Art. 85(2)
Mapped SPARTA techniques (32)
Techniques referencing this article
Cryptographic-mode manipulation (primary: Art. 85(1)/(3)) cascades to 85(2)'s key lifecycle — generation, use, and rotation discipline limits adversary ability to flip to attacker-favored profiles.
Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to DE-0003.09, but key lifecycle does not interdict clock-source biasing; authenticated time distribution would be the interdicting mechanism.
Masquerading (primary: Art. 85(1)/(3)) cascades to 85(2) — key lifecycle policy ensures masquerading-relevant keys (signing/MAC) follow secure generation/storage/rotation.
Replay (primary: Art. 85(1)/(3)) cascades to 85(2) — anti-replay counters and key rotation are part of the key lifecycle policy.
85(2)'s key lifecycle policy includes counter management and key rotation — limiting the operational window in which captured commands can be replayed against extant keys.
85(2)'s key lifecycle policy can prevent downgrade-via-key-substitution by enforcing per-mission key versioning and counter discipline.
Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to clock manipulation, but does not interdict time-source manipulation; authenticated time distribution would interdict.
Spoofing parent (primary: Art. 85(1)/(3)) cascades to 85(2) — key lifecycle includes counter discipline against spoofed-input acceptance.
Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to EX-0014.01, but key lifecycle does not interdict time-source spoofing; authenticated time distribution would be the interdicting mechanism.
Side-channel attack (primary: Art. 85(1)) cascades to 85(2) — key rotation limits the value of keys recovered through side channels.
Replay exfiltration (primary: Art. 85(1)/(3)) cascades to 85(2) — counter discipline within key lifecycle limits the operational window for replay.
Side-channel exfiltration parent (primary: Art. 85(1)) cascades to 85(2) — key rotation discipline limits the value of side-channel-recovered keys.
Power-analysis attacks (primary: Art. 85(1)) cascade to 85(2) — key rotation cadence limits how many traces an attacker can amass against a single key.
EM-leakage attacks (primary: Art. 85(1)) cascade to 85(2) — key rotation limits exposure window.
Timing attacks (primary: Art. 85(1)) cascade to 85(2) — periodic key rotation limits the window for statistical timing recovery.
Signal interception (primary: Art. 85(1)/(3)) is mitigated by 85(2)'s key rotation — limiting the operational window in which intercepted material can be decrypted.
Uplink interception (primary: Art. 85(1)/(3)) is mitigated by 85(2)'s key lifecycle — counter and key rotation discipline limits replay/clone potential of captured material.
Downlink exfiltration (primary: Art. 85(1)) is mitigated by 85(2)'s key rotation — limiting how much intercepted downlink content remains decryptable per key.
Proximity TEMPEST/EMSEC exfiltration (primary: Art. 85(1)) cascades to 85(2) — key lifecycle discipline limits exposure window from proximity capture.
Compromised-partner exfiltration (primary: Art. 85(1)) is mitigated by 85(2) — partner-segment key rotation limits cross-organization compromise impact.
Use of stolen signing keys to issue malicious patches directly attacks the cryptographic-key lifecycle 85(2) places on the operator — secure generation, storage, and distribution disciplines limit signing-key exposure.
SDR compromise (primary: Art. 85(1)) cascades to 85(2) — when SDR compromise touches crypto material, key lifecycle discipline (signed waveform updates, rotation) is the operator-side control.
Crosslink-via-compromised-neighbor (primary: Art. 85(1)/(3)) cascades to 85(2) — crosslink key lifecycle limits the window during which a compromised neighbor's keys remain valid.
Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to compromise-emanations, but limits leaked-key value rather than interdicting the side-channel extraction; physical shielding and power masking are the actual mitigation (the Sprint D IA-0005.01 call).
On-orbit-update pipeline compromise (primary: Art. 85(1) signed updates) cascades to 85(2) — signing-key lifecycle is the operator-side discipline that limits malicious-update insertion.
Rogue-external-entity (primary: Art. 85(3)) cascades to 85(2) — proper key lifecycle ensures only authorized identities hold valid keys.
Rogue ground station (primary: Art. 85(3)) cascades to 85(2) — key-lifecycle discipline ensures rogue stations cannot acquire valid keys through stale or improperly disposed material.
Rogue spacecraft (primary: Art. 85(1)) cascades to 85(2) — crosslink/proximity key lifecycle limits rogue-vehicle ability to present valid credentials.
Replacing cryptographic keys directly attacks the lifecycle 85(2) places on the operator — secure generation, storage, distribution, and disposal disciplines must include controls on rekey command authorization itself.
Cryptographic-key acquisition from operator-controlled sources (compromised ground systems, repositories, contractor channels) directly attacks the lifecycle 85(2) places on the operator — generation, use, storage, distribution, and disposal disciplines limit key exposure.
85(2)'s cryptographic-key lifecycle policy governs the protection of key types and lifecycles that REC-0001.03 reconnaissance seeks to enumerate.
Cryptographic-key acquisition by adversaries directly attacks the lifecycle (generation, use, storage, distribution, disposal) that 85(2) places on the operator.