Art. 84(3)
Mapped SPARTA techniques (24)
Techniques referencing this article
84(3)'s only-authorized-devices rule applies to crosslink and bus participants — preventing masqueraded peer identities from being honored.
84(3)'s only-authorized-devices rule extends to internal bus participants — limiting which on-board nodes can replay or inject historical traffic.
84(3)'s only-authorized-devices rule governs which sources can issue raw hardware commands — preventing maintenance/test interfaces from accepting unsanctioned actor traffic.
84(3)'s only-authorized-devices rule governs which sources can issue memory-load commands — preventing unauthorized writes via the command path.
84(3)'s only-authorized-devices-communicate rule governs internal-bus participants — preventing forged frames from being honored regardless of identifier validity.
84(3)'s authorized-devices rule governs sensor gateways — limiting which sensor sources can write into estimation/control pipelines.
84(3)'s only-authorized-devices-communicate rule applies to all command/control surfaces; out-of-band channels need the same authentication discipline as primary TT&C.
84(3)'s only-authorized-devices rule governs which subsystems can write to payload comms channels — preventing host-bus data from being injected into payload-customer downlinks.
Crosslink-borne traffic from a compromised neighbor must be filtered via the only-authorized-devices-communicate-with-control-systems rule under 84(3) — the canonical defense against trusted-neighbor abuse.
84(3)'s only-authorized-devices-communicate rule applies regardless of whether the path is primary or secondary — backup channels need the same authentication discipline.
Secondary on-board receivers must obey 84(3)'s only-authorized-devices-communicate rule even when activated under safing or maintenance modes.
Docking/OSAM interfaces that push firmware, load tables, or transfer files are controlled-system interfaces under 84(3) — only-authorized-devices governance must apply at the mechanical/electrical bridge.
Hosted-payload command sets that traverse the host bus must obey 84(3)'s only-authorized-devices-communicate rule — payload-host gateway processors are the boundary the obligation applies to.
Rogue external entities are the canonical case 84(3)'s only-authorized-devices-communicate-with-control-systems rule defends against — any external transmitter outside the approved set must be filtered.
Adversary-fielded ground stations transmitting mission-compatible signals are exactly what 84(3)'s only-authorized-devices rule excludes.
Adversary spacecraft emitting crosslink-compatible signals or relaying user traffic must be filtered by 84(3)'s only-authorized-devices rule on inter-satellite links.
When user-plane messages traverse gateways into control or management planes, 84(3)'s only-authorized-devices rule governs which user terminals can reach control systems.
Auxiliary devices (USB, removable media, peripherals) that ingest data into mission systems are 'devices' under 84(3)'s only-authorized-devices rule — auto-ingest of tainted media must be governed accordingly.
84(3)'s only-authorized-devices rule applies to host-payload bridges — limiting which host subsystems can issue commands or write to the hosted payload.
Hosted payload command sets traversing the host bus must obey 84(3)'s only-authorized-devices-communicate rule at the gateway processor.
84(3)'s only-authorized-devices-communicate rule directly defends against bus participants forging message IDs or impersonating bus controllers.
Crosslink hopping between vehicles is precisely the only-authorized-devices scenario 84(3) defends — crafted traffic from a compromised neighbor must be filtered.
Visiting-vehicle docking interfaces (umbilicals, firmware push channels) must obey 84(3)'s only-authorized-devices-communicate rule.
Launch-vehicle umbilicals and EGSE networks must obey 84(3)'s only-authorized-devices rule; tight integration timelines are not an exemption.