the shared keys, so its telecommands fail SDLS authentication and are rejected, interdicting unauthorized commanding over the space-ground link.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    moderate

    Where a crosslink runs SDLS, a rogue spacecraft without valid keys has its frames rejected; but coverage is conditional on SDLS being present on the crosslink and does not stop the proximity, RF-geometry, and relay vectors, so it governs rather than fully interdicts.

  • SDLS authentication rejects forged crosslink messages that merely appear to come from a trusted neighbor, but lateral movement through a genuinely compromised, validly-keyed vehicle is not stopped, so it governs rather than interdicts.

Cite as SafeMode Space, ccsds-sdls CCSDS-355.0-S02.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.