Art. 85(1)
Mapped SPARTA techniques (34)
Techniques referencing this article
Cryptographic-mode manipulation directly attacks the cryptographic concept 85(1) requires the operator to define — including which algorithms, modes, and key profiles are valid for the mission.
Masquerading defeats authentication — 85(1)'s cryptographic concept defines the authentication mechanisms (telecommand MACs, station-fingerprint resistance, crosslink auth) that defeat impersonation.
85(1)'s cryptographic concept must define anti-replay handling (counters, timetags, freshness windows) — the core protection against the EX-0001 family.
Disabling/bypassing encryption directly attacks the cryptographic concept 85(1) requires the operator to define — null-cipher fallbacks, downgrade attacks, and library substitutions are the failure modes the obligation must guard against.
Spoofing attacks input authenticity; 85(1)'s cryptographic concept defines the authentication mechanisms (TT&C MACs, crosslink auth, sensor source verification) that defeat spoofed inputs.
Side-channel attacks recover secrets via physical byproducts; 85(1)'s cryptographic concept must include constant-time, masked, and emanation-resistant implementations to defeat passive and active side channels.
85(1)'s cryptographic concept must include anti-replay handling (counters, timetags, freshness windows) — the core protection against replay.
Side-channel exfiltration is defeated by the cryptographic concept 85(1) requires — including constant-time, masked, and emanation-resistant implementations.
DPA/CPA-resistant crypto implementations (masking, randomization, power-balanced cores) are part of the cryptographic concept 85(1) requires the operator to define.
EM-leakage countermeasures (TEMPEST shielding, harness routing, decorrelation) are part of the cryptographic concept 85(1) places on the operator.
Traffic-analysis defenses (constant-rate transmission, padding) are within the cryptographic concept 85(1) scopes — not just confidentiality of payload but also of patterns.
Constant-time implementations of MAC verification and crypto routines — required to defeat timing attacks — are part of the cryptographic concept 85(1) places on operators.
Art. 85(1)'s cryptographic concept is crypto-domain-relevant to thermal side-channels, but does not interdict the thermal emanation; thermal-balancing physical design is the actual mitigation.
Signal interception across RF, optical, and ground-network paths is defeated by the cryptographic concept 85(1) requires the operator to define for confidentiality of mission traffic.
85(1)'s cryptographic concept governs uplink-side authentication and encryption design — limiting both content disclosure and the value of session-structure leaks.
Downlink interception captures real-time telemetry, recorder playbacks, and payload products; 85(1)'s cryptographic concept must cover downlink confidentiality where operator risk assessment requires it.
Proximity TEMPEST/EMSEC collection of near-field RF, optical/IR, and conducted emissions defeats confidentiality — 85(1)'s cryptographic concept must include constant-time, masked, and emanation-resistant implementations.
End-to-end encryption (rather than relying on partner-segment trust) is part of the cryptographic concept 85(1) requires — limiting partner-side compromise impact.
Art. 85(1)'s cryptographic concept is domain-relevant to SDR-mediated crypto, but the generic concept names no mechanism interdicting SDR compromise itself.
85(1)'s cryptographic concept must cover crosslink protocols including authentication of inter-satellite traffic — defeating crafted-traffic-from-trusted-neighbor attacks.
Art. 85(1)'s cryptographic concept is crypto-domain-relevant to compromise-emanations, but does not interdict the side-channel extraction; physical shielding and masked implementations are the actual mitigation (the Sprint D IA-0005.01 call).
Update-image authentication relies on cryptographic signing — 85(1)'s cryptographic concept must cover signed-update verification end-to-end from build to flight.
85(1)'s cryptographic concept must define authentication for crosslink and proximity-link contexts so that a rogue spacecraft cannot present itself as a trusted neighbor.
Compromised allied ground infrastructure presenting itself as the source of communications is an authentication-bypass scenario; 85(1)'s cryptographic concept must defeat it through end-to-end auth.
Stealing mission-critical data is the canonical confidentiality breach 85(1)'s cryptographic concept addresses — encryption at rest and in transit limits exfiltration value.
85(1)'s cryptographic concept must define authentication on inter-satellite links — defeating crafted-traffic-from-trusted-neighbor scenarios.
The cryptographic concept that 85(1) requires the operator to define is exactly the artifact (algorithms, modes, key types, anti-replay windows, link-layer protections) reconnaissance against cryptographic algorithms targets — its existence and protection are the cyber resilience measure.
Art. 85(1)'s cryptographic concept is domain-relevant to the authentication scheme REC-0003.02 reconnoiters, but defining the crypto concept does not interdict reconnaissance of its details; information classification would.
Eavesdropping on TT&C and payload links is the canonical case 85(1)'s cryptographic-concept obligation addresses — the operator must define crypto mechanisms specifically to defeat passive interception.
The cryptographic concept under 85(1) defines the crypto posture (algorithms, modes, anti-replay) on the uplink that defeats eavesdropping-derived attack capability.
Downlink eavesdropping captures housekeeping/payload data; 85(1)'s cryptographic concept must cover downlink confidentiality where the operator's risk assessment requires it.
Crosslink eavesdropping is within 85(1)'s scope — the cryptographic concept must consider all space-segment links including inter-satellite paths.
Art. 85(1)'s cryptographic concept is domain-relevant to active-scanning recon, but RF emissions are observable regardless of crypto; emission discipline and LPI waveforms (signal-domain) would interdict it.
Safe-mode indicators leak through RF emissions; 85(1)'s cryptographic concept can extend to telemetry encryption that obscures mode-bit information from passive observers.