eu-space-act

Art. 85(1)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (34)

Techniques referencing this article

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    direct

    Cryptographic-mode manipulation directly attacks the cryptographic concept 85(1) requires the operator to define — including which algorithms, modes, and key profiles are valid for the mission.

  • DE-0004MasqueradingST0006
    addresses
    high
    direct

    Masquerading defeats authentication — 85(1)'s cryptographic concept defines the authentication mechanisms (telecommand MACs, station-fingerprint resistance, crosslink auth) that defeat impersonation.

  • EX-0001ReplayST0004
    addresses
    high
    direct

    85(1)'s cryptographic concept must define anti-replay handling (counters, timetags, freshness windows) — the core protection against the EX-0001 family.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    high
    direct

    Disabling/bypassing encryption directly attacks the cryptographic concept 85(1) requires the operator to define — null-cipher fallbacks, downgrade attacks, and library substitutions are the failure modes the obligation must guard against.

  • EX-0014SpoofingST0004
    addresses
    high
    direct

    Spoofing attacks input authenticity; 85(1)'s cryptographic concept defines the authentication mechanisms (TT&C MACs, crosslink auth, sensor source verification) that defeat spoofed inputs.

  • EX-0015Side-Channel AttackST0004
    addresses
    high
    direct

    Side-channel attacks recover secrets via physical byproducts; 85(1)'s cryptographic concept must include constant-time, masked, and emanation-resistant implementations to defeat passive and active side channels.

  • EXF-0001ReplayST0008
    addresses
    high
    direct

    85(1)'s cryptographic concept must include anti-replay handling (counters, timetags, freshness windows) — the core protection against replay.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    Side-channel exfiltration is defeated by the cryptographic concept 85(1) requires — including constant-time, masked, and emanation-resistant implementations.

  • EXF-0002.01Power Analysis AttacksST0008
    addresses
    high
    direct

    DPA/CPA-resistant crypto implementations (masking, randomization, power-balanced cores) are part of the cryptographic concept 85(1) requires the operator to define.

  • EXF-0002.02Electromagnetic Leakage AttacksST0008
    addresses
    moderate
    direct

    EM-leakage countermeasures (TEMPEST shielding, harness routing, decorrelation) are part of the cryptographic concept 85(1) places on the operator.

  • EXF-0002.03Traffic Analysis AttacksST0008
    addresses
    moderate
    direct

    Traffic-analysis defenses (constant-rate transmission, padding) are within the cryptographic concept 85(1) scopes — not just confidentiality of payload but also of patterns.

  • EXF-0002.04Timing AttacksST0008
    addresses
    high
    direct

    Constant-time implementations of MAC verification and crypto routines — required to defeat timing attacks — are part of the cryptographic concept 85(1) places on operators.

  • EXF-0002.05Thermal Imaging attacksST0008
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is crypto-domain-relevant to thermal side-channels, but does not interdict the thermal emanation; thermal-balancing physical design is the actual mitigation.

  • EXF-0003Signal InterceptionST0008
    addresses
    high
    direct

    Signal interception across RF, optical, and ground-network paths is defeated by the cryptographic concept 85(1) requires the operator to define for confidentiality of mission traffic.

  • EXF-0003.01Uplink ExfiltrationST0008
    mitigates
    moderate
    direct

    85(1)'s cryptographic concept governs uplink-side authentication and encryption design — limiting both content disclosure and the value of session-structure leaks.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    high
    direct

    Downlink interception captures real-time telemetry, recorder playbacks, and payload products; 85(1)'s cryptographic concept must cover downlink confidentiality where operator risk assessment requires it.

  • EXF-0005Proximity OperationsST0008
    addresses
    moderate
    direct

    Proximity TEMPEST/EMSEC collection of near-field RF, optical/IR, and conducted emissions defeats confidentiality — 85(1)'s cryptographic concept must include constant-time, masked, and emanation-resistant implementations.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    End-to-end encryption (rather than relying on partner-segment trust) is part of the cryptographic concept 85(1) requires — limiting partner-side compromise impact.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is domain-relevant to SDR-mediated crypto, but the generic concept names no mechanism interdicting SDR compromise itself.

  • 85(1)'s cryptographic concept must cover crosslink protocols including authentication of inter-satellite traffic — defeating crafted-traffic-from-trusted-neighbor attacks.

  • IA-0005.01Compromise EmanationsST0003
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is crypto-domain-relevant to compromise-emanations, but does not interdict the side-channel extraction; physical shielding and masked implementations are the actual mitigation (the Sprint D IA-0005.01 call).

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    direct

    Update-image authentication relies on cryptographic signing — 85(1)'s cryptographic concept must cover signed-update verification end-to-end from build to flight.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    high
    direct

    85(1)'s cryptographic concept must define authentication for crosslink and proximity-link contexts so that a rogue spacecraft cannot present itself as a trusted neighbor.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    direct

    Compromised allied ground infrastructure presenting itself as the source of communications is an authentication-bypass scenario; 85(1)'s cryptographic concept must defeat it through end-to-end auth.

  • IMP-0006TheftST0009
    addresses
    high
    direct

    Stealing mission-critical data is the canonical confidentiality breach 85(1)'s cryptographic concept addresses — encryption at rest and in transit limits exfiltration value.

  • 85(1)'s cryptographic concept must define authentication on inter-satellite links — defeating crafted-traffic-from-trusted-neighbor scenarios.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    high
    direct

    The cryptographic concept that 85(1) requires the operator to define is exactly the artifact (algorithms, modes, key types, anti-replay windows, link-layer protections) reconnaissance against cryptographic algorithms targets — its existence and protection are the cyber resilience measure.

  • REC-0003.02Commanding DetailsST0001
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is domain-relevant to the authentication scheme REC-0003.02 reconnoiters, but defining the crypto concept does not interdict reconnaissance of its details; information classification would.

  • REC-0005EavesdroppingST0001
    addresses
    high
    direct

    Eavesdropping on TT&C and payload links is the canonical case 85(1)'s cryptographic-concept obligation addresses — the operator must define crypto mechanisms specifically to defeat passive interception.

  • The cryptographic concept under 85(1) defines the crypto posture (algorithms, modes, anti-replay) on the uplink that defeats eavesdropping-derived attack capability.

  • REC-0005.02Downlink InterceptST0001
    addresses
    high
    direct

    Downlink eavesdropping captures housekeeping/payload data; 85(1)'s cryptographic concept must cover downlink confidentiality where the operator's risk assessment requires it.

  • REC-0005.03Proximity OperationsST0001
    addresses
    moderate
    direct

    Crosslink eavesdropping is within 85(1)'s scope — the cryptographic concept must consider all space-segment links including inter-satellite paths.

  • REC-0005.04Active Scanning (RF/Optical)ST0001
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is domain-relevant to active-scanning recon, but RF emissions are observable regardless of crypto; emission discipline and LPI waveforms (signal-domain) would interdict it.

  • Safe-mode indicators leak through RF emissions; 85(1)'s cryptographic concept can extend to telemetry encryption that obscures mode-bit information from passive observers.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.