CCSDS Space Data Link Security
CCSDS-355.0-S03

Encryption

Description

Concealment of the contents of a data-link frame so that someone intercepting the radio signal cannot read the command or telemetry it carries. Confidentiality is applied at the link layer to the frame data using an approved symmetric cipher, addressing passive eavesdropping on the downlink or uplink rather than tampering.

Mapped SPARTA techniques

7 techniques

  • The CCSDS 352.0 cryptographic profile mandates strong algorithms and defines no null-cipher or downgrade fallback, which resists the force-fallback and downgrade sub-vector; but an adversary with the privilege to toggle configuration or patch flight software can still disable protection, so it governs by design rather than interdicting.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate

    SDLS encryption interdicts capture of mission traffic over the space link, but the technique also spans tapped ground LAN and WAN and baseband interfaces outside SDLS scope, so it governs the link portion rather than the whole.

  • EXF-0003.01Uplink ExfiltrationST0008
    mitigates
    moderate

    SDLS uplink encryption renders tapped telecommand frames unreadable, directly interdicting exfiltration of opcode and argument content, command dictionaries, and procedures; the technique's own precondition is that confidentiality is weak or absent.

  • EXF-0003.02Downlink ExfiltrationST0008
    mitigates
    moderate

    SDLS downlink encryption defeats demodulate-and-extract of spacecraft-to-ground frame content (real-time telemetry, recorder playbacks, payload products), interdicting exfiltration of mission data over the link.

  • REC-0005EavesdroppingST0001
    addresses
    moderate

    SDLS encryption protects the space-link portion of the eavesdropping surface (RF and optical link confidentiality) but not the terrestrial-network capture the technique also spans, so it governs rather than fully interdicts.

  • SDLS encryption conceals uplink command content, but the technique's dominant value is RF-signature and framing or timing reconnaissance (emission designators, symbol rates, Doppler, anti-replay behavior) that survives encryption, so coverage is partial.

  • REC-0005.02Downlink InterceptST0001
    mitigates
    moderate

    SDLS link-layer encryption conceals downlink frame contents (telemetry, event logs, ephemerides, payload data), interdicting the eavesdropper's core objective of harvesting spacecraft state from the RF downlink; low-rate ancillary and beacon channels remain a residual leak.

Cite as SafeMode Space, ccsds-sdls CCSDS-355.0-S03.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.